Skip to content
Log inRegister

Who Gets to Audit the AI? California Just Started Answering That Question

Dr. Abeer Alshammari · Published 9/19/2026

IntermediateProfessionalsCISOsExecutives

For three years the standard answer to "how do we know this AI system is safe?" has been a document the developer wrote about itself. That answer is now being legislated out of existence, and the mechanism is not a new control framework. It is a market for auditors.

What California enacted

On 9 September 2026, Governor Gavin Newsom signed two bills. Senate Bill 813, authored by Senator Jerry McNerney, establishes a framework for certifying independent verification organisations — third parties with demonstrated expertise and demonstrated independence from AI companies — to assess AI systems and models for safety and risk. Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan, creates a state registry for AI auditors and sets standards for their independence, transparency and integrity.

The two do different jobs. SB 813 defines who is competent to verify. AB 1405 defines who is permitted to audit, and creates the register, the annual fee structure and the misconduct-reporting channel that make that permission revocable. Under AB 1405 as enacted, the Government Operations Agency has until 1 January 2029 to stand the registry up; from that date, an unregistered person may not offer, sell or conduct a covered AI audit.

Nine days later, on 18 September, the Governor issued an executive order directing GovOps to accelerate both implementation timelines and to convene national experts to deliver recommendations within two months. The proposals named in that order are considerably sharper than the statutes themselves: embedding a designated independent verification organisation on-site inside frontier labs to conduct regular audits; requiring that the safety frameworks, transparency reports and risk assessments filed under state law be verified against standards an independent verification organisation deems adequate; advancing an emergency shutoff — a "kill switch" — for frontier models, with the efficacy of that switch verified on an ongoing basis; and updating the definition of a critical safety incident to include loss-of-control events such as the Hugging Face attack.

Disclosure was the old regime. This is assurance.

SB 53, California's 2025 Transparency in Frontier Artificial Intelligence Act, was a disclosure law: publish your safety framework, report specified critical incidents to the state, protect whistleblowers. What arrived this month is different in kind. Bauer-Kahan put the logic plainly in the signing announcement — we cannot expect industry to grade its own homework.

Assurance regimes behave differently from disclosure regimes, and governance teams built only for disclosure will feel the difference in three places.

Independence becomes an auditable attribute of your auditor, not only of your controls. A registry with a misconduct channel and revocable standing means an assessor's file can be challenged by someone other than you. Advisory engagements, equity, staff secondments and multi-year consulting relationships with the same vendor being certified all turn into live questions. This is the conflict-of-interest logic that reshaped financial audit two decades ago, arriving now in model evaluation.

Evidence has to survive being read by someone who is not you. An AI risk assessment written to satisfy an internal committee is a different artefact from one written to be verified by a party with no incentive to agree. Most organisations have the first and assume they have the second. The test is simple: could a competent stranger reproduce your conclusion from your evidence alone, without a conversation?

The binding constraint moves to capacity. California is manufacturing demand for a profession that does not yet exist at scale. Illinois approached the same problem from the other end: its Artificial Intelligence Safety Measures Act, signed in July 2026, mandates annual independent third-party audits for major frontier developers without first defining who may perform them. Taken together, the limiting factor before 2029 will not be regulation. It will be the supply of assessors who are simultaneously technically competent and genuinely independent — and those two qualities tend to be found in the same small group of people who already work for the labs.

Why this reaches organisations outside California

None of this is directly enforceable on an entity in Riyadh, Dubai or Brussels, and it should not be presented internally as though it were. It will still reach them. The EU AI Act already contemplates conformity assessment for high-risk systems; ISO/IEC 42001 already contemplates certified AI management systems. What California adds is the plumbing — a public register, independence criteria, a way to lose your standing — that turns "independently audited" from a marketing phrase into a status someone can check. Procurement functions will start asking for that status well before any regulator requires it of them, for the ordinary reason that checking a register is cheaper than verifying a vendor yourself.

The useful step this quarter is not to wait for a registry that opens in 2029. It is to rehearse once. Take your highest-consequence AI system, hand its risk assessment and evidence pack to someone with no stake in the outcome — an internal audit colleague, a peer from another business unit, an external reviewer — and ask them to verify one safety claim end to end. Whatever that exercise exposes is what a registered auditor will expose later, under a contract, on a deadline, at a considerably higher price.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights