Governor Gavin Newsom signed two bills on September 9, 2026, that outlets are already calling the "first-in-the-nation AI audit laws." That headline is accurate but easy to misread. SB 813 and AB 1405 don't order anyone to audit an AI system. They regulate who is allowed to call themselves an AI auditor once some other California law says an audit has to happen. That distinction — audit mandate versus auditor licensing — is the whole story, and it's the part most aggregator summaries drop.
This matters because "AI audit" is a term of art that means different things depending on who's using it. A compliance officer means an independent third-party review with legal teeth. A vendor means a marketing checkbox. explainx.ai has covered the broader AI regulation landscape between the EU AI Act and US state law before; this post is narrower and more practical — what exactly do these two new California statutes require, who has to care, and how do they sit inside California's three-year run at regulating frontier AI, from the SB 1047 veto through SB 53 to this.
TL;DR: what SB 813 and AB 1405 actually do
| Question | Answer |
|---|---|
| What do the laws require? | SB 813 sets qualification standards for independent verification organizations; AB 1405 creates a public AI Auditor Registry and bars unregistered audits |
| Do they mandate AI labs get audited? | No — they govern who can perform an audit that some other state law already requires |
| Who is covered? | Auditors and verification organizations directly; indirectly, any entity — frontier lab or downstream deployer — that a separate CA law obligates to commission an audit |
| What triggers an audit? | Not these bills. Triggers come from statutes like SB 53 (frontier AI transparency) or sector rules on hiring, insurance, and lending automated decision tools |
| Effective dates | SB 813 criteria due January 1, 2028; AB 1405 registry live and unregistered-audit ban effective January 1, 2029 |
| Penalties | Registry removal, referral to the Attorney General or other enforcement bodies for auditor misconduct — no published fine schedule for AI companies specifically |
| Does it name Anthropic, OpenAI, or Google? | No — it's a licensing framework for the auditing profession, not a company-specific or hard compute-threshold trigger like SB 1047 proposed |
| Industry stance | Both Anthropic and OpenAI publicly backed the bills before signing — a marked contrast to the SB 1047 fight |
What the bills say, in order
Senate Bill 813, authored by state Sen. Jerry McNerney (D-Pleasanton), tells the California Government Operations Agency to build criteria for "independent verification organizations" — expert bodies that can assess whether an AI system or model complies with state law. Applicants have to disclose their qualifications, testing methodologies, and tooling; the agency evaluates technical expertise and how well an applicant manages conflicts of interest. That criteria has to exist by January 1, 2028. McNerney called it a codification of "one of the primary recommendations of the governor's blue-ribbon panel on AI."
Assembly Bill 1405, from Assemblymember Rebecca Bauer-Kahan (D-Orinda), goes further: it stands up an online AI Auditor Registry by January 1, 2029. After that date, an unregistered person or organization generally cannot "offer, sell, or conduct an AI audit required to assess compliance with state law." Registered auditors have to disclose material gaps in the evidence or access they were given, identify deficiencies and remedies in their reports, and — critically — cannot audit systems they materially designed, operated, or held responsibility for within the prior 12 months. That last rule is modeled on the independence standards that govern financial auditors, and it's the mechanism StateScoop's coverage and PYMNTS' reporting both flag as the real substance: turning AI auditing from an unregulated consulting service into something closer to a licensed profession, with rules on who can be paid how and by whom.
Compensation itself is restricted, too — auditors can accept "reasonable payment" for their work, but it cannot be contingent on what they find. That single clause is aimed directly at the most common criticism of self-commissioned corporate audits: that a firm paid only if it finds no problems has an obvious incentive not to look too hard.
Why this reads as narrower than "AI audit laws for California AI labs"
The aggregator framing — "first-in-nation AI audit laws for California AI labs" — implies SB 813 and AB 1405 put frontier labs under a new, direct audit mandate the way SB 1047 would have. That's not what happened. Neither bill creates a new obligation for a lab to submit to an audit. What they create is the supply side: a pool of state-vetted, independence-checked auditors who are qualified to perform an audit whenever some other law says one is required.
That "some other law" part matters more than it sounds. As of September 2026, the laws that actually trigger a required audit in California include:
- SB 53 (2025), the Transparency in Frontier Artificial Intelligence Act, which requires large frontier developers to disclose how they manage catastrophic risk — but notably dropped SB 1047's mandatory independent-verification requirement when it passed.
- SB 1119 ("Adam's Law"), also signed in this legislative window, which requires companion-chatbot providers to run child-safety risk assessments before launch (effective July 1, 2027) and an initial independent child-safety audit by January 1, 2029 or before first availability, repeated every two years.
- Sector-specific automated-decision-tool rules covering hiring, insurance pricing, and lending, where a deployer using an off-the-shelf model to screen applicants or price a policy can be the one on the hook for an audit — not the model's original developer.
So the practical effect right now, in September 2026, is closer to "California is building the auditor-licensing infrastructure ahead of when it will actually need it" than "California AI labs must now submit to mandatory audits." The audit requirement lives in SB 53, SB 1119, and future bills; SB 813 and AB 1405 answer the question those laws leave open — audited by whom, under what standard, with what independence guarantee.
How this fits the SB 1047 → SB 53 → today lineage
California has now made three serious runs at regulating frontier AI in three years, and each one has been narrower than the last:
- SB 1047 (2024) — would have directly mandated safety testing, incident reporting, and a shutdown capability for frontier models above a compute threshold, enforced by the state Attorney General. Newsom vetoed it in September 2024, arguing it applied uniformly regardless of actual deployment risk and could push AI development out of California.
- SB 53 (2025) — the industry-negotiated successor. It required large frontier developers to publish how they assess and manage catastrophic risk, but dropped SB 1047's centerpiece: mandatory third-party verification. That gap is exactly what SB 813 and AB 1405 now start to fill — not by reviving a hard audit mandate, but by making sure that if a future law (or SB 53 itself, amended later) requires third-party verification, there's already a licensed, independence-vetted auditor pool ready to do it.
- SB 813 / AB 1405 (2026) — regulate the auditors, not the labs directly. Anthropic and OpenAI both publicly backed these bills in the weeks before signing, a sharp contrast to the open industry fight over SB 1047. That endorsement is itself informative: a bill the frontier labs actively support is, almost by definition, a lighter lift than one they fought to kill.
Newsom's own signing statement leaned into that same framing, reportedly telling the state to press for federal rules of its own: "The federal government must step forward with robust, national regulations that match the urgency of this moment." Read against three years of vetoes and rewrites, that's Newsom positioning California's approach as building compliance infrastructure while waiting for Washington to act — not as an admission that California alone can force frontier labs into a compute-threshold regime the way SB 1047 tried to.
The "California effect" argument
California is home to Anthropic, OpenAI, Google DeepMind, and most other frontier labs' primary US operations, which is the same dynamic that made CCPA a de facto national privacy standard and the EU AI Act a de facto global one — companies build one compliance program and apply it everywhere rather than maintaining 50 state-specific versions. explainx.ai's EU AI Act and US policy guide covers that dynamic in more depth for the EU side.
The honest caveat: a licensing scheme for auditors has much less "California effect" leverage than a compute-threshold mandate would. SB 1047 would have forced every frontier lab doing business with California users to build a specific compliance program regardless of headquarters. SB 813 and AB 1405, by contrast, mostly matter to the (smaller) set of organizations that want to become registered auditors, plus whichever entities a future or existing law obligates to hire one. The de facto national standard here, if it emerges, is more likely to be "which auditing firms are California-certified" than "what every AI company must disclose" — a narrower, slower-moving kind of influence.
What people are asking
Does this apply to me if I build on top of these labs' APIs? Almost certainly not directly. You are neither an auditor nor, in most cases, the covered entity an audit requirement attaches to. The exception worth watching: if you deploy AI to screen job applicants, price insurance, or make comparable high-stakes automated decisions, sector-specific rules (separate from SB 813/AB 1405) may eventually require you to commission an audit — at which point these two laws determine who you're allowed to hire to do it.
Is this the same as SB 1047? No. SB 1047 was a direct mandate on frontier developers with a compute threshold and an Attorney General enforcement hook. SB 813 and AB 1405 build the auditor-licensing layer that sits underneath audit requirements imposed by other laws — a structural difference, not just a difference in strictness.
Will this survive legal challenge or federal preemption? Untested. Industry backing from Anthropic and OpenAI lowers the odds of a direct industry lawsuit, but it says nothing about federal preemption arguments the current administration has floated against state AI legislation broadly. Because these laws regulate a licensed profession (auditors) rather than AI models directly, they may be more defensible than a model-specific mandate would be — but that's a prediction, not a settled legal outcome.
Does this actually change what these companies do, today? Not immediately. The first hard deadline — SB 813's verification-organization criteria — isn't due until January 1, 2028. AB 1405's registry and unregistered-audit ban land January 1, 2029. Companies have more than two years before either law forces a concrete compliance action, which is part of why the industry response was support rather than opposition.
Who actually enforces this? Reporting describes registry removal and referral to the California Attorney General or other enforcement authorities as the consequence for auditor misconduct — independence violations, operating unregistered after 2029, or misrepresenting qualifications. Neither bill's coverage specifies penalties for AI companies themselves, because the direct regulatory target is the auditing profession, not the labs.
The honest state of enforcement debate
Critics quoted in coverage of the signing have already flagged these laws as "industry-friendly" — a label earned partly by the fact that Anthropic and OpenAI supported rather than fought them, and partly by the multi-year runway before any deadline bites. That's a fair read held next to SB 1047's immediate compute-threshold mandate. Whether "industry-friendly" means "toothless" is a separate, unresolved question: a licensed-auditor regime with real independence rules (no contingent pay, no auditing your own recent work) is a meaningfully different animal from the informal, marketing-driven "AI audit" services currently sold with no standard behind the term. The test will be what SB 53 or a future bill actually requires audited, and whether the auditor pool SB 813/AB 1405 create turns out to be rigorous or a rubber stamp. Neither outcome is knowable in September 2026 — mark this post for a follow-up once the 2028 criteria and 2029 registry actually exist.
Related on explainx.ai
- AI regulation: EU AI Act and US policy complete guide
- Amodei vs Baker: the $500M line that decides who gets regulated (SB 53 and SB 1047 context)
- California passes data center bills as AI infrastructure faces backlash
- Every 2026 "AI ban" story: what actually got banned?
- The 2026 AI export-control timeline
- Sanders introduces superintelligence ban bill after Anthropic's 10% extinction-risk warning
- California AG Bonta opens investigation into OpenAI and Hugging Face
- Official source: Governor Newsom signs first-in-the-nation AI safeguards
This post reflects reporting and official sources available as of September 12, 2026. SB 813 and AB 1405 were signed September 9, 2026; their substantive deadlines (January 1, 2028 and January 1, 2029) had not yet arrived at publication, and neither bill's full enrolled text was independently reviewed beyond what primary and news sources describe — treat specific procedural details as subject to correction once the chaptered bill text is checked against California's official legislative record.
