The short version
On September 9, 2026, Governor Newsom signed two bills that make California the first US state to build an official framework and registry for independent AI auditors. SB 813 (Sen. Jerry McNerney) creates certified independent verification organizations that assess AI systems for compliance with state law; AB 1405 (Assemblymember Rebecca Bauer-Kahan) sets up a state registry of AI auditors with standards for independence, transparency and integrity. The scope is broad: not just OpenAI or Anthropic, but any company that uses an off-the-shelf model to screen job applicants, price insurance, or make decisions that materially affect people. For teams that build and ship AI and data systems, this signals a shift from voluntary AI claims to third-party evidence — on a staggered timeline running into 2028–2029.
What California signed
Governor Newsom framed the move plainly: “AI has the potential to improve our lives, but without effective guardrails, it poses significant risks.” The two bills he signed on September 9, 2026 are designed to work as a pair. SB 813, authored by Senator Jerry McNerney (D–Pleasanton), establishes a first-in-the-nation framework for “independent verification organizations” — outside bodies that can formally assess whether an AI system or model complies with state law. AB 1405, authored by Assemblymember Rebecca Bauer-Kahan (D–Orinda), creates a state registry for those AI auditors and sets standards for their independence, transparency and integrity.
Read together, the laws answer a question that has dogged AI governance from the start: who audits the auditors? Plenty of consultancies already offer “AI assessments,” but there has been no shared bar for what qualifies someone to sign off on a high-stakes AI system. California is now defining that bar and backing it with a government registry. The California Government Operations Agency must stand up the certification process and certify the first verification organizations by January 1, 2028, and establish the AI Auditor Registry by January 1, 2029. From that date, unregistered persons are barred from offering, selling or conducting a covered AI audit.
Both Anthropic and OpenAI backed the legislation, which builds on California's 2025 Transparency in Frontier Artificial Intelligence Act (SB 53). That industry support is telling: large developers would rather have a credible, standardized audit regime than a patchwork of ad hoc reviews demanded state by state and customer by customer. For everyone downstream, the practical takeaway is that AI compliance is moving from self-attestation toward independent, credentialed verification — the same trajectory that independent security audits and SOC 2 attestations followed a decade earlier.
Who is actually in scope?
The most important detail is one the headlines often bury: these laws are not just about frontier labs. As one analysis put it, any company that takes an off-the-shelf AI model and deploys it to screen job applicants, price insurance policies, or make other calls that affect people's lives is as much in scope as OpenAI or Anthropic. If you fine-tune a hosted model to rank candidates, or wire a vendor's model into an underwriting flow, the fact that you did not train it does not put you outside the frame.
That is a meaningful expansion of who has to think about AI audits. A mid-size HealthTech or FinTech company that has quietly embedded a third-party model into a consequential decision is exactly the kind of deployer these frameworks are designed to reach. The obligations are not fully switched on yet — the certification and registry machinery has to exist first — but the direction is set, and it is aimed at deployers, not only builders.
Where this fits: Illinois, the EU, and a US audit market
California is not acting in a vacuum. Illinois has already enacted SB 315, the AI Safety Measures Act, which forces the largest AI developers to pair published safety frameworks with annual independent third-party audits. The EU AI Act, whose high-risk obligations began phasing in during 2026, leans on conformity assessments performed through its own notified-body regime. What California adds is the piece the others assume but do not build: a certified, registered profession of AI auditors, with the state defining who is qualified to perform the work.
For teams operating across borders, this is the start of an audit-market layer that will increasingly be referenced in contracts and procurement. A US enterprise buyer that once accepted a vendor's word on model behavior will soon be able to ask for verification from a registered auditor — and once that option exists, it tends to become the expectation. If you already map to EU AI Act conformity or a structured AI governance program, much of the underlying evidence (documentation, testing records, risk assessments) is reusable; what changes is who signs off and against which standard.
What it means for US & EU software teams
For US teams, the near-term risk is not a fine — it is being unprepared when a customer asks for audit-ready evidence. The registry does not go live until 2029, but enterprise procurement moves ahead of statutes. If you deploy AI in hiring, lending, insurance or any decision that materially affects people, assume that by 2027 a serious buyer will want documentation that could withstand an independent review, whether or not the law compels it yet. The teams that treat this as a data-and-documentation problem now will not scramble later.
For EU teams, the signal is convergence. California is building a US counterpart to the conformity-assessment logic already embedded in the EU AI Act, which means a single, well-run AI governance program can increasingly satisfy both. The reusable core is the same on either side of the Atlantic: a maintained inventory of where AI touches consequential decisions, records of how each system was tested and evaluated, documented human-oversight and appeal paths, and a clear owner for each model in production. Build that once, and adapting to California's registered-auditor regime or an EU notified body becomes a mapping exercise rather than a rebuild.
The strategic caution applies everywhere: independent AI audits are becoming a market, and markets reward the prepared. The organizations that come out ahead will be the ones whose AI systems are already legible — documented, tested, and owned — long before an auditor, registered or not, ever knocks.
How to get ahead of AI-audit demand
- Inventory your consequential AI. List every place AI — including fine-tuned or hosted third-party models — touches hiring, credit, insurance, health or access decisions. That inventory is the map auditors and buyers will ask for.
- Know if you are a deployer, not just a builder. Using an off-the-shelf model in a high-stakes decision can put you in scope even though you did not train it.
- Keep testing and evaluation records. Document how each system was validated, what was measured, and what mitigations exist — this is the evidence an independent audit runs on.
- Assign an owner per model. Every production model should have a named human accountable for its behavior, oversight and appeal paths.
- Reuse your EU AI Act or SOC 2 groundwork. Documentation, risk assessments and control evidence map across regimes; do not build parallel stacks.
- Track the 2028–2029 milestones. Watch for the first certified verification organizations (Jan 2028) and the live auditor registry (Jan 2029) so you engage registered auditors, not unqualified ones.
- Prepare for customer questions before the law. Assume enterprise buyers will ask for audit-ready evidence in 2027, ahead of any statutory trigger.
Frequently asked questions
What did California sign into law on September 9, 2026?
Governor Gavin Newsom signed two bills: SB 813, authored by Senator Jerry McNerney, which creates a framework for independent verification organizations to assess AI systems for compliance with state law, and AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, which establishes a state registry for AI auditors with standards for independence, transparency and integrity. Together they form the first US framework for independent third-party AI audits.
Do the California AI audit laws only apply to frontier labs like OpenAI and Anthropic?
No. While frontier developers are in scope, so is any company that takes an off-the-shelf AI model and deploys it to screen job applicants, price insurance, or make other decisions that materially affect people. If you deploy AI in high-stakes contexts in California, you can be pulled into the audit ecosystem even if you did not build the model.
When do the California AI auditor rules take effect?
Implementation is staggered. The California Government Operations Agency must stand up the certification process and certify the first independent verification organizations by January 1, 2028, and establish the AI Auditor Registry by January 1, 2029. Beginning January 1, 2029, unregistered persons are barred from offering, selling or conducting a covered AI audit.
How is this different from the EU AI Act and Illinois's AI audit law?
Illinois's SB 315 mandates annual independent audits for the largest AI developers. California's laws are infrastructure: they define who is qualified to perform AI audits and create a certified, registered profession of AI auditors, while pulling deployers into scope. The EU AI Act requires conformity assessments for high-risk AI but relies on its own notified-body regime. California is building a US-side auditor market that regulated buyers and their customers will increasingly reference.
Sources
Office of Governor Gavin Newsom — Governor Newsom signs first-in-the-nation AI safeguards to protect Californians (September 9, 2026)
CIO Dive — What California's AI auditing bills mean for enterprises (September 2026)
Quartz — California enacts first U.S. laws requiring independent AI audits (September 10, 2026)