Skip to content

California AI readiness

Selected California AI audit and verification requirements

This page describes selected California measures for independent verification organizations and covered AI audit providers. It does not inventory every California audit, assessment, testing or review requirement that could apply in another context.

Current as of 2026-09-26. Agency implementation continues; the covered audit practice restriction begins January 1, 2029. General information, not legal advice.

In this sectionAI audits

California enacted two AI audit statutes in September 2026. SB 813 creates a state designation program for independent verification organizations. AB 1405 creates an AI Auditor Registry and rules for providers of covered AI audits. Executive Order N-9-26 speeds the agency setup and requests recommendations for possible additional frontier model verification duties. Sources: SB 813; AB 1405; Executive Order N-9-26.

What does SB 813 do?

SB 813 directs the Government Operations Agency to develop requirements, procedures and criteria for designating independent verification organizations. An IVO is an AI auditor designated as having demonstrated expertise in assessing risks from an AI system or model and in identifying the metrics and methods behind that assessment. Sources: SB 813.

In developing the designation criteria, the agency must consider, at a minimum, the organization's ability to assess AI risks and identify the supporting metrics and methodologies, sufficient technical expertise, management of conflicts of interest and financial relationships, and independence from the party assessed, including no operational or management dependence on it. SB 813 separately requires the agency's procedures for suspending or terminating a designation to consider matters including inadequate documentation, conduct that reasonably calls the IVO's integrity, objectivity or competence into question, and cybersecurity lapses. To the extent practicable, the agency must also align its procedures and criteria with existing professional and regulatory audit and assurance standards. A designated IVO must report annually after its first year of designation. Sources: SB 813.

SB 813 addresses the designation framework and the qualifications and reporting of designated IVOs. It states that it does not require a person that develops, deploys or operates an AI system or model to engage an IVO or undergo a covered AI audit as a condition of doing so in California. Any requirement to obtain an audit or other independent review must come from another applicable legal, regulatory or contractual source, and the organization's facts determine whether that source applies. Sources: SB 813.

What does AB 1405 do?

AB 1405 directs the Government Operations Agency to establish an AI Auditor Registry. Beginning January 1, 2029, a person may not offer, sell or conduct a covered AI audit without registering. Sources: AB 1405.

The statute defines a covered AI audit as an audit that assesses internal controls, processes or systems implemented for an AI system or model that are necessary for compliance with state law. Registered auditors must provide information about their methods, standards, services and relevant qualifications. They must also follow requirements concerning independence, objectivity, integrity, documentation, reports and conflicts of interest. Sources: AB 1405.

Those requirements include a self-review restriction. A registered auditor may not conduct a covered AI audit that requires it to evaluate its own work, including a system, process, control, assessment or other subject matter that it materially designed, developed, implemented or operated for the auditee. A registered auditor must also retain, for at least 10 years, the information it provides to the auditee under the statute and the documentation needed to demonstrate the basis of the audit results. Accountants and accounting firms licensed or authorized to practice public accountancy in California are deemed to meet the report and independence requirements when they comply with the applicable professional standards. Sources: AB 1405.

What changed with Executive Order N-9-26?

The order directs the Government Operations Agency to publish the IVO application requirements, procedures and criteria by May 1, 2027. It also directs the agency to establish the AI Auditor Registry and begin specified actions by December 1, 2027. Sources: Executive Order N-9-26.

The order separately asks for recommendations by November 16, 2026 on possible amendments to state law. The requested topics include onsite IVOs at large frontier developers, independent verification of frontier safety materials, an independently tested emergency shutoff and a broader definition of reportable safety incidents. Those topics are proposals for analysis. They are not yet duties imposed on frontier developers. Sources: Executive Order N-9-26.

What do these selected measures require?

SB 813 directs the Government Operations Agency to create the IVO designation program. AB 1405 directs it to create the AI Auditor Registry and regulates who may offer, sell or conduct a covered AI audit beginning January 1, 2029. Executive Order N-9-26 directs earlier agency implementation and requests recommendations. An organization should identify the specific source that requires an audit, assessment, test or review before describing the work as mandatory.

Internal review, assessment and independent audit are different

ActivityPurposeIndependenceTypical output
Internal governance reviewDecide whether a system may be released, changed or continuedPerformed within the organization, with appropriate separation from delivery where possibleapproval, restrictions, findings and action plan
Risk or impact assessmentIdentify processing, benefits, risks, safeguards and residual concerns under a defined method or lawMay be internal or include outside specialistsdocumented assessment and approval record
Technical evaluationTest model or system behavior against defined requirementsMay be performed by the developer, deployer or a specialisttest plan, results, limitations and failures
Independent audit or verificationExamine evidence and reach a conclusion without management or operational dependence on the party assessedRequires defined independence and conflict controlsreport, opinion, findings or verification statement

The Intelligence Coalition recommends naming each activity accurately and reserving "independent" for work performed under defined independence and conflict controls.

What evidence should an organization prepare?

A reliable audit or independent verification engagement generally requires evidence beyond policy statements. The evidence will depend on the system and legal duty, but organizations should expect to produce:

  • a defined audit scope, criteria and period
  • a system and model inventory tied to owners and versions
  • architecture and data flow records
  • risk, impact or privacy assessments
  • testing methods, datasets, results and known limitations
  • release criteria and approval records
  • human review and appeal records
  • monitoring, incident and corrective action records
  • model, prompt, data and vendor change history
  • notices, disclosures and consumer request records where applicable
  • contracts, conflict disclosures and independence safeguards
  • evidence that samples are complete and traceable to the underlying system

This is an Intelligence Coalition readiness recommendation. The exact evidence request must follow the audit criteria and applicable law.

How should organizations prepare for independent review?

Start with the claim

Write down what the organization expects the reviewer to conclude. Examples include that a control operated during a period, that a system met defined release criteria or that a required notice process worked.

Name the criteria

Identify the statute, regulation, contract, standard or agreed control set against which the reviewer will assess the claim. Without defined criteria, a reviewer can provide observations or advisory findings, but the engagement should not be characterized as an assurance engagement.

Preserve versioned evidence

Keep records tied to the system version, period and decision. A current screenshot cannot prove what operated six months earlier.

Test the evidence path

Select a sample decision or output and reconstruct it. The organization should be able to find the input, relevant data, model and rule versions, output, human action, approval and later correction or appeal.

Examine independence before engagement

Review financial terms, other services, employment relationships, management roles and any condition that could affect the auditor's judgment. AB 1405 and SB 813 make independence a central issue. Sources: SB 813; AB 1405.

What remains unsettled

  • The Government Operations Agency has not yet published the IVO criteria or AI Auditor Registry procedures.
  • Executive Order N-9-26 accelerates agency setup, but the statutory restriction on unregistered covered AI audits begins January 1, 2029 unless the law changes.
  • The November 2026 recommendations may lead to bills, regulations or no change.
  • The relationship between IVO designation and auditor registration will need agency clarification.
  • Organizations will need to determine when a review is a covered AI audit and when other professional licensing or assurance standards apply.

Primary sources