California Gov. Gavin Newsom signed two AI-governance bills on Sept. 9 that build state infrastructure for independent assessment of artificial-intelligence systems. One measure, AB 1405, creates a registry and conduct rules for people and firms that perform certain AI compliance audits; the other, SB 813, establishes a framework for independent verification organizations.
The laws are consequential less because they order every company using AI to get an audit—AB 1405 does not do that—than because they define how a growing category of AI assurance work will be supervised in California. The registry, its fees and its misconduct-reporting channel must be in place by Jan. 1, 2029. From that date, an unregistered person may not offer, sell or conduct a covered AI audit in the state.
In its Sept. 9 announcement, the governor’s office described the combined legislation as a framework for independent third-party evaluation and audits, and called the standards first in the nation. The enacted language of AB 1405, however, draws a more precise line: it regulates the auditors when a covered audit is performed, rather than creating a general audit obligation for AI developers, model providers or business customers.
What AB 1405 regulates
Under the statute, a covered AI audit examines internal controls, processes or systems used for an AI system or model when those measures are necessary to comply with state law. The definition focuses on compliance work, not on every form of testing, benchmarking or safety evaluation that companies may label an audit.
The California Government Operations Agency is directed to run a public AI Auditor Registry, set annual registration fees and establish a way for people to report alleged misconduct. Applicants must supply information including the state laws or regulations under which they conduct covered audits, relevant qualifications, operating procedures, and the basis for any assertions that their audit protocols are accurate, reliable or valid.

The law also specifies how a registered auditor is expected to work. Where applicable standards are widely recognized in the industry, auditors must follow them. Their reports to auditees must address the audit’s scope and results, identified deficiencies, recommendations when appropriate, limitations, and a signed statement of compliance with the statutory requirements.
Those details make AB 1405 more than a directory of firms. It attaches documentation, reporting and professional-practice requirements to a defined service. An audit may still be required by some separate California law, regulation or contract; AB 1405’s role is to govern the provider of a covered audit, not to supply a blanket trigger for commissioning one.
Independence rules and a long record trail
AB 1405 requires auditors to maintain independence and manage conflicts of interest. It also requires them to retain audit documentation and related information for at least 10 years. That period is unusually important for AI systems, whose models, data, controls and uses can change after an assessment has been completed. The statute preserves material that may be relevant if an auditor’s work is later challenged.
The agency can investigate alleged violations. A violation may lead to removal from the registry and referral to the attorney general or another enforcement authority. The bill contains a tailored exemption from specified reporting and independence provisions for qualifying accountants and accounting firms that meet conditions set out in the law. For allegations involving those qualifying accountancy professionals, the California Board of Accountancy has an investigatory role.
Registration is therefore not merely an administrative filing. The framework links eligibility to a professional record, mandated report contents and possible loss of the ability to conduct covered work. It leaves considerable practical detail for the agency, which must determine registration fees and administer the registry before the 2029 deadline.
A companion bill, but a distinct mechanism
SB 813 and AB 1405 are often discussed together, but they perform different jobs. The governor’s office says SB 813 establishes a framework for independent verification organizations to assess AI systems and models for compliance with California law. AB 1405 is the statute that establishes the auditor registry, rules for covered audits and the enforcement pathway.
That division is relevant to broad descriptions of California as having enacted “AI audit requirements.” Some accounts use that shorthand, but the AB 1405 text does not state that all organizations developing or deploying AI must obtain a third-party audit. It imposes its core registration prohibition only on the person offering, selling or conducting a covered audit after Jan. 1, 2029.
The administration’s first-in-the-nation characterization should also be read as its policy description rather than a settled comparison across every AI law. StateScoop reported that Illinois enacted a July law requiring annual independent third-party audits for major frontier-AI developers. The available accounts point to different legal designs and covered populations, but do not fully resolve how the two states’ definitions and obligations compare.
Why the implementation date matters
California has enacted the framework, but its operative registry requirement is not immediate. The state has until Jan. 1, 2029—more than two years after the signing date—to establish the registry, annual fees and misconduct-reporting process. The prohibition on unregistered covered AI audits starts on the same date.
That schedule gives the statute a phased structure. The present result is a legal foundation for verification organizations and for a regulated class of AI compliance auditors. The next fixed milestone is the agency’s 2029 launch of the registry and the associated registration requirement.
Industry reaction has largely focused on that institutional direction. Miranda Bogen of the Center for Democracy and Technology told CIO Dive that the measures could be an initial move toward a more complicated AI-audit ecosystem. The legislation itself is narrower and more concrete: California will maintain a registry for covered AI auditors, prescribe their baseline obligations and provide a route for investigating misconduct.
