California Starts Regulating the People Who Audit AI

California has moved beyond requiring companies to examine the risks of artificial intelligence and has begun regulating the people hired to perform those examinations.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Gov. Gavin Newsom on Wednesday (Sept. 9) signed two bills that California described as the nation’s first framework for independent AI verification organizations and auditors. A day later, he signed a companion chatbot law that makes independent auditing part of the product safety process.

    Together, the laws begin to turn AI auditing from a loosely defined consulting service into a regulated profession with standards for competence, independence and evidence.

    Under SB 813, the California Government Operations Agency must establish criteria for independent verification organizations by Jan. 1, 2028. Applicants will need to disclose their qualifications, methodologies and proposed testing tools. The agency must also consider whether an organization has enough technical expertise and adequate systems for managing conflicts of interest.

    An auditor may accept reasonable payment from the company being assessed. However, compensation cannot depend on the findings. The auditor also must remain operationally and managerially independent from the company and retain control over its conclusions and recommendations.

    The law directs the agency to align its criteria, where practical, with national and international audit and assurance standards. That provision could help move AI assessments closer to the controls used in financial reporting, where independence, documented methods and sufficient evidence underpin credibility.

    The statute does not require every AI company to hire a state-designated verification organization, but it builds the framework that California can use when state law does require an audit.

    AB 1405 addresses the audit market more directly. California must establish an online AI Auditor Registry by Jan. 1, 2029. After that date, an unregistered person or organization generally cannot offer, sell or conduct an AI audit required to assess compliance with state law.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Registered auditors must provide clients with reports describing the audit’s scope, objectives, findings and supporting documentation. Reports must also identify deficiencies, suggest appropriate remedies and disclose limitations, including material gaps in evidence, information, systems or access.

    That access requirement may carry the largest practical consequence for enterprises and their technology providers. A company can commission an independent assessment, but the result may provide little assurance if a vendor withholds the model documentation, system access or operational records needed to test its claims. California’s framework requires auditors to put those gaps on the record.

    The law also limits who can audit whom. Auditors cannot evaluate systems, processes or controls they materially designed or operated. An employee generally cannot audit an area for which that person held material responsibility at the client during the previous 12 months. Violations can result in removal from the registry and referral to the attorney general or another enforcement authority.

    California connected those professional standards to a specific product category Thursday (Sept. 10), when Newsom signed SB 1119, known as Adam’s Law.

    Beginning July 1, 2027, operators must assess child-safety risks before offering a new or substantially modified companion chatbot in California. The legislation connects those assessments to design safeguards, parental controls, disclosures and protections against foreseeable physical, financial, psychological or emotional harm.

    Operators must arrange an initial independent child safety audit by Jan. 1, 2029, or before first making a chatbot available, whichever comes later. Audits generally repeat every two years and may also be required before higher-risk modifications. The lead auditor must certify the results under penalty of perjury.

    The law gives prosecutors enforcement authority and lets children who suffer specified harm, or their guardians, pursue certain civil claims.

    The broader precedent extends beyond chatbots. California has created a model that connects product design, documented risk assessment, independent testing and legal accountability. Financial institutions and FinTech companies could eventually face similar approaches for artificial intelligence used in lending, underwriting, fraud decisions or autonomous payments.

    For platforms selling into regulated sectors, the immediate lesson is straightforward: An AI audit may soon be judged as closely as the system it examines.