California Just Created the First US AI Audit Law — What Service Businesses Need to Know in 2026

Governor Newsom signed SB 813 and AB 1405 on September 9, 2026, creating America's first framework for independent AI audits. Here is what service businesses must do now.

Ido Cohen · Published 2026-09-13 · AI News

California just became the first state in the United States to require independent, third-party audits of artificial intelligence systems — and the law reaches well beyond Silicon Valley labs. On September 9, 2026, Governor Gavin Newsom signed two bills, Senate Bill 813 and Assembly Bill 1405, that together build a legally enforceable audit infrastructure for any company deploying AI in hiring, insurance, or what the legislation calls "critical services." If you run a dental practice, a med spa, a law firm, a real estate agency, or any service business that uses AI tools to screen applicants or make consequential decisions about clients, this law is already on the books and the compliance clock is ticking.

What Actually Changed on September 9

Two bills, one framework — and audits are no longer optional in principle, even if the enforcement teeth arrive in stages.

Senate Bill 813 creates a new California Artificial Intelligence Standards and Safety Commission. That commission will recognize Independent Verification Organizations — think of them as certified AI testing labs — that can assess whether an AI system actually complies with state law. Assembly Bill 1405 is the companion piece: it establishes a state registry for AI auditors and sets mandatory standards for their independence, transparency, and integrity.

According to the Governor's office, together the bills establish the nation's first framework for independent third-party evaluation and audits of artificial intelligence, "laying the foundation for greater transparency and accountability as AI becomes increasingly embedded in critical sectors." The Transparency Coalition described the laws as building a legal compliance standard for AI "similar to the auditing systems that operate in the financial world" — the same kind of external check that keeps CPAs and bank examiners honest.

OpenAI and Anthropic both backed the legislation. OpenAI's chief global affairs officer stated the company intends to push for internationally aligned standards on capability measurement, risk governance, and human oversight. That endorsement is worth noting: even the largest AI labs decided it was better to help write this framework than to fight it.

Who Is Actually in Scope — and It Is Not Just OpenAI

Here is the part most service-business owners will miss: this law does not only target frontier AI labs.

Both SB 813 and AB 1405 cover AI systems and the applications built on them. According to TechTimes's analysis of the bill text, the laws reach "any company deploying AI in hiring, insurance, or critical services" — not just companies that trained the underlying model. If you take an off-the-shelf AI tool from any vendor and use it to screen job applicants, score insurance applications, or make decisions that "materially affect people," you are potentially in scope.

The specific trigger categories that service businesses should pay attention to:

California's existing automated decision-making technology regulations already cover AI used in "consequential decisions involving housing, insurance, healthcare, and employment." SB 813 and AB 1405 give those existing rules an independent verification mechanism they previously lacked.

The Timeline — When the Deadlines Actually Hit

The good news for service businesses: the hardest enforcement deadlines are still years away. The bad news: the legal infrastructure is being built right now, and the companies that wait until 2028 to start asking questions will be behind.

The IAPP noted an important nuance: "Whether an AI developer ever seeks out an audit remains voluntary — for now." The law sets up the who, the how, and the standards. Future California legislation — or federal action — can then flip the switch and make audits mandatory for specific sectors. Given the pace of California AI lawmaking since 2025, that future legislation is a question of when, not if.

Why This Is the Most Important AI Regulation for Small Service Businesses Since GDPR

This law matters more to service businesses than most AI news precisely because it is not about chatbots or content generation. It targets the AI tools that make decisions about people — and service businesses make those decisions constantly.

Consider the scenarios that are now in the regulatory spotlight:

A med spa using AI intake software that categorizes prospective clients by treatment suitability — that is a consequential decision affecting healthcare access.

A real estate brokerage using AI to triage leads and route them to agents based on predicted transaction value — that is a consequential decision affecting housing access.

A law firm using AI to screen paralegal or associate applicants — that is a hiring decision, explicitly in scope.

A plumbing or HVAC company using AI scheduling software that de-prioritizes service requests based on location or predicted job value — potentially in scope under "critical services."

The law's definition of a "covered AI audit" is broad: it assesses whether an AI system meets "minimum safety, efficacy, reliability, or security requirements necessary to comply with applicable state law." That language is designed to catch the deployer — the business using the tool — not just the vendor who built it.

Pymnts.com put it plainly: the new laws are turning AI auditing "from a loosely defined consulting service into a regulated profession with standards for competence, independence, and evidence."

What Is Missing From This Law — and Why That Actually Matters

Let's be honest about what SB 813 and AB 1405 do not do.

They do not force a single audit to happen before 2029. They do not tell any service business to stop using any specific AI tool. And they do not set the substantive safety standards the auditors will eventually enforce — that work is left to the commission and future legislation.

Gizmodo covered the signing under the headline "Newsom Signs AI Industry-Approved AI Regulation Bills Into Law in California," pointing out that the companies most affected by the rules helped write them. That criticism has merit. Newsom vetoed the far tougher SB 1047 in 2024, and his pattern has been to favor narrower, industry-negotiated measures. Startup Fortune noted that AB 1405 "sets real independence standards on paper, but it doesn't force a single audit to happen until 2029" — and that "three years is a long runway in an industry that ships new frontier models every few months."

The cynical read: this is a credentialing law for auditors, not an accountability law for AI deployers. It creates a market for AI auditors before it creates a legal obligation to hire them.

The practical read for service businesses: the infrastructure is being built. California's regulatory record on AI — deepfakes law, watermarking requirements, child safety rules, the transparency act — shows a legislature that builds layer by layer. SB 813 and AB 1405 are the foundation layer. The load-bearing layers come later, and they will be heavier.

What to Do This Week

You do not need a compliance team or a legal budget to start preparing. Here is the practical checklist for a service-business owner right now:

1. Audit your AI vendor stack. List every AI tool your business uses that touches hiring, client screening, pricing decisions, or service prioritization. Ask your vendors directly: "Does your tool make or assist with decisions that materially affect people?" If the answer is yes or unclear, flag it.

2. Pull your vendors' data processing agreements. California's existing automated decision-making regulations (effective since January 1, 2026) already apply. If your AI vendor does not have a DPA that addresses California compliance, that is a problem today, not in 2029.

3. Document your AI decision workflows. If you use an AI hiring tool, write down what it screens for, who reviews its output, and what human override process exists. The audit framework rewards demonstrable human oversight — having a paper trail now is cheap compared to scrambling for one later.

4. Watch for future companion legislation. SB 813 and AB 1405 are the audit infrastructure. The triggering laws that will mandate audits in specific sectors are almost certainly in the 2027 California legislative pipeline. Set a Google Alert for "California AI audit hiring" and "California AB 1405."

5. If you are a financial advisor, insurance broker, or healthcare-adjacent service: Get legal advice now. Your sector sits squarely in the categories the bill text targets first. The compliance deadline feels distant until it is not.

6. Ask your AI vendor what their audit story is. Forward-looking vendors — especially those selling to regulated industries — will already have answers. Vendors who cannot articulate their testing and accountability practices are a yellow flag.

Frequently Asked Questions

Does this law require my service business to get an AI audit right now?

No. SB 813 and AB 1405 are framework laws — they build the certification system for auditors and the standards they must follow. Audits become legally mandatory only when a separate California statute requires them for your specific AI use case. That mandatory layer does not yet exist for most sectors, but it is widely expected to follow in 2027 or 2028.

My business is not in California. Should I care about this?

Yes, for two reasons. First, California law has a history of becoming the de facto national standard — companies build one compliance program that satisfies California rather than 50 state-specific versions. Second, both OpenAI and Anthropic endorsed the bills and signaled support for international alignment, meaning this framework may influence federal or global AI governance within the next few years.

What counts as a "covered AI audit" under the new law?

The bill text defines a covered AI audit as an assessment of whether an AI system or model meets minimum safety, efficacy, reliability, or security requirements necessary to comply with applicable California law. Crucially, this definition applies to deployers — businesses using AI tools — not just the companies that built the models.

What is the difference between SB 813 and AB 1405?

They are intentionally designed to interlock. SB 813 creates the California AI Standards and Safety Commission and defines the Independent Verification Organizations (IVOs) — the certified testing labs — that assess AI systems. AB 1405 creates the state registry those IVOs must enroll in and sets the standards for auditor independence, transparency, and integrity. Neither works without the other.

Could a service business face liability for using an AI hiring tool that was never audited?

Not directly under SB 813 or AB 1405 as written today — they do not impose liability on deployers for failing to audit. However, California's existing automated decision-making regulations already create liability exposure for companies that use AI in consequential employment or housing decisions without adequate transparency and notice. Those existing rules apply now. The new audit laws add accountability infrastructure on top.

Sources: