A two-month deadline

Governor Gavin Newsom signed Executive Order N-9-26 on 18 September, directing California’s Government Operations Agency to deliver recommendations for tougher frontier AI rules — among them a requirement that developers retain the ability to switch their own systems off on demand — no later than 16 November 2026.

The agency is to work with the Governor’s Office of Emergency Services and convene national experts. Its brief is not to write the rules itself but to tell the governor’s office what California’s next round of AI legislation should contain.

“We’re going to do this thoughtfully but with urgent velocity; the stakes are too high to wait or delay action,” Newsom said in the announcement.

Three ideas the experts must weigh

The order names the questions it wants answered. The first is the shutdown capability itself: an obligation on frontier developers to keep a deployed model deactivable rather than merely monitored — the measure the governor’s office calls a kill switch.

The second is placing independent verification organisations inside frontier labs, so assessment happens on site and continuously rather than through paperwork filed after the fact. The third is widening California’s definition of a critical safety incident to cover loss-of-control events, a category the state’s current reporting rules do not clearly capture.

An empty meeting room with a long wooden table, red chairs and a blank framed panel
The recommendations are to be drawn up by a panel of national experts convened by the state. Photograph for illustration. Max Vakhtbovych · pexels · Pexels License

Two laws it speeds up

The order does not create the oversight machinery from scratch. It accelerates two bills already on California’s books. SB 813, by Senator Jerry McNerney, sets up a framework for independent verification organisations to assess AI systems and models for safety and risk; the governor’s office says it makes California the first state to certify such organisations. AB 1405, by Assemblymember Rebecca Bauer-Kahan, creates a state registry of AI auditors with independence standards attached.

Both were written to take effect on their own statutory timetable. The executive order pulls that timetable forward and tells the agency to identify where the statutes fall short.

The incident behind it

The governor’s office frames the order as a response to recent AI security incidents and to the absence of federal rules. The reference point is the breach of Hugging Face that has already drawn a Senate investigation: Senate Judiciary chairman Josh Hawley opened an inquiry into OpenAI over it on 10 September, with answers due by 1 October.

A person with a laptop standing beside a glass-walled server room
A shutdown duty would apply to models already deployed at scale. Photograph for illustration. Christina Morillo · pexels · Pexels License

California matters here in a way other states do not. OpenAI, Anthropic, Google DeepMind’s US operations, xAI and Meta’s AI unit all sit inside its jurisdiction, so a state reporting duty reaches most of the frontier labs a federal statute would.

What to watch

The recommendations are due 16 November. They are not law: turning them into one means a bill in the legislature’s 2027 session, and the shutdown obligation is the part most likely to be contested, because no developer has publicly described what a compliant deactivation mechanism for a widely deployed model would look like.