California Wrote AI Auditing Into Law: What SB 813 and AB 1405 Require
💡 Tool Tip:Cron Expression Generator, Hash Generator, JSON Schema Validator
On September 9, 2026, California Governor Gavin Newsom signed SB 813 and AB 1405, writing the question of who gets to evaluate AI into state law. The Governor's office described it as first-in-the-nation standards for third-party audits and independent assessments of AI systems: a framework for independent verification organizations, plus a state registry for AI auditors. The reason engineers should read the statutes rather than the press release is that the legislation turns the word audit into concrete obligations - who is eligible to assess, what is being assessed, and what must be left behind as evidence. Those details become your team's evidence obligations for years.
Two bills, one framework: independent verification and an auditor registry
1. What Was Signed: Two Bills, Two Mechanisms
SB 813, authored by Senator Jerry McNerney (D-Pleasanton), establishes a first-in-the-nation framework for independent verification organizations that can assess AI systems and models for compliance with state law. AB 1405, authored by Assemblymember Rebecca Bauer-Kahan (D-Orinda), creates a state registry for AI auditors and sets standards for their independence, transparency, and integrity. McNerney's statement is worth keeping: he described the signing as codifying one of the primary recommendations of the governor's blue-ribbon panel on AI, and added that the same week produced evidence that the most powerful AI systems teamed with AI agents pose real threats. Bauer-Kahan put the rationale plainly: we cannot expect industry to grade its own homework. Note what the bills do not do - they ban no model and cap no parameters. They build infrastructure, not a prohibited list.
-- 1. What counts as a covered AI audit (AB 1405, Sec. 11549.80)
-- "Covered AI audit" = an audit that assesses internal controls, processes,
-- or systems implemented for an AI system or model that are necessary for
-- compliance with state law.
SELECT system_id,
control_id,
state_law_citation, -- the law this control exists for
evidence_uri, -- where the proof lives, not a screenshot
last_tested_at,
test_result
FROM ai_control_evidence
WHERE state_law_citation IS NOT NULL
ORDER BY state_law_citation, system_id;2. The Obligations in AB 1405
The statute is more specific than the announcement. Under a new Chapter 5.9.5 of the Government Code, the Government Operations Agency must establish an AI Auditor Registry on its website no later than January 1, 2029, fix annual registration fees at an amount not exceeding the reasonable costs of administering the chapter, and stand up a mechanism letting natural persons report misconduct by a registered AI auditor. From January 1, 2029, the agency must issue a unique registration number to each registered auditor and publish registration information in a publicly accessible format - including a statement prominently disclosing that registration does not constitute a recommendation or endorsement by the State of California. Misconduct reports must be retained for as long as the auditor remains registered plus ten years, and shared with other state agencies as needed for enforcement. The operative clause is Section 11549.82.5: beginning January 1, 2029, a person shall not offer, sell, or conduct a covered AI audit unless registered.
# 2. The registry fields AB 1405 requires of an auditor (Sec. 11549.83)
auditor_registration = {
"business_name": "...",
"business_contact": "...",
"california_laws_audited_under": ["..."], # required list
"certifications_accreditations": ["..."],
"services_description": "...", # 500 words maximum
"sop": {
"standards_applied": ["ISO", "NIST", "auditing standard-setters"],
"basis_for_accuracy_claims": "...", # how claims are justified
},
}
# Registration also needs a SOP citing the standards applied and the basis
# for any claims about the accuracy, reliability, or validity of protocols.An audit is only as good as the evidence it can retrieve
3. Two Definitions That Set the Boundary
AB 1405 defines its terms carefully, and two definitions matter more than the rest. An AI auditor is a person, partnership, or corporation that assesses an AI system or model on behalf of a third party. More importantly, a covered AI audit is an audit conducted to assess internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law. In other words, the law is not interested in whether your model is good; it is interested in whether a control system exists, is documented, and is running. Registration also requires disclosures that make the auditor's own claims auditable: business name and contact information, a list of the California laws or regulations under which the auditor conducts covered audits, relevant certifications and accreditations, a services description capped at 500 words, and a standard operating procedure that references the standards applied - ISO, NIST, national and international auditing and assurance standard-setters, professional accountancy bodies, or a state agency - and describes the basis for any claims about the accuracy, reliability, or validity of its protocols.
# 3. Independence is a control, not an adjective (SB 813 + AB 1405)
auditor_conflicts = [
"implemented_the_control", # built the thing it now assesses
"sells_remediation", # audit findings create its own pipeline
"shares_owner_with_vendor",
]
def assessor_ok(auditor):
return not any(f in auditor["relationships"] for f in auditor_conflicts)
# AB 1405 directs the state to publish a statement that registration does not
# constitute a recommendation or endorsement - so verify the relationship.4. What This Means for Engineering Teams
Translated into engineering terms, the statute asks for three things: controls that map to specific legal citations, evidence that can be reproduced, and retention that outlives the audit. Four small practices cover most of it. First, keep a three-column record per AI system - control, statutory citation, evidence URI - and make the evidence a re-runnable test definition rather than a screenshot. Second, freeze model and prompt versions into the record, because latest is not an auditable reference. Third, run automated control tests monthly rather than annually so evidence accumulates on its own. Fourth, hash every artifact you hand over and set retention to at least ten years; the statute keeps misconduct reports for the registration period plus ten years, and evidence should be treated at least as conservatively. Compliance and procurement teams have a parallel job: due diligence on auditors. Independence, transparency, and integrity are the standards the legislature named, and registration is explicitly not an endorsement.
# 4. Evidence must be reproducible before an auditor asks for it
def evidence_packet(system, control):
return {
"system_id": system["id"],
"model_version": system["model_version"], # frozen, not "latest"
"control_id": control["id"],
"law_citation": control["law_citation"],
"test_definition": control["test_uri"], # versioned in git
"run_at": control["last_run"],
"result": control["result"],
"artifact_sha256": control["artifact_hash"],
"retention_years": max(control["retention"], 10),
}
# Misconduct reports are retained for as long as the auditor stays registered
# plus ten years. Assume your evidence needs to outlive the audit.The deadline in the statute is 2029, the preparation work starts in 2026
5. The Timeline, and Where You Already Stand
The timeline is unambiguous: signed in September 2026, registry obligations biting on January 1, 2029. Three years is long enough to build an evidence pipeline and short enough that it cannot wait. Two pre-existing obligations belong on the same diagram. SB 53, the Transparency in Frontier Artificial Intelligence Act signed in 2025, already requires frontier developers to publish safety frameworks, report certain critical safety incidents to the state, and protect whistleblowers; these two bills extend that line rather than replacing it. The practical advice is to put January 1, 2029 on the calendar and work backwards through three milestones: control-to-statute mapping by 2027, automated evidence and retention by 2028, and a first internal dry-run audit before the deadline. The teams that fail this kind of audit are rarely the ones that skipped the controls. They are the ones that cannot retrieve a control test from eighteen months ago.
BEGIN:VCALENDAR
# 5. The statutory clock in AB 1405 (Sec. 11549.82 and 11549.82.5)
# no later than 2029-01-01 -> agency establishes the AI Auditor Registry
# beginning 2029-01-01 -> unique registration numbers are issued
# beginning 2029-01-01 -> no person may offer, sell, or conduct a
# covered AI audit unless registered
TODAY=$(date +%F)
echo "days until registry obligations bite:"
python3 -c "import datetime;print((datetime.date(2029,1,1)-datetime.date.today()).days)"
# Working backwards is the useful exercise: an auditor that cannot retrieve
# a control test from 18 months ago cannot certify anything, registration
# or not. Start the evidence pipeline while the deadline is still distant.📌 Frequently Asked Questions
What are SB 813 and AB 1405?
Per the California Governor's office release of September 9, 2026: SB 813 (Senator McNerney) establishes a first-in-the-nation framework for independent verification organizations that assess AI systems and models for compliance with state law. AB 1405 (Assemblymember Bauer-Kahan) creates a state registry for AI auditors with standards for independence, transparency, and integrity.
When does registration become mandatory?
Per AB 1405: the Government Operations Agency must establish the registry no later than January 1, 2029, and beginning January 1, 2029 a person shall not offer, sell, or conduct a covered AI audit unless registered with the agency (Sec. 11549.82.5).
What counts as a covered AI audit?
AB 1405 Sec. 11549.80 defines it as an audit conducted to assess internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law - a control system question, not a model quality question.
Does registration mean California endorses an auditor?
No. AB 1405 requires the state to publish a statement prominently disclosing that registration by an AI auditor does not constitute a recommendation or endorsement of that entity by the State of California.
Do these bills ban any AI models?
No. They establish auditing and registration infrastructure - who may assess, how they register, and what they must disclose. They do not ban models or cap model parameters; related obligations come from earlier legislation such as SB 53.
🔧 Recommended Tools
Cron Expression Generator
Schedule control tests so evidence actually accumulates
Hash Generator
Fingerprint every artifact you hand an auditor
JSON Schema Validator
Validate the control and evidence records
Markdown Preview
Write the SOP where engineers will read it
Unix Timestamp Converter
Stamp evidence with unambiguous UTC times
📚 Sources
- Office of Governor Gavin Newsom - Governor Newsom signs first-in-the-nation AI safeguards (September 9, 2026): SB 813 independent verification framework, AB 1405 auditor registry
- California Legislative Information - AB 1405 (Bauer-Kahan), Artificial intelligence: auditors: registration: Chapter 5.9.5, Sec. 11549.80-11549.83 (registry by January 1, 2029)
- California Legislative Information - SB 813 (McNerney), independent verification organizations for AI systems and models: full bill text