Blog

California SB 813 and AB 1405: New AI Safeguards Explained

Governor Newsom signed SB 813 and AB 1405, creating first-in-the-nation AI safeguards. See scope, timelines, and how they interact with federal talks.

California SB 813 and AB 1405 AI safeguards independent verification and auditor registry
Governor Newsom signed SB 813 and AB 1405 on September 9, 2026, creating California's first independent AI verification and auditor registry framework.

On September 9, 2026, Governor Gavin Newsom signed Senate Bill 813 and Assembly Bill 1405, two companion measures that turn California's voluntary AI safety dialogue into a structured third-party oversight system. The signing arrived one day after frontier labs disclosed new agent security incidents and the same week Senate leaders began drafting federal catastrophic-risk legislation. California now has a registry-backed path for independent AI assessments, not just developer self-certification.

This analysis explains what California SB 813 AI law requires, how AB 1405 sets auditor independence and disclosure rules, which entities must comply, how the bills interact with federal preemption debates, and an enterprise compliance checklist for teams deploying AI chatbot products or buying frontier models. Compare vendor posture against AI regulation resources before your next procurement cycle.

What SB 813 Requires

SB 813 establishes a first-in-the-nation process for designating independent verification organizations that can assess AI systems and models for compliance with California law. Senator Jerry McNerney (D-Pleasanton) authored the bill to codify a primary recommendation from Governor Newsom's blue-ribbon AI panel: credible third-party evaluation instead of industry-only safety claims.

The California Government Operations Agency (GovOps) must create criteria for qualified assessors, including technical competence, security clearance for sensitive model access, conflict-of-interest rules, and transparency about assessment methods. Once designated, verification organizations can evaluate whether frontier and general-purpose AI systems meet obligations under existing California statutes, including SB 53 (Transparency in Frontier Artificial Intelligence Act) and sector-specific rules for government procurement.

SB 813 does not replace developer safety frameworks. It adds an external check that regulators, insurers, and enterprise buyers can reference when models touch critical infrastructure, public-sector contracts, or high-risk consumer applications. Newsom framed the bill as a response to accelerating capabilities and recent incidents where autonomous agents exposed infrastructure vulnerabilities during evaluation runs.

SB 813 element Requirement Expected timeline
Assessor designation process GovOps publishes qualification standards for independent verification organizations Rulemaking phase after January 1, 2027 effective date
Independent evaluations Designated orgs assess AI systems for compliance with applicable state law Assessments follow designation of first qualified orgs
Integration with SB 53 External verification supplements frontier developer safety disclosures Ongoing as SB 53 incident reporting already active
Public accountability Assessors identify risks, verify marketing claims, test against state standards Reports expected to inform enforcement and procurement

AB 1405 Disclosure and Testing Rules

AB 1405 creates a state registry for AI auditors and sets independence, transparency, and integrity standards for their work. Assemblymember Rebecca Bauer-Kahan (D-Orinda) argued that Californians cannot rely on developers to grade their own homework. The registry gives enterprises a single place to confirm whether an auditor meets statutory independence requirements before accepting assessment reports.

Registered auditors must disclose financial conflicts, methodology limitations, and scope of each engagement. GovOps maintains the public registry and can suspend or revoke listings when auditors fail independence tests or misrepresent findings. AB 1405 pairs with SB 813: SB 813 defines who can perform verification; AB 1405 defines how auditors stay credible once in the ecosystem.

OpenAI publicly supported both bills on September 9, 2026, stating that while it prefers federal assessor standards, California can establish rules of the road for a secure national independent-assessment system. Anthropic and several civil-society groups welcomed the registry approach but continue pushing for mandatory government-led testing in pending Senate legislation.

Who Must Comply

SB 813 and AB 1405 primarily govern frontier AI developers, government contractors, and verification organizations, not every small SaaS chatbot vendor. However, downstream deployers that resell or fine-tune covered models inherit compliance gaps when upstream providers lack valid third-party assessments.

Covered entities include:

  • Frontier model developers subject to SB 53 transparency and incident-reporting duties
  • Independent verification organizations seeking GovOps designation under SB 813
  • AI auditors registering under AB 1405 before performing state-recognized assessments
  • California agencies procuring AI systems where executive orders require elevated trust-and-safety bars
  • Critical-infrastructure operators that integrate general-purpose models into cyber, health, or energy workflows

Consumer apps using API wrappers around frontier models should contractually require assessor reports and registry confirmation. Startups building narrow vertical models may fall outside direct SB 813 scope today, but procurement teams increasingly treat third-party verification as a de facto requirement regardless of statute.

Overlap with Federal Preemption Debate

California's new safeguards sharpen the national preemption fight as Senate negotiators draft a bill that may block states from enforcing certain AI catastrophic-risk laws. Reuters reported on September 11, 2026 that draft Senate language could preempt state rules governing biological, nuclear, and cyber misuse risks from frontier models. Senator Maria Cantwell (D-Wash.) warned that weak federal standards must not become a backdoor to wipe out stronger state protections.

Governor Newsom used the SB 813 signing to repeat his call for robust national regulation while defending California's right to act first. The tension is structural: SB 813 and AB 1405 build state infrastructure for independent assessment, while pending federal bills may centralize blocking authority in Washington. Enterprises operating nationally should map which obligations are California-specific, which may be preempted, and which federal duties could supersede state auditor registries if Congress passes capability-based national rules.

Policy layer California (Sep 2026) Federal (negotiation phase)
Independent assessment SB 813 designation + AB 1405 auditor registry OpenAI blueprint calls for federal assessor standards; Senate draft unsettled
Release blocking SB 53 incident reporting; no explicit federal-style block authority yet Draft may let government block unsafe model releases with court appeal
State law preemption California statutes remain enforceable until federal law passes Preemption language under active negotiation; Cantwell opposes weak floor
Whistleblower protection SB 53 protections for serious-risk reporters Not yet defined in public Senate draft summaries

Enterprise Compliance Checklist

Teams shipping AI in California should inventory frontier dependencies, track GovOps rulemaking, and contract for third-party assessments before SB 813 designations go live. Use this checklist as a starting point for legal, security, and procurement reviews.

  1. Map every production model to its developer, fine-tuning chain, and applicable California statutes (SB 53, sector rules, procurement EO requirements).
  2. Request current safety frameworks and critical-incident histories from frontier vendors; compare against SB 53 public disclosures.
  3. Monitor GovOps for assessor designation criteria; pre-qualify external firms that intend to register under AB 1405.
  4. Insert contractual clauses requiring registry-listed auditors for major model upgrades and annual reassessment.
  5. Document internal red-team results separately from vendor claims; regulators may ask how enterprise testing complements third-party reports.
  6. Track Senate preemption negotiations; update multi-state compliance matrices when federal text is introduced.
  7. Align incident response with California reporting timelines if your deployment qualifies as a covered developer or critical-infrastructure operator.
  8. Train procurement staff to reject unaudited frontier models for government-adjacent or regulated-sector use cases.

Insurance and enterprise risk teams should treat SB 813 assessments as emerging evidence in underwriting decisions, similar to SOC 2 reports for cloud services. Early adopters that publish assessment summaries may gain trust advantages with California public-sector buyers operating under Newsom's 2026 procurement executive order.

Frequently Asked Questions

When do SB 813 and AB 1405 take effect?

Both bills were signed September 9, 2026. Statutory effective dates follow standard California legislative calendars, with GovOps rulemaking for assessor designation expected to begin after January 1, 2027. Enterprises should monitor regulatory filings rather than waiting for the first enforcement action.

Does AB 1405 require every AI company to hire an auditor?

AB 1405 regulates auditors and their registry status, not every AI developer directly. Frontier developers and high-risk deployers will likely need registered auditors when SB 813 assessments become operational or when contracts and sector rules require external verification. Small narrow models may remain outside mandatory scope initially.

How do these bills relate to SB 53?

SB 53 (2025) requires frontier developers to publish safety frameworks and report critical incidents. SB 813 adds independent verification organizations that can test whether those frameworks hold up in practice. Together they move California from disclosure-only toward verified accountability.

Will federal law override California's auditor registry?

That depends on final Senate preemption language. As of September 2026, no federal AI safety bill has passed. California's registry remains enforceable. Enterprises should plan for dual compliance until Congress enacts national assessor standards and clarifies which state rules survive preemption.

Did OpenAI support these bills?

Yes. On September 9, 2026, OpenAI announced support for SB 813 and AB 1405 while urging Congress to adopt mandatory federal assessor standards. The company stated California can help establish national independent-assessment infrastructure in the absence of federal action.

Related blogs

  • AI Tool Login and SSO Problems: A Troubleshooting Guide

    AI Tool Login and SSO Problems: A Troubleshooting Guide

    SSO failures block entire teams. Troubleshoot SAML OIDC misconfigurations domain verification and session issues step by step.

  • AI Tools for Manufacturing: Shop Floor to Supply Chain Use Cases

    AI Tools for Manufacturing: Shop Floor to Supply Chain Use Cases

    Manufacturing AI spans predictive maintenance quality control and supply chain. Learn OT/IT boundary concerns and practical adoption outside hype.

  • AI Workflow for Construction: Submittal Cover Letters and RFI Drafts

    AI Workflow for Construction: Submittal Cover Letters and RFI Drafts

    Draft submittal cover letters and RFI clarifications with AI from spec sections and drawings your PM verifies before sending to GC.

  • Communication Plan for Migrating Between AI Tools

    Communication Plan for Migrating Between AI Tools

    Migrating tools fails when users learn last. Timeline communications for training, cutover, and support.

  • AI Prediction of Antibiotic Resistance Patterns

    AI Prediction of Antibiotic Resistance Patterns

    Research-backed explainer on antibiotic resistance prediction ai: what works today, limits, and workflows, without tool listicles.

  • AI Capability Maps: Documenting What Each Tool in Your Stack Does

    AI Capability Maps: Documenting What Each Tool in Your Stack Does

    Capability maps prevent duplicate subscriptions and shadow tools. Learn the fields to capture for every AI service.

Didn't find tool you were looking for?

Be as detailed as possible for better results