California Independent AI Verification Law

California SB 813 — Independent Verification Organizations

United States

RAI-US-CA-SB81300-2026

SB 813

Awaiting Entry(Awaiting Entry)

California Independent AI Verification Law is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.

ActGovernance and OversightSafety, Testing, and EvaluationAccountability and Documentation
Export PDF

California SB 813 creates an oversight framework for independent AI verification organizations.

Summary

California SB 813 creates a state framework for independent verification organizations that can audit AI systems and models for compliance with state law. It establishes designation, reporting, and oversight rules for the Government Operations Agency, while making clear that the law does not itself require AI audits or impose liability solely for failing to meet the chapter’s standards.

Full article

Read full text ↗

Overview

California SB 813 creates Chapter 14 of the Government Code to establish a state framework for independent verification organizations, or IVOs, that can assess artificial intelligence systems and models for compliance with state law. The statute is structured as a credentialing and oversight regime rather than a universal audit mandate. It directs the Government Operations Agency to develop application requirements, designation criteria, and suspension or termination procedures for entities seeking IVO status, and it requires the agency to publish those requirements and criteria in a publicly accessible format. The law also requires the agency to regularly review and revise its framework so that it reflects changes in state law, technology, recognized standards, and best practices. The operative date is January 1, 2027, and the enactment is chaptered as Chapter 179, Statutes of 2026.

The chapter’s design emphasizes independence, technical expertise, transparency, and practical alignment with established audit and assurance standards. It defines key terms such as “AI,” “AI auditor,” “covered AI audit,” and “independent verification organization,” and it requires the agency to consider conflicts of interest, staffing competence, cybersecurity, and documentation practices when deciding whether to designate or discipline an IVO. The law also creates reporting obligations for designated IVOs, including annual reports to the agency and Legislature beginning no sooner than 12 months after designation. Notably, SB 813 expressly states that it does not itself require any person or company to use an IVO or undergo a covered AI audit as a condition of developing, deploying, or operating AI in California, and it does not create liability solely for failing to comply with a standard adopted under the chapter.

Definitions

Section 8898 provides the statutory definitions that anchor the entire framework. “Agency” means the Government Operations Agency. “Artificial intelligence” is defined broadly as an engineered or machine-based system with variable autonomy that can infer from input how to generate outputs influencing physical or virtual environments. This definition is functional rather than product-specific and is designed to capture a wide range of AI systems and models. “AI auditor” covers a person, partnership, academic institution, nonprofit, or corporation that conducts a covered audit on behalf of a third party, which gives the statute flexibility as to the institutional form of qualified auditors.

The most important new term is “independent verification organization,” defined as an AI auditor designated by the agency for demonstrated expertise in assessing AI risk and identifying the metrics and methodologies underlying that assessment. The statute also defines “covered AI audit” as an audit of internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law. This distinction matters because the chapter is aimed at audit capacity and verification standards, not at requiring every AI developer or deployer to obtain a certification. The definitions therefore frame IVOs as specialized third-party experts whose role is to support state-law compliance, while leaving the substantive compliance obligations to other statutes and regulatory regimes.

Governance and Institutional Framework

The Government Operations Agency is the central administrative body under SB 813. By assigning the designation and oversight function to that agency, the statute places AI auditor credentialing within a state-level governance structure that already interfaces with cross-agency operational issues. The agency must create application requirements, designation criteria, and discipline procedures by January 1, 2028, which gives it time to consult with stakeholders and align its framework with existing professional and regulatory auditing standards. The law also requires the agency to consult, as appropriate, with AI auditors, IVOs, academic institutions, startups, deployers, consumer protection groups, labor and civil society organizations, federal and local agencies, and national and international standards-setting organizations.

SB 813 goes further by requiring the agency to convene working groups to solicit stakeholder input in identifying standards and in developing and revising procedures, requirements, and criteria. Those working groups must include engineers from competing AI companies and AI safety experts, signaling an intent to combine technical expertise with market and public-interest perspectives. The agency must report to the Legislature on the working groups’ findings under Government Code Section 9795. This framework creates a hybrid oversight model: the agency has formal legal authority, but its substantive criteria must be informed by technical and multi-stakeholder input, and its public-facing criteria are meant to support comparability and reliability across audit frameworks.

Key Focus Areas

SB 813 focuses on four substantive areas: independence, expertise, transparency, and consistency. Independence is addressed through criteria that require the IVO to remain free from the assessed party’s operational or management control and to avoid conflicts of interest that would undermine integrity, quality, or independence. The statute permits payment from the assessed party at reasonable market rates, but forbids payment terms that condition compensation on the results of the assessment. Expertise is addressed by requiring sufficient technical personnel and by directing the agency to consider a range of existing standards, frameworks, guidelines, criteria, and best practices from government agencies, standards bodies, and independent experts.

Transparency is reflected in the public posting of requirements and criteria, annual reporting obligations, and a specific disclosure that the publication of criteria is not a state endorsement of any AI system or model. Consistency is addressed by the requirement that the agency align its criteria, to the extent practicable, with professional and regulatory audit and assurance standards and minimize duplicative compliance obligations by allowing substantially similar reports or engagements to satisfy the chapter where appropriate. The law also emphasizes cybersecurity, requiring the agency to consider lapses in cybersecurity when determining whether to suspend or terminate an IVO designation. These focus areas show that the statute is meant to build an ecosystem for credible third-party evaluation rather than merely create a registry.

Implementation Framework

Section 8898.1 establishes the implementation steps the agency must complete by January 1, 2028. First, it must develop application requirements for designation as an IVO and specify what an applicant must submit. The application must include the applicant’s qualifications, information sufficient to address designation criteria published by the agency, the benchmarks, technologies, metrics, and methodologies the applicant proposes to use, and documentation necessary for the agency to verify the accuracy of application information. This structure allows the agency to evaluate both substantive competence and the credibility of the applicant’s proposed methods.

Second, the agency must develop procedures for suspending or terminating an IVO designation. Those procedures must account for failures to adhere to appropriate standards, material misrepresentations in applications or reports, conflicts of interest that impair independence, failure to maintain adequate documentation, conduct calling into question integrity or competence, and cybersecurity lapses. Third, the agency must develop criteria for qualification as a designated IVO, considering existing professional and regulatory standards and best practices. The statute instructs the agency to publish these requirements and criteria online and to state prominently that publication does not constitute recommendation or endorsement by the state. This implementation model is procedural and iterative, giving the agency an ongoing rule-shaping role rather than a one-time certification function.

Monitoring and Evaluation

Monitoring occurs through annual reporting, ongoing review, and the possibility of designation suspension or termination. Under Section 8898.3, each designated IVO must submit an annual report to the agency and the Legislature, beginning no sooner than 12 months after initial designation. The report must include summaries of the IVO’s standards and methodologies, descriptions of changes to governance policies or funding sources relevant to conflicts of interest or independence, and any changes to application information. This is an important accountability mechanism because it requires designated organizations to keep the state informed about methods and structural changes that could affect audit reliability.

The statute also permits redaction of information necessary to protect trade secrets, cybersecurity, public safety, or the national security of the United States, or to comply with federal or state law. When redactions are made, the IVO must describe the character and justification for the redaction in any published version to the extent permitted and must retain the unredacted information for five years. In addition, the agency must regularly review and revise its requirements and criteria to reflect legal and technological changes. Together, these provisions create a continuous evaluation model that depends on reporting, disclosure, and adaptive rulemaking rather than static certification. The Legislature’s access to working-group findings adds another layer of political and policy oversight.

Penalties, Liability, and Appeals

SB 813 is notably restrained in its enforcement design. Section 8898.4 states that the chapter does not establish liability solely for failure to comply with a standard adopted pursuant to the chapter. This means the statute does not create a standalone cause of action or strict liability regime based only on noncompliance with the chapter’s standards. The law also specifies that it does not require AI developers, deployers, or operators to engage an IVO or undergo a covered AI audit as a condition of operating in California, and it does not require an IVO to conduct audits to assess compliance with state law in order to register with the agency.

The principal consequences in the chapter are administrative, not punitive: the agency may suspend or terminate designation, and it may evaluate conflicts, documentation, misrepresentation, and cybersecurity lapses in doing so. The statute does not establish a separate statutory appeals process for designation decisions, so any challenge or review path would likely depend on otherwise applicable administrative law principles and procedures. The statute does state that in litigation alleging harm caused by development, modification, or use of an AI system or model, the fact that an audit was performed in accordance with a standard identified under the chapter is relevant but not conclusive. That rule speaks to evidentiary weight rather than liability, suggesting that audit compliance may be considered by courts without creating a safe harbor.

Relationship to Other Instruments

SB 813 is explicitly designed to complement, rather than replace, other AI-related laws. The legislative digest notes its relationship to California’s Transparency in Frontier Artificial Intelligence Act, which requires large frontier developers to publish frontier AI frameworks and incorporate national, international, and industry-consensus best practices. SB 813 draws from that broader regulatory environment by building a third-party evaluation infrastructure that can support compliance review and verification. It also refers to existing state law requiring the Department of Technology to inventory high-risk automated decision systems used by state agencies, illustrating that California’s AI governance framework spans both public-sector deployment and private-sector verification.

The law further contemplates use of existing audit and assurance materials to reduce duplication. The agency is instructed, to the extent practicable, to structure requirements so that reports, assessments, audits, or assurance engagements created for similar purposes can be reused if they satisfy the chapter’s requirements. This creates an interoperability principle between SB 813 and other professional, regulatory, or sectoral standards. The statute’s anti-endorsement language also helps separate it from product approval regimes: the state is building a credentialing framework for auditors, not certifying AI systems themselves. In that sense, the chapter sits alongside frontier AI disclosure laws, state procurement protections, and broader automated decisionmaking oversight, while preserving doctrinal separation between audit accreditation and substantive AI regulation.

National/Federal Alignment

SB 813 aligns with federal and national auditing concepts, but it remains a California-specific framework. The statute expressly directs the agency to consider standards and best practices developed by government agencies, national and international auditing and assurance organizations, AI auditors, deployers, developers, and independent experts. It also instructs the agency, to the extent practicable, to align its criteria with existing professional and regulatory audit and assurance standards, which suggests compatibility with broader assurance practices rather than a uniquely California method. This makes the chapter easier to harmonize with multi-jurisdictional audit work and potentially more useful for firms operating across state or international markets.

At the same time, SB 813 differs from federal AI regulation in that it does not depend on a federal mandate or federal certification pathway. It establishes state administrative oversight over who may be designated as an IVO and how that designation is monitored, but it does not preempt federal law or claim nationwide effect. The Governor’s signing statement explicitly called for robust national regulations, indicating that the state framework is intended to fill a gap rather than displace federal action. Because the chapter allows reuse of substantially similar assessments and emphasizes comparability, it may be operationally compatible with federal audit expectations if and when those emerge. For now, however, it is a distinct California mechanism focused on oversight, transparency, and the credibility of third-party AI assessment.

Implementation Timeline

MilestoneDateNotes
Approved by Governor2026-09-09Signed into law as Chapter 179, Statutes of 2026.
Filed with Secretary of State2026-09-09Chaptered and filed on the same date as approval.
Effective date2027-01-01Operative date under California constitutional timing rules for non-urgency statutes.
Agency must develop IVO framework2028-01-01Deadline for application requirements, designation criteria, suspension/termination procedures, consultation, publication, and legislative reporting.
First annual IVO report due2028-01-01No sooner than 12 months after initial designation as an IVO, and annually thereafter.

Compliance Checklist

CheckRequired Action
Designation frameworkDevelop and publish application requirements, designation criteria, and suspension/termination procedures.
Stakeholder consultationConsult with auditors, IVOs, academics, industry, civil society, and relevant agencies.
Working groupsConvene working groups including engineers from competing AI companies and AI safety experts.
Public disclosurePost requirements and criteria on the agency website in a publicly accessible format.
No state endorsementPublish a prominent statement that the framework is not an endorsement of any AI system or model.
Annual reportingSubmit annual IVO reports to the agency and Legislature beginning at least 12 months after designation.
Conflicts and independenceEnsure payment, governance, and contractual terms do not compromise independence.
Documentation retentionRetain unredacted information for five years when redactions are used.
Cybersecurity oversightConsider cybersecurity lapses in designation suspension or termination decisions.

Sources and References

SourceType
California SB 813 — Chapter 14 (commencing with Section 8898) of the Government Codeofficial
Governor Newsom signs first-in-the-nation AI safeguards to protect Californians, calls on the federal government to do its partgovernment
California Legislative Informationlegal
California Government Operations Agencygovernment
California Governor's Officegovernment

Sources and References

SourceType
Senate Bill No. 813, Chapter 179, Statutes of 2026 — California Legislative Informationofficial
Governor of California — signing announcement, 9 September 2026official

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash