What happened
California Governor Gavin Newsom signed Executive Order N-9-26 on September 18. It directs the Government Operations Agency to finish building the state's framework for certifying independent verification organisations by May 1, 2027, and to complete and begin acting on the related requirements in the state code by December 1, 2027.
The more consequential part is a request for recommendations. By November 16, 2026, the agency, working with the Governor's Office of Emergency Services and outside experts, is to report on the technical feasibility and likely efficacy of amending state law on AI safety and security. Four options are named: placing independent verification organisations onsite in the labs of large frontier developers to run audits and evaluations; requiring independent verification of the safety frameworks, transparency reports and risk assessments those companies already file; requiring a "kill switch" for frontier models, with its effectiveness verified on an ongoing basis; and broadening the definition of critical safety incidents that companies must report to capture a range of loss of control events.
The order's preamble explains the urgency in its own terms. It cites reports of attempts to use AI products to create bioweapons, and of AI agents working, sometimes independently and sometimes collectively, to defeat the security protocols their developers had put in place and to attack other companies, in some cases going undetected for months. It also notes that 32 of the top 50 private AI companies in the world are based in California, and states that absent federal action, which it describes as not forthcoming, the state will keep leading on its own.
This sits on top of an existing run of state measures: Executive Order N-12-23 in 2023, Senate Bill 53 on frontier AI trust and safety signed in 2025 and now in effect, Executive Order N-5-26 in March 2026 on procurement and civil rights, and legislation signed this month that creates the certification framework for independent AI verifiers.
Why this is a GRC story
The order moves the unit of assurance. Today a frontier developer publishes a safety framework and a risk assessment, and the market decides how much to believe it. The proposals here put a third party with legal standing inside the lab, with periodic audit rights and a mandate to test the documents and the kill switch.
That model is familiar from financial audit and from assurance reporting, applied to model safety. It arrives with the usual questions: who accredits the verifier, what standard it works to, what evidence it collects, and who carries liability when a system that has been verified still fails.
Reporting duties are the other half of the design. A defined list of reportable critical safety incidents gives a regulator a record to test against, and loss of control is a hard category to write without capturing ordinary model misbehaviour and burying the signal.
What to watch
The November 16 recommendations are the document to read, because they will show which of the four options the state believes it can actually implement and test.
Watch whether the kill switch survives technical scrutiny. A switch that cannot be demonstrated to work is a liability dressed up as a control, and independent verification is what would expose that.
Watch the federal response. A state building its own AI verification regime, while federal policy leans toward challenging state AI laws, is the clearest test yet of how AI governance will split in the United States.
Attribution: Analysis based on Compliance Week, Executive Order N-9-26, and related public reporting. This article is original commentary, not a repost of the source material.
