Listen to this post: California Signs SB 813 and AB 1405, Creating the First State AI Auditor Registry

Last updated: 11 September 2026. Figures and quotes below are sourced to primary publications, linked inline.
The 60-second version
- On 9 September, Governor Gavin Newsom signed SB 813 and AB 1405, creating the first state-level framework in the US for independently verifying and auditing AI systems.
- SB 813 (authored by Sen. Jerry McNerney) sets up Independent Verification Organizations (IVOs) that assess AI systems against state law. AB 1405 (authored by Asm. Rebecca Bauer-Kahan) creates a state registry: from 2029, only registered auditors may legally perform a “covered AI audit” in California.
- Neither bill mandates that any specific company get audited. They build the certification and registry infrastructure that other laws can plug into — SB 813’s framework must exist by 1 January 2028, AB 1405’s registry by 1 January 2029.
- Scope reaches well past frontier labs: any organisation that takes an off-the-shelf model and uses it to screen job applicants, price insurance, or make another decision that materially affects people can be pulled into a covered audit once one is required.
- OpenAI and Anthropic both publicly backed the bills — support that critics have flagged as reason for scrutiny, though it may equally reflect a preference for a predictable verification market over a regulator with pre-approval power.
Key dates and numbers
| Date / figure | What it refers to |
|---|---|
| 2025 | SB 53, the Transparency in Frontier Artificial Intelligence Act, becomes law — requires frontier developers to publish safety frameworks and report critical incidents, but drops an earlier mandatory-independent-audit requirement |
| 9 September 2026 | Newsom signs SB 813 and AB 1405 |
| 1 January 2028 | Deadline for California’s Government Operations Agency to stand up the IVO certification framework under SB 813 |
| 1 January 2029 | AB 1405’s auditor registry goes live; conducting a “covered AI audit” without registration becomes unlawful |
| 2 | Frontier labs (OpenAI and Anthropic) that publicly announced support for the bills on signing day |
| 0 | State or sector laws currently on the books that actually require a “covered AI audit” — the trigger AB 1405’s registry depends on doesn’t yet exist |
What the two laws actually do
SB 813 and AB 1405 are companion bills, easy to blur together, but they do different jobs. SB 813 creates Independent Verification Organizations — expert panels approved by the state to assess whether an AI system complies with California law, focused on named risk areas: cyberattacks, chemical, biological, radiological or nuclear (CBRN) weapons, mass manipulation (what the bill calls “malign persuasion”), and AI systems that act with significant autonomy or attempt to exfiltrate themselves. An earlier draft went further, granting developers certified by an IVO a rebuttable presumption that they exercised “reasonable care” if sued over an AI-related injury — a real litigation shield. Lawmakers struck that provision during the amendment process, after opposition from groups including Consumer Attorneys of California, and it is not in the version Newsom signed. As enacted, IVO certification is a compliance signal a company can point to — not a legal defence.
AB 1405 is narrower: it decides who is allowed to call themselves an AI auditor in California. From 2029, anyone conducting a “covered AI audit” must be on a state registry, with independence rules modelled on financial-accounting standards — no financial stake in the audited company, no auditing your own prior work, and no assigning an auditor to a job where they held material responsibility for the system under audit at the company being audited within the preceding 12 months. It is licensing for a profession that barely exists yet.
The detail most coverage is skipping: this doesn’t mandate a single audit
Here is the nuance separating a careful read from a quick one. AB 1405’s registry only becomes operative “once another law requires an audit” — and as of this week, no such requirement exists on the books. SB 813 builds the certification apparatus; AB 1405 builds the licensing apparatus for who can use it. Together, they’re best understood as plumbing: infrastructure that future laws, from Sacramento or a sector regulator, can connect to and require use of. Some coverage of the signing read as though a new audit obligation had just landed on AI companies. It hasn’t, not yet. What has changed is that once California, or another law referencing this framework, does mandate an AI audit, there’s now a defined, licensed pool of people allowed to conduct it, with enforced independence rules behind them.
The scope surprise: this isn’t only a frontier-lab law
The framing in most headlines — “California regulates AI” — undersells how far the trigger for a covered audit reaches. It isn’t restricted to companies building frontier models. Any organisation that takes an off-the-shelf model, including a general-purpose LLM licensed from a third party, and deploys it to screen job applicants, price an insurance policy, or make another decision inside a “critical service” that materially affects a person, falls within the same scope as the model’s original developer. A mid-sized HR-tech vendor running résumé screening on a licensed API is, on paper, in the same regulatory conversation as the lab that trained the underlying model.
That’s a different posture from the EU’s approach to platform accountability, where Brussels recently designated ChatGPT a “Very Large Online Search Engine” under the DSA and regulates specific large platforms directly. California is instead building a verification market that any deploying company can be pulled into by the nature of the decision it automates, not by its size or supply-chain position. For readers who publish or deploy vendor AI tools rather than build models, that’s the detail worth sitting with — this law was written with your compliance department in mind too, not only OpenAI’s or Google DeepMind’s.
Why frontier labs said yes — and what that says about the bill’s teeth
OpenAI and Anthropic both announced support for SB 813 and AB 1405 around signing day, prompting some coverage — Gizmodo framed it outright as “industry-approved” regulation — to question whether rules the regulated companies happily endorse can really constrain them. Bauer-Kahan anticipated exactly that scepticism: “We cannot expect industry to simply grade its own homework; third-party auditors are essential,” she said of the bill’s purpose. It echoes a point this site has made before — OpenAI’s own account of reward-hacking agents on Hugging Face was, after all, an internal report grading the company’s own incident. The value of an IVO is precisely that it wouldn’t be.
A more mundane explanation has had less coverage than “industry-approved”: predictability. A licensed verification market with known, stable standards is easier for a lab’s legal team to plan around than the alternative most frontier labs spent 2026 trying to avoid — a regulator with direct pre-approval power over releases. The more interesting unanswered question is whether either lab plans to actually seek IVO certification once the framework exists in 2028, or whether backing it was simply the cheaper way to shape a bill they couldn’t stop.
It’s worth reading this alongside Anthropic’s recent disclosure of a fourth Claude cybersecurity breach, where it brought in METR — an independent AI evaluation nonprofit — for an eight-week external review because an internal assessment wasn’t considered sufficient alone. That’s close to what SB 813’s IVOs are meant to formalise industry-wide. Anthropic reaching for that voluntarily, before state law required it, is a reasonable data point for the bills’ underlying theory.
How this compares with the frontier labs’ own safety promises
California’s bet is a market-based verification layer, similar in structure to financial auditing, rather than a regulator that pre-clears models before release. That fits a pattern this site covered when OpenAI’s Astra crossed the “critical” cyber-capability threshold under the company’s own preparedness framework, with Google and Anthropic following under their own, self-assessed thresholds. An operational IVO framework is one of the more plausible paths to someone other than the lab checking that self-assessment — but it’s a 2028 plan for a 2026 problem.
It’s worth situating this inside the broader debate this site has tracked about whether governments can regulate AI without falling behind it. These bills don’t try to freeze a fast-moving technology in statute; they build a licensing profession future rules can point to. Whether that’s a strength or a way of deferring hard decisions to 2028 rulemaking isn’t yet answerable.
What this means if you build, deploy, or publish with AI
- Map your California exposure now, not in 2028. If you deploy any third-party AI model in hiring screening, insurance-adjacent decisioning, or another “critical service” affecting Californians, start documenting which models make which decisions. An audit-ready paper trail is cheaper built gradually than assembled under deadline pressure once a triggering law lands.
- Ask your AI vendors about certification plans. Whether a model your product relies on eventually carries IVO certification could still matter to you as a downstream deployer for procurement and reputational reasons — though be aware the certified law carries no automatic litigation shield; an earlier draft’s liability presumption for certified developers was removed before Newsom signed it.
- Don’t assume “frontier lab” language means this is someone else’s problem. Scope is written around the decision automated, not company size. A publisher using a licensed model for ad-targeting or moderation should read the “critical services” language once implementing regulations appear.
- Watch the rulemaking, not just the bill text. The Government Operations Agency has roughly 15 months to define IVO standards and a further year for the auditor registry. The framework’s real strength, or its gaps, will be set there — largely outside this week’s headlines.
What we still don’t know
A fair amount here is genuinely open. No penalty schedule for conducting an unregistered “covered audit” after 2029 has been published in any source reviewed for this piece. It isn’t yet clear which law — state or sector-level — will be first to actually trigger a mandatory covered audit under AB 1405’s definition; none does today, and no confirmed plan to create one has surfaced. How courts and litigants will actually treat IVO certification as evidence of care is untested — no IVO has been certified yet, and, notably, lawmakers removed the bill’s original statutory liability presumption before passage, so certification carries no automatic weight in court. And whether other states adopt California’s model, or wait for the federal rules Newsom explicitly called on Washington to write, remains unclear — Congress has not, as of publication, answered with comparable legislation.
FAQ
Does this law require companies to get their AI systems audited?
Not by itself. The bills build certification and registry infrastructure; a company only has to undergo an audit once a separate law specifically requires it, and none currently does.
Which companies are actually covered?
Far more than frontier labs. Any organisation deploying an AI system — including a licensed, off-the-shelf model — in hiring screening, insurance pricing, or another “critical service” that materially affects people can fall into scope once a covered-audit requirement exists.
When does this actually take effect?
SB 813’s verification framework must exist by 1 January 2028. AB 1405’s auditor registry goes live 1 January 2029, after which performing a covered audit without registration becomes unlawful.
Why did OpenAI and Anthropic support a bill meant to add oversight of AI companies?
Both publicly backed it. That could reflect genuine alignment with independent verification, a preference for a predictable certification market over a regulator with pre-approval power, or an attempt to shape a bill they couldn’t block. Coverage hasn’t gone beyond the companies’ own statements to settle which is closest to the truth.
Sources
- Office of Governor Gavin Newsom — “Governor Newsom Signs First-in-the-Nation AI Safeguards to Protect Californians” (9 September 2026)
- California Legislative Information — AB 1405 bill text and status
- Office of Senator Jerry McNerney — “Sen. McNerney and Asm. Bauer-Kahan Partner on AI Safety Standards and Verification”
- Transparency Coalition — “California Gov. Newsom Signs Two Bills to Create Nation’s First AI Auditing Framework”
- byteiota — “California AB 1405: AI Audit Law Puts Developers in Scope”
- Conformance AI — “California AI Audit Bills: SB 813 and AB 1405 Explained”
- Startup Fortune — “Newsom Signs AB 1405 Creating California’s First AI Auditor Registry”
- Gizmodo — “Newsom Signs AI Industry-Approved AI Regulation Bills Into Law in California”
