California Gov. Gavin Newsom has signed two bills establishing standards for independent assessments of AI systems and creating a state registry for AI auditors. The measures are intended to make outside reviews more transparent and credible as increasingly capable AI systems move into everyday products and critical services.
Senate Bill 813, authored by state Sen. Jerry McNerney, D-Pleasanton, establishes a framework for independent verification organizations that assess AI systems and models. Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan, D-Orinda, creates a state registry for AI auditors and sets requirements covering their independence, transparency and integrity, according to Newsom’s office.
The two laws establish a formal role for organizations that assess AI systems independently of their developers. The framework is intended to make it easier to judge whether outside assessors meet common standards for independence and transparency.
“AI has the potential to improve our lives, but without effective guardrails, it poses significant risks,” McNerney said.
Why independent testing matters
The move comes as AI systems become more capable and increasingly connected to tools, businesses and public infrastructure. California says that makes independent verification more important because failures can extend beyond a chatbot or software product and affect critical parts of the economy and public life.
Bauer-Kahan argued that developers should not be solely responsible for judging the safety of their own systems.
“We cannot expect industry to simply grade its own homework,” she said. For IT and procurement leaders, the framework could provide another due-diligence resource when evaluating AI vendors or commissioning outside reviews. Registration would not eliminate the need for an organization’s own security testing, privacy review, legal analysis and monitoring after deployment.
California’s wider AI push
The bills add to a growing set of California AI rules. Newsom previously signed SB 53, requiring frontier AI developers to disclose safety frameworks, report certain critical incidents and protect whistleblowers who report serious risks.
The state has also enacted measures covering AI-generated content, privacy, AI-enabled fraud and cybersecurity. In August, Newsom announced an AI Cyber Defense Program aimed at helping detect vulnerabilities, strengthen networks and support incident response.
California is also tightening rules around AI used by children. A separate package signed by Newsom includes requirements for companion chatbots, including parental controls and crisis protocols, along with restrictions on addictive social media features for users under 16.
The bigger regulatory question
California’s approach could affect how AI developers document safety claims and how customers select outside assessors. If independent reviews become a common procurement expectation, they could add costs and time to deployments, particularly for smaller companies with limited compliance teams.
But the state’s strategy also addresses a practical problem: AI capabilities are developing faster than traditional oversight systems can adapt.
Newsom has called for federal regulation as well, arguing that AI risks require national action. In the meantime, IT and compliance leaders should watch for details about when the registry will launch, which organizations can register and whether California incorporates registered assessors into future procurement or compliance requirements.
Read more: An OpenAI scientist’s warning about the limits of AI safety research explains why oversight is becoming more urgent as advanced models grow harder to evaluate.


