NewsMacroCalifornia Moves AI Governance Toward Independent Verification

California Moves AI Governance Toward Independent Verification

Author: AI Business·

Key Takeaways

  • California enacted two laws that create a framework allowing third-party organizations to independently audit AI systems for compliance with state law.
  • The legislation sets standards for auditor independence, transparency and integrity, moving AI governance away from developer self-reported safety claims.
  • The new laws extend California's multi-year AI policy agenda, which includes the Transparency in Frontier Artificial Intelligence Act requiring frontier developers to disclose safety frameworks and report critical incidents.
  • Recent incidents at OpenAI and Anthropic, in which AI agents and models bypassed safeguards, highlight why regulators are pushing for verified rather than promised safety measures.
  • Independent audits could provide enterprises with outside evidence to evaluate whether AI vendors' claims about safety, security and governance are credible.
California Moves AI Governance Toward Independent Verification

California Moves AI Governance Toward Independent Verification

California’s new AI auditing laws point to a shift from companies making their own safety claims to proving those claims through independent review.

September 11, 2026

For years, companies developing artificial intelligence have largely been responsible for evaluating the safety of their own systems. California is beginning to change that approach.

California Gov. Gavin Newsom signed two laws this week that lay the groundwork for independent, third-party AI audits. The bills establish a framework for independent audits, including how third-party organizations can assess AI systems for compliance with state law. They also set standards for auditor independence, transparency and integrity.

The legislation follows several years of AI policy development in California. In 2023, Newsom issued an executive order establishing guidelines for the state’s use of generative AI. In 2024, the state adopted a broader package of AI legislation addressing issues including deepfakes, watermarking, children and workers. Last year, California enacted the Transparency in Frontier Artificial Intelligence Act, which requires frontier AI developers to publicly disclose their safety frameworks and report certain critical safety incidents.

The timing is notable as frontier systems increasingly behave in ways their developers did not anticipate or authorize.

OpenAI acknowledged this week that more of its agents went astray in May, bypassing sandbox restrictions and taking unauthorized actions on several websites. The company initially did not acknowledge its involvement in one of the incidents, but later confirmed that its agents had written to several internet sites. The episode underscores a broader challenge as AI systems become more autonomous: Developers remain largely responsible for investigating and explaining their systems’ behavior.

Anthropic raised a similar concern this week, calling for a “verifiable effort” to pace frontier AI development after an incident in July in which its Claude Mythos model circumvented safeguards. The proposal reflects growing recognition that AI safety measures may need to be demonstrated rather than simply promised.

Implications for enterprises

Third-party auditing is not only a matter of regulators policing AI companies. For enterprises, independent audits could provide another layer of due diligence when they evaluate AI vendors, particularly as autonomous systems take on more responsibility within organizations.

That could become increasingly important as businesses give AI systems access to sensitive data, applications and workflows. If independent evaluation becomes more common, enterprises adopting AI could gain outside evidence of whether vendor claims about safety, security and governance hold up.

The next phase of AI governance may therefore focus less on what companies promise and more on what they can prove.

Also in AI news this week

  • Qualcomm to Make Custom Chips for Amazon as Part of $4B Deal: The chipmaker struck a major deal with Amazon to develop custom AI and data center chips, adding another hyperscaler customer as it expands further into AI infrastructure. Source

  • John Deere Harvests Data Insights With New AI Technology: The agricultural giant is adding generative AI to its farm management platform, helping farmers turn equipment and operational data into practical decisions about planting, harvesting and machine performance. Source

  • Dell Faces Widening Supply Shortages as High AI Demand Persists: The multinational technology company is facing widening supply shortages as AI demand strains not only memory, storage and CPUs, but also the cooling, networking and power components needed to build complete AI systems. Source

  • AI Coding Startup Cognition Now Valued at $48B: The AI coding vendor raised $2 billion at a $48 billion valuation as investor enthusiasm for AI coding tools continues. Source

  • Google to Invest $15B in Finland’s AI Infrastructure: The search and AI giant plans to invest $15 billion in Finland’s AI infrastructure, expanding its data center footprint as demand for AI computing capacity grows. Source

  • Inside Google AI Worker’s Union Drive to Instill Company Ethics: Google DeepMind employees are pushing to unionize over ethical concerns about the military’s use of the company’s AI and cloud technologies. Source

  • Threat Groups Enhance Cyberattack Capabilities With AI: State-linked and criminal hackers are increasingly using AI and automation to scale attacks, find new targets and bypass traditional defenses. Source

  • AWS AI Symposium: TeenTech Alumni Call for AI Literacy in Schools: Alumni of the nonprofit are calling for more AI literacy in schools as skills shortages remain a major barrier to AI adoption. Source