1. Home
  2. |Insights
  3. |California Establishes First-in-the-Nation Framework for Verifying Independent AI Auditors

California Establishes First-in-the-Nation Framework for Verifying Independent AI Auditors

What You Need to Know

  • Key takeaway #1

    California is the first state in the nation to regulate who may conduct AI audits, establishing both a mandatory registration regime for all AI auditors and a voluntary tier of government-credentialed Independent Verification Organizations (IVOs).

  • Key takeaway #2

    The laws do not require AI developers, deployers, or operators to obtain an audit as a condition of doing business in California, but an audit can help mitigate legal liability for AI harms, according to one of the new laws.

  • Key takeaway #3

    Days after signing the laws, Governor Newsom issued an executive order directing the accelerated implementation of SB 813 and AB 1405 and contemplating more aggressive measures, including embedding IVOs onsite at frontier AI companies and advancing a government-verified AI “kill switch,” signaling that the current framework may be a floor, not a ceiling.

Client Alert | 5 min read | 10.01.26

On September 9, 2026, California Governor Gavin Newsom signed into law SB 813 and AB 1405, creating the nation’s first regulatory framework for AI auditors. And on September 18, Gov. Newsom signed Executive Order N-9-26 (Order) which moved up by about a year some of the implementation deadlines for SB 813 and AB 1405 and convened an expert group to recommend how the Golden State can strengthen existing AI safety laws.

By establishing an independent auditor infrastructure, the laws build on California’s prior AI legislation, including the Transparency in Frontier AI Act (SB 53), which requires certain frontier AI developers to implement safety frameworks and disclose and report safety incidents. The auditor infrastructure operates on two tiers: a baseline mandatory registration regime applicable to all covered AI auditors, and a voluntary government-credentialed tier for organizations designated as Independent Verification Organizations (IVOs).

Together, the two tiers establish who may conduct covered AI audits, under what standards, and at what level of government-recognized credentialing.

Tier One — AB 1405: Mandatory Registration

Beginning January 1, 2029, no person in California who is not properly registered with the California Government Operations Agency (Agency) may offer, sell, or conduct a covered AI audit—defined under SB 813 and AB 1405 as an audit conducted to assess internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law.

An entity registers with the Agency by providing the business name, contact information, a list of California laws or regulations under which audits are conducted, relevant certifications or accreditations that the auditor possesses, a written description of services that the auditor provides, and a standard operating procedure referencing applicable standards, including those published by the International Organization for Standardization (ISO), and the National Institute of Standards and Technology (NIST), and national auditing and assurance bodies.

Once registered, auditors must update the Agency within 90 days of any change that materially affects the accuracy or completeness of their respective auditor information published by the Agency, retain all audit reports and supporting documentation for at least ten years, and display their registration number clearly and conspicuously on all advertising materials offering or soliciting covered AI audit services. Independence standards are rigorous: auditors may not conduct a covered AI audit where any financial, business, employment, or other interest would reasonably be expected to impair objectivity; may not evaluate their own prior work; and may not assign an individual who held material responsibility for the audit’s subject matter at the auditee within the preceding 12 months.

AB 1405 also establishes guardrails on what an AI audit report must include. Each covered AI audit report must include scope and objectives, results and supporting documentation, remediation measures for identified deficiencies, a description of whether the auditee adhered to internal safety standards, a description of audit limitations, and a signed and dated compliance statement.

Licensed Certified Public Accountants and accounting firms in good standing with the California Board of Accountancy are deemed to satisfy certain independence and reporting requirements, with the Board serving as the coordinating enforcement authority for that population.

AB 1405 authorizes the Agency to investigate alleged violations and provides that a confirmed violation constitutes grounds for removal from the registry and referral to the Attorney General or other appropriate enforcement authority.

Pursuant to the Order, the Agency has until May 1, 2027, to establish an AI Auditor Registry and begin registering auditors.  

Tier Two — SB 813: A Government-Credentialed Tier

SB 813 creates a voluntary tier of government-credentialed AI auditors known as Independent Verification Organizations (IVOs). To receive IVO designation, AI auditors must demonstrate to the Agency expertise in assessing AI risks and identifying the metrics and methodologies that form the basis for such assessments.

The law establishes that, if a company is sued for an alleged “harm” caused by an AI model, the fact that the company performed an audit under this statute “is relevant to, but not conclusive of,” the lawsuit. While the exact meaning of that phrase is unclear, it suggests courts may consider an audit a mitigating factor in such suits.

Pursuant to the Order, the Agency must develop and publish application requirements, designation criteria, and suspension and termination procedures for IVO status by May 1, 2027. The framework will define what AI auditors must demonstrate to qualify for and maintain IVO designation.

One notable feature of SB 813 is its treatment of prior audit work. The Agency must structure its requirements to minimize duplicative compliance obligations, including by allowing reports, assessments, audits, or assurance engagements prepared to satisfy substantially similar requirements to be used to satisfy SB 813’s requirements. This is not automatic equivalency and requires a gap analysis, but it is a significant cost-saving provision for organizations that have already invested in rigorous third-party AI audits under frameworks such as NIST AI Risk Management Framework, ISO 42001, or System and Organization Controls (SOC) 2.

Once designated, an IVO must submit an annual report to the Agency and Legislature, beginning no sooner than 12 months after designation. The reports must cover summaries of IVO’s standards and methodologies, governance changes, funding sources relevant to independence, and any changes to its application information.

Organizations that wish to pursue both tiers of credentialing may do so. IVO designation under SB 813 is a tier built on top of registered auditor status under AB 1405, and the two regimes are not mutually exclusive.

Recommended Next Steps

  1. For AI Developers and Deployers: Make a Documented, Deliberate Decision About Voluntary Audits. The laws do not require an audit, but SB 813 establishes that a company that performs an audit under the law may have some protection if sued for a “model caused harm.”
  2. For AI Auditors: Begin Registration Preparation Now. Beginning January 1, 2029, it will be unlawful in California to conduct a covered AI audit without meeting the laws’ registration and independence requirements, with no grace period or retroactive cure available. Building compliant standard operating procedures, governance structures, and independence policies takes time, and companies should consider moving quickly, even before the registry opens in 2027.
  3. For Investors: Incorporate AI Audit Status into Due Diligence. Whether a target has commissioned a covered AI audit, the framework it was conducted under, what findings were identified, and how deficiencies were remediated may be relevant to assessing litigation exposure and AI governance quality. Unresolved deficiencies or the complete absence of an audit record should prompt targeted follow-up.
  4. Watch for what comes next. The Order directs the Agency to accelerate implementation and calls for national experts to consider more aggressive measures, including onsite IVO embedding at frontier AI companies and a government-verified AI “kill switch.” Companies should thus monitor Agency rulemaking for further developments. In particular, keep these deadlines in mind:
      1. No later than November 16, 2026: The Agency must submit recommendations to the Governor’s office, developed with national experts, on the feasibility and efficacy of onsite IVO embedding at frontier developer labs; independent IVO verification of frontier AI companies’ safety frameworks, transparency reports, and risk assessments; a government-verified “kill switch” for frontier models; and expanded critical safety incident reporting to cover loss-of-control events.
      2. No later than May 1, 2027: The Agency must complete and publicly post IVO application requirements, procedures, and designation criteria.
      3. No later than December 1, 2027: The Agency must establish an AI Auditor Registry and begin registering auditors.

Crowell & Moring will continue to monitor these legal developments. For further information, please contact our team.

Insights

Client Alert | 7 min read | 10.21.26

Securities Law for Entrepreneurs

Do you want your startup to expand and become a major player in your industry? If so, you will most likely need to seek capital from outside investors to help you build infrastructure and fulfill orders....