A view from DC: What will all these AI auditors be auditing?

With two new laws on the books, California is building a regulatory structure for AI auditors, even as audits remain entirely voluntary.

Contributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP
Editor's note
There's an oft-quoted line from Milton Friedman: "Only a crisis — actual or perceived — produces real change. When that crisis occurs, the actions that are taken depend on the ideas that are lying around. That, I believe, is our basic function: to develop alternatives to existing policies, to keep them alive and available until the politically impossible becomes the politically inevitable."
This remains the primary function of the beltway policy community today, kindling ideas and keeping them burning even when they are politically untouchable. Whether this is in service of what Naomi Klein critically labeled "the shock doctrine," or the lofty missions and disparate goals of our think tank stakeholders, we keep the flames alive.
The shock has not happened yet, but the air nonetheless is starting to smell of change. Maybe this is what it feels like when the hot girl summer of AI begins to come to an end.
As IAPP's Alex LaCasse covered Thursday, federal policymakers have rapidly shifted their messaging on AI regulation in recent weeks. So, too, have companies. In a post signed by its chief global affairs officer, Chris Lehane, OpenAI wrote this week that "The AI policy window is open. We need to act."
In some ways, this statement, which promised to push for "mandatory national AI safety requirements" is not a pivot from Lehane's prior support of a moratorium for state-level AI laws, as that was always framed in favor of a national standard.
But the statement also threw support behind four new California AI laws, even as Gov. Gavin Newsom's, D-Calif., signing hand was hovering over the page. The company explains, "Until Congress acts, we will continue supporting state legislation that strengthens the broader AI safety ecosystem."
Auditing the auditors, eventually
Two of the now-signed laws in California relate to the still-nascent industry of AI auditors, AB 1405 and SB 813. For what it’s worth, Anthropic threw its support behind these two laws a couple of weeks ago while the state legislature sprinted to the end of its session, and passed dozens of tech policy bills.
Overall, these laws begin to build the market infrastructure for auditors and other independent accountability mechanisms. But whether an AI developer ever seeks out an audit remains voluntary — for now — despite headlines to the contrary. The most relevant existing law, California's Transparency in Frontier Artificial Intelligence Act, requires developers to disclose their use of third-party assessments as part of a publicly posted safety framework, but it does not mandate third-party review or other accountability.
Considering these two new laws as a package, they outline a two-layered structure for oversight of the AI auditing marketplace, though it will be a while before the structure is built.
The first layer comes from AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, D-Calif. It starts the process to create a state registry for AI auditors, with standards for their independence, transparency, integrity and operational requirements including a 10-year records retention rule. Auditors will be required to list any relevant certifications they have achieved and a standard operating procedure identifying standards and the basis for accuracy, reliability and validity claims.
After 1 Jan. 2029, AI auditors who conduct "covered AI audits" will not be able to legally operate in California unless they are registered and compliant. But how much time is 27 months in AI years?
Notably, TechNet, which counts OpenAI as a member, opposed an earlier version of 1405 in an industry coalition letter, calling it premature and deficient, at least in part because of the lack of legal requirements to conduct audits in the first place.
A year before the registry deadline, on 1 Jan. 2028, is the deadline for California's Government Operations agency to deliver a finalized regulatory framework for independent verification organizations under SB 813. This will build the second layer of requirements for AI auditors.
SB 813 is among a trend of state-level bills exploring mechanisms to create rigor and consistency among IVOs by building qualification requirements to ensure that only reputable auditors flourish.
Although the California law is the first such bill to cross the finish line as a standalone measure, a number of similar proposals have been spreading across state legislatures. And Illinois' recent frontier AI law has a mandatory requirement for independent assessments from IVOs, with its own qualification requirements, for those models and developers that cross the law's thresholds.
Until GovOps delivers its final rules, it is difficult to fully assess the accountability structure baked into SB 813. It does include standards for transparency, including annual reports from IVOs, as well as some detailed specifications for independence. Compared with a mature auditing regime like in the financial sector, there is a long way to go. But the new laws create a baseline to combat fly-by-night external auditing operations.
Not all registered AI auditors will be IVOs, but it is likely all IVOs will be required to register as AI auditors. What they are auditing — compliance with state laws, conformity with benchmarks and standards — is generally left open to future refinement under both laws. SB 813 tells GovOps to "identify and consider" standards, frameworks, guidelines and best practices. AB 1405 requires widely recognized standards appropriate to the system only "to the extent appropriate standards are available."
Through the EU looking glass
Also difficult to unpack is how this emerging regime compares with the approach to assessment and verification under the EU AI Act. In many ways, California and the EU have embraced approaches that are mirror images of each other.
The EU mandates conformity assessments for high-risk systems, but most of the actual assessment is internal. Its independent third-party route is narrow and conditional, such as in context of biometrics in Annex III. The standards against which systems should be assessed are more prescriptive, but the EU has not embraced an auditing regime.
Building on its existing product safety regulatory structure, EU member states designate national notifying authorities, which must meet minimum requirements under the EU-level law. Many of the impartiality, independence, and transparency requirements apply to both structures, but they diverge as much as they overlap.
California also has not embraced an auditing regime, yet, but it has laid the foundation for a robust regulated marketplace of independent assessors. Together these two new auditing laws are a presage of future requirements.
AI researchers, the tech policy community, and AI governance professionals will all be continuing to keep the ideas flowing as we collectively wrestle with the question of what these future auditors will actually be testing.
Please send feedback, updates and independent assessments to cobun@iapp.org.
This article originally appeared in The Daily Dashboard and U.S. Privacy Digest, free weekly IAPP newsletters. Subscriptions to this and other IAPP newsletters can be found here.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP


