California's New AI-Auditor Registry Is Real Infrastructure — With a Three-Year Head Start Built In

SB 813 and AB 1405 separate AI evaluation from compliance auditing and begin defining who is qualified to provide independent assurance — but the laws do not themselves impose a general audit mandate, and mandatory auditor registration does not begin until 2029.
🏛️ California is building the referee before requiring the game
On September 9, 2026, Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405, creating what his office called a “first-in-the-nation framework” for independent organizations assessing AI systems and models.
The headline sounds like California just mandated independent audits of AI.
It didn’t.
What California did may be more institutionally interesting: it started defining who an independent AI auditor is, what independence means, and what professional obligations come with performing an AI audit.
SB 813 creates a framework for Independent Verification Organizations, or IVOs. The California Government Operations Agency will designate organizations that demonstrate expertise in assessing AI risks and the methodologies used to measure them.
AB 1405 creates an AI Auditor Registry and establishes standards around independence, objectivity, competence, disclosure, documentation and conflicts of interest for entities performing covered AI audits.
Neither law creates a universal requirement that AI developers or deployers submit their systems to those auditors.
California is building the referee system first.
🔍 The important thing the laws don’t do
Some early coverage emphasized the potential reach beyond frontier labs. TechTimes focused on applications such as hiring and other consequential decisions, while ByteIota highlighted implications for developers and deployers.
But the final statutory structure is narrower than a blanket AI-audit mandate.
SB 813 explicitly says it does not require an AI developer, deployer or operator to engage an IVO or undergo an audit.
AB 1405 instead regulates who may conduct a “covered AI audit” — an examination of internal controls, processes and systems relevant to compliance with California law.
Beginning January 1, 2029, someone offering, selling or conducting such an audit must be registered.
That distinction matters.
California isn’t yet saying every important AI system must be independently audited.
It is saying something closer to: when California law calls for an AI audit, not everyone gets to call themselves an independent auditor.
⚖️ Audit is not evaluation
This may be the most important idea in the legislation.
AI governance frequently collapses benchmark testing, red-teaming, risk assessment, compliance review and independent assurance into the broad category of “evaluation.”
California is beginning to separate them.
An evaluation asks about the AI system: What can it do? What risks does it pose? Under what conditions does it fail?
An audit asks whether the organization around that system has the controls, evidence and processes necessary to comply with its obligations.
Anthropic explicitly praised this distinction when it endorsed SB 813 and AB 1405 in August.
That separation also connects to a broader problem I’ve been writing about in AI evaluation: better benchmarks tell us more about model behavior, but they do not automatically tell us whether an organization has built reliable governance around that behavior.
You can evaluate a model without auditing the company deploying it.
And you can audit a company’s controls without proving that the underlying model is safe.
Those are different assurance problems.
🧾 The accounting analogy is becoming literal
Assemblymember Rebecca Bauer-Kahan explained the concept to KQED using financial auditing: financial institutions do not simply declare themselves compliant; independent professionals examine the evidence.
AB 1405 imports some of that logic directly.
The law establishes requirements around integrity, objectivity, independence, competence and due care. It recognizes applicable professional-accounting standards, including AICPA standards. Auditors must disclose limitations and evidentiary gaps and retain supporting documentation for at least ten years.
That is more significant than another benchmark requirement.
The law is beginning to define the professional obligations of the person signing the assurance report.
Mature assurance systems depend on exactly this layer.
Financial markets do not operate solely because companies publish financial statements. There are standards governing who may independently examine those statements, what evidence auditors must maintain and what relationships compromise independence.
AI governance has largely lacked an equivalent institution.
California is starting to build one.
🏭 Industry support doesn’t erase the substance
The political framing around these laws diverged sharply.
The Governor’s office calls the legislation “nation-leading” accountability infrastructure.
Gizmodo characterized the same package as “AI Industry-Approved AI Regulation.”
Anthropic publicly endorsed SB 813 and AB 1405 before passage and specifically praised the distinction between audits and evaluations.
Those facts can coexist.
A regulatory framework can establish meaningful infrastructure while also being acceptable to companies that expect to operate inside it.
The better question is what the final law actually requires — and when.
⏳ The three-year runway is real
Startup Fortune highlighted AB 1405’s creation of California’s first AI-auditor registry.
But January 1, 2029 is easy to misunderstand.
That is not the date California suddenly requires every consequential AI system to undergo an independent audit.
It is the deadline for the registry to be operational and the point after which entities conducting covered AI audits must be registered.
SB 813 moves somewhat earlier: GovOps must develop its IVO designation framework by January 1, 2028.
So California has created a three-year institution-building runway.
There is a reasonable administrative argument for that. A credible assurance market requires standards, qualified practitioners, independence rules and procedures before regulators can rely heavily on its conclusions.
But three years is also an unusually long period in AI.
The models, agent architectures and deployment patterns auditors encounter in 2029 may look substantially different from those legislators were debating in 2026.
🧩 Adam’s Law shows how the pieces could connect
The sequencing became clearer one day later.
On September 10, Newsom signed a separate child-safety package including SB 1119, “Adam’s Law,” named for Adam Raine, the 16-year-old whose death after months of conversations with a chatbot helped drive the legislative debate.
SB 1119 requires companion-chatbot operators to conduct child-safety risk assessments and subjects that process to independent auditing.
That illustrates the emerging architecture.
One set of laws can create substantive obligations. Another can define the independent institutions trusted to verify them.
That is much closer to how established regulatory systems work than asking AI companies to grade their own homework.
🎯 The governance question is moving up a layer
For the past several years, much of the AI-safety debate has focused on models and evaluations:
How capable is the model? How dangerous is it? Which benchmark should measure that?
Those questions remain necessary.
But California’s new laws point toward the next institutional problem.
Who is qualified to inspect the evidence? What makes that person independent? What standards govern the audit? What records must be preserved? And who is legally allowed to put their name on the conclusion?
SB 813 and AB 1405 do not solve the AI-auditing problem, and they do not create a universal audit mandate.
What they do is arguably more foundational.
California has started turning “independent AI auditor” from a description into a regulated role.
The audit requirements can come later.
The infrastructure for deciding whom to trust has already started being built.