Control
AI product without the independent third-party audit a law requires of it
Where a law requires an AI product's operator to have it audited, an external, independent and competent auditor examines the operator's compliance on the required cycle (and before a risk-increasing release where the law says so), the operator gives the auditor the documents it needs and keeps them and the signed report for the required period, and it files and publishes the summaries the law requires.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in California (US-CA); next date 2029-01-01.
The guard to add
Schedule the required independent audit of the AI product, give the auditor access, keep the signed report and documents, and file and post the required summaries on time.
An audit cycle owned by the operator's governance or legal lead and tracked as calendared tasks with evidence links: the first audit by the statutory date (or before first public release if later), repeat audits on the statutory cycle, and an audit before any release whose risk assessment shows increased risk; an engagement letter recording the auditor's independence and non-contingent fee; auditor access to the documentation it needs, under security protocols for trade secrets and privacy; retention of that documentation and the unredacted signed report for the period the law sets; and, after each report, the summary and attestation filed with the regulator and the high-level public summary posted within the statutory deadlines. This is an organizational record, not a code change; the repository can hold the evidence index for each cycle and a release gate that checks it.
Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.
What reviewers look for: for each audit cycle, an engagement letter with independence and fee terms, the signed report with its date, a filing receipt for the regulator summary, the public summary link and its posting date, and a retention entry; and, for releases flagged by the risk assessment as raising risk, an audit completed before the release date.
Organizational control: the evidence is a kept record, its owner and its upkeep, not code.
Example (Audit evidence index (repo record)), before:
# governance/child-safety-audit.yaml
2029: internal review doneAfter:
# governance/child-safety-audit.yaml
2029:
auditor: Example Assurance LLP # external; no financial interest either way
engagement_letter: evidence/2029/engagement.pdf # fee not conditioned on results
signed_report: evidence/2029/report-signed.pdf
report_received: 2029-03-02
ag_summary_filed: 2029-04-10 # within 30 business days, with officer attestation
public_summary_url: https://example.com/safety/child-safety-audit-2029 # posted within 90 days
retention: records-vault://child-safety-audit/2029 (deployment + 5 years)
next_audit_due: 2031-03-02Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Companion chatbots need an independent child safety audit by 2029 and every two years, filed with the Attorney General and posted online (California SB 1119) (California (US-CA); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- California (US-CA)
- Companion chatbots need an independent child safety audit by 2029 and every two years, filed with the Attorney General and posted online (California SB 1119) Cal. Bus. & Prof. Code 21814(a) (AB 1405 version) · applies from 2029-01-01