California AI Auditors Registration Law

California AB 1405 — Artificial Intelligence: Auditors: Registration

United States

RAI-US-CA-AB14050-2026

AB 1405

Awaiting Entry(Awaiting Entry)

California AI Auditors Registration Law is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.

ActGovernance and OversightConformity Assessment and RegistrationAccountability and Documentation
Export PDF

California creates a registration and oversight regime for third-party AI auditors.

Summary

California AB 1405 creates a state registration system for AI auditors who perform covered audits for third-party compliance purposes. It adds public disclosure, independence, recordkeeping, complaint, and enforcement requirements, with operative obligations phased in beginning in 2027 and registry enforcement by 2029.

Full article

Read full text ↗

Overview

Assembly Bill 1405 is a California statute chaptered as Chapter 178, Statutes of 2026, that creates a state registration system for artificial intelligence auditors. The law adds Chapter 5.9.5 (commencing with Section 11549.80) to the Government Code and is designed to regulate persons who assess AI systems or models on behalf of third parties when those assessments are used to evaluate compliance with California law. It is part of California’s broader AI governance package and reflects a policy choice to separate the market for AI auditing from the entities being audited by imposing public registration, disclosure, and independence requirements. The bill was approved by the Governor and filed with the Secretary of State on 2026-09-09, and it becomes operative on 2027-01-01 under the state constitutional default rule for non-urgency statutes.

The law requires the Government Operations Agency to establish an AI Auditor Registry by no later than 2029-01-01, fix annual fees at a level not exceeding reasonable administrative costs, and create a public mechanism for natural persons to report misconduct by registered auditors. Beginning on 2029-01-01, no unregistered person may offer, sell, or conduct a covered AI audit. The agency must issue unique registration numbers, publish registration information on its website, retain misconduct reports for the duration of the registration plus 10 years, and may adopt implementing regulations. The statutory framework also creates the AI Auditors’ Registration Fund in the State Treasury to support administration of the chapter. Official state information on the Governor’s signing announcement is available at Governor of California, and the enrolled bill text is posted through the Legislature’s bill information system.

Definitions

The statute defines “agency” as the Government Operations Agency and defines “artificial intelligence” using a broad systems-based definition that covers engineered or machine-based systems with varying autonomy that infer from input how to generate outputs capable of influencing physical or virtual environments. It defines “AI auditor” as a person, partnership, or corporation that assesses an AI system or model on behalf of a third party. The law’s operative category is “covered AI audit,” which means an audit conducted to assess internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law. This definition is important because it limits the statute to audits tied to legal compliance rather than all technical assessments of AI.

The registration disclosures required from an AI auditor are also tightly defined by function. An auditor must provide business name, contact information, relevant California laws or regulations under which it performs covered audits, certifications or accreditations, a written description capped at 500 words, and a standard operating procedure identifying the standards applied and the basis for claims about accuracy, reliability, or validity. The statute expressly permits reasonable redactions to protect trade secrets as defined in Civil Code Section 3426.1. It also embeds a professional standards carve-out for licensed or authorized public accountants and firms holding a valid California Board of Accountancy permit when they meet the specified reporting and independence standards and comply with the California Accountancy Act, the AICPA Code of Professional Conduct, and applicable AICPA attestation standards.

Governance and Institutional Framework

AB 1405 places primary implementation authority in the Government Operations Agency, which must operate the registry, maintain the website, collect and publish registration information, process misconduct reports, investigate alleged violations, and refer matters to the Attorney General or other enforcement authorities when necessary. The statute also authorizes the agency to adopt regulations reasonably necessary to carry out the chapter under the Administrative Procedure Act. This institutional design keeps the program within the executive branch while allowing the agency to create procedural details such as registration mechanics, reporting formats, and removal procedures. The public-facing registry and misconduct portal are central governance tools, making the state’s oversight role visible and accessible.

The law also creates an interagency relationship with the California Board of Accountancy. If the Government Operations Agency determines that a certified public accountant, public accountant, or accounting firm in good standing has violated the chapter, it must notify both the accountant or firm and the board in writing. The board then investigates under its existing authority and procedures and reports findings and any resulting action back to the agency. This linkage is significant because it preserves the board’s professional-discipline role while avoiding duplication of enforcement. The statute also specifies that registration is not state endorsement, which limits any inference that inclusion in the registry is a credentialing or licensing seal beyond compliance with the chapter’s requirements.

Key Focus Areas

The statute’s core policy objectives are transparency, independence, and accountability in AI auditing. It requires public publication of the registration number and auditor-supplied registration information, along with a prominent disclaimer that registry entry is not an endorsement by California. It also mandates clear display of the registration number on all advertising materials offering or soliciting covered AI audit services. These disclosure rules are designed to let auditees, regulators, and the public distinguish registered auditors from unregistered providers and to reduce misleading marketing in a relatively new professional market.

A second focus area is auditor competence and methodological rigor. Registered auditors must provide a standard operating procedure identifying recognized standards they apply, including standards from ISO, NIST, national and international auditing and assurance standard-setters, professional accountancy bodies, or a California governmental agency. They must conduct audits according to widely recognized industry standards appropriate to the system or model being audited, to the extent such standards are available. The law also requires auditors to provide a detailed report to the auditee that includes the scope, results, supporting documentation, remediation-oriented observations for deficiencies where appropriate, limitations, and a signed and dated statement of compliance. A third focus area is whistleblower protection: auditors may not prevent employees from reporting to the Attorney General or Labor Commissioner or from filing a misconduct report, and they may not retaliate against employees for doing so.

Implementation Framework

AB 1405 uses a phased implementation model. The statute becomes operative on 2027-01-01, but the registry, fee-setting, and reporting mechanism must be established no later than 2029-01-01. Beginning on that same date, the agency must issue unique registration numbers, publish registration data, and retain misconduct reports for the length of registration plus 10 years. The law therefore gives the state time to design the registry infrastructure and administrative processes before the licensure-like obligations become enforceable. This phased design is consistent with a new regulatory program that needs time for rulemaking, website development, intake procedures, and public education.

Applicants must submit specified information to the agency and update materially changed information within 90 days. Registered auditors must preserve for at least 10 years the information provided to auditees and documentation supporting audit results. The law also requires the registration fee to be capped at reasonable administrative costs, which suggests a cost-recovery model rather than a revenue-generating assessment. A person may not offer, sell, or conduct a covered AI audit unless registered, so the registry functions as a market-entry control. The statute further permits reasonable redactions of trade secrets in the standard operating procedure, balancing transparency with proprietary business interests.

Monitoring and Evaluation

The monitoring structure in AB 1405 is built around public visibility, complaint intake, retention, and interagency sharing. The Government Operations Agency must maintain a mechanism on its website for natural persons to report misconduct by registered auditors, must retain those reports for the period tied to the auditor’s registration plus 10 years, and may share reports with other state agencies as necessary for enforcement purposes. This creates a record-based oversight system that supports both real-time complaint handling and later investigations. Because the registry information is publicly accessible, outside stakeholders can compare advertised services, registration status, and disclosed methodology against the statutory requirements.

The statute also requires the agency to periodically review and update the annual registration fees and the reporting mechanism, which creates an ongoing evaluation loop rather than a one-time launch. In addition, auditors must notify the agency within 90 days of material changes to published information, allowing the registry to remain current. The requirement that auditors provide auditees with a detailed report, including audit limitations and evidence gaps, also helps monitoring by creating documentation that can later be reviewed if a complaint arises. The law does not prescribe a single scoring system or substantive performance metric; instead, it relies on documentation, complaint-driven oversight, and professional standards to assess compliance.

Penalties, Liability, and Appeals

AB 1405 does not create a standalone criminal penalty scheme, but it gives the agency meaningful administrative enforcement authority. If the agency receives a report alleging a violation, it may investigate and obtain information reasonably necessary to determine whether the auditor violated the chapter. A violation constitutes grounds for removal from the registry and referral to the Attorney General or another appropriate enforcement authority. Before removal, however, the agency must give the auditor written notice of the basis for removal and a reasonable opportunity to cure or contest the action in a manner prescribed by the agency. That notice-and-opportunity structure functions as the statute’s primary due process protection.

The law also addresses the special case of accountants and accounting firms. If the agency determines that a certified public accountant, public accountant, or accounting firm in good standing has violated the chapter, the agency must notify the person or firm and the California Board of Accountancy, and the board must investigate under its existing procedures. The statute ties report quality, retention, independence, and retaliation restrictions into the compliance regime, so violations may arise from deficient reporting, lack of independence, improper employment negotiations during an audit, or whistleblower interference. The statute does not specify civil damages, private rights of action, or appellate tribunal review, so any further remedies would depend on generally applicable administrative or judicial review rules.

Relationship to Other Instruments

AB 1405 operates alongside California’s other AI statutes and with the professional standards governing accounting and assurance work. The measure expressly references the Transparency in Frontier Artificial Intelligence Act in the bill digest as part of the broader regulatory landscape, but it regulates a different actor class: not frontier developers, but third-party auditors. It also incorporates external technical and professional standards by reference, including ISO, NIST, national and international auditing and assurance standard-setters, professional accountancy bodies, and California governmental agency standards. This creates a hybrid legal-technical framework in which statutory compliance is partly measured by conformity to recognized industry standards.

The law also preserves the operation of other required audits and does not displace them. Section 11549.86 provides that nothing in the chapter may be construed to impede, delay, or otherwise affect an audit required under any other statute or regulation operative before AB 1405’s effective dates. In parallel, the chapter says that registry inclusion is not a recommendation or endorsement by the State of California. That disclaimer prevents the registry from being treated as a state certification beyond the narrow registration function. For accountants, the statute respects the existing California Board of Accountancy framework and the AICPA professional standards, thereby avoiding a conflict between the new AI-specific registration scheme and established professional regulation.

National/Federal Alignment

At the federal level, there is no single comprehensive AI auditor registration regime comparable to AB 1405. The California statute therefore fills a state-level governance gap by imposing registration and disclosure obligations on third-party AI auditors operating in California. Its standards-based approach aligns with the broader federal preference for risk management and professional accountability rather than rigid technology-specific product licensing, but it goes further by mandating a public registry and a mandatory unique registration number for advertising. In that sense, the law is more prescriptive than most federal AI guidance and more directly tied to market access.

AB 1405 also aligns with federal and national professional norms by recognizing standards from NIST, ISO, and accountancy bodies. Its treatment of whistleblower protection and documentation retention is consistent with federal compliance and assurance practices, even though the statute is grounded in state law. The Governor’s signing announcement emphasized that California is building safeguards while calling for robust national regulations, which underscores that this chapter is intended as a state complement to, not a substitute for, federal action. No specific federal statute is preempted by the chapter, and the law’s savings clause helps preserve audits already required by other laws. For official California executive-branch context, see the Governor’s announcement at CA.gov.

Implementation Timeline

MilestoneDateNotes
Chaptered and filed2026-09-09Approved by the Governor and filed with the Secretary of State as Chapter 178, Statutes of 2026.
Statute operative date2027-01-01Non-urgency statute takes effect under California constitutional default timing.
Registry and fee framework deadline2029-01-01Agency must establish the registry, set fees, and create a misconduct-reporting mechanism.
Registration-number and publication obligations begin2029-01-01Agency must issue unique registration numbers and publish required registry information.
Unregistered audit prohibition begins2029-01-01No person may offer, sell, or conduct a covered AI audit without registration.

Compliance Checklist

CheckRequired Action
Registry statusRegister with the Government Operations Agency before offering covered AI audit services after 2029-01-01.
Public disclosuresProvide business name, contact details, relevant California authorities, certifications, description, and SOP information.
AdvertisingDisplay the unique registration number clearly and conspicuously on all audit-service advertisements.
MethodologyUse widely recognized industry standards appropriate to the system or model being audited.
IndependenceAvoid financial, business, employment, or other relationships that could impair objectivity.
ReportingDeliver the auditee a signed, dated report covering scope, results, deficiencies, limitations, and supporting documentation.
RecordkeepingRetain required audit records and auditee materials for at least 10 years.
Whistleblower protectionsDo not restrict or retaliate against employees who report suspected noncompliance.

Sources and References

SourceType
Assembly Bill No. 1405, Chapter 178, Statutes of 2026 — California Legislative Informationofficial
Governor of California — signing announcement, 9 September 2026official

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash