California Creates an AI-Auditor Registry—but Registration Starts Later

California Governor Gavin Newsom signed SB 813 and AB 1405 on September 9, 2026, creating two distinct systems for independent assessments of artificial intelligence. SB 813 covers state-designated verification organizations; AB 1405 establishes a registry and operating rules for auditors performing a defined class of California compliance audits.
Neither law means that every AI developer or vendor serving California must commission an audit now. The registry is not yet the gateway for offering covered audit services, and the state still has to build the designation and registration machinery. The Associated Press account likewise distinguishes between planned rules for independent evaluators and a future registry for financially independent auditors.
SB 813 creates a designation for verification organizations

SB 813 establishes the status of independent verification organization, or IVO. An IVO is an AI auditor designated by the California Government Operations Agency after demonstrating expertise in assessing risks posed by an AI system or model and identifying the metrics and methods supporting that assessment.
Under the chaptered SB 813 text, the agency must develop and publish application requirements, qualification criteria, and procedures for suspending or terminating an IVO designation by January 1, 2028. The application framework must cover an organization’s qualifications, proposed benchmarks and methodologies, and documentation that allows the agency to verify its claims.
The statute tells the agency what its eventual criteria must examine. Those factors include technical expertise, management of conflicts and operational independence from the assessed party. An IVO may receive reasonable market-rate compensation, but neither payment nor its amount may depend on the assessment’s outcome.
The agency must also convene working groups that include engineers from competing AI companies and AI-safety experts. Once organizations are designated, they will have continuing reporting duties concerning their standards, methodologies, governance, funding and material changes to their applications.
AB 1405 regulates covered AI-audit services

AB 1405 addresses a different point in the market: who may offer a covered AI audit. That term means an audit examining controls, processes or systems implemented for an AI system or model that are necessary for compliance with California law. It is narrower than every technical evaluation, red-team exercise or voluntary safety review an AI company might purchase.
The chaptered AB 1405 text requires the Government Operations Agency to establish the public registry, annual fee structure and misconduct-reporting mechanism no later than January 1, 2029; beginning on that date, an unregistered person may not offer, sell or conduct a covered AI audit, and an auditor cannot assign someone who held a materially relevant position with the client during the preceding 12 months.
Registration will require business and contact information, a list of the California laws or regulations under which the auditor conducts covered audits, relevant certifications or accreditations, a description of services and standard operating procedures. Registered auditors must also use appropriate recognized industry standards where available and give the audited organization a report covering scope, objectives, results, supporting evidence, deficiencies, possible corrective measures and material limitations.
Some independence duties are already written into the statute rather than awaiting an agency standard. A registered auditor cannot evaluate material work it designed or operated, accept an engagement when a financial or business relationship would reasonably impair objectivity, or pursue employment with the audited organization while participating in the engagement. The law also requires independent professional judgment and personnel collectively competent for the audit’s subject and scope.
The two-law implementation matrix

- Verification organizations: SB 813 creates the IVO designation, while the agency must still produce the application, qualification and removal framework.
- Auditor registry: AB 1405 establishes the registry in law, but the agency must build the public listing, registration-number process, fee system and misconduct channel before registration becomes compulsory for covered services.
- Independence: SB 813 directs the agency to turn statutory factors into IVO qualification criteria. AB 1405 places baseline conflict, self-review, employment, judgment and competence restrictions directly in the law.
- Administration: The Government Operations Agency runs both systems. The California Board of Accountancy has a complaint-investigation role when the matter involves a qualifying accountant or accounting firm.
- AI vendors: SB 813 expressly declines to make use of an IVO or completion of a covered audit a condition for developing, deploying or operating an AI system in California. AB 1405 regulates providers of covered audits; it does not independently order every AI developer or deployer to buy one.
- Timeline: The IVO framework is due in 2028. The registry deadline and prohibition on unregistered covered-audit services arrive in 2029.
Future agency work does not erase the rules already in statute
The distinction between implementation and formal rulemaking matters. SB 813 requires the agency to develop and publish criteria and procedures, but its text does not say that every component must be created through a separate regulation. Bloomberg Law describes SB 813 as a voluntary designation program whose qualification criteria and procedures remain to be developed by the agency.
AB 1405 expressly permits the agency to adopt regulations reasonably necessary to implement the law. That authority is discretionary, while the command to create the registry and its associated mechanisms is mandatory. The statute itself already supplies the definition of a covered audit, the future registration condition, required disclosures, core report contents and baseline independence duties.
For operators, the present result is therefore limited but concrete. California has enacted the legal architecture and assigned the Government Operations Agency responsibility for completing it, while vendors remain outside any universal audit mandate created by these two measures. What comes next is administrative: publication of the IVO criteria and procedures, followed by an operational registry through which covered AI-audit providers can register before the prohibition takes effect.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.