NewsTradingSentimentCalendarCommunityBriefing
Tech

California Creates Rules for Voluntary AI Auditors

By Tech Desk · 2026-09-12 · 3 min read
A wooden gavel resting on a polished desk surface
Illustration: Tradingbird

Two new California laws establish a registry for AI auditors, but the process remains entirely voluntary. This regulatory framework aims to standardize oversight as the industry matures.

California has added two new laws to its books that begin to structure the emerging market for AI auditors. Despite headlines suggesting immediate regulation, the core mechanism remains voluntary. Companies are not yet forced to submit their models to third-party review, but the state is laying the groundwork for a standardized industry. This shift signals a move away from pure self-regulation toward a more formalized accountability structure.

The move comes as federal policymakers and major tech firms adjust their stances on artificial intelligence governance. OpenAI recently signaled support for mandatory national safety requirements, while acknowledging the need for state-level measures in the interim. This legislative activity in California represents a concrete step in that transition, creating a legal framework that auditors must follow if they wish to operate in the state. The primary stake for readers is the increased complexity of compliance for developers and the potential for a more transparent assessment market.

New laws define auditor standards

The legislation, including AB 1405 and SB 813, creates a two-layered structure for oversight. The first layer establishes a state registry for AI auditors. To be listed, these entities must demonstrate independence, transparency, and integrity. They are required to maintain records for ten years and disclose any relevant certifications they have achieved. This creates a baseline of operational requirements that did not previously exist in a unified state framework.

According to reporting by GN technics/ai (en-US), the laws also require auditors to publish standard operating procedures. These procedures must identify the specific standards used and the basis for claims regarding accuracy and reliability. This transparency measure is designed to allow consumers and regulators to understand the methodology behind an audit, reducing the risk of opaque or biased assessments.

Voluntary audits remain the norm

A critical trade-off in this new framework is that seeking an audit is not mandatory. The existing Transparency in Frontier Artificial Intelligence Act requires developers to disclose their safety frameworks, but it does not compel them to undergo third-party review. The new laws regulate the auditors themselves, not the companies being audited. This means that while the marketplace for audits becomes more regulated, the demand for those services remains dependent on corporate choice.

This distinction is important for understanding the current regulatory landscape. Companies can continue to rely on internal assessments without legal penalty, provided they disclose their methods. The new laws only become binding on the auditors who choose to enter the California market. This creates a scenario where rigorous external verification is available and standardized, but not universally required.

Compliance deadline set for 2029

The enforcement timeline provides a significant buffer period. AI auditors conducting covered audits will not be legally able to operate in California unless they are registered and compliant after January 1, 2029. This gives the industry nearly three years to adapt to the new standards. For developers, this means the immediate pressure to hire certified third-party auditors is low, as the regulatory hook for mandatory external review is absent.

Industry groups have expressed mixed views on this timeline. Some, including members of TechNet, have argued that such regulations are premature or deficient, citing the rapid pace of technological change. Others, like Anthropic, have supported the legislation as a necessary step toward a robust safety ecosystem. The result is a regulatory environment that balances immediate flexibility with long-term structural integrity, leaving the ultimate decision to audit in the hands of the companies.

Based on reporting by IAPP, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories