All insights
Industry newsSep 10, 2026Source: California Governor and Legislature

California signs AI audit and independent verification laws

An AI audit report, evidence files, and an independent verification seal beside an outline of California

California Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 on 9 September 2026. Together, the laws create a state framework for independent verification organizations and a registry with conduct rules for people and firms that perform covered AI audits.

The practical change is narrower than a universal AI audit mandate. SB 813 tells the California Government Operations Agency to develop requirements for designated independent verification organizations by 1 January 2028. AB 1405 requires an AI Auditor Registry by 1 January 2029 and, from that date, restricts covered AI audit services to registered auditors. Neither law requires every developer, deployer, or operator of an AI system to commission an audit simply because it operates in California.

What the two laws do

SB 813 defines a covered AI audit as an assessment of controls, processes, or systems needed for compliance with state law. The agency must develop application requirements, criteria for expertise and independence, and procedures for suspending or ending an organization's designation. It must consider conflicts of interest, documentation quality, cybersecurity, technical competence, and recognized standards.

The law also requires stakeholder working groups and annual reports from designated organizations. Those reports must summarize methods and disclose relevant changes to governance policies or funding. Sensitive material may be redacted for trade secret, cybersecurity, public safety, national security, or legal reasons, but the organization must describe the nature and justification of a redaction where permitted.

AB 1405 governs the auditor rather than creating new audit duties for every AI system. By 2029, the registry must publish registration information and accept misconduct reports. Registered auditors must describe the laws under which they conduct covered audits, their relevant credentials, their services, the standards they use, and the basis for claims about the reliability of their methods.

Audit reports gain minimum evidence requirements

For a covered audit, AB 1405 requires a report that identifies scope and objectives, results, supporting documentation, deficiencies, reasonable corrective measures where appropriate, adherence to internal safety protocols, audit limitations, and material evidence or access gaps. The auditor must sign and date a statement that the audit followed the law.

Those requirements matter because an audit conclusion without its evidence boundary can create false assurance. A useful report should show what was examined, what could not be examined, which controls were tested, and why the evidence supports the result. Maetra's guide to AI audit evidence explains the operational records teams can preserve before an assurance request arrives.

Registered auditors must retain core reports and supporting documentation for at least ten years. They must also meet independence and competence standards, avoid auditing their own material work, and protect employees who report suspected noncompliance. Violations can lead to removal from the registry and referral to the Attorney General or another enforcement authority.

What the laws do not require

SB 813 expressly says it does not require an AI developer, deployer, or operator to engage a designated organization or undergo a covered audit as a condition of operating in California. It also says that following an identified standard does not by itself create liability, and state designation does not endorse an AI system or model.

An audit completed under an identified standard may be relevant in a lawsuit alleging harm from an AI system, but it is not conclusive. This distinction is important. Independent review can improve evidence quality, yet it cannot replace the duties attached to a specific product, sector, or use.

AB 1405 likewise applies to audits required under another California law. It builds the market rules for those audits rather than imposing a new audit on every AI system. Teams should therefore map the laws and regulations that actually apply to their systems before assuming the registry creates a direct duty for them.

What teams should prepare now

The implementation dates leave time, but the evidence model is clear. Organizations likely to undergo a covered audit should identify owners for controls, record system and model versions, retain test results, document known limitations, and preserve the connection between each conclusion and its source evidence.

Audit buyers should also review independence before an engagement begins. A firm that designed or operated the control under review may not provide the objective assessment the law expects. Procurement records should capture conflicts, qualifications, scope, access, methods, retention, and the handling of confidential material.

The guide to proving AI controls work offers a useful starting point: evidence should link the stated policy to a tested control and a current operational result.

Maetra analysis

California is moving assurance from an informal promise toward a regulated evidence practice. The strongest operational signal is not the word audit. It is the requirement to expose scope, methods, limitations, gaps, and the basis for results.

That favors teams that maintain current evidence continuously instead of assembling screenshots shortly before review. Inventory, control ownership, test history, exceptions, and change records should be connected while the system operates. When an auditor arrives, the organization can then show what changed, which evidence is current, and where uncertainty remains.

The laws still depend on future agency criteria and implementation. Organizations should track that work without treating designation or registration as a guarantee of system safety. Independent verification can strengthen accountability, but the quality of the result will continue to depend on access, methods, evidence, and honest limits.

Sources

California AI lawAI auditsindependent verificationAI compliance