Why it matters
  • First US state. California became the first US state to require independent third-party audits of AI systems, moving beyond disclosure mandates to mandatory external verification of AI compliance and safety.
  • Two laws, one framework. SB 813 (Sen. Jerry McNerney) creates an accreditation framework for independent AI verification organisations; AB 1405 (Assemblymember Rebecca Bauer-Kahan) establishes a state registry for AI auditors and sets their independence and transparency standards.
  • Newsom’s shift. The signings come two years after Newsom vetoed the tougher SB 1047, which would have imposed direct liability on frontier AI developers — a veto he justified as premature. The new laws take a narrower but more durable approach.

The Two Bills

Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 on September 9, 2026, at a ceremony in Sacramento that the governor’s office described as establishing “first-in-the-nation AI safeguards.” Together, the laws create the institutional infrastructure for independent oversight of AI systems deployed in California — directing that neither the state nor any developer is able to self-certify compliance.

SB 813, authored by Senator Jerry McNerney, establishes a framework through which independent verification organisations can be accredited to assess AI systems against California law. AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, creates a state registry for those auditors and defines standards governing their independence, transparency, and integrity — provisions designed to prevent the appearance of independence without its substance.

What the Laws Require

Together, the statutes mandate third-party evaluation of AI systems for companies developing and deploying AI in California — home to the majority of large AI labs and the largest US market by consumer volume. Unlike the vetoed SB 1047, which would have imposed affirmative safety obligations and liability on frontier AI developers before deployment, SB 813 and AB 1405 operate as audit and accountability mechanisms applied to systems already in the market.

Assemblymember Bauer-Kahan framed the gap the laws address directly: “We cannot expect industry to simply grade its own homework; third-party auditors are essential.” Senator McNerney added that the signing “sends a clear message that California is taking the lead on assessing AI’s safety risks.” The laws apply to developers and to companies deploying AI systems within California’s jurisdiction, a scope that reaches most large US technology firms given the state’s market weight.

Context: What Newsom Signed — and What He Didn’t

The 2024 SB 1047 veto established Newsom’s posture on AI regulation: interventionist on transparency, cautious on pre-market liability for frontier models. SB 813 and AB 1405 are consistent with that position. They create auditing infrastructure without restricting what can be deployed or assigning liability for harms before they occur. The signing also carries a call for federal action: Newsom explicitly urged the federal government to match California’s framework nationally, positioning the state laws as a template rather than a substitute for a federal regime.

California’s approach contrasts with the EU’s, where the AI Act imposed a risk-tier classification system with pre-deployment conformity assessments for high-risk applications. The EU framework has faced implementation delays, most recently pushed to December 2027 for high-risk AI compliance under the Digital Omnibus revision — examined in detail in earlier coverage here. California’s auditor-registry model is lighter and faster to implement, but also narrower in its reach: it requires assessors to exist and be accredited before it can function as intended.