Dashboard

California AI Audit Laws: What Small Builders Owe

California's SB 813 and AB 1405 create AI auditors and a registry of them. Nothing lands on a small builder today, but procurement will carry it eventually.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
11 September 20261 min read

California AI Audit Laws: What Small Builders Owe

If you sell a small AI product, the useful answer about California's new AI audit laws is this: on the evidence of the signing announcement, nothing lands on your desk today. SB 813 and AB 1405, signed on 9 September 2026, build the machinery for independent AI audits. They create the auditors and the register of who counts as one. They are not, on their face, a blanket instruction that every AI tool must now be audited.

That distinction is the whole post, because the coverage collapsed it fast and a lot of founders spent the weekend assuming a compliance bill had landed on them.

What the two bills actually do

From the Governor's office announcement:

  • SB 813 (Senator Jerry McNerney) establishes a framework for independent verification organisations that can assess AI systems and models for compliance with state law.

  • AB 1405 (Assemblymember Rebecca Bauer-Kahan) creates a state registry for AI auditors and sets standards for their independence, transparency and integrity.

Read together, they are supply-side. California is answering the question of who is qualified to audit an AI system before it answers the question of which systems must be audited. The announcement does not give effective dates for either bill, which is itself informative: the registry has to exist before anyone can be required to use it.

Why this still reaches you eventually

Not through the statute. Through procurement.

The moment a recognised auditor register exists, it becomes the thing a buyer's legal team points at. This is exactly how SOC 2 spread: never a legal requirement for a five-person company, and yet every five-person company selling to an enterprise ends up paying for one, because a procurement form asked and there was no other box to tick. Anyone who has been through a client security review for an AI product will recognise the pattern immediately.

So the realistic timeline for a solo founder or a small agency is not a compliance deadline. It is the first RFP that asks whether your model has been independently verified, and whoever asks will be a California-exposed enterprise or a public body.

What is worth doing now, and what is not

Not worth doing: hiring an auditor. The register does not exist yet, and anyone selling you a California AI audit this month is selling you something the state has not defined.

Worth doing, because it is cheap and it is what an audit would ask for anyway:

  1. Write down what your system does. Which model, which version, what it decides, what a human reviews. If you cannot describe your own inference path in a paragraph, an auditor certainly cannot.

  2. Keep a record of use. Timestamps, inputs, outputs, who overrode what. The single most expensive gap in every audit is the one where the logs were never kept. Our notes on keeping an audit trail of AI use cover the minimum viable version.

  3. Know your vendors' answers. Most of what an auditor asks about a small AI product is really a question about the model provider behind it. Vetting an AI vendor before you build on them saves the scramble later.

  4. Do not wait for one rule. Colorado, the EU and now California are each building different machinery on different clocks, and none of them will harmonise for you.

The honest uncertainty

Two things are unresolved and you should treat anyone who states them confidently with suspicion. First, the scope: which systems will eventually be required to submit to independent verification, and at what risk threshold, is not settled by these bills. Second, the cost: nobody knows what an audit from a registered California auditor will price at, because no such auditor has been registered yet.

What is settled is direction. Independent third-party assessment of AI systems is moving from a voluntary signal to formal infrastructure, and the general trend across AI risk and regulation is toward proving your claims rather than making them. If you build in a way that could survive an audit, the regulation arriving later is somebody else's fire drill. For the neighbouring rules already in force, see our breakdown of the Colorado AI chatbot law and the EU AI Act transparency rules.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.