AI governance
AI Auditor Registry Act (AB 1405)
Cal. Gov. Code Sections 11549.80 to 11549.86 (AB 1405, Ch. 178, Stats. 2026)Chaptered bill text, California Legislative Information
In force in 831 days, effective 1 January 2029. Binds private bodies.
What this law does
This chapter regulates AI auditors, meaning any person, partnership, or corporation that assesses an AI system or model on behalf of a third party, and does not impose duties on the AI system's own developer or deployer unless that developer or deployer also offers covered AI audit services to others.
Beginning January 1, 2029, a person may not offer, sell, or conduct a covered AI audit (an audit assessing internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law) unless registered with the Government Operations Agency, which must itself establish the AI Auditor Registry, fix registration fees, and stand up a misconduct-reporting mechanism no later than that same date.
An auditor who registers must give the agency its business name and contact information, a list of the California laws or regulations it audits under, any relevant certifications, a description of its services, and a standard operating procedure describing the standards it applies and the basis for its accuracy and reliability claims; the agency then publishes that registration information, including the list of laws audited under, on its own website.
A registered auditor may not conduct a covered AI audit of a system, process, control, assessment, or other subject matter it materially designed, developed, implemented, or operated for the auditee, and must otherwise maintain independence, objectivity, and competence throughout the engagement.
For each covered audit, the auditor must give the auditee a report covering the audit's scope and objectives, its results and the documentation behind them, each deficiency found and what could reasonably address it, whether the auditee followed its own internal safety standards and protocols within the audit's scope, the audit's limitations and any material gaps in the evidence available, and a signed and dated statement that the audit met this chapter's requirements.
The auditor must retain the information it gave the auditee and the documentation behind its results for at least 10 years, display its registration number on advertising for its audit services, and may not retaliate against an employee who reports suspected noncompliance.
A licensed CPA or accounting firm performing the audit under applicable AICPA and California Board of Accountancy standards is deemed to satisfy the reporting and independence requirements without separately meeting every listed element, and a violation by such an accountant is referred to the California Board of Accountancy rather than handled solely by the agency.
What it requires