California AI Audit Laws Signed as Newsom Pushes for National Rules
California has become the first U.S. state to require independent audits of artificial intelligence systems. Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 on September 9, 2026, creating a state registry of approved AI auditors and a formal route for outside organizations to verify whether AI systems comply with California law. The two California AI audit laws drew public backing from both leading frontier labs: Anthropic endorsed the package roughly a month before the signature, and OpenAI added its support in the hours before the signing.
Newsom presented the laws as a first-in-the-nation step and asked Congress to pass binding national AI safety rules that match the state's effort. OpenAI made a parallel argument the same day, urging federal lawmakers to adopt mandatory national safety requirements and describing a patchwork of state statutes as unworkable for frontier developers. The signing capped a week in which both labs publicly endorsed the measures.
What the California AI audit laws do
SB 813 defines the verification process. It gives independent organizations a recognized path to assess whether an AI system meets California law, which turns third-party evaluation from a voluntary practice into a state-sanctioned function.
AB 1405 builds the supply side of that function. The bill establishes a state registry of AI auditors and sets standards for their transparency, independence, and competence, treating those three qualities as conditions for a credible audit rather than optional credentials.
| Provision | SB 813 | AB 1405 |
|---|---|---|
| Core function | Process for independent verification of AI compliance with state law | State registry of AI auditors |
| Standards set | Recognized route for outside organizations to assess compliance | Transparency, independence and competence criteria for auditors |
| Practical effect | Makes third-party evaluation a defined state process | Determines who may perform those evaluations |
| Signed | September 9, 2026 | September 9, 2026 |
The registry is the mechanism that changes the incentive structure. Safety documentation produced by the company being evaluated reflects that company's own judgment; a registered auditor answers to state-set criteria for independence. That shift is what gives the framework teeth, and it is why the competence standards in AB 1405 matter more than their brief wording suggests.
A related measure, AB 1864, addresses screening against AI-enabled biological threats, extending the legislature's attention from how models are evaluated to the specific harms they might enable. The stated goal across the package is greater transparency and accountability as AI spreads through critical sectors of California's economy, the fourth-largest in the world.
How California got here
The audit framework is the third stage of a multi-year sequence rather than an isolated act.
| Date | Action |
|---|---|
| 2024 | Newsom vetoes SB 1047 after sustained industry opposition |
| September 2025 | SB 53 signed, imposing safety-framework, transparency and incident-reporting duties on large AI labs |
| May 2026 | Executive order on preparing workers and businesses for AI disruption |
| September 9, 2026 | SB 813 and AB 1405 signed, creating the auditor registry and verification process |
That sequence shapes how the current bills should be read. Newsom vetoed the far more expansive SB 1047 in 2024 after sustained opposition from technology companies, then signed the narrower SB 53 in September 2025. SB 813 and AB 1405 add external verification while keeping the earlier law's design principle: obligations that large labs can plausibly meet with processes they already run.
The 2024 veto and the 2025 signing bracket a change in industry posture as much as in policy. The same sector that fought the broadest bill now endorses the audit framework built on top of the narrower one.
The industry calculus
Anthropic's support predates the signing by about a month. The company took the same position on SB 53, where it said the requirements largely matched practices it had already adopted. OpenAI's endorsement arrived hours before Newsom signed, and the company said it will keep promoting AI safety legislation in other states. Google has not opposed the earlier transparency law but has stressed the importance of federal action.
OpenAI's timing is instructive. Its endorsement of the state bills and its call for federal legislation landed on the same day, which makes the two positions one strategy: accept the state framework as a floor, then argue that only Washington can make it uniform.
Backing audits you will have to pay for looks counterintuitive. The position is coherent. One national rule is cheaper to comply with than fifty divergent state regimes, and a framework drafted with industry input is easier to absorb than prescriptive mandates written over company objections. By endorsing California's model early, both labs gain influence over what an audit looks like before other states copy it.
The costs fall asymmetrically. Frontier developers can absorb audit fees and dedicated compliance staff; smaller model providers and open-weight distributors cannot as easily. If the registry standard becomes the default national template, that burden becomes a competitive filter favoring the largest labs, which is one reason their endorsements cost them less than they appear to.
What the framework does not settle
The registry has a supply problem. Auditing frontier models against legal standards requires specialized expertise, and the number of firms able to do it is small. Independence criteria narrow the pool further, since organizations best equipped to evaluate a model are often the ones already working with its developer. A registry that certifies too few auditors can slow compliance instead of accelerating it.
The scope of an audit is a second unresolved question. California's AI obligations now sit across several statutes, including SB 53's safety-framework and incident-reporting duties and AB 1864's biological-threat screening. An auditor certifying compliance with California law has to define which obligations fall inside the review, and a narrow definition produces a certificate with little informational value.
Whether the state can police its standards after certification is the part of AB 1405 that will be tested first. Setting competence and conflict-of-interest criteria is easier than enforcing them against auditors who depend on the labs for revenue.
Federal preemption is the larger open question. Newsom's request for national rules and OpenAI's differ in effect: a federal standard set at California's level would lock in the state's approach, while one written to displace state authority would erase it. The Newsom administration has framed Sacramento as acting because Washington has stalled, and that framing leaves the jurisdictional question open.
What to watch
The practical test of the California AI audit laws is administrative. The state has to certify enough independent firms to make verification routine, and the registry standards have to survive a challenge to state authority over AI development. A first round of applications will show whether the accredited group is broad enough to serve the labs, state agencies and enterprises that will need audits.
For enterprise buyers, the registry creates something new. A list of evaluators whose independence has been reviewed by a state agency is a stronger procurement signal than a vendor's own safety documentation, and it gives risk and legal teams an external reference point when they assess a model provider.
California's rules also apply to a market the state cannot fence off. Frontier labs train and deploy globally, so an audit performed for Sacramento is likely to be reused as evidence of compliance elsewhere.
Other states now have a template they can copy from the California AI audit laws at low political cost, with two major labs already on record supporting it. That is the milestone to track: how many legislatures file companion bills, and whether Congress acts on national rules before they do.
Why this matters
California has turned AI safety from a set of voluntary corporate commitments into a state-verified process, and it did so with the endorsement of the two labs most affected. That combination is the actual news. The frontier developers have concluded that a predictable audit regime, even one they must fund, is preferable to fifty competing ones. Independent evaluation is moving from a marketing claim to a compliance requirement, and vendors that can document how their models behave will move through whichever regime comes next with less friction.
Photo by clement proust on Unsplash
Related Articles
- Illinois Mandates Independent AI Safety Audits in Landmark Accountability Law
- Bipartisan Proposal for Great American AI Act Establishes National Oversight Standards
- Massachusetts AI safety bill wins Anthropic's backing as OpenAI and Google push annual audits
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.