Dive Brief:
- California Governor Gavin Newsom signed two bills establishing a framework for independent third-party evaluation and audits of AI models in the state on Wednesday.
- Senate Bill 813 establishes how third-party verification organizations can assess AI systems and models for compliance with state law. Assembly Bill 1405 creates a state registry for AI auditors featuring standards for independence, transparency and integrity that match existing AI safety laws. Currently, enterprises may seek out independent testing of AI or oversight practices.
- Rep. Jerry McNerney, D-Calif., sponsor of SB 813, said that more oversight on AI models is needed as the public learns of the potential risks the technology could pose to humanity. “AI has the potential to improve our lives, but without effective guardrails, it poses significant risks,” he said in a statement.
Dive Insight:
Although American AI providers and the companies that use them have been mostly spared from government regulation of the technology, states have been regulating AI on their own.
California has been a leader in AI regulation, establishing public sector usage guidelines for the technology in 2023, and establishing the Transparency in Frontier Artificial Intelligence Act, which requires frontier AI developers to publish a framework detailing how they incorporated best practices and standards into their AI models, in 2025.
Now California is attempting to add some structure to AI oversight, said Miranda Bogen, chief technologist at The Center for Democracy and Technology and director of the organization’s AI Governance Lab. Under the framework, businesses that need to engage with a third-party assessor can have more awareness of the options that they can turn to to obtain those services.
“I think this is the first step in what will ultimately be a more complex ecosystem where there are more required or expected audits,” she told CIO Dive.
Many enterprises currently participate in voluntary auditing of their AI systems by third-party vendors. If there were eventually requirements for AI auditing or testing, a foundational system, similar to the one California is aiming to build, would be the first step.
Auditing of AI by third-party vendors could help develop more trust in the technology, a win for both AI developers and enterprises that deploy it. It could help settle some of the risk enterprises feel around developing AI technologies, Bogen said.
Safety auditing is most effective when there’s a standard or defined set of expectations, Boden said. The bills are a small step in the right direction toward a uniform safety standard for AI, she added.
“It seems only beneficial, from an information perspective, for enterprises at this point,” she added.
When signing the bills Wednesday, Newsom urged the federal government to develop national AI regulations, as the technology develops at breakneck speed.
“The scale and potential consequences of this technology demand sustained action from every level of government,” Newsom said in a statement.
It’s a sentiment that AI provider OpenAI echoed in a blog post Wednesday. Company leadership said it would prefer independent technical assessments to be required at the federal level, but described California’s laws as a step in the right direction.
“California can help establish the rules of the road for a secure, capable national independent-assessment system that produces better safety outcomes,” the statement said.