New California AI executive order
California Executive Order N-9-26 was signed by Governor Gavin Newsom on September 18, 2026. The purpose of this executive order is to increase AI security controls.
The order builds on existing legislation and moves up existing deadlines. The order directs the Government Operations Agency (GOA) to complete the requirements of Section 8898.1 of the Government Code by May 1, 2027, instead of by January 1, 2028. This means the GOA will need to establish a framework for certifying independent verification organizations that assess AI systems and models by the new deadline.
Additionally, the order directs the GOA to act on certain sections of Section 11549.82 of the Government Code by December 1, 2027 instead of the previously designated January 1, 2029 deadline. The GOA will need to have a system established for registering independent AI auditors and for allowing the public to report an auditor’s misconduct.
The executive order also directs the GOA and the Governor’s Office of Emergency Services to consult with experts and to submit AI safety recommendations to the governor by November 16, 2026. These recommendations will focus on how California state law should be amended to address AI security concerns. The executive order lists four specific amendments for consideration:
- Require each large frontier developer to have a designated independent verification organization at their facility to conduct periodic audits and evaluations.
- Require each large frontier developer to have their risk assessments, safety frameworks, and transparency reports verified by an independent verification organization according to standards the organization determines to be adequate.
- Require frontier models to contain “kill switches”, with the efficacy of the kill switch verified by an independent verification organization on an ongoing basis.
- Update the definition of reportable critical security incidents to include a range of loss-of-control incidents.
Those in California working in the AI field and developing AI models should familiarize themselves with this executive order. To stay ahead of the coming changes, AI developers can prepare to work with independent verification organizations. Further, developers can plan on how to incorporate “kill switches” into frontier AI models. Finally, it will be important to understand the updated definition of a reportable critical security incident to remain compliant with California law.