On September 9, 2026, Governor Gavin Newsom signed the California AI audit law — two companion bills making California the first state to require independent, third-party audits of AI systems and to license the people who perform them. It closes a gap regulators have worried about for years: nobody outside the AI labs themselves has been formally verifying their own safety claims.
The California AI Audit Law: Two New Bills Explained
The California AI audit law is really two separate pieces of legislation working together. Senate Bill 813, authored by Senator Jerry McNerney, creates a framework for designating “independent verification organizations” — outside groups authorized to formally assess whether an AI system or model complies with state law. Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan, does the licensing side of the job: it sets up a public AI Auditor Registry, requires auditors to register with the state, and holds them to real standards of independence and integrity — no auditing a company you’re about to go work for, no financial stake in the outcome.
Neither bill takes effect overnight. Per the bill text itself, AB 1405 gives the state’s Government Operations Agency until January 1, 2029 to stand up the registry, and SB 813’s framework only becomes operative once AB 1405 is in force — this is the rulebook getting written, with enforcement arriving over the next few years.
Why Newsom Signed It Now
The timing wasn’t random. In his signing statement, Senator McNerney pointed to a specific trigger: “Just this week we learned that the most powerful AI systems teamed with AI agents pose real threats to humanity.” That’s a pointed reference to the kind of frontier-model safety concerns that have been piling up all year, as AI systems get paired with autonomous agents capable of taking real-world actions on their own. The pace at which AI has been adopted — faster than the internet, faster than smartphones — has left very little runway for anyone outside the labs to independently check the work.
This isn’t California’s first move here. The state signed the nation’s strongest AI safety law, SB 53, in 2025, requiring frontier developers to publish their own safety frameworks. SB 813 and AB 1405 add the missing second half: an outside party actually checking whether those self-published claims hold up, rather than letting AI companies grade their own homework.
What the New Rules Actually Require
Strip away the legislative language and the California AI audit law adds a few concrete new pieces to how AI oversight works in the state:
- A public registry of licensed AI auditors — searchable on the state’s website, so anyone can verify an auditor is legitimate before trusting their findings
- Independence requirements — auditors can’t accept employment with a company they’re actively auditing, and can’t have a financial interest that could bias their findings
- Whistleblower protections — auditors and their employees can’t be retaliated against for flagging misconduct during an audit
- A signed, dated audit report — every covered AI audit has to produce a report confirming it followed the law’s actual procedures, not just a vague “looks fine” sign-off
- Enforcement teeth — violations can get an auditor removed from the registry and referred to the Attorney General
That last point matters for anyone evaluating AI vendors going forward: once this registry exists, “independently audited” will mean something specific and checkable in California, not just a marketing phrase attached to a system whose real behavior nobody outside the company has actually verified. It’s the same accountability gap that’s driven scrutiny of AI-generated content more broadly — the ethics questions around AI output have always circled back to who, if anyone, is checking the work.
Not Everyone’s on Board: Industry Pushback
The law has real critics. The Business Software Alliance (BSA), a trade group representing major enterprise software and AI companies, argued in August that SB 813 and AB 1405 “put the cart before the horse” — creating a California-specific audit regime before the technical standards needed to support real audits actually exist. BSA wants national and international standards bodies to lead this work instead, warning that a patchwork of state-by-state AI audit rules adds unnecessary complexity for companies deploying AI across state lines.
That tension — oversight now versus standards first — is the same one playing out around the usage limits AI companies have been tightening this month. Each time a major AI player unilaterally pulls back capacity or access, it’s a reminder that these companies still make the calls about how their own systems get checked — which is exactly the discretion this law tries to take out of their hands.
What to Watch Next
For most people using AI tools day to day, nothing changes yet — the registry doesn’t open until 2029, and the independent-verification framework won’t kick in before then either. But a few things are worth tracking as this plays out:
- Whether other states start drafting similar audit-and-registry frameworks, following California’s usual role as the first mover on AI regulation
- How the Government Operations Agency defines a “covered AI audit” in its rulemaking — that definition will decide how much of the AI industry the law actually reaches
- Whether federal regulation ever arrives to replace this state-by-state approach, which is the outcome Newsom himself explicitly called for in his signing statement
California has spent three years building toward this — from Newsom’s 2023 executive order through 2024’s deepfake and watermarking laws to 2025’s frontier-model transparency law — and the AI audit law is the next deliberate step, not a one-off reaction. Whether it becomes the national model or a cautionary tale about state-by-state fragmentation is the real story to watch over the next few years.
One thought on “California AI Audit Law: The Nation’s First AI Auditor Registry, Explained”
Comments are closed.