Technology
Independent verification organizations
California will create a state designation framework for independent organizations that assess AI-system risks.
The law sets public criteria and oversight for AI auditors without requiring AI developers or users to hire them. It also makes a qualifying audit relevant, but not decisive, evidence in AI-harm lawsuits.
What the law does
- Requires the Government Operations Agency by January 1, 2028, to create IVO application requirements, qualification criteria, and suspension or termination procedures.
- Requires designated IVOs to demonstrate AI-risk assessment expertise, technical staffing, independence, conflict management, documentation, and cybersecurity safeguards.
- Requires the agency to publish and regularly update its standards and criteria, align them with existing audit frameworks where practical, and reduce duplicative compliance work.
- Requires stakeholder working groups and a report to the Legislature on their findings.
- Requires designated IVOs, beginning no sooner than 12 months after designation, to annually report their methods and relevant governance, funding, and application changes.
- Allows IVOs to redact protected trade-secret, cybersecurity, public-safety, national-security, or legally protected information while retaining unredacted records for five years.
Who it affects
- AI auditors seeking state designation as independent verification organizations.
- AI developers, deployers, and operators that may choose to use an IVO or covered AI audit.
- Consumer, labor, civil-society, academic, standards-setting, and government stakeholders participating in the agency process.
- Parties in lawsuits alleging harm caused by an AI system or model.
Context
The law does not require AI companies to obtain an IVO audit, creates no standalone liability for missing a standard, and does not endorse any AI system or model.