On September 9, 2026, California's governor signed two bills that do something new: instead of regulating AI systems, they regulate the people who audit AI systems. Put that next to Colorado's Automated Decision-Making Technology Act, whose obligations take effect January 1, 2027, and a pattern shows up that AAISM™ candidates should be reading carefully — third-party AI assurance is turning into a legal category, and the timing is awkward.

What Actually Passed

Senate Bill 813 directs California's Government Operations Agency to build, by January 1, 2028, a framework for designating independent verification organizations — third parties recognized as competent to assess the risks an AI system or model poses. The agency has to set application criteria, define how a designation gets suspended or revoked, draw on existing government and international frameworks, and convene working groups spanning engineers, safety researchers, developers, and civil society.

Assembly Bill 1405 comes at the same problem from the other end. It requires an online AI Auditor Registry by January 1, 2029, after which an unregistered person or firm generally cannot offer or perform an AI audit conducted to assess compliance with state law. Registered auditors must declare which laws they audit against, describe their methods, and hold to independence rules — no negotiating for employment with a client while auditing them, no taking on work where a financial or business interest would compromise objectivity. Audit documentation has to be retained for at least ten years.

Colorado is further along on obligations and further behind on infrastructure. Its ADMT Act, signed May 14, 2026, covers automated systems that materially influence consequential decisions — employment, housing, lending, insurance, healthcare, education, government benefits. Developers owe deployers technical documentation on intended uses, training-data categories, known limitations, and human-review instructions. Deployers owe consumers notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, and a route to correction and meaningful human review. The Attorney General published draft rules on August 11, 2026; a revised draft is due September 23, with the formal hearing and final written comment deadline on October 26.

Why this matters for AAISM™: This is Domain 2 third-party risk management arriving as statute rather than best practice. The exam tests whether you can evaluate an external assurance artifact as one input to your own risk assessment — and these laws are unusually explicit about that distinction.

The Part Most Summaries Skip

SB 813 goes out of its way to withhold the thing most organizations would want from it. Certification by an independent verification organization does not create a safe harbor. The law does not require developers to use one, does not require those organizations to verify legal compliance, and does not establish liability for skipping the process. An audit is treated as evidence that bears on a question of harm without settling it.

That is a meaningful design choice, and it mirrors something AAISM™ Domain 2 keeps returning to: assurance obtained from a third party does not relocate accountability. A vendor's SOC 2 report has never discharged the acquiring organization's duty to assess its own risk, and the same logic is being written directly into AI statute. If you are the deployer, a clean report from a registered auditor is input to your risk determination, not a substitute for making one.

The Timing Gap Worth Planning Around

Line the dates up and the sequencing problem is obvious. Colorado's substantive duties land January 1, 2027. California's verification framework is not due until January 1, 2028, and its auditor registry not until January 1, 2029. Organizations will owe documented, defensible AI governance roughly a year before there is a regulated assurance market to buy it from, and two years before the registry that identifies qualified auditors exists.

The practical read: the capability has to be built internally first. Frameworks like the NIST AI RMF are the available scaffolding for that — its Govern and Measure functions map closely onto what both states are asking deployers to evidence, which is a documented basis for the decision rather than a certificate.

Want to go deeper on how this domain is tested on the AAISM™ exam? The AI Security Management Prep App covers it across 307 practice questions, fully offline — coming soon to Google Play as a free download.

Explore the App

Related Reading

For the full exam breakdown, see the AAISM™ Certification Study Guide. On third-party risk specifically, see The Vercel Breach: An AI Vendor Risk Case Study and One Vendor, Three AI Breaches. For a risk framework operating under pressure, see OpenAI's Astra Pause.

Sources

California Legislature — SB 813, independent verification organizations
California Legislature — AB 1405, AI auditor registration
Office of the Governor of California — September 9, 2026 signing announcement
Colorado General Assembly — SB26-189, Automated Decision-Making Technology
Colorado Attorney General — ADMT and Chatbot Safety Act rulemaking
NIST — AI Risk Management Framework