What California’s AI Assurance Laws Signal for Organizations Building AI
A self-declared auditor with no defined method, no technical depth, no context, and no accountability can still take on an AI audit today, and an organization that hires one usually finds that out only after the damage is done. On September 9, California closed that gap. AB 1405 and SB 813 became law, making California the first state with a complete framework for independent AI assurance, effective January 1, 2027.
I worked on both bills over the past fourteen months, directly on AB 1405 and through coalition work on SB 813. Here’s what the two laws do, what they mean for organizations building AI, and where A-LIGN fit into getting them passed.
What is AB 1405?
AB 1405 holds the individual practitioner accountable. It directs the Government Operations Agency to have an AI Auditor Registry running by January 1, 2029, and from then on no one can offer or perform a covered audit without being registered. Registered auditors have to display their registration number on their advertising, they can’t pursue employment with a client mid-engagement or take work where their own interests would compromise their objectivity, every covered audit ends in a signed and dated report, and their employees get whistleblower protection. The Agency can investigate, pull a registration, and refer a case to the Attorney General.
What is SB 813?
SB 813 sets the standard instead of monitoring the practitioner. It creates the California Artificial Intelligence Standards and Safety Commission, whose seats will be filled by July 1, 2027. The commission has two jobs: write assessment standards in two tiers, a minimum compliance tier and an advanced safety tier, and set the criteria for designating Independent Verification Organizations (IVOs). To earn that designation, an IVO must show it can evaluate a system’s safety, efficacy, reliability, security, and robustness, identify foreseeable risks, staff the work with qualified people, and manage its own conflicts of interest. Participation is voluntary, and an IVO attestation will not shield anyone from liability. Its value depends on how much the market trusts the organization that issued it.
What this means for organizations building AI
I testified in support of AB 1405 before the Senate Judiciary Committee, and I represented A-LIGN in founding PACT AI, the coalition that helped shape SB 813. The same gap I described to lawmakers is the one A-LIGN’s AI governance practice exists to close: an audit only means something when it comes from a defined method and real accountability, not a title someone gave themselves.
California’s framework is a preview of where AI regulation is headed: independent verification, backed by defined standards and enforceable accountability. AB 1405 and SB 813 apply directly to a narrow set of California-mandated audits for now, but that scope is written to grow, and the standards the commission writes will likely shape how AI assurance gets defined well beyond California.
Legitimacy in this market tends to go to whoever moves first, and ISO 42001 is how organizations get there before the commission writes a single standard. It doesn’t satisfy SB 813’s IVO criteria on its own, but it gives organizations a documented method, clear internal accountability, and an evidence trail, rather than assurance nobody can back up. That’s a foundation you build once, not a program you start from nothing once a covered audit becomes mandatory, or rebuild every time another state passes its own AI law. The organizations doing that work now are the ones that will have an answer ready when a customer, an auditor, or a regulator asks for one.
Reach out to our team to get started with ISO 42001 and build the AI governance foundation your organization needs.





