bytevyte
bytevyte
Language
ai-beats

California AI Audit Laws Signed as Newsom Pushes for National Rules

California AI audit laws

California has become the first U.S. state to require independent audits of artificial intelligence systems. Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 on September 9, 2026, creating a state registry of approved AI auditors and a formal route for outside organizations to verify whether AI systems comply with California law. The two California AI audit laws drew public backing from both leading frontier labs: Anthropic endorsed the package roughly a month before the signature, and OpenAI added its support in the hours before the signing.

Newsom presented the laws as a first-in-the-nation step and asked Congress to pass binding national AI safety rules that match the state's effort. OpenAI made a parallel argument the same day, urging federal lawmakers to adopt mandatory national safety requirements and describing a patchwork of state statutes as unworkable for frontier developers. The signing capped a week in which both labs publicly endorsed the measures.

What the California AI audit laws do

SB 813 defines the verification process. It gives independent organizations a recognized path to assess whether an AI system meets California law, which turns third-party evaluation from a voluntary practice into a state-sanctioned function.

AB 1405 builds the supply side of that function. The bill establishes a state registry of AI auditors and sets standards for their transparency, independence, and competence, treating those three qualities as conditions for a credible audit rather than optional credentials.

ProvisionSB 813AB 1405
Core functionProcess for independent verification of AI compliance with state lawState registry of AI auditors
Standards setRecognized route for outside organizations to assess complianceTransparency, independence and competence criteria for auditors
Practical effectMakes third-party evaluation a defined state processDetermines who may perform those evaluations
SignedSeptember 9, 2026September 9, 2026

The registry is the mechanism that changes the incentive structure. Safety documentation produced by the company being evaluated reflects that company's own judgment; a registered auditor answers to state-set criteria for independence. That shift is what gives the framework teeth, and it is why the competence standards in AB 1405 matter more than their brief wording suggests.

A related measure, AB 1864, addresses screening against AI-enabled biological threats, extending the legislature's attention from how models are evaluated to the specific harms they might enable. The stated goal across the package is greater transparency and accountability as AI spreads through critical sectors of California's economy, the fourth-largest in the world.

How California got here

The audit framework is the third stage of a multi-year sequence rather than an isolated act.

DateAction
2024Newsom vetoes SB 1047 after sustained industry opposition
September 2025SB 53 signed, imposing safety-framework, transparency and incident-reporting duties on large AI labs
May 2026Executive order on preparing workers and businesses for AI disruption
September 9, 2026SB 813 and AB 1405 signed, creating the auditor registry and verification process

That sequence shapes how the current bills should be read. Newsom vetoed the far more expansive SB 1047 in 2024 after sustained opposition from technology companies, then signed the narrower SB 53 in September 2025. SB 813 and AB 1405 add external verification while keeping the earlier law's design principle: obligations that large labs can plausibly meet with processes they already run.

The 2024 veto and the 2025 signing bracket a change in industry posture as much as in policy. The same sector that fought the broadest bill now endorses the audit framework built on top of the narrower one.

The industry calculus

Anthropic's support predates the signing by about a month. The company took the same position on SB 53, where it said the requirements largely matched practices it had already adopted. OpenAI's endorsement arrived hours before Newsom signed, and the company said it will keep promoting AI safety legislation in other states. Google has not opposed the earlier transparency law but has stressed the importance of federal action.

OpenAI's timing is instructive. Its endorsement of the state bills and its call for federal legislation landed on the same day, which makes the two positions one strategy: accept the state framework as a floor, then argue that only Washington can make it uniform.

Backing audits you will have to pay for looks counterintuitive. The position is coherent. One national rule is cheaper to comply with than fifty divergent state regimes, and a framework drafted with industry input is easier to absorb than prescriptive mandates written over company objections. By endorsing California's model early, both labs gain influence over what an audit looks like before other states copy it.

The costs fall asymmetrically. Frontier developers can absorb audit fees and dedicated compliance staff; smaller model providers and open-weight distributors cannot as easily. If the registry standard becomes the default national template, that burden becomes a competitive filter favoring the largest labs, which is one reason their endorsements cost them less than they appear to.

What the framework does not settle

The registry has a supply problem. Auditing frontier models against legal standards requires specialized expertise, and the number of firms able to do it is small. Independence criteria narrow the pool further, since organizations best equipped to evaluate a model are often the ones already working with its developer. A registry that certifies too few auditors can slow compliance instead of accelerating it.

The scope of an audit is a second unresolved question. California's AI obligations now sit across several statutes, including SB 53's safety-framework and incident-reporting duties and AB 1864's biological-threat screening. An auditor certifying compliance with California law has to define which obligations fall inside the review, and a narrow definition produces a certificate with little informational value.

Whether the state can police its standards after certification is the part of AB 1405 that will be tested first. Setting competence and conflict-of-interest criteria is easier than enforcing them against auditors who depend on the labs for revenue.

Federal preemption is the larger open question. Newsom's request for national rules and OpenAI's differ in effect: a federal standard set at California's level would lock in the state's approach, while one written to displace state authority would erase it. The Newsom administration has framed Sacramento as acting because Washington has stalled, and that framing leaves the jurisdictional question open.

What to watch

The practical test of the California AI audit laws is administrative. The state has to certify enough independent firms to make verification routine, and the registry standards have to survive a challenge to state authority over AI development. A first round of applications will show whether the accredited group is broad enough to serve the labs, state agencies and enterprises that will need audits.

For enterprise buyers, the registry creates something new. A list of evaluators whose independence has been reviewed by a state agency is a stronger procurement signal than a vendor's own safety documentation, and it gives risk and legal teams an external reference point when they assess a model provider.

California's rules also apply to a market the state cannot fence off. Frontier labs train and deploy globally, so an audit performed for Sacramento is likely to be reused as evidence of compliance elsewhere.

Other states now have a template they can copy from the California AI audit laws at low political cost, with two major labs already on record supporting it. That is the milestone to track: how many legislatures file companion bills, and whether Congress acts on national rules before they do.

Why this matters

California has turned AI safety from a set of voluntary corporate commitments into a state-verified process, and it did so with the endorsement of the two labs most affected. That combination is the actual news. The frontier developers have concluded that a predictable audit regime, even one they must fund, is preferable to fifty competing ones. Independent evaluation is moving from a marketing claim to a compliance requirement, and vendors that can document how their models behave will move through whichever regime comes next with less friction.

Photo by clement proust on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.