What AB 1405 Actually Licenses

On September 9, Governor Gavin Newsom signed AB 1405, written by Assemblymember Rebecca Bauer-Kahan, alongside its companion, SB 813, from Senator Jerry McNerney. Both bills came out of the same signing session as California's new child-safety rules for AI companion chatbots, but they do a different job: they decide who is allowed to call themselves an AI auditor in the first place.

AB 1405 orders the state's Government Operations Agency to build a public AI Auditor Registry by January 1, 2029. From that date, offering, selling, or conducting a covered AI audit without a valid state registration number is prohibited. A covered AI audit, under the bill's own text, means an audit that checks the internal controls, processes, or systems an AI system or model uses to comply with California law. Every registered auditor gets a unique registration number, and that number has to appear on any advertising for their audit services.

Bauer-Kahan put the reasoning plainly: "We cannot expect industry to simply grade its own homework; third-party auditors are essential to ensuring AI is safe for our communities and critical infrastructure."

The Independence Rules Nobody Else Has Written Down

The bill text goes further than just handing out registration numbers. A registered auditor cannot have a financial, business, or employment relationship with the company being audited that would reasonably be expected to impair their independence. They cannot grade their own earlier work. They cannot go looking for a job at the company they are auditing while the audit is still open, and they have to wait 12 months after leaving an employer before they are allowed to audit that same employer.

Auditors also have to protect whistleblowers who report violations, and the agency can pull a registration and refer the case to the Attorney General if any of these rules are broken. Nothing in AI regulation anywhere else reads like this. It reads like the independence rules written for financial auditors after Enron, applied for the first time to the people who check whether an AI system does what the law says it should.

No Audit Is Required. The License Still Is.

Here is the part almost every early headline on this law got wrong: SB 813 says, in its own text, that neither bill requires any person, partnership, or corporation that develops, deploys, or operates an AI system to engage an independent verification organization or undergo a covered AI audit as a condition of operating in California. There is no audit mandate. There may never be one. What exists now is only the credential a person would need if a client, a court, or a future law ever asked for one.

SB 813 sets its own earlier deadline: the Government Operations Agency must publish the designation criteria for Independent Verification Organizations, the more specialized tier of registered auditor, by January 1, 2028, a full year ahead of AB 1405's public registry. California is building the licensing and independence infrastructure before it builds any rule that would make the license matter to every company, not just the ones who choose to hire an auditor.

QuestionCalifornia (AB 1405 / SB 813)EU AI Act
Who must be independently auditedNobody, by law, as of this signingOnly remote biometric identification systems (Annex III, point 1)
Who may call themselves an AI auditorOnly a holder of a state registration number, from Jan 1, 2029No registry or credential exists for the role
Independence rules for auditors12-month cooling-off, no self-review, whistleblower protection, AG referralAccreditation rules for notified bodies, applied only in the narrow mandatory case
First compliance deadlineJan 1, 2028 (IVO designation criteria)Notified-body designation rules already in force

What This Means If You Sell Compliance Services Into California

For an EU or UK compliance, audit, or risk-consulting firm, this opens a market niche that does not exist anywhere else yet. Any firm that wants to offer AI audit services to a client operating in California will need at least one registered person on staff by 2029, the same way European accountants once needed a separate US credential to sign off on a company listed on an American exchange. Nobody in the EU currently holds an equivalent California credential, which means the firms that get registered early become the first to combine EU AI Act familiarity with a California registration number in the same practice.

It also previews where the EU's own rules could go next. The AI Act's mandatory third-party assessment today reaches only remote biometric identification systems; almost every other high-risk AI system in the EU can still self-certify through internal control, with no outside auditor ever required to look at it. California has just built the licensing and independence infrastructure a broader audit mandate would need, without writing that mandate yet. If Brussels ever decides to widen its own third-party requirement, the profession it would need to regulate already has a working blueprint, written in Sacramento, not Brussels.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.