California has taken another step toward turning AI safety from a promise made by technology companies into something outsiders can independently test.
Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405 on September 9, establishing what the state describes as first-in-the-nation standards for independent third-party evaluation and auditing of artificial intelligence systems. The laws arrive as increasingly capable AI models and autonomous agents are raising harder questions about how companies demonstrate that their systems are safe.
The important part is not simply that California has passed two more AI laws. It is the idea behind them: developers should not be the only ones assessing their own claims.
What California actually changed
SB 813 establishes a framework for independent verification organisations that can assess AI systems and models for compliance with California law. The state says qualification standards will address expertise, credible testing methods and independence from the companies being evaluated.
AB 1405 goes alongside it by creating an AI Auditor Registry and standards around auditor independence, transparency and integrity. The registry is scheduled to be established no later than January 1, 2029, and the law is designed to give the state a clearer mechanism for identifying who is qualified to perform covered AI audits.
That distinction matters. An audit is considerably less useful if the organisation conducting it depends financially on the company whose claims it is supposed to scrutinise.
Why this matters now
The timing is difficult to ignore. AI systems are moving beyond chat windows and into agents that can interact with websites, software and other external systems. That makes unexpected behaviour potentially more consequential than an inaccurate chatbot answer.
OpenAI has also called for mandatory, capability-based national AI safety requirements, including testing standards, independent assessments, cybersecurity protections and incident reporting for the most advanced systems. The company has backed California measures involving third-party AI evaluation while arguing that the United States ultimately needs a federal framework.
That creates an unusual moment in technology regulation. Some of the companies building the most capable models are themselves acknowledging that voluntary commitments may not be enough.
AI companies may increasingly have to prove their claims
AI developers routinely publish model cards, safety reports, benchmark results and descriptions of internal testing. Those disclosures can be valuable, but the fundamental problem remains: much of the evidence originates with the organisation developing the technology.
Independent evaluation changes that relationship. A credible outside evaluator can test whether stated safeguards work under pressure, whether known risks have been adequately measured and whether a company’s public claims match observable behaviour.
This does not mean California has created an all-purpose government certification declaring an AI model “safe.” The framework is more nuanced than that, and parts of its implementation will develop over several years. But it builds infrastructure for a future in which independent verification becomes a normal part of deploying powerful AI.
What it means for ordinary users
For most people, an AI auditor registry will sound distant from the experience of opening an app and asking a chatbot a question. The connection becomes clearer as AI gains permission to do more.
An assistant that drafts an email presents one level of risk. An agent that can browse websites, execute tasks, interact with business systems or make decisions involving sensitive information presents another.
As those capabilities expand, readers may increasingly see independent testing, incident reporting and security assessments become part of the trust signals surrounding AI products — much as independent testing and certification already matter in other safety-sensitive industries.
California could influence rules far beyond California
California’s importance comes partly from scale and partly from geography. Many of the world’s most influential AI companies operate there. Rules developed in the state can therefore influence how companies design compliance systems even when their products are used globally.
There is still a larger unresolved question: whether the United States will eventually replace today’s state-by-state approach with a comprehensive national AI safety regime. Newsom has called for stronger federal action, while OpenAI is now publicly pushing Congress toward mandatory national requirements.
Until that happens, California is effectively building pieces of the oversight architecture itself.
The bigger shift
The most significant part of SB 813 and AB 1405 may not be any individual registration requirement or deadline. It is the direction of travel.
For the first years of the generative AI boom, extraordinary capabilities arrived faster than institutions could decide how they should be evaluated. Companies largely developed their own safety frameworks while governments tried to understand a technology changing underneath them.
California’s new laws suggest the next phase could look different. The question may increasingly shift from whether an AI company says its system is safe to whether an independent organisation can verify the evidence behind that claim.
Sources: Office of Governor Gavin Newsom, California SB 813 and AB 1405 materials; Reuters reporting on OpenAI’s call for mandatory U.S. AI safety requirements.




