Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending Regulation

California Signs America's First AI Audit Law

California passed the first US AI audit laws. SB 813 and AB 1405 require certified auditors for hiring, insurance, and critical AI decisions by 2029.

Enterprise DNA | | via Governor of California
California Signs America's First AI Audit Law

California moved the goalposts for enterprise AI governance on September 9, 2026. Governor Gavin Newsom signed two bills — Senate Bill 813 and Assembly Bill 1405 — that together create the first legal framework in the United States requiring businesses to use certified, independent third-party auditors when assessing their AI systems for compliance.

This is not a transparency pledge or a voluntary pledge. Starting in 2029, deploying covered AI without a registered auditor on file is illegal.

What the Two Bills Actually Do

SB 813 (authored by Senator Jerry McNerney, D-Pleasanton) establishes the framework for Independent Verification Organizations — the entities that will be legally qualified to assess AI systems. The California Government Operations Agency has until January 1, 2028 to publish the criteria these organizations must meet, including their qualifications, methodologies, and proposed testing tools.

AB 1405 (authored by Assemblymember Rebecca Bauer-Kahan, D-Orinda) creates the California AI Auditor Registry — a public, searchable database of certified auditors. After January 1, 2029, any individual or organization conducting a covered AI audit without a valid registration number is operating illegally under state law.

Both Anthropic and OpenAI backed the legislation, a notable alignment between frontier AI developers and regulatory oversight.

Who Is in Scope

The legislation covers AI systems used in decisions that affect people’s lives in material ways. The three main categories triggering coverage are:

  • Hiring and employment screening — any AI tool used to filter resumes, rank candidates, or make recommendations on advancement or termination
  • Insurance underwriting and pricing — models that factor into coverage decisions or premium calculations
  • Critical services — a deliberately broad category that regulators will define, but understood to include credit assessment, healthcare triage tools, and housing eligibility

The scope is not limited to AI developers. A company that takes an off-the-shelf model from any vendor and deploys it to screen job applications is as much in scope as the original model developer.

The Timeline

The law phases in over two and a half years:

  • January 1, 2028 — California Government Operations Agency publishes criteria for Independent Verification Organizations
  • January 1, 2029 — AI Auditor Registry goes live; unlicensed AI auditing in covered categories becomes illegal

That window sounds generous. It is not. Building audit readiness for AI systems already in production — getting documentation in order, establishing model cards, mapping decision flows — takes considerably longer than most teams expect.

What This Means for Business

If your company operates in California and uses AI in hiring, insurance, or customer decisions, you need to treat this as a compliance project that starts now, not in 2028.

Three things to do immediately:

Inventory your AI touchpoints. Many businesses have more AI-assisted decision-making than they realize, embedded in vendor tools, ATS platforms, and analytics dashboards. A complete map of where AI influences human-affecting decisions is the first step.

Understand your vendor contracts. If your AI system was built or supplied by a third party, your contract should clarify who carries audit responsibility. In many cases, both the developer and the deployer are in scope. Do not assume the vendor handles it.

Build for auditability now. The technical requirements for a compliant AI audit — model documentation, data lineage, decision logging — are easier to build in than to retrofit. Systems deployed after this signing should be designed with audit readiness in mind.

The regulation also signals something broader: the era of “move fast, figure out compliance later” in enterprise AI is ending. California sets the tone for US regulation, and this framework is already being studied by state legislatures in New York, Washington, and Illinois.

What Makes This Different From the EU AI Act

The EU AI Act and California’s new laws approach the same problem differently. The EU Act classifies AI systems by risk level and mandates conformity assessments — largely a self-assessment model with third-party review for the highest-risk systems.

California’s framework does something more structural: it creates a certified profession of AI auditors and makes that certification mandatory. It is less about classifying AI systems and more about who is legally allowed to say an AI system is compliant.

That distinction matters for enterprise compliance teams. EU compliance is largely an internal exercise. California compliance will require engaging external, state-registered professionals — and the profession that regulatory infrastructure creates does not fully exist yet.

The Bigger Picture

This is the most concrete step any US jurisdiction has taken to make AI accountability operational rather than aspirational. For businesses already investing in AI governance frameworks, it validates the approach. For businesses that have treated governance as a checkbox, it is a signal to get serious.

Enterprise DNA’s view: the businesses that use the 2026-2029 window to build genuine audit readiness will enter the compliance era with a structural advantage. Those that wait for the January 2029 deadline will be scrambling for a small pool of certified auditors, paying premium rates, and explaining gaps to regulators.

The window is open. Use it.


If you are planning your AI governance strategy and want to understand where data infrastructure fits, talk to the Enterprise DNA team — we work with businesses on the data and AI foundations that make compliance tractable.