Insights · AI Assurance
California just put AI auditors on the map.
Two bills signed on 9 September build the legal infrastructure for independent AI assurance. No audit is mandatory yet — which is exactly why the next three years matter.
Most coverage of California’s 9 September AI package has focused on the registry. That is the visible part. The consequential part is quieter: the state has written definitions for what an AI audit is, who is qualified to perform one, and what independence means in that context. Once that machinery exists, future regulation does not have to invent an assurance mechanism. It can point at one.
This brief covers what the two laws establish, the dates that actually bind, and why I think organizations should treat this as a three-year runway rather than a 2029 problem.
The package
What was actually signed
On 9 September 2026, Governor Newsom signed Senate Bill 813, authored by Senator Jerry McNerney, and Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan. The state describes the pair as a first-in-the-nation framework for independent third-party evaluation and audit of AI systems.
They address different halves of the same problem.
| Law | What it establishes | Operative date |
|---|---|---|
| SB 813 | A framework for Independent Verification Organizations — bodies recognised as competent to assess AI systems for compliance with state law, with criteria set by the Government Operations Agency | First IVOs certified by 1 Jan 2028 |
| AB 1405 | A public AI Auditor Registry, with standards for auditor independence, transparency and integrity, registration numbers, and a misconduct reporting mechanism | Registry live by 1 Jan 2029 |
SB 813 defines a covered AI audit around assessing whether an AI system or model meets the safety, efficacy, reliability or security requirements necessary to comply with applicable state law. The independence conditions are specific: compensation cannot depend on the findings, the assessor must remain operationally and managerially independent from the organization being assessed, and it must retain control over its own conclusions and recommendations.
One provision deserves more attention than it has received. The legislation directs the agency to align its criteria, where practical, with national and international audit and assurance standards. That is the sentence that moves AI assessment toward the evidentiary discipline of financial and security auditing rather than leaving it as a bespoke consulting product.
Timing
The two dates that matter
Coverage has settled on January 2029, because that is when the prohibition bites: after that date an unregistered person or organization generally cannot offer, sell or conduct a covered AI audit.
The earlier date is the more useful one. The Government Operations Agency must establish criteria and certify the first class of Independent Verification Organizations by 1 January 2028. For anyone who intends to perform AI assessments in California — or to buy them — that is when the shape of the market becomes visible: what qualifications count, what methodologies are recognised, what evidence an assessment is expected to produce.
Scope
What the laws do not do
This is where I would be careful, because several outlets have described the package as a mandate and it is not one.
Neither law requires an organization that develops or deploys AI to obtain an independent audit. They build the infrastructure California can use when some other law requires an assessment. The most relevant existing statute, the Transparency in Frontier Artificial Intelligence Act, requires developers to disclose their use of third-party assessments within a published safety framework — but it does not compel third-party review.
So the honest summary is: the state has defined who may audit, and set standards for how, without yet requiring that anyone be audited.
It is also worth noting who supported the bills. Both OpenAI and Anthropic publicly backed them, and that has drawn the obvious criticism — that the regulated parties helped shape the rules. Readers should weigh that. It does not make the framework less real, but it does suggest the independence provisions will be tested by practice rather than settled by statute.
The direction of travel
Governance is becoming an assurance problem
For several years, enterprise AI governance has largely meant policy. Is there an AI policy? Which models are approved? Can staff paste confidential material into public tools? Who signs off a new use case?
Those are necessary. They are also the easy half. The harder question arrives with an assessor: can you demonstrate that the controls work?
Suppose an organization states that it security-tests its AI systems. The follow-up questions write themselves. Which systems. How often. Against which threats. Using what methodology. Who defines an acceptable result. Who approves exceptions. Where is the evidence. What happens when the model changes. Can the results be reproduced. Was the tester independent of the team that deployed the system.
At that point AI governance stops being a drafting exercise. It becomes an evidence problem — and evidence has to be generated as you go. It cannot be reconstructed after the fact, which is the argument against waiting for 2029.
The evidence an AI assessment will ask for
- Inventory and ownership. What AI operates here, who owns each system, who owns the risk.
- Classification. Risk tier and role per system, with the criteria written down.
- Impact assessment. Effects on the people the outputs are applied to, not only on the organization.
- Testing. Pre-deployment evaluation, bias testing, red-team results, with dates and methods.
- Monitoring. Production metrics, thresholds, and what happened when a threshold was breached.
- Change control. Records of model, version and provider changes, and what was re-tested after each.
- Supplier terms. Audit rights, model-change notice, incident notification, evidence availability.
- Human oversight. Who can override an output, and evidence that they can and do.
First finding
Your inventory becomes the first finding
You cannot provide assurance over systems you cannot identify. That sounds obvious until you try to produce the list.
AI now enters organizations through SaaS platforms, productivity suites, developer tooling, APIs, cloud services, support platforms, security products, embedded copilots and workflows built by staff without anyone procuring anything. A list of approved foundation models is not an inventory. It is a list of the AI you know about.
A usable inventory answers more than which products were purchased: which business processes depend on each system, what data it can reach, what decisions it can influence, which third party supplies the model, who owns it, and what happens when the provider changes the model underneath you.
Practical effect. For many organizations the first significant finding in an AI assessment will not be an exotic model-safety failure. It will be that nobody can produce a complete list. That is a solvable problem, but only with lead time.
Both directions
Independence cuts both ways
The independence provisions are aimed at the assurance market, and they describe a conflict that market currently tolerates: the same firm designing a governance program, selecting the controls, implementing them, testing them, and then attesting that they work.
We would not accept that arrangement in financial audit. AI should not be the exception.
The practical consequence for buyers is that vendor due diligence has to mature alongside. “Do you perform AI audits” stops being a sufficient question. The useful ones are about methodology, technical competence, financial relationships, parallel consulting engagements, and whether the resulting findings would survive regulatory scrutiny.
Which is to say you will shortly be performing third-party risk management on the third party assessing your AI risk.
Action
What I would be doing now
I would assume that consequential AI systems will face independent assurance requirements within a few years, arriving from whichever direction moves first — regulators, enterprise customers, contract terms, insurers, or a board that has read about this package.
- Build a defensible inventory with named owners. Not a department. A person.
- Map AI controls into existing processes — security, privacy, risk, procurement — rather than creating a separate governance island that no other function feeds.
- Identify where evidence is generated and retained, and test whether you could reproduce it for someone external.
- Govern model and provider changes. An assessment of one model version means little if it is silently replaced six months later.
- Review AI supplier contracts for audit rights, security documentation, incident and model-change notification, and evidence availability.
- Apply real scrutiny to assurance vendors, including your own advisors.
References
Primary sources for this brief
- Office of Governor Gavin Newsom, 9 September 2026 — signing announcement for SB 813 and AB 1405
- California Senate Bill 813 (McNerney) — Independent Verification Organizations; covered AI audit definition; independence conditions
- California Assembly Bill 1405 (Bauer-Kahan) — AI Auditor Registry; registration, transparency and integrity standards
- California Transparency in Frontier Artificial Intelligence Act — third-party assessment disclosure obligations
FAQ
Common questions
Do we now need an independent AI audit?
No. Neither law requires an organization to obtain one. They establish who may perform covered AI audits and to what standard, so that the mechanism exists when another law, a contract or a customer requires an assessment.
We are not in California. Does this reach us?
Directly, the framework is Californian. Practically, California has repeatedly set the template other states and enterprise buyers adopt, and assurance expectations travel through contracts long before they travel through statutes. The evidence an IVO would ask for is the same evidence ISO/IEC 42001 certification and EU AI Act conformity assessment require.
Should we wait until the registry opens in 2029?
The gap between now and then is the point. Assurance evidence is generated by operating controls, not by assembling documents afterwards. An organization that starts in 2028 will be reconstructing two years of decisions it did not record.
How does this relate to ISO/IEC 42001?
Closely. SB 813 directs alignment with recognised audit and assurance standards where practical, and an AI management system audited against ISO/IEC 42001 produces much of the same evidence base — inventory, impact assessment, lifecycle controls, supplier management, monitoring. Organizations already pursuing certification are further along than they may realise.
Who owns this internally?
In practice it lands across legal, privacy, security and the business owner of each system, which is why it stalls. Someone has to own the inventory and the evidence chain specifically, with authority to require both from the functions that generate them.
Where does your program stand today?
Our free assessment scores your AI governance against the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, and shows the gaps an assessor would find first. Twenty to thirty questions, about ten minutes, no signup.
Related reading
This brief reflects published information as of 13 September 2026 and describes legislation signed on 9 September 2026. Implementing criteria, agency guidance and operative dates may change as the Government Operations Agency develops the framework — verify the current bill text and agency guidance before relying on them. Advisory content, not legal advice.
AI GRC Advisory · Insights · AI Governance Brief 01 · 13 Sep 2026
