This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎙️ Episode 37 is live

California Licenses the First AI Auditors · ~8 min

▶️ Listen on the web  ·   🎧 Direct MP3  ·   📡 Subscribe (RSS)

This week California became the first jurisdiction anywhere to license the people who audit AI, signing SB 813 and AB 1405 into law — landing in the same 72 hours as two of the year's hardest EU and Korean deadlines and a $13 billion money-laundering signal from FinCEN.

Top stories

  • California licenses the first AI auditors. Governor Newsom signed SB 813 and AB 1405 on 9 September — the first US statutes to regulate who may assess AI systems. SB 813 creates independent verification organizations; AB 1405 establishes a state registry for AI auditors. Unregistered covered audits become a prohibited act from 1 January 2029.

  • EU Cyber Resilience Act — Article 14 reporting goes live 11 September. Manufacturers must report actively exploited vulnerabilities and severe incidents on a 24h / 72h / 14-day clock through ENISA's new Single Reporting Platform. Scope reaches products already on the market, plus software components and remote data-processing solutions.

  • Korea's amended PIPA takes effect 11 September. The CEO is named ultimately responsible for data-protection compliance, with a punitive fine track of up to 10% of total annual turnover for the most serious systemic failures.

  • EU Data Act — data-access-by-design attaches to connected products 12 September. Under Regulation (EU) 2023/2854 Art. 3(1), newly placed connected products must be designed so in-use and readily available data are directly accessible to the user by default.

  • FinCEN flags nearly $13B in crypto "scam center" fraud. FIN-2026-Alert005 (3 September) maps roughly $12.7 billion tied to overseas scam-center fraud; examiners will expect the red-flag typologies folded into transaction monitoring and SAR narratives.

Enforcement watch

  • Spain's AEPD fined Yoti €950,000; the vendor pulled its Digital ID app from Spanish stores rather than add a non-biometric path.

  • France's CNIL fined Hôpital Privé de la Loire €500,000 after a 2025 intrusion reached ~524,867 patient records via remote access with no VPN and no MFA.

On the calendar

11 Sep — CRA Art. 14 + ENISA SRP (EU) · 11 Sep — PIPA in force (Korea) · 12 Sep — Data Act Art. 3(1) (EU) · 14 Sep — Alabama AG / OpenAI production · 23 Sep — Colorado ADMT rule draft · 30 Sep — UK cryptoasset window opens · 1 Oct — China MPS Order 176; Connecticut PA 26-15.

Full analysis in this week's CyberEyeQ Weekly Briefing (Issue #35). Informational only; not legal advice.