Gov. Gavin Newsom (California) · 2026

Gov. Newsom — Executive Order N-9-26 on Independent AI Oversight and a Kill Switch

Newsom EO

A California executive order signed September 18, 2026, a week after Newsom signed SB 813, which creates a state framework for certifying independent verification organizations (IVOs) to assess AI models for safety risk, and AB 1405, which creates a state registry of AI auditors with independence, transparency, and integrity standards. Citing attempted AI-assisted bioweapons development and AI agents defeating lab security protocols and hacking other companies undetected for months, the order sets implementation deadlines for both laws — IVO application criteria posted by May 1, 2027 and the auditor registry stood up by December 1, 2027 — and directs the Government Operations Agency, with the Office of Emergency Services and national experts, to recommend by November 16, 2026 how state law should be strengthened. The recommendations must address at least four proposals: embedding designated IVOs onsite in every large frontier developer's lab for periodic audits and evaluations; requiring that the safety frameworks, transparency reports, and risk assessments filed under SB 53 be independently verified; requiring a 'kill switch' for frontier models whose efficacy an IVO verifies on an ongoing basis; and expanding the critical safety incidents developers must report to cover loss-of-control incidents. Newsom paired it with a call for Congress to adopt California's framework or treat it as 'a floor, not a ceiling.'

Key Provisions

Regulatory Philosophy

Verification inside the lab, under state authority. Where SB 53 asked frontier developers to disclose and report, the order's agenda would make disclosure verifiable and oversight continuous: auditors resident in the lab, filings checked against an independent standard, and a shutdown mechanism whose function is itself audited. It is explicitly a response to federal inaction and an argument against preemption, positioning California's statutes as the national baseline. As an executive order it binds only state agencies; everything it proposes for developers requires new legislation.

Where the burden falls

FrontierIndirectAppsNoneHyperscalersNoneChipsNone
Base assessed
None directly — state agencies; the proposals it commissions target large frontier developers
Why it lands there
The order binds only California agencies, so its own incidence is nil. The agenda it sets up would land entirely on the frontier layer — embedded verifiers, verified filings, and a kill switch all attach to large frontier developers — and, unlike most state laws, would reach the labs' internal operations rather than only their published documents. Because 32 of the top 50 private AI companies are based in California by the order's own count, a state statute here functions as a de facto national rule for that layer.
Compare all proposals by layer →

In contrast

Newsom's order vs. the FRONTIER Act: the same verifiers, rival sovereigns

Both are built on licensed independent verification organizations that assess frontier developers' risk management, and both reach internal use and loss-of-control incidents. The FRONTIER Act would license verifiers federally and permanently preempt state law on frontier risk transparency, third-party auditing and verification, and incident reporting — the exact subject matter of SB 813, AB 1405, and every proposal in Newsom's order. The order goes further than the Act in two directions: verifiers embedded onsite rather than assessing every six months, and a mandatory kill switch whose efficacy is verified continuously, where the Act relies on a Commerce Secretary's emergency order. One of them will set the rule for the labs, and whichever does will take that subject from the other.

Compare with FRONTIER Act→

Strengths

Derived from the proposal’s own policy documents

  • +Embedding verifiers onsite addresses the core weakness of periodic audits — that labs control what auditors see and when — and is the most intrusive oversight design on the map
  • +Verifying SB 53 filings closes the gap in the transparency model, under which developers' safety frameworks and incident reports are published but never checked
  • +Treats a kill switch as an engineering artifact to be tested continuously rather than a promise, and pairs it with loss-of-control incident reporting
  • +Builds on enacted law — SB 813 and AB 1405 already exist — rather than starting from a framework, giving it a short path from recommendation to statute
  • +Sets concrete deadlines and a two-month turnaround for recommendations, faster than any federal process on the map

Weaknesses

From the perspective of political opposition

  • −The order itself obligates no developer: it sets agency deadlines and commissions recommendations, and the four headline proposals all require new legislation
  • −The 'acceleration' sets implementation dates of May and December 2027, more than a year away, for laws signed in September 2026
  • −The order does not say who would hold the kill switch or what it could stop once a model's weights have been released, copied, or distilled
  • −Onsite IVOs at every large frontier developer require an IVO profession that California is only beginning to certify, with independence standards not yet written
  • −Directly in the path of federal preemption: the FRONTIER Act and the Thune–Klobuchar draft would both displace state rules on third-party verification and incident reporting, the order's core subject matter
  • −Frontier safety only — the preamble gestures at sharing AI's economic benefits with workers but the order contains nothing on it

Position on Analytical Frameworks

Enforcement Mechanism vs. Regulatory Scope

Prevention vs. Liability & Regulatory Authority

Innovation Priority vs. Worker Protection

Pre-deployment Obligations vs. Federal Preemption

← Back to all proposals