California AI auditor registry bills signed by Governor Gavin Newsom
California Governor Gavin Newsom has signed bills AB 1405 and SB 813, which establish a state registry and regulatory framework for independent AI auditors. The legislation mandates that auditors meet specific independence and operational standards by 2029, creating a formal market infrastructure for AI system verification.
Key Takeaways
- AB 1405 requires AI auditors to register and maintain 10-year records retention starting January 2029
- SB 813 mandates the Government Operations agency finalize a regulatory framework for verification by 2028
- OpenAI and Anthropic supported the legislation despite TechNet's earlier opposition regarding premature mandates
- Illinois recently passed similar frontier AI laws requiring mandatory independent assessments for specific models
Why It Matters
The establishment of a formal registry signals a shift from voluntary self-regulation to state-enforced accountability for AI developers. By codifying standards for independence and integrity, California is building the market infrastructure necessary for third-party verification, which could eventually become a prerequisite for operating in the state. This move aligns with broader efforts in Illinois and the EU to standardize how high-risk systems are assessed for safety and bias. While the current framework does not yet mandate audits for all developers, it creates a baseline to eliminate unreliable external auditing operations. Watch for the Government Operations agency to release specific qualification requirements for independent verification organizations by the 2028 deadline.
Additional Context
California's move to formalize AI auditing infrastructure arrives as multiple jurisdictions build parallel verification regimes. In August 2026, Illinois enacted its own AI accountability law requiring algorithmic impact assessments for high-risk systems used in employment and housing decisions, creating a second major U.S. state with mandatory third-party evaluation requirements. The European Union's AI Act, which entered full enforcement in August 2025, already requires conformity assessments by notified bodies for high-risk AI systems, and the European Commission published guidance in March 2026 specifying that notified bodies must demonstrate auditor independence through organizational separation and conflict-of-interest policies. These parallel frameworks suggest that California's registry will need to address cross-jurisdictional recognition to avoid duplicative compliance burdens on companies operating in multiple markets.
The business implications for AI developers and auditing firms are significant. OpenAI's head of policy Chris Lehane stated in July 2026 that the company supports standardized third-party auditing frameworks but cautioned that inconsistent state-level requirements could fragment the compliance landscape. TechNet, which represents major technology companies including OpenAI and Anthropic, filed comments with California's Government Operations Agency in June 2026 urging that auditor qualification criteria align with existing ISO and NIST standards rather than creating novel state-specific requirements. The auditing market itself is nascent but growing: a report from the Partnership on AI estimated that fewer than 50 organizations globally currently offer independent AI system evaluations meeting basic independence criteria, suggesting the registry could catalyze a new professional services category.
Technical standards for AI auditing remain under development, which will shape what California's registered auditors actually assess. NIST released version 2.0 of its AI Risk Management Framework in May 2026, adding specific evaluation protocols for generative AI systems including red-teaming requirements and bias measurement methodologies. The framework provides a potential baseline for California's qualification standards. Meanwhile, Anthropic published a technical paper in April 2026 proposing structured evaluation rubrics for third-party auditors assessing large language model safety properties, arguing that without standardized scoring criteria, different auditors could reach contradictory conclusions about the same system. The interplay between these technical standards and California's 2029 compliance deadline will determine whether the registry produces meaningful verification or becomes a checkbox exercise.
Read full article at iapp.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source