> ## Content Index
> Fetch the complete content index at: https://unhyd.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# California AI Audit Laws Set New Rules for Auditors
- URL: https://unhyd.com/article/california-ai-audit-laws-new-rules-auditors/
- Published: 2026-09-10T13:08:14.000Z
- Updated: 2026-10-01T19:38:59.000Z
- Description: Two newly signed California laws build oversight around AI audits, but they do not require every developer to submit a model for review.
- Author: Ryan Lenett
- Tags: AI, Technology, #unhyd-import, #sidebar-popular-posts

California’s new **AI audit laws** are designed to make the people who assess artificial-intelligence systems more visible, more accountable and more independent. On September 9, Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405, two measures that create complementary oversight structures around AI auditing.

The key distinction is easy to miss. The laws do *not* require every company that develops, deploys or operates an AI system in California to hire an auditor. Instead, they set rules for auditors and create a state process for recognizing qualified independent verification organizations. That makes the package less a universal audit mandate than an attempt to build an assurance infrastructure that future laws, regulators and buyers could use.

## What California’s AI audit laws actually do

[AB 1405](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill%5Fid=202520260AB1405&ref=unhyd.com), authored by Assemblymember Rebecca Bauer-Kahan, directs the Government Operations Agency to establish an online AI Auditor Registry no later than January 1, 2029\. From that date, a person may not offer, sell or conduct a covered AI audit unless registered with the agency.

A covered audit is defined narrowly: an assessment of the internal controls, processes or systems needed for an AI system or model to comply with state law. Registered auditors must provide information about their services, relevant certifications, applicable laws, operating procedures and standards. The law also requires audit reports to identify their scope, results, deficiencies, limitations and supporting evidence.

Independence is a central part of the measure. An auditor cannot assess work it materially designed, developed, implemented or operated for the client. It also cannot take on an audit when a financial, business, employment or other relationship would reasonably be expected to impair its independence or objectivity. The agency can investigate alleged violations, remove an auditor from the registry and refer matters to the attorney general or another enforcement authority.

[SB 813](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill%5Fid=202520260SB813&ref=unhyd.com), authored by Senator Jerry McNerney, addresses a related question: who is qualified to assess AI risk? It directs the Government Operations Agency, by January 1, 2028, to develop a process for designating independent verification organizations, or IVOs. Applicants will need to show competence, describe the benchmarks and methods they propose to use, and meet agency criteria covering technical expertise, risk assessment and conflicts of interest.

The law requires the agency to publish its criteria and consult stakeholders, including auditors, academics, developers, deployers, labor and civil-society groups. Designated organizations must later report annually on their standards, methods, governance policies and relevant funding sources. Crucially, SB 813 says that it does not itself create liability for failing to meet a standard, require a company to engage an IVO, or require an IVO to perform a covered audit as a condition of registration.

## Why the distinction matters

AI audits are often discussed as though the term describes one settled procedure. It does not. An audit might examine whether a model meets a legal requirement, whether a developer’s internal controls work as represented, whether a system creates a discrimination risk, or whether operational safeguards are adequate. The usefulness of an audit depends on its scope, the evidence available to the assessor, the reviewer’s independence and what follows when a problem is found.

California’s package focuses on those preconditions. AB 1405 establishes public registration, reporting and conduct rules for auditors. SB 813 gives the state a route to identify organizations with relevant risk-assessment expertise and to develop criteria in public. Neither statute turns a favorable audit into a state endorsement of an AI system or model.

That separation is important for readers and businesses alike. A registered auditor is not necessarily an official seal of approval; an audit is not necessarily a guarantee that a system is safe; and an audit framework is not the same as a legal requirement that every AI product be reviewed. The new laws begin with the credibility of the assessor rather than prescribing a single technical test for every system.

The timing also places California in a broader governance debate. On the same day, OpenAI publicly endorsed both bills while arguing for federal, capability-based AI safety rules. Separately, the UN human rights chief recently called for agreed AI red lines and independent verification—a proposal Unhyd examined in its [coverage of the governance debate](https://unhyd.com/article/un-rights-chief-ai-governance-red-lines/). California’s statutes do not resolve how a national or international audit regime should work. They do, however, establish state-level machinery around the people and organizations that may be asked to provide assurance.

## What to watch next

The next test is implementation. The Government Operations Agency must translate broad statutory principles—competence, independence, methodology and conflict management—into usable application requirements, registry procedures and designation criteria. Stakeholder working groups under SB 813 will shape those choices, while AB 1405 leaves room for the agency to adopt regulations necessary to carry out the registry.

For companies that already commission AI assessments, the practical question is whether their providers will need to register, how they will document independence and how their reports will change. For policymakers, the larger question is whether a credible pool of auditors and IVOs can emerge before new obligations ask them to assess more systems.

**California’s AI audit laws are therefore a governance foundation, not a final verdict on AI safety.** They set deadlines for building oversight of assessors. Whether that oversight becomes an effective protection for people will depend on the standards the state adopts, the evidence auditors can access and the laws that may eventually require their work.

## Sources

- [California Legislative Information: SB 813, Independent verification organizations](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill%5Fid=202520260SB813&ref=unhyd.com)
- [California Legislative Information: AB 1405, Artificial intelligence: auditors: registration](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill%5Fid=202520260AB1405&ref=unhyd.com)
- [Office of Governor Gavin Newsom: announcement of the September 9 signings](https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/?ref=unhyd.com)
- [OpenAI: September 9 policy statement](https://openai.com/index/ai-policy-window/?ref=unhyd.com)