SB 813 and AB 1405 Explained:
California’s proposed independent AI audit framework
In June 2026, two California legislators announced they were rewriting their AI bills to work as one. Senator Jerry McNerney's SB 813 and Assemblymember Rebecca Bauer-Kahan's AB 1405 share a goal that Bauer-Kahan articulated directly: "Good AI policy requires independent verification of safety." Both would build the apparatus requiring AI systems be checked by someone independent of the people who made them.
If you build or deploy AI, this is aimed at you, not only at the frontier labs. California's existing AI law covers the few companies training the largest models. These bills go wider: they reach any company that takes an off-the-shelf model, including an LLM like the ones behind most AI products, and builds it into something that screens job applicants, prices a policy, or makes another call that affects people. Neither is law yet, but both are positioned for an August 31 deadline.
How SB 813 and AB 1405 would regulate AI Audits
The two bills address the same problem from opposite ends.
SB 813, from McNerney, would create a voluntary certification system. A new California AI Standards and Safety Commission would approve expert panels, called Independent Verification Organizations, that set safety standards for a field such as health care or energy and certify the systems that meet those standards. If a certified system causes harm and the developer is sued, the court starts from the assumption that it took reasonable care. A plaintiff can argue otherwise, but certification is a legal head start.
AB 1405, from Bauer-Kahan, comes at it from the other side. It would set up a state registry for the auditors who check AI systems. To take the work, an auditor would enroll, disclose its credentials and methods, follow recognized standards, and stay clear of the companies it audits, much as outside accountants certify a company's books.
Neither bill is limited to frontier models. Both cover AI systems and the applications built on them, so a company that wraps an existing LLM into a hiring tool or a claims bot is as much in scope as the lab that trained the model. Nothing is mandatory yet: SB 813 is opt-in, and AB 1405's rules apply only once another law requires an audit. The intent is to make independent verification available and credible before that day comes. So far SB 813 has cleared the state Senate; AB 1405's matching changes are promised but unwritten.
Why independent AI audits are becoming a business expectation
At present, no deadline forces anyone to act, so the reason to watch is a different one. These bills are the missing piece of a longer story. California tried to regulate its largest AI developers directly in 2024, with SB 1047; the governor vetoed it. A slimmer successor, SB 53, became law in 2025 and forced frontier developers to disclose how they manage risk, but dropped the part that drew the most fire: mandatory checks by an independent party. A report the governor himself commissioned had urged exactly that, under the banner "trust but verify." SB 813 and AB 1405 are the attempt to build the "verify" half.
In December 2025 the White House moved to limit how far states can regulate AI. A standards-based system has a better chance of surviving that than a hard mandate, and McNerney has said so: if Washington overrides state law, "standards will be the only tool" left.
The market is ahead of the legislature anyway. New York City's bias-audit law showed that once an independent audit exists, buyers ask for it before they sign. The cost of not showing your AI was checked is already climbing and expanding in scope.
What SB 813 and AB 1405 would do in practice
In practice, SB 813 does three things.
The standards and who sets them. Each verification panel is a group of industry experts, academics, and officials that write the safety standards for its field and certify the systems that meet them. To win approval, a panel must show the state how it will handle the worst risks: cyberattacks, AI that helps build chemical or biological weapons, mass manipulation, and models that act on their own or copy themselves out of their environment.
The certificate and what it buys. Certification earns a developer a presumption, in an injury or property-damage suit, that it acted reasonably. That better starting position can be contested in court — it’s not immunity, and not a way to avoid being sued, but proactive verification can help avoid a purely reactive legal posture.
Keeping the verifiers honest. A panel can lose its standing, and a system its certificate, if the verifier's independence slips or an approved system causes real harm.
AB 1405 is narrower. An auditor would enroll before working, document who it is and how it operates, follow accepted standards, and keep its distance from clients: no auditing a company it just worked for, no job with one it just audited. Its reports would say what was examined, what was found, and what needs fixing.
Only audits that another law requires are governed by AB 1405, and today no California law requires an independent AI audit. Its own legislative analysis admits it: "Currently, no such auditing requirements exist." The law meant to create that requirement had its audit rule pushed to 2030, then stalled. California is registering AI auditors before it requires anyone to be audited, which is almost certainly why the two bills are being joined.
The biggest challenges in independent AI auditing
Both bills focus on the same thing: an independent check that means something. People who can do that work are scarce, and everyone involved admits it. The software industry's main trade group, while opposing AB 1405, conceded the field lacks agreed standards on how an audit should run, any way to govern the auditors, and enough qualified ones to meet demand. Supporters say the same.
Checking an AI system, rather than an administrative exercise, requires probing the system like a determined adversary: making it misbehave, testing whether it treats people unfairly, and pressing it against the serious risks the standard addresses. That is a different skill from authoring or reading policy, and most teams lack the technical expertise.
The second requirement, that the auditor cannot be the builder, strips a verifier's standing if its independence slips, and AB 1405 bars auditors from evaluating work they have a stake in. Independence is the whole point, and is what makes a verification meaningful to a regulator, customer, or court.
How California’s AI audit bills compare with other regulations
None of this is happening in isolation, and anyone who tracks AI rules elsewhere will be familiar with the narrative. New York City got there first: since 2023, employers using AI to screen candidates have had to commission an independent bias audit and post the results. Buyers and candidates look for the audit (and civil suits have hinged on its absence), a sign that an independent check becomes a market expectation before regulatory consequences are in place for skipping it.
Europe has built the fullest version. Under the EU AI Act, the riskiest AI must pass an assessment before sale, and some must be checked by accredited outside bodies, the same structure California is reaching for: a meaningful certificate (SB 813) and a roster of the bodies that grant it (AB 1405). This regulatory pattern is well precedented. Banks have long had their risk models checked by external parties, and markets run on independent audits and credit ratings. Standards like ISO 42001 are becoming baseline. Each version comes back to the independence of the auditors.
How to prepare for California AI audit requirements
Waiting for the bills to pass is the wrong move, because what they are organizing, independent verification, is already a cost of doing business. A few steps make sense now, whatever Sacramento does:
-
Know what AI you run, and which systems make decisions that affect people. To verify, you need to be aware of what systems are relevant first.
-
Have the systems that matter checked independently and maintain the documentation, having it ready before a customer, regulator, or court asks.
-
Treat a clean verification as an asset for a board, a buyer, or an insurer.
-
Watch the next legislative developments: the amendments joining these bills, and any law that requires an audit rather than enabling one.
How Conformance AI supports independent AI verification
The companies ready when legislation passes will be the ones familiar with treating independent verification as part of shipping AI, rather than as an obligation relevant only after a law forces it.
That’s what Conformance AI does. We are an independent, third-party check on AI systems: we evaluate them adversarially, test for biased and unsafe behavior, find why they fail, and produce evidence and documentation. It is the role these bills describe: the verifier SB 813 would certify through, and the auditor AB 1405 would register.
The upside is not only avoiding trouble, since a system that an outsider has checked is one you can deploy with the board behind you, sell to buyers who ask about safety first, and stand behind if it is challenged. Done right, verification speeds deployment rather than blocking it. And because the value rests on independence, it has to come from outside: a company vouching for its own AI is the one claim that carries no weight.
This article is general information, not legal advice. SB 813 and AB 1405 are pending as of June 2026 and their text is still changing; confirm specifics against the current bills and your own advisors.


