California Builds AI Auditor Registry Ahead of Federal Action
Two new state laws create a framework for independent AI assessments, though actual audit requirements remain voluntary for now.

California has enacted two laws that lay groundwork for a regulated marketplace of AI auditors, even as the actual requirement to conduct such audits remains voluntary under current state law.
Governor Gavin Newsom signed AB 1405 and SB 813 into law, creating what amounts to a two-tier oversight structure for organizations that assess AI systems. The move comes as federal policymakers signal renewed interest in AI regulation but have yet to pass comprehensive legislation.
A registry without mandates
AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, initiates creation of a state registry for AI auditors. Starting January 1, 2029, auditors conducting "covered AI audits" in California must register and comply with standards covering independence, transparency, and operational requirements. Registered auditors will need to maintain records for 10 years and list relevant certifications alongside standard operating procedures.
The second law, SB 813, tasks California's Government Operations agency with delivering a regulatory framework for independent verification organizations by January 1, 2028. These IVOs represent a second layer of requirements, with qualification standards designed to ensure only credible auditors operate in the market.
Notably, no California law currently mandates that AI developers actually obtain audits. The state's Transparency in Frontier Artificial Intelligence Act requires developers to disclose their use of third-party assessments in public safety frameworks, but stops short of requiring such reviews. Both new laws establish infrastructure for a future where audits may become compulsory.
What auditors will assess remains unclear
Both laws leave substantial questions unanswered about what AI auditors will actually evaluate. SB 813 directs the Government Operations agency to "identify and consider" relevant standards, frameworks, and best practices. AB 1405 requires auditors to use widely recognized standards only "to the extent appropriate standards are available."
This contrasts with Illinois' recent frontier AI law, which includes mandatory independent assessments for certain models and developers, along with its own qualification requirements for verification organizations.
Why it matters
California's approach creates market infrastructure for AI accountability before establishing the accountability requirements themselves. This sequence could allow a mature auditing industry to develop in parallel with evolving technical standards and regulatory frameworks. However, the 27-month timeline to the 2029 registry deadline may prove either generous or inadequate depending on how rapidly AI governance practices solidify. The laws also diverge significantly from the EU AI Act's approach, which mandates conformity assessments for high-risk systems but relies primarily on internal review rather than independent auditors.
OpenAI voiced support for both California laws this week, with Chief Global Affairs Officer Chris Lehane stating the company would back state legislation "until Congress acts." Industry group TechNet, which counts OpenAI as a member, had previously opposed an earlier version of AB 1405, calling it premature given the absence of legal audit requirements.
Details of California's AI auditor framework were first reported by the International Association of Privacy Professionals.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call