You Can't Backfill an Audit Trail
On September 9, Governor Newsom signed two bills that got a fraction of the attention the same week's model releases did. Neither one regulates artificial intelligence. They regulate the people who check it.
SB 813, from Senator Jerry McNerney, creates a category called an independent verification organization — an AI auditor that the state has designated as competent to assess the risks of a given system. California's Government Operations Agency has to build the application requirements, the qualification criteria, and the suspension and termination procedures on or before January 1, 2028. AB 1405, from Assemblymember Rebecca Bauer-Kahan, builds the registry those auditors sign into. Starting January 1, 2029, an unregistered person cannot offer, sell, or conduct a covered AI audit in California. Registered auditors get a number they have to display on their advertising. They keep their working papers for at least ten years.
The votes were not close. The Senate passed SB 813 37-0 and the Assembly 53-4. Anthropic backed both bills; OpenAI supported all four AI bills California moved that week.
Read the independence rules and you can see what this is modeled on. An auditor cannot evaluate a system they designed or operated. They cannot audit their own work. They cannot be seeking employment with the organization they are auditing during the engagement. Compensation is allowed, but it cannot depend on what they find. That is financial-audit architecture, transplanted. Somebody in Sacramento decided that AI assurance should look like the accounting profession rather than like a certification badge you buy.
The part that sounds like it lets you off the hook
None of this makes an audit mandatory.
That is not a loophole — it is the design. The International Association of Privacy Professionals' Cobun Zweifel-Keegan made the point plainly: California is building the infrastructure for AI audits before it has decided what will be audited or when. The standards themselves don't exist yet; GovOps doesn't owe them until 2028. SB 813 goes out of its way to say the chapter does not establish liability solely for failing to meet a standard under it.
So a hospital in Fredericksburg running an intake assistant, a county deploying a permitting chatbot, a university using an admissions screening tool — none of them are required by this to do anything, this year or in 2029. If your read is "California problem, later problem," the statute will not argue with you.
Here is why I'd argue with you anyway. It has nothing to do with California.
What an audit actually looks at
AB 1405 defines a covered AI audit as an assessment of "internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law."
Read that again, slowly. Controls. Processes. Systems implemented for. Not the model.
That distinction is the whole thing. Almost none of the organizations reading this build models. You buy them — from Microsoft, from Epic, from whoever sold you the scheduling platform that grew an AI feature in a release note you didn't read. You cannot be audited on the weights inside a model you licensed, and no auditor is going to try. What can be examined is the part you own: what you deployed, where it touches a person, what you told that person, who reviewed the output, and whether anyone was watching when it drifted.
That is a record. And a record has a property that policies and platforms do not: it is a byproduct of how you already work, or it does not exist.
You can write an AI governance policy in an afternoon. A good consultant can write you a better one in a week. What nobody can produce on demand is eighteen months of evidence that a human being reviewed the output before it reached a patient, a constituent, or an applicant. You either logged it as you went or you didn't. The ten-year retention requirement on the auditor's side is a quiet signal about the timescale the state has in mind, and it isn't a quarter.
This is the same failure mode organizations hit with accessibility, then security questionnaires, then data processing agreements. The requirement arrives as a document request. The document is easy. The evidence behind it takes two years.
Three artifacts, not a program
I am not going to tell you to stand up a governance function. Most of the organizations we work with have between four and forty people who could plausibly own this, and all of them are busy. The useful version is smaller than it sounds.
An inventory. One list: every AI feature currently touching your work, including the ones that arrived inside a tool you already paid for. Vendor, what it does, what data it sees, who turned it on. Most organizations that write this list for the first time are surprised by its length, and the surprise is the finding.
A disclosure record. What you have told people about AI in your service — on the site, in the intake form, in the chatbot's first message — and when that language changed. California's chatbot disclosure law took effect this January; more states are following. The question an auditor asks is not "do you disclose," it is "since when," and that is a versioning question, which means it is a website question.
A review trail. For anything AI-generated that reaches a member of the public, some durable record that a named human looked at it before it went. It does not have to be a platform. It has to be durable, timestamped, and legible to a stranger who does not work for you — because the independence rules guarantee the reader will be a stranger.
Our own version of this is unglamorous: every change to a client system arrives as a pull request with an author, a reviewer, a timestamp, and a description of what changed. We did not build that to be audit-ready. We built it because small teams moving fast need to know who did what. The audit-readiness is a side effect, which is the only reliable way to get it.
What I can't tell you
The standards don't exist. GovOps has until 2028 to write them, and what they'll say about a county government using a licensed tool is genuinely unknown right now. Anyone selling you "California AI audit compliance" this month is selling you their guess about a document that hasn't been drafted.
It's also one state, and Virginia is not California. The honest case is not that this law will reach you. It's that California has now defined what an AI audit is — an examination of internal controls, conducted by someone with no relationship to you, who keeps the file for a decade. That definition will get borrowed. Definitions always do.
The deadline that matters isn't 2029. It's the first time a payer, a grantor, a board, or a journalist asks what your organization does with AI and who checks it. On that day your answer is whatever record already exists. There is no version of this where you start the trail after the question.
Sources
- SB 813, Independent verification organizations — chaptered September 9, 2026
- AB 1405, Artificial intelligence: auditors: registration — chaptered September 9, 2026
- Office of the Governor, "Governor Newsom signs first-in-the-nation AI safeguards to protect Californians", September 9, 2026
- Senator Jerry McNerney, "Legislature Approves McNerney's Landmark Bill to Assess Artificial Intelligence Safety Risks", August 30, 2026
- PYMNTS, "California Starts Regulating the People Who Audit AI"
- IAPP, "A view from DC: What will all these AI auditors be auditing?"
- Transparency Coalition, "California Gov. Newsom signs two bills to create nation's first AI auditing framework"
