7 min read · 1,837 words
This article was written with AI. It was drafted from the sources it cites and checked against the full text of those sources before publishing. How we make articles
California Writes AI Auditor Rules Before Any Audit Is Required
September 9, 2026: Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 (Daily 49er), a pairing that is itself the story because one bill builds a framework while the other builds a list. His office promoted both as “first-in-the-nation” AI safeguards (Office of Governor Newsom), and together they create California’s new AI audit rules: a statewide registry of AI auditors, plus standards for independence, transparency, and integrity.
The two bills ban no model and order no audit themselves (Yahoo News); they certify the profession that would perform one. The next day, Newsom signed SB 1119, known as Adam’s Law, which does order audits: companion-chatbot operators must arrange an initial independent child-safety audit by January 1, 2029, or before first making a chatbot available, whichever comes later (PYMNTS). Full registry operations are not required until January 1, 2029, the date from which auditors conducting covered AI audits cannot legally operate in California unregistered (IAPP).
Meanwhile, the companies the regime would examine endorsed it, with Anthropic backing the package and OpenAI announcing support in the hours before the signing (Gizmodo). Two years earlier, in late September 2024, Newsom vetoed Senate Bill 1047 (Mission Local), a contrast that raises the question of why regulated parties who rarely cheer the hiring of their own referees applauded this time (Gizmodo).
Sacramento Is Licensing a Profession, Not a Product
Signing came on September 9, 2026 (Office of Governor Newsom), and reading the machinery rather than the headlines reveals that Senate Bill 813 directs the Government Operations Agency to establish criteria for independent verification organizations that assess AI systems and models (PYMNTS), with Senator Jerry McNerney of Pleasanton authoring the bill and Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan of Orinda, establishing the registry itself while spelling out auditor qualifications and reporting obligations (Daily 49er). StateScoop’s split, citing Newsom’s office, is the cleanest summary: SB 813 creates the framework for verification organizations, AB 1405 creates the registry and its independence standards (StateScoop).
Standards, as described in the coverage, govern independence, transparency, and integrity (IAPP), and one published rule assigns a number: an employee generally cannot audit an area for which that person held material responsibility at the client during the prior 12 months (PYMNTS), reducing the substance to relationships, paperwork, and dates.
The runway runs from signing on September 9, 2026 (Office of Governor Newsom) to required full registry operations on January 1, 2029 (Yahoo News).
Between the signing ceremony and the first morning California’s auditor registry must be operational, these two laws ban no model and order no audit (Yahoo News).
Why the Audited Applauded
Gizmodo’s headline renders the verdict on the package as “AI industry-approved,” noting that Anthropic endorsed the bills and OpenAI announced support hours before Newsom signed (Gizmodo), with Chris Lehane, OpenAI’s chief of public affairs, writing that “We’ve reached a new chapter in AI capabilities, and that demands a new chapter for AI policy” (Gizmodo). OpenAI’s own policy statement listed SB 813 first among four supported bills, backing it as “overall infrastructure for independent safety assessments” (OpenAI).
Contrasting two years back, Newsom vetoed SB 1047 in late September 2024, a defeat that capped a season in which, as SB 1047’s author, Senator Scott Wiener, recalled to Mission Local, “We were called ‘doomers’ and ‘decels,’ and told that the risks we warned about were science fiction and not a serious risk we would see anytime soon” (Mission Local). Our read: opposition worked once, and endorsement may work better, because a defeated bill can come back stronger while an adopted one can crowd out tougher successors.
The bill’s sponsor was Fathom, an independent nonprofit that developed and championed the independent verification model, and it billed SB 813 as the country’s first state framework for independent verification organizations that test AI safety claims (Yahoo Finance). Andrew Freedman stated in the announcement that “The power of the independent verification model is that it lets independent, qualified experts assess the risk of AI capabilities, and it keeps pace with the technology instead of freezing a single test into law” (Yahoo Finance). The verification model is Fathom’s (Yahoo Finance); the organizations that will verify under it are not due to be certified until January 1, 2028 (TechTimes).
What did the labs buy with their applause for these AI audit rules? A licensing system for referees, an endorsement on the record (Gizmodo), and an auditor registry that does not have to be fully operational until January 1, 2029 (Yahoo News). Cheap at the price.
The Verifier’s Tab: Who Paid for the Inquiry the Coverage Cites
Mandatory channel first: a year after the veto, Newsom signed Wiener’s follow-up, SB 53, which placed transparency requirements on frontier companies (Mission Local). When the OpenAI/Hugging Face agent incident arrived, Jonathan Snow, deputy director for the Homeland Security Division of the Governor’s Office of Emergency Services, said the hack “did not meet the threshold” for reporting under SB 53 (Mission Local). At the same Aug. 10 hearing, Assemblymember Rebecca Bauer-Kahan said: “It’s unclear to date if anyone is actually complying with SB 53” (Mission Local).
“It's unclear to date if anyone is actually complying with SB 53”
— Assemblymember Rebecca Bauer-Kahan
Voluntary channel next, and the example the coverage cites is telling: The Next Web reported that METR’s inquiry into the Hugging Face incident ran on compute credits paid by OpenAI (The Next Web), so on the only large worked example available, as The Next Web put it, the tool, the subject and the funder were the same company (The Next Web).
Put that case beside the independence standards. PYMNTS describes regulator-set criteria and a 12-month cooling-off on prior client responsibilities (PYMNTS), and TechTimes describes the party the framework certifies as one with no financial or operational dependence on the company being evaluated (TechTimes). The completed inquiry the coverage cites consumed about $400,000 in API credits that OpenAI supplied for the inquiry into its own agents (The Next Web). Whether free compute from the company under review counts as the financial dependence the framework rules out is the question the first designations will have to answer.
Call that the Verifier’s Tab: in the one worked example so far, the audit’s operating cost, compute metered by the auditee, ran through the one party the auditor is meant to be independent of (The Next Web).
Brussels Built a Panel. Sacramento Built a Market.
Steelman first, because the sequencing defense is real: you cannot compel audits before credible auditors exist since mandates without a profession produce sham audits, and Brussels made a related wager with the EU AI Act’s Article 68 scientific panel building union-level expert infrastructure, a comparison The Next Web draws explicitly (The Next Web); Newsom’s office pitched California’s move as leadership while calling “on the federal government to do its part” (Office of Governor Newsom), and as Newsom put it, “The concerns raised in recent incidents reinforce what California has long recognized: artificial intelligence holds extraordinary promise, but it must be developed and deployed with meaningful safeguards to protect the public” (StateScoop).
Put the three side by side. Brussels is building a union-level expert panel under the EU AI Act (The Next Web). California is setting criteria for independent verification organizations (PYMNTS). Washington, by the governor’s telling, has yet to do its part (Office of Governor Newsom). And in the one completed inquiry the coverage cites, the compute came from the company under investigation (The Next Web). Certifying verifiers first is defensible; the one worked example shows why the question of who pays matters before the first certificate is issued.
Nor is the runway to January 1, 2029, when the auditor registry becomes fully operational (Yahoo News), a build schedule for a profession that does not exist. METR has already run an inquiry into OpenAI’s Hugging Face incident (The Next Web), confirming the field is not empty, and the clock is a grace period.
Three Questions No Vendor Deck Answers
Until these AI auditing rules produce an actual registry, your use is the contract, and TechTimes counts frontier labs and hiring tools inside the new scope (TechTimes), so if your ATS runs on a large model, your vendor shortlist just met these questions, which you should ask in writing before signature:
- Which statute designates you? From January 1, 2029, covered auditors cannot legally operate in California unregistered (IAPP). The state must certify the first verification organizations by January 1, 2028 (TechTimes), so ask for the certificate, not the promise.
- Which independence standard do you meet? “Independent,” backed by no named standard, is a logo. Make the vendor quote the rule, cooling-off period included.
- Who pays for eval compute? Demand the line item. If the answer is the model’s developer, your company has taken on a Verifier’s Tab of its own, with your logo on the report.
Audit-the-auditor checklist. Score your vendor before signing:
– Designation status answered with a date, not a mood
– Independence claim tied to a named standard, cooling-off rule quoted back
– Compute funding named in the contract, not the marketing
– Every evaluation in the deck discloses who financed it
Three clean answers: sign with eyes open. Any claim to state certification that the vendor cannot document: walk.
Watch the First Designations
Prediction: By January 1, 2029, the registry’s first designation paperwork is likely to ask about prior employment and financial ties to AI developers; whether it also asks who funded an audit’s compute is the question to watch.
Between September 9, 2026 and January 1, 2029, California’s two audit laws define who gets to audit AI systems and what those auditors must do to qualify, and neither bans a model or orders an audit (Yahoo News); the inquiry the coverage cites was financed, in compute credits, by the company under investigation (The Next Web). So watch the registry’s first designations: if the paperwork asks about equity stakes and past employment but never asks who bought the tokens, the Verifier’s Tab will have gone unasked at the one point where it could be.
References
- California Sets First-In-Nation AI Audit Standards — Daily 49er
- Governor Newsom Signs First-In-The-Nation AI Safeguards — Office of Governor Newsom
- California Just Passed Two Major AI Laws… But They Don’t Ban or Audit a Single Model Yet — Yahoo News
- A View From DC: What Will All These AI Auditors Be Auditing — IAPP
- Newsom Signs AI Industry-Approved AI Regulation Bills Into Law in California, Gizmodo
- California’s First AI-Safety Law Didn’t Cover the OpenAI Hack, Mission Local
- Newsom Signs Legislation Establishing Framework for Third-Party AI Auditors, StateScoop
- California Starts Regulating the People Who Audit AI, PYMNTS
- California SB 813, Independent Verification Organisations, METR, and the EU AI Act Article 68, The Next Web
- The AI Policy Window Is Open. We Need to Act, OpenAI
- California Legislature Overwhelmingly Passes SB 813, Yahoo Finance
- California Signs First US AI Audit Law: Frontier Labs, Hiring Tools Now Scope, TechTimes
