Skip to content

Build1 publisher3 min readPublished

California will bar unregistered AI audits from January 1, 2029

Newsom signed AB 1405 on September 9, giving California's Government Operations Agency until 2029 to publish a registry of AI auditors, complete with registration numbers, annual fees and independence rules for anyone selling a covered audit.

The Engineer · Build desk

Photograph accompanying California will bar unregistered AI audits from January 1, 2029
Photo: startupfortune.com

What happened

  • Newsom signed AB 1405 from Assemblymember Rebecca Bauer-Kahan of Orinda on September 9, 2026, alongside SB 813 from Senator Jerry McNerney of Pleasanton, according to the governor's office.
  • The Government Operations Agency has until January 1, 2029 to put an AI Auditor Registry on its website, and from that same day no unregistered person or company may offer, sell or conduct a covered AI audit in California.
  • The state must give each registered auditor a unique registration number, publish registration information online, set annual registration fees and open a channel for reporting auditor misconduct.
  • An auditor may not take a covered engagement where a financial, business, employment or other relationship would reasonably be expected to impair independence, and staff on the audit may not job-hunt at the client while working on it.
  • OpenAI publicly supported AB 1405 on the day it was signed, and Gizmodo reported that Anthropic backed the same package of bills.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint The 12-month prior-responsibility bar limits who can staff an engagement: an auditor cannot use the person who ran the controls program at the client in the past year, so audit teams will be built from people who need to learn your stack from scratch.
  • decision Firms deciding whether to sell AI assurance in California now choose between the accountancy route, where the Accountancy Act and AICPA standards already carry them part of the way, and building an independence and standards story from nothing.
  • capability A buyer of an AI audit will be able to check a provider against a public state list and a registration number.
  • precedent California licensed the auditor supply before naming the systems that must be audited, which sets up any later mandate to draw from whoever registered by 2029.

Read the definition before the signing statement. A covered AI audit under AB 1405 assesses the internal controls, processes or systems used for an AI system or model, and only where those controls are necessary for compliance with state law [6]. The duty to have such controls has to come from somewhere else. The bill does not order every developer in California to submit every model for a public audit, and it does not settle which systems must be audited, how often, or what happens when an auditor finds something bad [7].

So on that date, a team putting a model into hiring screening or a benefits eligibility queue gets a shorter list of firms allowed to sign the report, and no new audit obligation. startupfortune.com says the registry is meant to raise the quality of audits that already have to happen or that future laws will require [16].

About 27 months separate the September 9 signing from the January 1, 2029 deadline [17].

The independence provisions are where this reaches into staffing. A registered auditor cannot audit its own work [9]. If a consultancy helped design your model risk controls or built your evaluation harness, that firm is out of contention for attesting them. The auditor also cannot assign a person to the engagement who had material responsibility for the audit subject while employed by the audited company during the previous 12 months [11]. The people who understand a controls program best are usually the ones who built it, and that clause keeps the most recent of those hires off the file.

Registered auditors must follow widely recognized standards where available, and licensed accountants or accounting firms can satisfy parts of the law by complying with the California Accountancy Act, the AICPA Code of Professional Conduct and AICPA attestation standards [12]. Only accounting firms get that shortcut. An accounting practice already documents engagement acceptance, independence checks and workpapers against those standards; a model evaluation lab does not, and will have to name whatever standard it follows. I would expect the first registered cohort to lean heavily on firms with existing attestation practices.

Gizmodo reported that Anthropic backed the signing package, and covered the laws under the headline "Newsom Signs AI Industry-Approved AI Regulation Bills Into Law in California" [14]. The companies most likely to be audited supported the rules for their auditors. That does not weaken the independence clauses, but it does mean those clauses were acceptable to the firms they will eventually be used against. Bauer-Kahan said after the signing: "We cannot expect industry to simply grade its own homework; third-party auditors are essential to ensuring AI is safe for our communities and critical infrastructure." [15]

What to watch

  • Whether the Government Operations Agency publishes the registry, the fee schedule and the misconduct process before the January 1, 2029 deadline, and which standards it accepts as widely recognized.
  • Whether a later California statute names specific AI uses whose controls must be audited. Such a statute would create paying work for registered auditors.
  • Whether the first registered cohort is dominated by accounting firms using the AICPA path, or whether evaluation specialists register under other standards.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories