You're not a frontier AI lab. You don't train models, you use them. But California's two new AI audit laws — SB 813 and AB 1405, signed by Governor Newsom on September 9, 2026 — just redrew the line between who this applies to and who it doesn't. And the line is much closer to your business than you might think.
Here's the plain version: if your company deploys AI to screen job applicants, price insurance, make lending decisions, or otherwise take automated actions that materially affect people's lives in California, you are now inside a compliance framework that will require independent third-party audits. Starting January 1, 2029, only state-registered auditors will be permitted to conduct those audits. The framework isn't just for OpenAI and Anthropic — it covers any operator using an off-the-shelf model for consequential decisions. That could be your AI-assisted hiring screen, your automated pricing tool, or a workflow that routes customer service outcomes. Bigger than you expected? Good. Now you have time.
The reason this matters more to small operators than to large enterprises is simple: large companies already have legal teams preparing for scenarios like this. You probably don't. And the two-year runway to January 2029 will evaporate faster than you think if you spend 2027 in "wait and see" mode.
What should you actually do with this information? Start with documentation, not panic. Run an audit of every AI-assisted decision in your business right now. Not a formal legal audit — just a plain-language inventory. What does the AI touch? What decisions does it influence? What data does it process about real people? How are those outputs reviewed before they affect a customer or candidate? You don't need an attorney to answer those questions today. But you will need those answers before an attorney can help you later.
The second move is to build a governance layer that survives growth. "Governance" sounds like enterprise-speak, but for a small operator it's actually quite simple. It means knowing which AI tool is doing what, having a documented human review step for anything consequential, and keeping a record of that review. That's the kind of paper trail that turns an audit from a crisis into a one-day exercise.
Here's the contrarian take worth sitting with: most founders are reading this law as a compliance burden. The operators who read it as a structural advantage will build cleaner systems now, establish trust signals that competitors won't have, and be positioned to serve California-based enterprise clients who will increasingly require their vendors to demonstrate AI governance. That's not optimism — that's how financial compliance and data privacy law have worked in every prior cycle.
The businesses that treated SOC 2 as optional until a large client required it know exactly what this moment feels like. Don't wait for that conversation. The California AI audit framework gives you the clearest roadmap yet for building AI systems you can defend. The clock started September 9. Two years and four months is enough time — if you start now.