Summary

  • California’s AB 1405 creates a mandatory AI Auditor Registry from 1 January 2029, with public registration information, conduct and independence rules, a misconduct channel, removal procedures and ten-year evidence retention.
  • SB 813 separately requires criteria for designating independent verification organizations by 1 January 2028. The laws do not make an audit compulsory for AI developers, do not turn registration or designation into state endorsement, and say a qualifying audit is relevant but not conclusive in a harm case.

Two statutes create different kinds of trust

Governor Gavin Newsom signed AB 1405 and SB 813 on 9 September. The Governor’s announcement presents them as a combined framework for independent third-party evaluation. Read together, however, they do not create one universal California seal. They create two institutional tests with different purposes and deadlines.

AB 1405 governs entry into the business of covered AI auditing. A covered audit is an assessment of internal controls, processes or systems necessary for compliance with state law. By 1 January 2029, the Government Operations Agency must operate a public registry, set annual fees that do not exceed reasonable administrative costs and provide a channel through which natural persons can report misconduct. From that date, an unregistered person may not offer, sell or conduct a covered AI audit.

SB 813 asks a harder but narrower question: which AI auditors have demonstrated enough competence, methods and independence to be designated as independent verification organizations, or IVOs? GovOps must develop the application, qualification and suspension machinery by 1 January 2028. The one-year difference matters. The designation architecture is supposed to precede the mandatory registration market, but the enacted text does not collapse the two into the same status.

The official directory link in this briefing is intentionally unresolved. GovOps is the cabinet-level agency to which both statutes assign the work, and its own institutional description identifies it as the body implementing strategic initiatives across state operations. BTW’s existing directory rows for the California Department of Technology and the State of California describe different or conflicted objects. Naming the missing GovOps entry is more truthful than borrowing another institution’s identity.

Registration is a permission to operate, not a quality medal

An auditor applying to the AB 1405 registry must disclose its business identity and contact information, the California laws or regulations under which it conducts covered audits, relevant certifications, a description of its services and a standard operating procedure. That procedure must identify the standards the auditor uses and the basis for claims about the accuracy, reliability or validity of its protocols. Material changes that affect published information must be reported within 90 days.

The registry will publish the registration number and the information the auditor supplied. The number must also appear clearly and conspicuously on every advertisement offering or soliciting covered-audit services. The registry itself must display a prominent warning: registration does not constitute California’s recommendation or endorsement of the entity. The law repeats that boundary at the end. This is more than legal caution. It prevents a baseline permission to sell a regulated service from being marketed as a state judgment that the provider is superior, trustworthy in every domain or correct in a particular engagement.

AB 1405 does impose substantive conduct. A registered auditor cannot review work it materially designed, developed, implemented or operated. It cannot conduct an engagement when financial, business, employment or other relationships would reasonably impair independence or objectivity. An individual on an audit cannot negotiate employment with the auditee, and someone who held material responsibility at that auditee during the preceding 12 months cannot be assigned to audit the same subject. Reasonable compensation for the audit alone is not treated as a forbidden interest.

The report delivered to the auditee must state scope, objectives, results, supporting documentation, deficiencies and possible remedies where appropriate. It must say whether relevant internal safety standards were followed and disclose unassessed matters, evidence gaps and access limitations. The auditor signs and dates a statement that the work complied with the chapter, then retains the report information and supporting basis for at least ten years.

Those duties are meaningful, but they do not make the registry a public archive of audit outcomes. The statute sends the report to the auditee. It requires GovOps to publish registration information, not each engagement report. The misconduct channel is public-facing, but submitted reports are retained and shared with agencies for enforcement rather than automatically published. A reader looking only at the registration number may therefore know that an auditor is eligible to operate without knowing which systems it reviewed, what it excluded, whether a complaint is pending or what changed after a deficiency.

IVO designation tests capability and independence more directly

SB 813 requires an IVO applicant to provide qualifications, evidence against future criteria, and the benchmarks, technologies, metrics and methodologies it proposes to use. GovOps must consider technical expertise, risk-assessment capability, conflict management and freedom from the assessed party’s operational or managerial control. Payment at a reasonable market rate is permitted, but neither payment nor its amount may depend on the result.

The suspension and termination rules must be able to address standards failures, material misrepresentation, impaired independence, inadequate documentation, conduct calling competence or integrity into question, and cybersecurity lapses. That makes designation more than registration with a different name. It is meant to express a state-administered judgment about demonstrated verification capacity under published criteria.

Yet SB 813 draws its own limits. It does not require a developer, deployer or operator to hire an IVO or undergo a covered audit. It creates no liability solely because a standard was not followed. Publication of criteria does not endorse an AI system or model. In litigation alleging harm caused by AI, the fact that an audit followed an identified standard is relevant, but it does not decide the case.

The designated organization also has an annual reporting duty, beginning no sooner than twelve months after initial designation. It must summarize standards and methods and disclose changes in governance, funding or application information that bear on independence. Trade secrets, cybersecurity, public safety, national security and legal duties may justify redaction. Any published version must, where the underlying concern permits, describe the character and justification of the redaction; the unredacted material must be retained for five years.

The missing join is where badges can outrun facts

The two statutes describe many useful fields but do not expressly require one public record joining them. AB 1405 promises registration numbers and self-supplied registry information. SB 813 promises public designation criteria and recurring IVO disclosures. Neither provision, on its face, requires a reader-facing crosswalk showing whether a registered auditor is also a currently designated IVO, the term or scope of that designation, a pending suspension or removal contest, and the specific engagement behind a commercial claim.

That seam matters because five different assertions can look almost identical in marketing. “Registered” means eligible to offer a covered audit after the 2029 gate. “Designated IVO” should mean demonstrated capability under the criteria then in force. “Audit completed” means an engagement occurred within a stated scope and evidence window. “Compliant” is a conclusion bounded by applicable law, methods and exclusions. “Safe” is a broader claim that neither statute grants automatically.

A useful public assurance receipt would keep those states apart. It could show the registration number and current status; IVO designation and term, if any; standards and methodology version; relevant conflict or funding update; the auditee, system and model version; the California-law scope; evidence cut-off; exclusions and limitations; report date; later correction; and the exact claim that the audit supports. Complaint identities and protected technical evidence can remain private while the status vocabulary and disposition history remain inspectable.

The laws do not require this artifact, so it should not be reported as a feature California has already promised. It is an implementation test. GovOps says it leads statewide AI work through its official GenAI programme. By 2028 and 2029, the quality of that work will be visible in whether two legal regimes become one comprehensible evidence path rather than two disconnected badges.

Heng Lu’s policy-mirror discipline is useful here. A public rule is credible when readers can see who holds authority, what evidence supports a decision and how a wrong state can be corrected. His running-code argument adds an operational standard: judge the institution at the transition points where records change, not only by the language of the framework. Applied to California, the revealing events will be registration, designation, complaint, investigation, suspension, contest, correction and expiry.

The strongest feature of the new laws is that they refuse the easiest shortcut. They do not say an audit proves safety, or that a state number transfers government judgment to every report. Their success will depend on whether the public surface preserves that restraint after the market begins selling trust.

Sources

  1. California AB 1405 — chaptered text
  2. California SB 813 — chaptered text
  3. Governor of California — signing announcement
  4. California Government Operations Agency — mandate
  5. GovOps — statewide GenAI work
  6. Lu Heng — The Policy Mirror
  7. Lu Heng — Running Code Primary
  8. Lu Heng — Why BTW Media Exists