California sets rules and a registry for independent AI auditors
September 10, 2026
With SB 813 and AB 1405, California is building a first-of-its-kind state infrastructure for independent AI assessment. The laws set auditor standards, but not universal review of every model.
What this is about
California Governor Gavin Newsom signed two laws for independent assessment of AI systems on September 9, 2026. Senate Bill 813 creates a framework in which qualified independent organizations can assess AI systems and models for compliance with California law. Assembly Bill 1405 establishes a state registry for AI auditors and requires standards for independence, transparency, and integrity.
This matters because technical evaluations are often commissioned, scoped, or published by the developer itself. California is now building public infrastructure around the evaluators: Who may conduct an assessment, which conflicts must be visible, and which minimum requirements apply? The laws do not automatically require an audit of every AI model. They first create the institutional framework for more credible independent assessment.
What the new rules actually do
SB 813 establishes a process for independent verification organizations. These bodies are intended to have the capability to evaluate risks from AI systems and assess compliance with state law. AB 1405 complements that structure through registration and requirements for the auditors themselves. The state is separating two questions: What must an assessment accomplish, and who is trustworthy enough to perform it?
The official announcement connects the laws to California’s existing framework. SB 53, adopted in 2025, requires certain developers of highly capable models to publish safety frameworks, report defined critical incidents, and protect whistleblowers. The new laws add external assessment infrastructure to those transparency rules. They neither replace SB 53 nor create comprehensive federal regulation.
Why it matters
An audit is only as credible as its independence, access, and method. An evaluator that receives nearly all its funding from one provider, sees only prepared demonstrations, or cannot publish critical findings offers little public assurance. Registry and integrity rules can at least make such dependencies visible and reviewable.
The approach can also influence practice beyond California. Many leading AI companies develop and operate systems in the state. Common criteria for evaluators may therefore enter contracts, procurement, and internal safety programs even where a particular test is not legally mandatory. KION’s reporting confirms the central elements of the two laws, while Mission Local illustrates why supporters consider earlier rules such as SB 53 incomplete.
In plain language
Imagine the safety inspection for a car. It is not enough for the manufacturer to test its own vehicle and display a green check mark. Trust grows when people know who oversees the garage, which instruments it uses, which ties it has to the manufacturer, and how defects are recorded. California is building parts of that inspection infrastructure for AI, but not an identical mandatory test for every model.
A practical example
A fictional provider wants to deploy a powerful model in a sensitive California service. It hires a registered evaluation organization. The evaluator first discloses revenue sources and possible conflicts of interest. A secured team then gets access to a defined model version, tests cyber capabilities, deceptive behavior, and safeguards, and records the limits of its sample.
Suppose 120 tests produce six serious failures. The report must not turn that into a general five-percent failure rate for everyday use, because the cases were deliberately difficult. It can still document which safeguard failed, whether the provider reproduced the issue, and which retest is needed. This example illustrates a possible evaluation workflow; the laws do not prescribe these particular test numbers or methods.
Scope and limits
First, SB 813 and AB 1405 do not create an automatic safety test for every model and application. Their reach and effect depend on when other rules, agencies, or contracts require an independent assessment.
Second, a registered evaluator can still be wrong. Models change through updates, system prompts, tools, and deployment environments. A sound report on version A does not guarantee that version B or another integration will behave the same way.
Third, independence remains difficult. Evaluators need funding and deep access, while providers need to protect trade secrets and sensitive security information. Too little access produces superficial audits; too much poorly secured access creates new risks. Registries, disclosure, and methodological standards are therefore necessary foundations, not proof that a specific AI system is safe.
SEO & GEO keywords
California, SB 813, AB 1405, AI audit, independent AI evaluators, Gavin Newsom, AI auditor registry, frontier models, AI regulation, SB 53, model evaluation, algorithmic accountability
💡 In plain English
California is defining how independent AI evaluation organizations can be recognized and AI auditors registered. That improves the conditions for credible oversight, but it does not mean every model is now automatically audited.
Key Takeaways
- →Governor Gavin Newsom signed SB 813 and AB 1405 on September 9, 2026.
- →SB 813 creates a framework for independent organizations that assess AI systems.
- →AB 1405 establishes a registry and integrity standards for AI auditors.
- →The laws complement California’s SB 53 but do not replace comprehensive federal rules.
- →Registration improves transparency but guarantees neither a sound method nor a safe model.
FAQ
Must every AI model in California now be audited?
No. The laws create evaluation infrastructure, registration, and standards. Whether a specific assessment is mandatory depends on other rules and the deployment context.
How do SB 813 and AB 1405 differ?
SB 813 concerns the framework for independent verification organizations. AB 1405 focuses on registry and integrity requirements for AI auditors.
Why are internal tests not sufficient?
Internal teams know a system well but face conflicts of interest. Independent evaluation can challenge assumptions, methods, and findings from outside.
Does a registered evaluator guarantee safety?
No. Registration adds minimum requirements and transparency. Quality still depends on access, methodology, model version, and deployment environment.
Sources & Context
- California Governor: Newsom signs new AI safeguards, September 9, 2026
- California Legislature: Senate Bill 813
- California Legislature: Assembly Bill 1405
- KION: California adopts new AI laws requiring independent audits, assessments
- Mission Local: California’s first AI-safety law did not cover first rogue AI hacks
- OpenAI: The AI policy window is open
- Wikimedia Commons: California State Capitol dome and pediment (CC0)