The California State Capitol dome in Sacramento against a clear blue sky, with the American and California state flags flying beside it.
← Back to Blog
AI Governance

California Just Built a Market for AI Auditors

Head portrait of Alex Goryachev
Alex Goryachev·September 12, 2026·5 min read

Two laws signed September 9 create a state registry of AI auditors and a legal path for independent organizations to verify AI systems against California law. The design lets outside technical expertise keep flowing in as the technology changes.

Key Takeways

  • California's SB 813 and AB 1405, both signed September 9, 2026, create a third-party AI verification framework and a state registry of AI auditors with standards for independence, transparency, and integrity.
  • The state set the terms of trust and let a private market of qualified verifiers form around them, which keeps technical depth entering the system continuously.
  • The half-life of skills applies to anyone evaluating AI systems, which is why a registry that requalifies auditors holds up better over time than a fixed roster of experts.
  • For any company deploying AI, the practical question is who inside the organization could judge whether an independent auditor's findings are correct.

As of September 9, California has a state registry for AI auditors. Independent organizations can now examine an AI system and verify whether it follows state law. Governor Gavin Newsom signed the two bills that create it. SB 813, from Senator Jerry McNerney of Pleasanton, sets up the third-party verification framework. AB 1405, from Assemblymember Rebecca Bauer-Kahan of Orinda, establishes the registry of AI auditors. It sets the standards they have to meet on independence, transparency, and integrity. The state describes the combination as first in the nation.

That is the news. The design choice underneath it is the part worth studying. It applies well beyond California.

California licensed a profession into existence

Consider what the direct approach would have required. To inspect AI systems itself, a state would need engineers who can read model evaluations and probe a system's behavior under pressure. They would need to hold their own against the teams that built it. Those engineers are the most competitively recruited people on earth right now. No state payroll in the country is going to win that bidding war. No legislature should be asked to try.

So these two laws do something more durable. They set the terms of trust and let a market of qualified outsiders form around them. The state defines what independence means. It defines what an auditor has to disclose, and what it takes to sit on the registry. Verification organizations then compete to clear that bar, and keep clearing it. The technical depth stays where technical depth naturally accumulates. The authority to define credibility stays with the state.

Public institutions have made this move before, with financial auditors and with clinical laboratories. California applied it to artificial intelligence first. The state defines credibility. The market supplies the expertise.

AB 1405 spells out what that credibility actually requires. Starting January 1, 2027, an AI auditor has to enroll with the state and disclose real qualifications. The conflict-of-interest rule has teeth: an auditor cannot review a company it worked for in the prior year. It cannot take a job with a company it just audited for a full year afterward. Every completed audit gets filed with the state, kept on record for at least a decade.

A registry does not need California to out-recruit the AI industry for talent. It only needs California to decide who gets to be trusted, and that decision moves at the speed of law, not the speed of hiring.

The half-life of skills applies to the people doing the checking

Here is the harder problem the registry has to solve over the next decade. Anyone qualified to evaluate a frontier AI system today is working from knowledge with a short shelf life. Evaluation methods that were current 18 months ago miss behaviors that today's systems display routinely. This is the half-life of skills showing up in an unusual place. It shows up in the expertise of the people we appoint to judge the technology, not just in the jobs the technology is reshaping.

A registry absorbs that kind of change well. Auditors requalify. They answer to standards the state can revise as the systems move. The knowledge refreshes because the people carrying it keep re-entering through a door the state controls, at whatever pace the field itself develops. Every institution that writes rules, public or private, works on a longer clock than a model release cycle. These laws put that fact into the design instead of fighting it.

The audit reaches the school district and the hospital

Take a school district that buys an AI tool to flag which students need reading support. The vendor's brochure says the model was tested for bias. A parent has no way to check that claim. Neither, in any practical sense, does the assistant superintendent who signed the contract. Under a registry system, someone independent, with a name and a license on the line, can look. Most parents will never read an audit report. What changes for them is that one exists, and that a qualified person can be held responsible for what it says.

That is the whole point of building verification as a profession. It moves accountability from a marketing document to a human being with something to lose.

The question worth asking inside your own company

If you deploy AI in California, the practical work starts long before any auditor knocks. Two questions keep coming back in my advisory work, and neither one is technical. Who inside your organization could read an independent auditor's findings and tell whether they are right? And if the honest answer is your vendor, what happens on the day the vendor's interests and yours point in different directions?

Good AI governance works best when the checking is continuous, and when somebody in-house can evaluate the checkers. A registry of active auditors makes the first part possible. The second part is a hiring and retraining decision. It sits entirely with you, and it is the one most organizations defer.

Rules written for a slower world are the default condition of nearly every institution right now, public and private. I have come back to that condition twice this month already, once on who gets to stop an AI agent and once on the standard that will say who an agent is. This law answers a third version of the same question: who gets to check an agent's work before it becomes a problem. Your own AI policy was probably written against a model generation that no longer exists. Newsom, McNerney, and Bauer-Kahan put a mechanism into statute that is built to keep absorbing new expertise as it arrives. The rest of us get to decide whether our internal policies are built to do the same thing, or just built to survive one review.

California built the door. Whether real expertise walks through it depends on enough people deciding this work is worth a career. It also depends on enough executives deciding it is worth paying for. If you sit on either side of that, here is the question I am asking myself this week: what would it take for someone outside your company to verify what your AI actually does? Take it into your next leadership meeting. And if you see this differently, I'm easy to find.

How is an AI audit different from a financial or security audit?

A financial audit checks records that hold still once they are written. An AI system keeps changing as it is retrained, updated, and wired into new data, so verification has to test how the system behaves rather than confirm what a document claims. That is why AB 1405's standards concentrate on the auditor's independence and integrity, since more of the weight falls on the auditor's judgment.

What can a company do now to prepare for third-party AI verification?

Start with evidence: records of what data trained or fed each system, what evaluations were run and when, and who approved the deployment. That testing history is what an independent verifier will ask for, and it is usually far harder to assemble after the fact than the vendor paperwork most organizations already keep.

Here is what makes Alex a credible voice on this topic: Alex Goryachev advises the California State University system on AI governance, giving him a direct view into exactly the kind of public-institution process that SB 813 and AB 1405 now put into law, and he shaped Cisco's $1.1 billion innovation portfolio across nearly 20 years before that.

Bringing AI verification or governance questions to your leadership team this quarter? Book a conversation →

← Back to Blog
Head portrait of Alex Goryachev
Alex Goryachev

WSJ-bestselling author · Former Managing Director of Innovation, Cisco · Advisor, CSU AI Working Group · LinkedIn Top AI Voice

Work with Alex

Bring this thinking to your organization

Alex works with executive teams at global enterprises on AI strategy, governance frameworks, and organizational readiness. Available for keynotes, C-suite workshops, and advisory engagements.