I have spent my entire adult life trusting certificates I have never once read properly.
The card behind scratched plastic in the elevator. The letter grade taped inside a restaurant window. "Licensed and insured" painted on a van by a man who then spent four hours under my sink. In three countries I have glanced at each and felt the same small, specific relief — a thing handled by somebody other than me.
Here is what I never separated out, and I suspect you have not either. A certificate can make two completely different claims that look identical from a distance. It can say somebody went and checked this. Or it can say the person who would do the checking is qualified to do it. That is the distance between a verdict and a résumé — and I have read the second as the first for about thirty years.
California has just built one of those certificates for artificial intelligence. It is the second kind — and the statute admits it, in a sentence almost nobody quoted.
Two bills, one apparatus, and the sentence nobody quoted
On September 9, 2026, Governor Gavin Newsom signed SB 813 and AB 1405 — two items in a wave of privacy and AI bills that reached his desk at the end of the session.
SB 813, from state Senator Jerry McNerney, tells the Government Operations Agency to build an approval process for what the law calls "independent verification organizations" — IVOs, the licensed AI auditors — and to publish the application criteria on or before January 1, 2028. It is now Chapter 179 of the 2026 statutes.
AB 1405, from Assemblymember Rebecca Bauer-Kahan, supplies the teeth. The agency must establish an AI Auditor Registry, and then: "Beginning January 1, 2029, a person shall not offer, sell, or conduct a covered AI audit unless the person is registered with the agency." That one is Chapter 178.
So far, so orthodox.
Now the sentence. SB 813's chapter lists things it expressly does not do, and third on that list is this: it does not require anyone who develops, deploys or operates an AI system or model "to engage an IVO or to undergo a covered AI audit as a condition of ... operating an AI system or model in this state."
Not a loophole somebody found. An affirmative disclaimer, written in on purpose.
And a "covered AI audit" is defined by pointing outward: an audit assessing the "internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law." The controls have to be ones some other law already requires. Which other law? Hold that thought.
AB 1405 goes further still. It tells the agency to publish, on the registry itself, "A statement prominently disclosing that registration by an AI auditor does not constitute recommendation or endorsement of that entity by the State of California."
Read that next to the card in my elevator. California will publish a list of people permitted to check, with a notice on top saying the list is not a recommendation — and no general law saying anyone must call them.
So where was the demand supposed to come from? California's frontier transparency law, SB 53, makes the largest developers publish a safety framework describing how they use third parties to assess the potential for catastrophic risks. Describing. Two days after the signing, Cobun Zweifel-Keegan of the IAPP drew the distinction: that law "does not mandate third-party review or other accountability." Whether an AI developer ever seeks out an audit, he wrote, "remains voluntary — for now — despite headlines to the contrary."
He was not inventing a straw man: the CBS station in Sacramento headlined its report "California adopts new AI laws requiring independent audits, assessments," while the story underneath said only that the laws set what the governor's office calls "the nation's first standards for independent third-party audits." Standards for audits — not a duty to have one. The trade press got closer: these laws "build the regulatory plumbing that future, harder rules will run through."
Plumbing is a good word for it — and plumbing is useless until somebody turns on a tap.
Then, on Friday, the governor moved the dates
On the morning of September 18, 2026 — nine days after the signing — Newsom issued Executive Order N-9-26.
It accelerates. The order tells the Government Operations Agency to finish the IVO criteria "No later than May 1, 2027," eight months ahead of the statute. Fathom, the nonprofit that sponsored SB 813 — an advocate, not a neutral read — says it "moves up the deadline ... from January 2028 to May 2027." The registry build-out moves too: application procedures by next May, then "begin implementing related requirements by the end of 2027."
Here is the asymmetry, and it is the entire piece. The order accelerates subdivision (a) of section 11549.82 — where the state builds the registry. It does not move section 11549.82.5, where unregistered auditing becomes unlawful. That date is still January 1, 2029.
The apparatus now arrives early. The prohibition arrives on schedule. The requirement to be audited does not arrive at all.
One more paragraph is the most interesting thing in the order, provided you read it for what it is. By November 16, 2026, the agency must send the governor recommendations "addressing the technical feasibility and potential efficacy of amendments to existing state laws" — one of them on "Requiring that all large frontier developers embed designated independent verification organizations onsite in their labs."
That is a recommendation to study a requirement. Not a requirement. The governor's own announcement files these as "proposals under consideration," alongside the "kill switch" that took the headlines; CNBC read the order as calling for experts to "create recommendations for the state to enhance its AI safety laws." The order also disclaims itself — it does not "create any rights or benefits ... enforceable at law or in equity."
Nothing signed on Friday requires an audit either. It is a faster calendar for the half already being built.
So nobody in California has to be audited? Not quite — and the exception is stranger than the rule
Here I have to argue against my own headline. One California statute does contain a genuine audit mandate, and it was signed the very next day.
SB 1119 — "Adam's Law" — became Chapter 190 of the 2026 statutes on September 10. It reaches operators of companion chatbots, and it does not hedge: "On or before January 1, 2029 ... an operator shall ensure the performance of a child safety audit." Then another every two years.
Two things matter. First, it is narrow — one product class, and within it not most of the companies: "Before January 1, 2032, this section does not apply to an operator that had less than five hundred million dollars ($500,000,000) in gross revenue in the prior calendar year."
Second — the detail that made me rewrite this section — the operative version of that duty exists only because AB 1405 passed. The legislature wrote two alternative versions of the same code section and flipped between them on a condition: "This section shall become operative only if Assembly Bill 1405 ... is chaptered and takes effect on or before January 1, 2027."
Read that for what it is: somebody in Sacramento wired a demand-side duty onto the supply-side registry — one bridge across the canyon, for one product, for the largest operators.
The fairest thing I can say about the registry is that researchers asked for it first. The 2022 field scan of the AI audit ecosystem by Sasha Costanza-Chock, Inioluwa Deborah Raji, Joy Buolamwini and two co-authors ended by asking regulators to "formalize evaluation and, potentially, accreditation of algorithmic auditors." The objection is not that California built the registry — it is that it stopped there.
America has run this experiment before, on accountants
Nothing here is novel. The country built this machine a generation ago, for an industry that had just failed at policing itself. The Sarbanes-Oxley Act of 2002, Public Law 107–204, approved July 30, 2002, came out of Enron. It did three things; California has done one.
One: it made registration compulsory. "It shall be unlawful for any person that is not a registered public accounting firm to prepare or issue ... any audit report with respect to any issuer, broker, or dealer." California's 2029 prohibition is a near-echo — narrower, in fact, since the federal version also catches anyone who merely participates.
Two: it sat that ban on top of a duty to actually be audited. This is the half California left out. Federal accounting rules require every registrant to file "audited balance sheets as of the end of each of the two most recent fiscal years." Section 404 then requires each annual report "to contain an internal control report," and tells the registered firm it "shall attest to, and report on, the assessment made by the management of the issuer." Shall. Not may. Be precise, though: Congress exempted issuers that are "neither a 'large accelerated filer' nor an 'accelerated filer'" from that attestation — those companies still get audited, they just skip the internal-control layer.
Three: it made inspection of the auditors compulsory. The Public Company Accounting Oversight Board, the body the act created, says the statute "requires public accounting firms to register" with it to issue an audit report for a public company. The act then puts the board on a clock: firms with more than 100 issuer clients are inspected annually, everyone else "not less frequently than once every 3 years." California's chapter has designation and suspension — no inspection clock at all.
Why all three? A PCAOB board member later explained what the act replaced: the old system, "called 'peer review', relied on firms to inspect each other." Then the sentence that should be pinned above every voluntary-audit proposal ever drafted — "Peer review did not look at audits that were the subject of litigation or investigation." The audits most likely to be bad were the ones nobody examined. The new law, he said, "ended the accounting profession's long tradition of self-regulation."
Enforcement looked like this: in September 2007 the Securities and Exchange Commission charged 69 audit firms and partners for issuing audit reports while not registered with the PCAOB — 60 reports for 53 companies between November 2003 and October 2005. Linda Chatman Thomsen, then the SEC's enforcement director, said they "violated one of the key requirements of Sarbanes-Oxley and evaded the PCAOB's oversight authority."
None of it is free, and none of it is beyond criticism: the Government Accountability Office found the costs "proportionally more burdensome for smaller (exempt) companies" even as larger firms paid more overall, and the Competitive Enterprise Institute notes that Christina Ho, a former PCAOB board member writing in Cato's Regulation, "identifies legitimate deficiencies" in the board itself. The mirror is not a utopia — just one in which both halves are visible.
Here is the arithmetic I keep returning to. In 2002 the registration ban arrived bolted to a duty to be audited and a duty to be inspected — one act, one day, one signature. California's registration ban arrives January 1, 2029. The general duty to be audited has no arrival date, because nobody has written it.
Now run the clock forward to 2031
Picture the registry live — several dozen approved IVOs, a respectable public list, the state's disclaimer at the top where nobody reads it. Then the slide in a procurement deck: independently verified by a California-registered independent verification organization. True statement. And nobody asks the only question that matters — verified against what?
Because in a voluntary market the company being examined picks the examiner, signs the check, and sets the scope. Access is the other lever, and far easier to close than to open. Maurice Chiodo, a mathematician at Cambridge's Centre for the Study of Existential Risk who says he has audited around 30 AI companies, put the failure mode to Scientific American in one line: "Giving an auditor access to nothing and giving them access to a million documents has exactly the same effect, which is: they can't get anything done."
The name for where that ends already exists: Ellen P. Goodman and Julia Tréhu called it audit-washing in a 2022 German Marshall Fund paper, and their warning is sharper than the label — a poorly designed or executed audit is "at best meaningless and at worst even excuses harms that the audits claim to mitigate."
So: 2031. A product hurts somebody. The company produces a certificate from a registered IVO. The audit was real, the auditor was licensed, the scope ran to three pages — and the thing that went wrong was on page four. Nobody broke a single law.
That is the failure mode of a half-built machine. Not corruption — just a certificate that means exactly what it says, rather than what you assumed.
Who else is uneasy — and they are not all on the same side
This is not a left or a right objection, which usually means it deserves attention.
From the right: the Reason Foundation told an Assembly committee on June 30, 2026 — writing about an earlier version of SB 813, before the amendments that removed the safety commission it describes — that the bill's standards and auditing framework are "better suited to the federal level." It also made my point in reverse: the bill "would not itself impose new mandatory safety obligations on all AI developers, would not create automatic liability."
From the left: the AI Now Institute has argued for years that the audit frame can backfire — "audits run the risk of entrenching power within the tech industry, and take focus away from more structural responses." Its sharper point lands on California's design, which designates an IVO partly for expertise in "identifying the metrics and methodologies that form the basis for that assessment" and does not set that scope itself: an audit regime "leaves enormous discretion for the auditing entity ... to limit the scope of the audit to those issues least threatening to their interests."
From the academy: a 2026 paper by Miles Brundage and 47 co-authors defines real frontier auditing as verification "based on deep, secure access to non-public information" — which neither bill creates. And the researchers who asked for accreditation also warned that claims a system "has been audited ... are difficult to verify and may potentially exacerbate, rather than mitigate, bias and harm."
And from the author herself, on signing day. Bauer-Kahan: "We cannot expect industry to simply grade its own homework; third-party auditors are essential to ensuring AI is safe for our communities and critical infrastructure."
I agree with every word of that. It is a description of what she wants the ecosystem to become — not of what her bill requires.
So what does this mean for you?
When a product says it was independently audited, ask three questions. Who chose the scope, who paid, and what did the auditor get to see? In a voluntary market all three answers belong to the company being audited.
Do not read the registry as a rating. California's auditor list will carry the state's own warning that registration "does not constitute recommendation or endorsement of that entity by the State of California." Not modesty — the legal status of the list.
If you buy or procure software, write the audit into the contract. The state has told you who may check. It has not told anybody they must be checked — your purchase order can, including the scope and the access that decide whether an audit means anything.
If you operate a companion chatbot, check your revenue line. The child safety audit duty starts January 1, 2029 — but an operator under $500 million in gross revenue in the prior calendar year sits outside it until January 1, 2032.
Put November 16, 2026 in your calendar. Recommendations on embedded onsite auditors and a kill switch are due to the governor that day — not rules, but the earliest honest signal of whether California means to build the other half.
Watch what your own state copies. Ask whether it took both halves, or only the tidy one.
The lesson, as I see it
Let me be fair to California: the sequencing argument is real. You cannot mandate an audit into a profession that does not exist yet. Licensing first is defensible.
But a licensing regime with no demand behind it does not grow into an inspection industry. It grows into a credential market — and a credential market optimizes for the credential.
Congress did not build a register and hope. It bolted the ban to an existing duty to file audited accounts, added the internal-control attestation, and put the auditors on an inspection clock. Three interlocking pieces — because any one alone is a card in a frame.
My vote? Build the other half — or say out loud that you are not going to, so nobody mistakes a register for a verdict.
I still do not know when the elevator in my building was last inspected, and I am not going to check. But what makes that little card worth anything is not the card, and not the inspector's qualification. It is the rule behind both, saying the checking happens whether or not anybody feels like paying for it.
California has printed the card. The rule behind it is the part still missing.
A license tells you who is allowed to look. It never tells you whether anybody did. The HAIA Foundation spends its week on that second question — and if you would rather be asking it too, come along.




