Three things to know this week, and all three are about who checks the AI rather than about the AI itself. California created a registry of AI auditors and defined an AI auditor in a way that reaches well past accounting firms. A private standard for proving that an AI safeguard actually ran changed hands. And thirty-odd AI bills sit on the Governor's desk until Wednesday, one of which would put an unlicensed practice running a wellness chatbot into a medical confidentiality category. None of it was written for a practice of one.
Signal 1
California creates a registry of AI auditors, and defines an AI auditor broadly
On September 9 the Governor of California signed AB 1405. It sets up a state registry of AI auditors. Starting January 1, 2029, an unregistered person may not offer, sell or conduct what the law calls a covered AI audit in California. Two definitions do all the work, and both are short. An AI auditor is a person, partnership or company that assesses an AI system or model on behalf of a third party. A covered AI audit is an audit of the controls, processes or systems built around an AI model that are needed to comply with state law. So the rule does not reach you for looking at your own tools. It reaches you for looking at somebody else's, for pay, when the question is whether they meet a state requirement. I will say the obvious part out loud. I sell an AI review to other practices. This is a rule about my own work, and I am reading it the same way I would ask you to read it. Registered auditors also get independence rules, a public registration number and a public channel for the public to report them. A companion bill, SB 813, was signed the same day.
Sources: Office of the Governor of California, September 9, 2026 | AB 1405, full text, California Legislative Information
What this means for you
Read the definition, not the headline. The headline says California is regulating AI auditors. The definition says an AI auditor is anyone who checks somebody else's AI for them. That is a much larger group than the accounting firms this was written with in mind. It covers a consultant who reviews a clinic's intake bot. It covers a coach who sets other coaches up with AI tools and charges for it. What decides whether you are inside the rule is not your credential. It is whether the review is about complying with state law. Three years is a long runway and that is the useful part of this. Nobody has to do anything in 2026. But if any part of your income comes from telling another practice whether their AI setup is sound, that work now has a name in statute, and things with names in statute get rules.
Signal 2
A private standard for proving an AI safeguard actually ran changes hands
On September 21, Glacis Technologies said it will hand its standard OVERT to the Coalition for Health AI and the AIGovOps Foundation to steward together. OVERT sets a common format for the record an AI system leaves behind when it does something, so that somebody can check later whether the safety rules that were supposed to apply actually applied. The idea behind it is sound. A policy sitting in a document proves nothing. A control that runs and leaves a record proves something. Under the arrangement, CHAI and AIGovOps oversee the standard together. Glacis keeps maintaining it, keeps running its registry, and sits as a non-voting editor. CHAI says it will take the standard to its members. The announcement is clear about the limits. OVERT is voluntary. It does not certify that an AI tool is safe. It does not create a legal requirement. It does not decide whether anyone has complied with anything. Conformance requires an independent attestation.
Sources: Coalition for Health AI, September 21, 2026 | Healthcare Innovation, David Raths, September 21, 2026
What this means for you
Watch who ends up owning the word proof. Nobody in government is defining what it means to show that an AI tool behaved. So the people who build and sell the tools are defining it instead. CHAI is a serious body and this looks like a serious standard. It is also true that CHAI writes guidance, helps decide who adopts it, and runs deployment programs that vendors fund, and that the company that wrote this standard still runs its registry. Both of those things can be true at once and nobody has to be acting in bad faith. For a small practice the effect is simple. This standard is built for places with an IT team and a written governance policy to check against. You do not have either. So when a vendor tells you a tool is verified, verified will mean it passed a test designed for a hospital. It will not mean anyone checked what happens in your office.
Signal 3
Thirty AI bills sit on a desk until Wednesday, and one of them defines a wellness chatbot
The California legislature adjourned on August 31 and left more than thirty AI bills with the Governor. He has until September 30 to sign or veto each one. His legislative update on September 27 signed a long list of bills and not one of the health AI bills was on it. The one to read is AB 1979, which has been sitting with him since September 4. It defines a health care chatbot by three tests. It gives adaptive, human-like responses through a natural language interface. It is marketed as facilitating or supporting health services. And it handles information about a consumer's physical or mental health or wellness. A business that offers one to a consumer for diagnosis, treatment or management of a medical condition would be deemed a provider of health care under the Confidentiality of Medical Information Act. The word wellness is in that definition. The word license is not in it anywhere.
Sources: Governor's legislative update, September 27, 2026 | AB 1979, full text, California Legislative Information
What this means for you
The word wellness is doing a lot of work there, and it was put in on purpose. Most rules about health AI open by naming a licensed setting, which is exactly why practitioners outside one have been able to skip them for three years. This one opens with what the tool does and what it handles. If you run an intake form that talks back, a symptom questionnaire, or a chat assistant on your site that asks people how they are feeling, California would put you in a medical confidentiality category. Not because of your credential. Because of the software on your website. A veto would not undo the definition either. It is written down now, and written definitions get copied by other states, usually word for word, usually within a session or two.
The Pattern
Look at what moved in one week. A standard for proving an AI system behaved changed hands on September 21. Illinois created an AI cabinet by executive order on September 22. Oregon ordered outside safety reviews for the AI its agencies buy on September 23. California is deciding thirty-odd AI bills by Wednesday. None of it was written with a solo practice in mind, and that is the thing to notice rather than to complain about. Rules for AI in health are being built in two places at once. Governments are writing them for licensed settings. Private bodies are writing them for organizations large enough to have a compliance department. A small practice sits outside both and gets handed the results anyway, through a vendor contract, a platform policy or a question from a client. Nobody is coming for you. The point is that the vocabulary is being set without you, and you will be asked to answer in it.
One Thing You Can Do This Week
Take five minutes and answer one question on paper: what does the AI I use actually see. List every AI tool you touched in the last week. Beside each one write what client information goes into it. A name. A symptom. A whole client history. A session recording. Nothing at all. Then write the date at the top. That is the whole exercise. It is not a policy and it is not compliance. It is the answer to the first question anybody is going to ask you, whether that turns out to be a client, an insurer, a platform or a state. Most people in this position cannot answer it today, and not because they were careless. Because nobody ever asked them to write it down.