California SB 813 independent AI certification framework and what third-party safety audits mean for builders deploying production AI systems
California Just Changed Who Gets to Call AI Safe
I’ve been waiting for something like this. Not because I think state-level legislation is the ideal venue for AI governance, but because the alternative, which is letting the labs grade their own homework indefinitely, was never going to hold.
On September 18th, Governor Newsom signed SB 813. California is now the first state in the country with a legal framework for certifying independent verification organizations that can objectively assess AI systems before they reach the public. These aren’t internal red teams. They’re not safety councils with lab employees on the board. The law explicitly requires demonstrated independence from AI companies.
That word, independence, is doing a lot of work here. Let’s talk about why.
The Self-Certification Problem
For the past two years, the de facto safety standard in AI has been: the lab publishes a document and you decide whether to trust it. OpenAI releases a system card. Anthropic publishes a responsible scaling policy. Google DeepMind ships an eval report before a new Gemini release. All of these are better than nothing. None of them are independent.
This isn’t a knock on the people writing those documents. Many of them are doing serious work. But the structural incentive is broken. A company with a product to ship is not the right entity to make the final call on whether that product is safe to ship. That’s not cynicism, it’s just how accountability works in every other high-stakes industry.
SB 813 says that’s no longer the whole answer in California.
What This Means for Builders
If you’re deploying production AI systems, this law matters to you more than it matters to the labs. The labs have legal teams. You have a sprint cycle and a deadline.
Here’s the practical read: California just created a new class of certified auditors with a legal role in AI safety determination. As that auditor ecosystem matures, enterprises deploying AI in California will face pressure, from procurement, from legal, from insurance carriers, to show they used a certified independent verifier before going live. That pressure will come whether or not the law explicitly requires it of downstream deployers.
The labs are already moving. OpenAI, Anthropic, and Google DeepMind have reportedly been in safety talks for weeks, exploring a shared standards body focused on independent pre-release evaluations and standardized risk-assessment frameworks. Dario Amodei published a 3,800-word essay calling for AI companies to slow frontier development until risk research catches up. Sam Altman endorsed it. These aren’t people who agree on much.
The Geopolitical Wrinkle
None of this happens in a vacuum. Amodei also called for restrictions on AI chip sales to China, which prompted Beijing to warn against “fear-mongering” in what Al Jazeera called a “silent cold war” over AI development pace. The US-China dimension complicates any argument for slowing down, because slowing down unilaterally is not the same as slowing down together.
California’s certification framework doesn’t resolve that tension. But it does establish that safety verification is a real legal construct, not just a marketing claim. That’s a foundation worth building on, even if the geopolitics make the roof harder to design.
My Take
I think SB 813 is the right move at the right time, with one caveat. The value of this framework is entirely dependent on the quality of the organizations California certifies. An independent auditor with weak methodology is just a different kind of rubber stamp. The hard work is in building the technical standards that make those audits meaningful, and that work hasn’t been done yet.
What I want to see next is the certification criteria for the verifiers themselves. Who audits the auditors, what technical depth is required, and whether the evaluation methods keep pace with model capabilities. Without that, we’ve got a governance structure with a strong skeleton and no muscle.
The labs defining “safe” on their own was always a placeholder. California just formally replaced the placeholder. What fills that space now is the question that actually matters.
Sources & Further Reading
#AIPolicy #MachineLearning #AIGovernance #SB813 #ResponsibleAI
