Skip to content

Product1 publisher2 min readPublished

California's AI auditor registry lets each firm declare the standards it audits against

Two now-signed California laws build a registry and a qualifications framework for AI auditors ahead of a 2029 deadline. The audit itself stays voluntary, and what it measures is left to whichever firm sells it.

The Product Desk · Product desk

Photograph accompanying California's AI auditor registry lets each firm declare the standards it audits against
Photo: pymnts.com

What happened

  • AB 1405, from Assemblymember Rebecca Bauer-Kahan, starts a California state registry for AI auditors, with standards for their independence, transparency, integrity and operational conduct.
  • Auditors conducting what the law calls covered AI audits will not be able to operate legally in California after 1 January 2029 unless they are registered and compliant.
  • SB 813 gives California's Government Operations agency until 1 January 2028 to deliver a finalized regulatory framework for independent verification organizations.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The registry limits who may sell a covered audit in California without limiting what the audit examines, so scope remains a private negotiation between the developer and the firm it hires.
  • decision A frontier developer publishing its safety framework has to decide whether to buy an assessment when the only legal obligation is to say whether it bought one.
  • exposure The retention rule keeps an auditor's file on a 2029 engagement, including whatever internal material the developer handed over, in existence until 2039 and reachable by anyone who can compel it.
  • precedent California got there first as a standalone measure while similar proposals spread through other states. The qualification rules drafted for 2028 are the reference text other legislatures start from.

The person who has to answer for this is whoever owns the published safety framework. California's Transparency in Frontier Artificial Intelligence Act requires a developer to disclose its use of third-party assessments in that document, and it stops there: the law does not mandate third-party review [8]. IAPP's Cobun Zweifel-Keegan writes that whether an AI developer ever seeks out an audit remains voluntary for now, "despite headlines to the contrary" [7].

AB 1405 sets out what an auditor has to put on file: any relevant certifications it has achieved, plus a standard operating procedure identifying the standards it uses and the basis for its accuracy, reliability and validity claims [3]. The standards in that procedure are the auditor's own.

Government Operations has to finalize its framework for independent verification organizations by 1 January 2028 [6], and registration becomes a condition of operating on 1 January 2029 [5], so a firm gets 12 months between the finished rules and the deadline [16]. Zweifel-Keegan, who reads the two laws as a two-layered structure for oversight of the auditing marketplace [18], counts 27 months to that deadline [15].

The industry filed the same sequencing complaint from the other side. TechNet, which counts OpenAI as a member, opposed an earlier version of AB 1405 in an industry coalition letter, calling it premature and deficient partly because there is no legal requirement to conduct audits in the first place [12]. OpenAI has since backed four of the new California laws in a post signed by chief global affairs officer Chris Lehane, which promised to push for "mandatory national AI safety requirements" [10]. "The AI policy window is open. We need to act," the company wrote [9]. Anthropic backed AB 1405 and SB 813 a couple of weeks before they were signed [13].

Ask who requires the assurance line item of you: a statute, a countersigned customer contract, or a questionnaire someone forwarded from a deal desk. Then ask whether you can write down the claim being tested and the failure the test would catch, in one sentence, before the auditor's procedure writes it for you.

Nobody and not yet is the common pair of answers right now. The 2029 registry tells a buyer that the seller is registered, independent under the state's criteria, and working to a procedure it filed itself [2][3].

What to watch

  • Whether the framework due from Government Operations on 1 January 2028 defines audit methods or only auditor qualifications.
  • Whether any legislature attaches a mandatory audit requirement to the registry, converting a voluntary market into a compliance one.
  • Whether the procedures auditors file converge on a common standard or stay firm-by-firm.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories