For two years the question in AI governance has been who audits the AI. A newer question is now being answered in state capitols: who gets to be the auditor, and under what rules. Three states are writing law about the assurance profession itself, and an independent AI assurer like Sentinel sits inside the scope of all three.
Illinois: the audit is mandatory
Illinois SB 315, signed in July 2026, is the first U.S. law to require regular independent third-party AI safety audits, with the audit duty landing on large frontier developers from 2028. It also draws the line that defines the profession: a firm cannot both remediate a system and sign its statutory audit. Independence is not a nicety here; it is the point.
California: the auditor has to enroll
California’s AB 1405, with companion SB 813, would require an AI auditor, from January 1, 2027, to enroll with a state agency and pay a fee before performing a “covered audit” (any audit a state law requires of an AI system). It carries independence rules with teeth: no audit where you hold a financial interest in the client beyond your fee, no going to work for the client in the year after, none where the client employed you in the year before. One caveat matters: AB 1405 is a bill, not law, and it faces an August 31 deadline. But the direction is unmistakable, a licensed, enrolled, conflict-screened auditor class.
Virginia: studying whether to license
Virginia HB 797 (Chapter 425, approved April 2026) directs a state commission to evaluate whether Virginia should build a framework, and possibly a licensing scheme, for independent verification organizations that assess AI systems against safety standards. The report is due November 1, 2026. It is a study, not yet a mandate, but it is the third state in a single year to reach for the same lever.
Why this matters, even if you are not an auditor
If you deploy AI, the audit or review you will increasingly be asked for is turning into a regulated act with real independence requirements. The cheap workaround, having the same vendor build your AI and then bless it, is exactly what these rules are being written to stop. And if you buy assurance, it is starting to matter whether your reviewer is independent by design rather than by claim. The firms already built that way have a head start.
What to do now
1. Separate build from check. If one vendor both builds your AI and audits it, you already fail the independence test these laws are converging on. 2. Ask your assurer the conflict questions now. Financial interest, prior employment, remediate-and-sign. The answers are becoming law. 3. Treat “independent” as a structural claim, not a marketing word. Ask how the independence is actually guaranteed. 4. Watch the calendar. California’s August 31 deadline and Virginia’s November 1 report will tell you how fast this is moving.
An honest limitation
Two of these three are not yet binding law. Illinois SB 315 is enacted, with its audit duty phasing in toward 2028; California AB 1405 is an advancing bill that may not survive its deadline; Virginia HB 797 is an enacted statute that orders a study, not a licensing regime. What is real today is the direction of travel: three states, independently, in one year, moving to regulate who may assure AI and how. Verify the current status of any specific bill before acting on it.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed August 17, 2026.
See how a Gap Assessment maps your exposure →Being asked for an independent AI review?
Make sure it actually is one.
The free AI Risk Exposure call shows where independence is required, and how a review built to be independent from the start holds up.
Book the call →