SACRAMENTO

California established some of the nation's first rules for artificial intelligence auditors on Sept. 9. The new policies define who can conduct these audits but do not require auditors to verify that an AI system's numbers are accurate.

Christina Ho, chief assurance officer of Oath Verified, highlighted this omission. Ho, who spent four years on a board regulating public company auditors, said the state's approach misses a critical component of auditing.

This gap mirrors a persistent problem in traditional financial auditing. In 2024, federal agencies reported an estimated $162 billion in improper payments. Most of these agencies received clean opinions on their financial statements, revealing a disconnect between audit results and financial realities.

Corporate fraud has also exposed the limits of current audit standards. Corporate fraud was estimated to destroy $830 billion annually at 2021 valuations. The Macy's case illustrates the problem: a single employee concealed over $100 million in expenses across nearly three years by falsifying documentation. In December 2024, Macy's announced that neither its internal financial controls nor its auditor's assessments could be trusted, despite controls being signed off on.

California's Assembly Bill 1405, authored by Assemblymember Rebecca Bauer-Kahan, establishes a state registry for AI auditors and sets standards for auditor independence, transparency, and integrity.

The law does expand who can perform AI audits. It allows smaller CPA firms, technology companies, nonprofit groups, and academic consortia to conduct audits if they demonstrate expertise—moving beyond the Big Four accounting firms, which audit nearly every large public company in the United States.

OpenAI supported this push for competition. The company also backed safeguards against conflicts of interest that California included in the legislation. The rules mandate firewalls for certain financial and operational relationships to prevent auditor conclusions from being influenced by external pressure—a direct response to situations like Arthur Andersen's dual role as auditor and consultant for Enron.

Both Anthropic and OpenAI backed the bill. OpenAI's chief global affairs officer, Chris Lehane, stated the company intends to advocate for internationally aligned standards on capability measurement, risk governance, and human oversight of AI.