AI Models & Enterprise AI · Updated

California AI auditing bills: what enterprises should ask vendors

California’s SB 813 and AB 1405 create voluntary AI verification and an AI auditor registry, giving enterprise buyers new diligence questions for AI vendors.

AppStack Insider Editorial Team
AppStack Insider Editorial Team
AI-assisted research, human-reviewed • 5 min read
California AI auditing bills: what enterprises should ask vendors

California Gov. Gavin Newsom signed SB 813 and AB 1405 on Sept. 9, 2026, CIO Dive and the Associated Press reported. The laws do not create an audit mandate. They set up a state process for designating independent verification organizations and, from 2029, a registry that auditors must join before offering a defined category of AI audits.

What changed

SB 813 directs California’s Government Operations Agency to designate independent verification organizations (IVOs): entities the agency recognizes as having demonstrated expertise in assessing the risks posed by an AI system or model. According to the chaptered text, the agency must develop application requirements, designation criteria, and suspension and termination procedures on or before January 1, 2028.

AB 1405 requires the same agency to establish an AI Auditor Registry no later than January 1, 2029. From that date, an unregistered person may not offer, sell, or conduct a “covered AI audit,” which the bill defines as an audit of internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law. An auditor may not conduct such an audit if a financial, business, employment, or other relationship would reasonably be expected to impair its independence, and may not seek or accept employment with the auditee while participating in the audit.

Neither law makes audits compulsory. SB 813 states that it does not require anyone who develops, deploys, or operates an AI system to engage an IVO or undergo a covered AI audit as a condition of doing so in California. Some follow-up coverage described SB 813 as creating a state AI standards and safety commission with a certification pathway; the chaptered text instead assigns IVO designation to the Government Operations Agency.

Why B2B teams should care

Many enterprises already take part in voluntary auditing of their AI systems by third-party vendors, CIO Dive reported. What changes is that California now defines who may perform one category of audit, those tied to compliance with state law, and how verification organizations obtain state designation.

For procurement and governance teams, that is a concrete reference point for vendor diligence. Rather than accepting a supplier’s general statement that its system was independently reviewed, buyers can ask whether the reviewer is a state-designated IVO or, from 2029, a registered auditor, and which independence rules applied to the engagement.

Miranda Bogen, chief technologist at the Center for Democracy and Technology, told CIO Dive: “I think this is the first step in what will ultimately be a more complex ecosystem where there are more required or expected audits.” She added that the framework “seems only beneficial, from an information perspective, for enterprises at this point.”

Who is affected

AI developers and model providers are the first group. Frontier labs backed the approach: the AP reported that Anthropic supported the laws, and the Yahoo-syndicated report said Anthropic and OpenAI endorsed the bills before signing. OpenAI said in a blog post that it would prefer independent technical assessments to be required at the federal level, but described California’s laws as a step in the right direction, according to CIO Dive.

Enterprises deploying AI systems are the second. Neither law places a new audit obligation on them; the practical effect runs through governance and procurement processes.

Organizations that want to act as IVOs are the third. They will apply to the Government Operations Agency under the designation criteria SB 813 requires it to develop.

Auditors are the fourth: from January 1, 2029, registration becomes a condition of offering covered AI audits in California.

What teams should check now

Teams do not need to prepare for a universal audit obligation, but they should know where internal approvals rest on unverified vendor claims:

  • Inventory AI systems and vendors where safety, oversight, or compliance claims are accepted largely on supplier documentation.
  • For vendors that already supply third-party assurance, record who performed the assessment and whether that assessor has financial or employment ties to the vendor.
  • Update procurement questionnaires to ask about independent assessments, assessor independence, and the documentation behind reported results.
  • If you sell AI-enabled products, map which existing external assessments cover internal controls for state-law compliance, since that is the audit category AB 1405 regulates.

What remains unclear

  • What the Government Operations Agency’s IVO application requirements and designation criteria will require in practice.
  • Whether future sector-specific rules will require covered AI audits. The Yahoo-syndicated report cited hiring, credit scoring, and health services as examples, but neither law does so now.
  • How widely enterprise buyers will ask for designated or registered assessors while audits remain voluntary; the sources offer no adoption data.
  • How California’s framework will sit alongside any federal rules.

What to watch next

Watch for the Government Operations Agency to publish IVO application requirements and designation criteria ahead of the January 1, 2028 deadline, and for the AI Auditor Registry to open no later than January 1, 2029.

Also watch federal action. When signing the bills, Newsom said that “the scale and potential consequences of this technology demand sustained action from every level of government,” according to CIO Dive, and urged the federal government to develop national AI regulations.

Sources

This article was produced with AI-assisted research and drafting and reviewed by a human editor. All sources are listed above. Read more about how we use AI and our editorial policy.

Spotted an inaccuracy? Email corrections@appstackinsider.com — see our corrections policy.

Related coverage

AppStack Insider Editorial Team

AppStack Insider Editorial Team

AI-assisted research, human-reviewed

AppStack Insider articles are produced with an AI-assisted research and drafting pipeline and reviewed by a human editor before publication. Every article cites its sources. See How We Use AI for the full process.

Don't miss the next market shift

Get our daily AI & SaaS insights delivered straight to your inbox.

By subscribing, you agree to our Privacy Policy.