Skip to main content
v2026.11,858 entries · CC-BY 4.0

Editorial · CASRAI · Compliance and regulatory

California Creates the Country’s First AI-Auditor Registry

California became the first state to require independent, registered AI auditors when Governor Newsom signed SB 813 and AB 1405 on September 9, 2026. A distinct development from CASRAI’s recent AI-incident coverage — and a real-world case for NIKOLAI’s Evaluator Independence element.

Published 20 Sept 2026· 5 minute read

Ask CASRAI · free to try

Ask about this story

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

CASRAI is the reference for research administration — bookmark it for the next question.

On September 9, 2026, Governor Gavin Newsom signed two bills that, taken together, do something no other state has done: put California in the business of formally registering the people and organizations who independently audit AI systems. Senate Bill 813, from Senator Jerry McNerney (D–Pleasanton), establishes what the Governor’s office calls “a first-in-the-nation framework for independent verification organizations that can assess AI systems and models for compliance with state law.” Assembly Bill 1405, from Assemblymember Rebecca Bauer-Kahan (D–Orinda), creates the registry itself — a state list of AI auditors, with standards attached for their independence, transparency, and integrity, intended to give California “a mechanism for credible third-party auditing” that can identify risks, verify a developer’s claims, and hold AI companies accountable rather than leaving compliance to self-assessment.

This is worth being precise about, because it is easy to file under the wrong story. It is not a new incident, a new model release, or a new enforcement action — it is a state legislature building the institutional plumbing (a registry, an independence standard, a verification framework) that decides who gets to say, credibly, whether an AI system does what its developer claims.

What the two bills actually do

The Governor’s office has not yet published implementing regulations or an operative date beyond the signing itself, and CASRAI has not been able to verify a specific registry-opens-for-applications date as of this writing — readers who need that detail for compliance planning should check the bill text and any forthcoming California Department of Technology or Government Operations Agency guidance directly, rather than relying on early press coverage. What is confirmed, directly from the Governor’s own September 9 announcement, is the shape of the two-bill package:

  • SB 813 sets up the framework an organization has to qualify under to act as an independent AI verifier — the mechanism by which a third party can assess whether a given AI system or model complies with state law, rather than a developer marking its own homework.
  • AB 1405 is the registry itself: a formal state list of AI auditors, paired with standards governing their independence (so an auditor isn’t financially or organizationally entangled with the company it’s auditing), their transparency, and their integrity.

Read together, the two bills are doing for AI auditing roughly what licensing boards and independence rules do in other assurance professions: not just saying “audits should happen,” but defining who is allowed to call themselves a qualified auditor and what has to be true about them before they can.

A distinct story, not a sequel to September’s incident cluster

CASRAI published two other frontier-AI-safety pieces this same week: a look at five separate AI-incident stories that broke in quick succession in September 2026 (most recently updated with reporting through September 19), and coverage of the UK AI Security Institute’s unsanctioned-agentic-AI incident report, published today, September 20. Both of those pages are same-day baselines — there has not been enough elapsed time for either to have a genuine follow-up yet.

SB 813 and AB 1405 are not that follow-up. They are a separate, distinct development: a state legislative action on AI-auditor infrastructure, not a response to any of the specific incidents covered in that cluster. Neither bill was drafted in reaction to the Gemini, OpenAI, or Anthropic stories from earlier in the month, and this piece is not treating it as if it were. The connection worth drawing here isn’t to any single incident — it’s to the broader question that incident cluster piece raised about discovery methods: who catches an AI system doing something it shouldn’t, and on what authority. California just answered part of that question for its own jurisdiction by deciding who gets to be a credentialed answerer.

CASRAI editorial note: how this lands on NIKOLAI

CASRAI’s own NIKOLAI project — an independent, unendorsed reference vocabulary for frontier-AI-safety terminology, not a standard adopted or endorsed by any lab, regulator, or evaluator — already has an element built for exactly this kind of question. Evaluator Independence and Conflict of Interest, part of NIKOLAI’s Transparency and Review track (N8), defines “a record of declared financial, organisational and personal relationships between an evaluator and the developer being evaluated, and the independence test applied to clear the evaluator for the engagement.”

That element currently maps, as shadow rows only, to seven existing organizations and frameworks — Anthropic’s Responsible Scaling Policy, the EU’s GPAI Code of Practice, METR, the Frontier Model Forum, the AI Evaluator Forum, and two pieces of pending US federal legislation. Every one of those rows is explicitly marked as a shadow mapping: CASRAI’s own read of how an organization’s practice lines up with the element, not something that organization has reviewed or agreed to. As NIKOLAI itself states on that page, no lab, evaluator, or regulator named on a shadow row has declared, endorsed, or been consulted on it — and that rule applies here too. This piece is not claiming SB 813 or AB 1405 currently appears in NIKOLAI’s crosswalk. As of this writing it does not; the law is eleven days old, and NIKOLAI’s element pages are not auto-updated from legislative feeds.

What is fair to say editorially is this: California’s AB 1405 registry is a real-world instance of exactly the accountability structure the Evaluator Independence element was built to describe — for the first time, a state government is formally registering and setting independence standards for the organizations that get to independently audit AI systems, rather than leaving that role undefined. That makes SB 813/AB 1405 a strong candidate for a future NIKOLAI Evaluator Independence crosswalk row, given the direct topical overlap between what the element documents and what the registry does. CASRAI has not added that row yet; this note is a flag for a future update, not a claim that the mapping already exists.

Sources

California Governor’s Office, “Governor Newsom Signs First-in-the-Nation AI Safeguards to Protect Californians” (gov.ca.gov, published September 9, 2026 — primary source for bill numbers, sponsors, and the description of what each bill does). Secondary confirmation via contemporaneous coverage from Transparency Coalition and SSBCrack, both dated September 9–12, 2026, describing the same signing and registry framework.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →