Compliance2026-09-298 min read

California Now Regulates the People Who Audit AI. Your Problem Is Whether They Can See Anything

On 9 September 2026 California signed SB 813 and AB 1405, which create designated AI verification organisations and, from 1 January 2029, a registry that auditors must join before conducting audits required by state law. The rules are about auditors, but the practical burden lands on the companies being audited and on the AI vendors whose evidence they depend on.

Governor Newsom signed two bills on 9 September 2026 that get less attention than the chatbot and employment laws signed alongside them, but that will shape how every future California AI audit is done. SB 813 tells the Government Operations Agency to set criteria, by 1 January 2028, for designating independent verification organisations, or IVOs, that assess AI models and systems. Applicants have to disclose their qualifications, the benchmarks, metrics and testing tools they plan to use, and how they manage conflicts of interest. AB 1405 goes further on the audit side: by 1 January 2029 the agency must publish an AI Auditor Registry, and from that date a person may not offer, sell or conduct a covered AI audit, meaning one required to show compliance with California law, without being registered.

It is worth being precise about what these laws do not do. Neither bill requires any company to be audited. SB 813 says plainly that there is no obligation to use a designated organisation, and a completed audit is relevant to, but not conclusive of, any later legal proceeding, so it is not a liability shield. The laws build the profession and its rules. The obligation to be audited comes from other statutes, and right now the clearest one is SB 1119, signed a day later, which requires operators of companion chatbots to complete an independent child safety audit by 1 January 2029 or before first offering the product. Expect more California laws to point at this registry as the mechanism, the same way financial regulation points at registered accounting firms.

The independence rules are the part that will change how audits are bought. Registered auditors cannot take fees that depend on their findings, must be operationally and managerially independent of the company they audit, cannot assess a system they materially designed or operated, and cannot put staff on an engagement covering an area those people were responsible for in the previous 12 months. Breaches lead to removal from the registry and possible referral to enforcement. Commentators have already noted the gaps: the audited company still pays the auditor at market rates, there is no fine schedule for auditor misconduct, and nothing forbids an auditor from using the audited company’s own AI tools to run the tests, only disclosing it. Those gaps will matter to regulators later. For you, the 12 month cooling off rule matters now if you plan to hire the consultancy that built your AI governance program to also audit it.

The more important requirement for founders is in the report itself. A registered auditor has to describe the scope, objectives, findings, deficiencies and remedies, and also any limitations, including material gaps in evidence, information, systems or access. That clause turns missing evidence into a published finding. If your chatbot runs on a model from OpenAI, Anthropic or Google, and the auditor cannot get the model documentation, evaluation results or operational logs needed to test a claim, the report will say so. As one analysis in PYMNTS put it, a vendor that withholds that material leaves the assessment worth little. Your audit outcome now depends partly on contracts you signed with suppliers, which is a vendor risk problem, not a model safety problem.

This is where existing frameworks help, and where they stop. ISO 42001 already expects you to document intended use, data, testing and monitoring for each AI system, and to manage third party and customer relationships across the AI life cycle in Annex A. SOC 2 CC9.2 expects you to assess and manage risk from vendors and business partners, and ISO 27001 Annex A 5.19 to 5.22 cover supplier agreements and monitoring. None of these will make you audit ready under California law on their own, because a covered audit tests compliance with a specific statute, not with a management system. But an organisation with an AI register, a model inventory and supplier evidence already filed in Vanta, Drata or Secureframe will spend its audit budget on the substantive questions rather than on reconstructing what it runs. Our ISO 42001 guide covers how to build that register as evidence.

For product teams, the dates are closer than they look. Registration starts on 1 January 2029, which is the same day the SB 1119 chatbot audit deadline lands, and the pool of registered auditors on that day will be small. Firms that want to be on the registry will spend 2028 applying under criteria the agency has not written yet. If you operate a companion or general purpose chatbot that minors can reach, assume audit capacity will be tight and priced accordingly, and plan to engage an auditor during 2028 on the understanding that they must be registered before the audit is conducted. If you sell AI into California businesses, expect customers to start asking in security questionnaires whether your product has been through a registered audit, well before any law requires one of you.

The procurement fix is the one to start now. Add clauses to AI vendor agreements that give you, and an independent auditor acting for you, reasonable access to model cards, system cards, evaluation results, incident history and the logs relevant to your deployment, under confidentiality. Ask vendors whether they will support a third party audit under California law and how, and record the answer in your vendor register. Where a vendor refuses, record that as a risk with an owner, because the auditor will record it as a limitation. This is the same argument we made about subprocessors and model gateways earlier this year: the evidence you need about an AI system usually sits with someone else, and the time to secure access is at signature, not during fieldwork.

A short list for this quarter. Inventory every AI system you offer to people in California and note whether any current or pending state law requires an independent audit of it. Check whether the firm that designed or runs your AI governance program could later be your auditor, and separate those roles now if you might need a covered audit. Update vendor agreements and your AI vendor questionnaire with audit access and evidence retention terms. Make sure your AI register, test records and incident log are kept in a form an outside party can read without your engineers narrating it. Our policy templates include an AI acceptable use policy and a vendor management policy you can extend with these clauses, and the compliance readiness checklist will show where AI evidence is missing.

Our view is that SB 813 and AB 1405 are the start of AI assurance becoming a licensed activity, in the way financial audit is, and that the interesting fights will be about access rather than method. Auditors will converge on test methods quickly. What they cannot fix is a client that does not know what it runs or a supplier that will not open the box. Companies that treat evidence access as a contract term today will get useful audits in 2029. Companies that do not will pay a registered auditor to write, in a report a regulator can read, that they could not check.

CaliforniaSB 813AB 1405SB 1119AI auditAI governanceISO 42001SOC 2ISO 27001vendor riskthird party assuranceVantaDrata

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

Loading comments...

Add a comment

Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.

0/4000 · plain text · links are held for review

More from the blog