Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →California AI Safeguards Act (Third-Party Audit and Independent Assessment Requirements)
Issued by
State of California, Office of the Governor
California enacted two AI-related bills establishing first-in-the-nation mandatory standards for third-party audits and independent assessments of AI systems. The legislation applies to AI developers and deployers operating in California or serving California residents. It imposes requirements across model evaluation, vendor assurance, audit governance, and documentation controls.
Applies To
Overview
Signed by Governor Newsom on September 9, 2026, these two bills collectively create binding obligations for entities that develop or deploy AI systems in California or directed at California consumers. The legislation centers on third-party audit requirements and independent assessments, making California the first state to mandate this level of external scrutiny for AI systems. Key provisions address how AI models must be evaluated before and after deployment, what documentation must be maintained, and how vendor relationships must be governed to ensure assurance obligations flow through supply chains. Enforcement authority rests with California state agencies, and the signing statement explicitly called on the federal government to adopt complementary national standards. Organizations that fail to comply with audit and documentation requirements face regulatory exposure under California's existing consumer protection and technology enforcement frameworks.
Key Requirements
- •Conduct mandatory third-party audits of covered AI systems prior to deployment and at defined intervals thereafter
- •Commission independent assessments that evaluate AI model behavior, outputs, and risk characteristics against documented criteria
- •Maintain audit governance documentation, including audit scope, methodology, findings, and remediation records
- •Impose contractual vendor assurance obligations on third-party AI suppliers, ensuring upstream compliance with assessment standards
- •Retain audit and assessment records for a period sufficient to support regulatory review and demonstrate ongoing compliance
- •Apply controls to both developers building AI systems and deployers integrating AI into products or services serving Californians
What Your Organization Must Do
- →Audit all AI systems currently in use and identify which fall within the scope of California's developer and deployer definitions
- →Engage qualified third-party audit firms and establish audit cycles that meet the legislation's timing requirements before deployment of any covered system
- →Update vendor and supplier contracts to require conformity with independent assessment standards and to flow down audit cooperation obligations
- →Build an internal documentation framework to capture audit scope, findings, and remediation actions in a format that supports regulatory inspection
- →Assign ownership of audit governance to a named compliance function or officer with authority over both internal teams and external vendors
- →Monitor California regulatory agency guidance for enforcement thresholds, penalty schedules, and clarifications on which AI system categories are covered
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does California's AI Safeguards Act apply to companies outside California that serve California residents?
- Yes. The legislation covers AI developers and deployers that operate in California or direct their services at California consumers, regardless of where the company is headquartered. Compliance obligations attach based on the residency of end users, not the physical location of the business.
- When must third-party audits be completed under CA-AISA-26 -- before or after AI deployment?
- Audits are required prior to deployment of covered AI systems, with additional assessments mandated at defined intervals after launch. Organizations should build pre-deployment audit timelines into product development cycles well before the September 9, 2026 effective date.
- What contractual obligations does CA-AISA-26 impose on companies using third-party AI vendors?
- Deployers must impose vendor assurance obligations through contract, ensuring upstream AI suppliers cooperate with independent assessment standards. This means existing supplier agreements may need to be renegotiated to include audit cooperation clauses and conformity requirements before the law takes effect.
- Which California enforcement agencies have authority under the AI Safeguards Act, and what penalties apply?
- Enforcement rests with California state agencies operating under existing consumer protection and technology enforcement frameworks. Specific penalty schedules have not yet been published, so compliance officers should monitor agency guidance closely for enforcement thresholds and clarifications on covered AI system categories.
- How long must audit records be retained to satisfy CA-AISA-26 documentation requirements?
- The legislation requires retention for a period sufficient to support regulatory review and demonstrate ongoing compliance, but does not specify an exact number of years. Until California agencies issue further guidance, organizations should align retention periods with comparable frameworks such as the EU AI Act or NIST AI RMF documentation standards.
- Does CA-AISA-26 apply to small and mid-size businesses, or only large enterprises?
- The law explicitly covers both large enterprises and SMBs that develop or deploy covered AI systems in California. Unlike some privacy statutes with revenue or data volume thresholds, CA-AISA-26 does not currently carve out smaller organizations, making early compliance planning important for companies of all sizes.
