Skip to content
Rush Commerce
AI & Automation3 min read

California just built a registry for AI auditors

Newsom signed SB 813 and AB 1405 on September 9, creating a state registry for independent AI auditors and a framework for third-party verification of AI systems.

California signed two AI audit bills into law on September 9, and the practical effect is that "we had it independently reviewed" is about to become a claim with a definition behind it. Governor Newsom signed SB 813 and AB 1405, creating a framework for independent verification organizations and a state registry for the auditors who staff them.

What actually happened

SB 813, authored by Senator Jerry McNerney (D-Pleasanton), establishes a framework for independent verification organizations that can assess AI systems and models for compliance with state law. AB 1405, from Assemblymember Rebecca Bauer-Kahan (D-Orinda), creates the state registry for AI auditors and sets standards for their independence, transparency, and integrity.

Together they answer a question SB 53 — the Transparency in Frontier Artificial Intelligence Act, passed in 2025 — left open: who is qualified to check, and what makes them credible enough to be believed. McNerney's framing in the announcement is blunt about the motive: California is moving because Washington is not.

Note what these bills do not do. They do not impose new testing obligations on the average business deploying AI. They build the supply side — the auditors, the standards, the registry. The obligations that route work to those auditors are the existing and future ones.

Why an AI auditor registry matters for your business

You will meet this law through your vendors, not your own compliance team.

Right now, when a software vendor tells you their model is "independently evaluated," that phrase carries roughly the weight of "artisanal." There is no registry to check the evaluator against, no independence standard they had to clear, no way to tell a real audit from a logo on a PDF. AB 1405 puts a list somewhere. Lists are checkable.

Three things worth doing before the vendor conversation gets there first:

Ask who did the evaluation, by name. Not "a third party." The organization. Write it into the security questionnaire you already send.

Separate the claim from the scope. An audit of a model is not an audit of the product you are buying. Ask what was assessed and against what.

Keep the evidence yourself. If a vendor's compliance story ever gets tested, you want the attestation in your own storage, dated, not a link to a page they control and can quietly edit.

None of this is new discipline. It is the vendor diligence you already do for SOC 2, applied to a claim that until now had no floor under it.

Key takeaways

  • Newsom signed SB 813 and AB 1405 on September 9, 2026
  • SB 813 creates a framework for independent verification organizations that assess AI systems for compliance with state law
  • AB 1405 creates a state registry of AI auditors with standards for independence, transparency, and integrity
  • The bills build audit supply and infrastructure — they do not themselves impose new testing duties on most deployers
  • Expect to encounter this through vendor claims: ask who evaluated the system, and what scope it covered

"Independently evaluated" is a sentence, not evidence. We build AI features with logged decisions, traceable inputs, and the kind of documentation that survives a diligence request. See how we ship AI you can actually account for, or bring us the vendor claim you cannot verify.

Sources: Office of Governor Gavin Newsom, AB 1405 bill record, CalMatters Digital Democracy.

  • #ai-regulation
  • #california
  • #ai-audit
  • #compliance
  • #vendor-risk
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.