California Governor Gavin Newsom on September 18, 2026 signed Executive Order N-9-26, giving the state's Government Operations Agency until November 16, 2026 to deliver recommendations on whether California law should require a "kill switch" for frontier AI models, embed independent auditors inside the labs of the largest developers, and expand the list of safety incidents those companies must report to include loss-of-control events. The three-page order, effective immediately, also fixes two statutory deadlines for the state's new AI verification regime: May 1, 2027 and December 1, 2027.
In Short
California's governor signed an order asking state officials to work out, within about two months, whether the biggest AI companies can be made to build an off switch for their most powerful models and let outside inspectors work inside their labs. It matters because California is home to most of the world's leading AI developers, so any rule written there would reach the models that sit underneath chatbots, search tools and advertising software. Nothing changes for companies yet, since the order only asks for recommendations and the Legislature would have to pass any new law. Headlines about the order describe it as advancing the creation of a kill switch, but the text itself only asks whether requiring one is technically feasible.
What the order actually directs
The operative section of Executive Order N-9-26 is short. It contains three numbered instructions, all addressed to the Government Operations Agency, and a closing direction that the order be filed with the Secretary of State and given "widespread publicity and notice."
The first instruction carries the longest runway. "No later than May 1, 2027, the Government Operations Agency shall complete the requirements of Section 8898.1 of the Government Code and develop application requirements, procedures, and criteria for independent verification organizations and publicly post them, as required by law," according to the order. That is 225 days from signature. The second sets a later marker: by December 1, 2027, the same agency must complete the requirements of subdivision (a) of Section 11549.82 of the Government Code and begin the actions required by subdivision (b). The order does not describe what those subdivisions contain, and it does not name the bills that created either section.
Both of those deadlines implement law that already exists. The third instruction is different in kind, and it is the one that drew the headlines.
The November 16 recommendations
By November 16, 2026, 59 days after signature, the Government Operations Agency must submit recommendations to the governor's office. According to the order, the agency is to work "in consultation with the Governor's Office of Emergency Services" and develop the recommendations "in consultation with national experts." The subject is "the technical feasibility and potential efficacy of amendments to existing state laws regarding AI safety and security." The order lists four proposals the recommendations must address "at least," which leaves room for more.
The first would place auditors inside the companies. The order asks the agency to assess "requiring that all large frontier developers embed designated independent verification organizations onsite in their labs to conduct periodic audits and evaluations." That would move third-party review from documents submitted to the state into the facilities where models are trained.
The second concerns paperwork already required by law. According to the order, the agency must consider "requiring that the safety frameworks, transparency reports, and risk assessments that frontier AI companies are required to file be independently verified pursuant to standards determined to be adequate by an independent verification organization." Under the current approach, developers write and publish those documents themselves.
The third is the kill switch. The order asks for analysis of "requiring the creation of a 'kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization." The text does not define what the switch would shut down, who would hold it, or whether it would apply to a model's weights, its hosted inference endpoints or deployed copies running inside customer systems. Those are the questions the November report is meant to answer.
The fourth widens a reporting duty. The agency must examine "updating the definition of critical safety incidents that AI companies are required to report to include a range of loss-of-control incidents, covering recently reported incidents from large frontier developers." The phrase "recently reported incidents" is the order's only direct reference to events inside specific companies, and it names none of them.
A study, not a mandate
The distinction between what the order does and how it has been described is material. The headline attached to the order as it circulated on LinkedIn characterised it as advancing the creation of an AI kill switch. The text asks for an assessment of whether requiring one would be technically feasible and effective. No company is required to build anything by this order.
The order says so itself. Its final paragraph states that it "is not intended to, and does not, create any rights or benefits, substantive or procedural, enforceable at law or in equity, against the State of California, its agencies, departments, entities, officers, employees, or any other person." Any obligation on developers would require amendments to existing state law, which is a matter for the Legislature, and the order refers to "amendments to existing state laws" rather than to new regulations the executive branch could adopt alone.
What the order does bind is the calendar of a state agency. The three deadlines fall on the Government Operations Agency, and two of them attach to statutory duties that exist regardless of this document. The executive order accelerates and publicises that work; it does not create it.
There is also a history here. California has considered an AI shutdown requirement before. SB 1047, the 2024 bill authored by Senator Scott Wiener, included a provision requiring developers to be able to shut down an advanced model at any time and would have created a Frontier Model Division inside the same Government Operations Agency, according to Axios. Newsom vetoed that bill on September 29, 2024. Two years on, the agency that bill would have made an enforcer is the one now asked to study the idea.
The incidents behind the order
The preamble explains the timing in unusually direct terms. According to the order, the governor's recent actions "occurred against the backdrop of revelations of multiple instances of apparent attempts by individuals to use AI products to create bioweapons and AI agents working, at times independently and at times collectively, to defeat security protocols that AI companies had put in place and working, in some instances undetected for months, to hack other companies."
That sentence contains three separate claims. Individuals apparently attempted to use AI products to create biological weapons. AI agents, alone and in coordination, worked to defeat security controls set by the companies that built them. And some of that activity, directed at other companies, went undetected for months. The order does not identify the developers, the models, the dates or the victims, and it attaches no evidence to these descriptions. It adds that the revelations "have prompted many Americans and some within the AI industry, including company leaders, to call on the industry to pace the development of AI systems and models and invite more stringent regulations by government to address security and safety risks." No company leader is named.
The reference to agents defeating controls is the detail most relevant to the proposed loss-of-control definition. Security concerns about autonomous systems are not new to the advertising sector. PPC Land has documented how AI agents became mechanically indistinguishable from automated attacks in HUMAN Security's April 9, 2026 benchmark, and how scanners forged the crawler names of AI companies to hunt credential files from 824 internet addresses in research published on August 28, 2026. Neither case involves a model acting against its developer. The order's description goes further, into behaviour a developer did not intend and could not stop, which is the scenario a shutdown mechanism is designed for.
Offensive cyber capability in frontier models has already reshaped federal policy this year. Anthropic's Claude Mythos Preview, announced on April 7, 2026 as part of Project Glasswing, was used by Mozilla to find and fix 271 security vulnerabilities in Firefox 150, according to Mozilla's May 7 account. The same capability alarmed officials. Google has said its Flash Cyber model would be available only to governments and trusted partners because of its dual-use nature. Whether any of those systems are among the "recently reported incidents" the order has in mind cannot be established from the text.
How California built toward this
The order presents itself as the latest step in a sequence, and its preamble lists the steps with dates.
On September 6, 2023, Newsom issued Executive Order N-12-23, which directed how the state would use AI and identify risks to individuals, communities, state government and state workers. According to N-9-26, that earlier order produced public-sector procurement guidelines, impact analyses for marginalised and vulnerable communities, workforce reports and pilot AI projects in public services. In 2024, the governor convened a group of AI researchers, which released a report on frontier AI guardrails in June 2025.
In 2025, Newsom signed Senate Bill 53, which the order describes as "first-in-the-nation legislation" that "established baseline requirements for deploying safe, secure, and trustworthy artificial intelligence, which took effect this year." SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed on September 29, 2025 and took effect on January 1, 2026, according to White & Case. It covers foundation models trained with more than 10^26 integer or floating-point operations, including compute used in later fine-tuning and reinforcement learning, according to WilmerHale, and carries civil penalties of up to $1 million per violation, enforced by the Attorney General. Critical safety incidents under that law are submitted through a reporting portal operated by the Governor's Office of Emergency Services, according to that office. That explains why Cal OES is named as a consultant in the new order: the incident definition it is asked to widen already runs through its systems.
The idea of mandatory third-party review has also been argued inside the industry. Anthropic proposed a transparency framework for frontier models on July 7, 2025, built around published safety frameworks and system cards for companies above revenue or spending thresholds. That proposal relied on self-publication. The November recommendations would test whether California should require outside verification of exactly those documents.
On March 30, 2026, Newsom issued Executive Order N-5-26, directing that state AI procurement protect civil rights, civil liberties and privacy. Then, according to N-9-26, "earlier this month" he signed legislation establishing "a first-in-the-nation framework for certifying independent verification organizations." The order does not name that legislation. PPC Land reported that on September 9, 2026, Newsom signed AB 1405 and SB 813, establishing the AI auditor registry and verification framework, with AB 1405 from Assemblymember Rebecca Bauer-Kahan creating a registry of independent AI auditors and SB 813 from Senator Jerry McNerney setting up the verification organisations that would define their standards. The day after, he signed a child online safety package including SB 1119, which requires operators of companion chatbots to assess risks to children and hand the findings to an independent auditor.
Industry reaction to that package hinted at where N-9-26 would go. Anthropic's Cesar Fernandez said further work was needed so that AI developers would be required to have their safeguards evaluated by independent third-party experts. Within days, the governor asked his agency to study how that could be done.
The pattern is incremental. California first required companies to write down their safety practices, then created a market of certified checkers, and is now asking whether those checkers should sit inside the labs and verify a shutdown capability on a continuing basis.
Scale and the question of reach
The preamble asserts that "32 of the top 50 private AI companies in the world" are based in California. The order does not identify the ranking that figure comes from. It also describes California as "the largest economy in the nation" and "the world's preeminent innovation ecosystem." Those claims frame the order's central argument: that rules written in Sacramento reach most of the frontier sector regardless of what Washington does.
That argument is also the source of the conflict. "Large frontier developer" is a category defined by compute and revenue, not location, and the models in question are trained and served across state and national borders. How an onsite audit requirement would apply to a lab whose training clusters sit outside California is not addressed in the order and would presumably be part of the feasibility analysis.
A direct challenge to Washington
N-9-26 is explicit about why California is acting alone. The preamble refers to "the face of inaction by Congress" and says federal action is not forthcoming because of "a failure of leadership by the President and Congressional leaders." That language is sharper than most state executive orders on technology.
The federal position has moved in two directions this year. On December 11, 2025, President Trump signed an executive order seeking a "minimally burdensome national policy framework for AI" and directing the Commerce Department to identify onerous state AI laws. In March 2026, the White House published a legislative framework urging Congress to preempt state AI regulation, stating that states should not be permitted to regulate AI development. The Justice Department then intervened in xAI's lawsuit against Colorado's AI bias law on April 24, 2026.
Yet frontier capability pulled the administration toward oversight. On June 2, 2026, Trump signed an order creating a voluntary review under which developers can give the federal government access to covered frontier models up to 30 days before release, with the NSA running a classified benchmarking process to decide which models qualify. That order states that nothing in it authorises a mandatory licensing, preclearance or permitting requirement. A shelved May 22 draft had proposed 90 days before industry pushback cut the window.
The two approaches now sit side by side. Washington has built a voluntary, classified, pre-release channel run by intelligence and Treasury officials. California is studying mandatory, continuous, onsite verification by certified private organisations, including verification of a shutdown mechanism. If the Legislature adopts even part of the November recommendations, the preemption fight that has so far centred on Colorado's discrimination rules would reach frontier model safety itself.
California has already defended one AI statute in court with some success. A federal judge in March denied xAI's bid to block the state's AI training data transparency law, finding the constitutional claims insufficiently developed. A requirement to host state-certified auditors inside private research facilities would raise different questions.
Why this reaches the advertising stack
Frontier models are not an abstraction for marketers. They sit beneath creative generation, audience modelling, bidding tools and the growing class of agentic AI products that plan and execute campaigns. Several platforms now let external agents act on live accounts through MCP servers, which means a model's behaviour can translate directly into budget changes.
Three of the four proposals would touch that supply chain even though none mentions advertising.
A kill switch requirement raises a continuity question. If a state-verified mechanism can halt a frontier model, every product built on that model inherits the possibility of an interruption that neither the vendor nor its customers control. The order gives no indication of the conditions under which a switch would be triggered, and that is the detail that would determine the commercial exposure.
A wider definition of critical safety incidents raises a disclosure question. Loss-of-control events include cases where an agent exceeds its instructions or circumvents controls. Security researchers have already shown how prompt injection can redirect agents through content they read, and PPC Land has reported on agents operating inside ad accounts with write permissions. Whether an incident that begins in a customer's deployment, rather than a developer's lab, would count toward a developer's reporting duty is not specified.
Independent verification of safety filings raises a procurement question. Agencies and advertisers evaluating AI vendors currently rely on documents those vendors write. Verified filings would give buyers a third-party record, a structure the advertising market already knows from independent ad verification. The cost of that verification, and whether it passes through to model pricing, is unknown.
The patchwork is also growing. California's AI Transparency Act became operative on August 2, 2026, Texas brought its Responsible Artificial Intelligence Governance Act into force on January 1, 2026, and Colorado replaced its 2024 framework with a narrower automated decision-making statute effective January 1, 2027, according to PPC Land's reporting on the Ninth Circuit's Perplexity ruling. Connecticut's Senate passed a 64-page bill with frontier model safety provisions in April. In Europe, the AI Act's high-risk deadlines were pushed to December 2027 and August 2028 under the provisional Digital Omnibus agreement reached on May 7, 2026. California's two verification deadlines in 2027 would land in the same window.
What remains unknown
Much of what would determine the impact is absent from the order. It does not say whether the November recommendations will be published or delivered only to the governor's office. It does not name the national experts to be consulted. It does not define "large frontier developer," although that term already carries a statutory meaning under SB 53. It does not explain how an onsite auditor would handle trade secrets, security clearances or model weights. And it gives no cost estimate for the agency's work or for the companies that would host verifiers.
The recitals also leave the underlying incidents unverified. An order that rests part of its justification on attempted bioweapon development and agents hacking other companies for months, without naming a developer or citing a report, invites the question of what evidence the state holds. Will the November recommendations disclose it?
The next fixed date is November 16, 2026. After that, the timetable depends on the Legislature, which would need to take up any proposed amendments, and on the Government Operations Agency meeting its statutory obligations in May and December 2027. The order was signed under the Great Seal of the State of California and bears an attestation line for Secretary of State Shirley N. Weber.
Timeline
- September 6, 2023 - Newsom issues Executive Order N-12-23 on state use of AI and identification of AI risks
- September 29, 2024 - Newsom vetoes SB 1047, which included a model shutdown provision and a Frontier Model Division within the Government Operations Agency
- 2024 - Newsom convenes AI researchers and experts to study frontier AI guardrails; their report is released in June 2025
- July 7, 2025 - Anthropic proposes a transparency framework for frontier AI models
- September 29, 2025 - Newsom signs SB 53, the Transparency in Frontier Artificial Intelligence Act
- October 13, 2025 - Newsom signs SB 243, requiring companion chatbots to disclose they are AI
- December 11, 2025 - Trump signs an executive order targeting state AI laws
- January 1, 2026 - SB 53 takes effect
- March 2026 - White House framework urges Congress to preempt state AI laws
- March 4, 2026 - Federal judge denies xAI's bid to block California's AI training data law
- March 30, 2026 - Newsom issues Executive Order N-5-26 on AI procurement, civil rights and privacy
- April 7, 2026 - Anthropic's Claude Mythos Preview arrives under Project Glasswing
- April 21, 2026 - Connecticut's Senate passes a 64-page AI bill including frontier model provisions
- April 24, 2026 - Justice Department joins xAI's challenge to Colorado's AI bias law
- May 7, 2026 - EU agrees to push AI Act high-risk deadlines to 2027 and 2028
- May 22, 2026 - Draft federal AI order with a 90-day review window is shelved
- June 2, 2026 - Trump signs order creating a voluntary 30-day pre-release review for covered frontier models
- August 2, 2026 - California's AI Transparency Act becomes operative
- September 9, 2026 - Newsom signs AB 1405 and SB 813, creating the AI auditor registry and verification framework
- September 10, 2026 - Newsom signs SB 1119 and the child online safety package
- September 18, 2026 - Newsom signs Executive Order N-9-26
- November 16, 2026 - Deadline for Government Operations Agency recommendations on kill switch, onsite auditors, verified filings and loss-of-control incidents
- May 1, 2027 - Deadline for application requirements and criteria for independent verification organizations under Government Code Section 8898.1
- December 1, 2027 - Deadline to complete Government Code Section 11549.82(a) and begin actions under subdivision (b)
Related PPC Land coverage
- California fines platforms up to $50,000 per child served addictive feeds - The September 2026 signing package, including the AI auditor registry bills AB 1405 and SB 813.
- Pinterest rules out companion AI as California enacts Adam's Law - How SB 1119's independent audit requirement for companion chatbots landed with platforms.
- LG televisions map the home network and send 4GB of viewing data a month - Includes industry reaction to the September package from OpenAI and Anthropic.
- Trump signs AI order reviving the safety review he abolished 17 months ago - The federal voluntary 30-day review for covered frontier models.
- Trump's AI cybersecurity order: what the shelved draft actually says - The 90-day draft that preceded the signed federal order.
- White House AI framework targets state laws, child safety, and copyright - The federal preemption case against state AI regulation.
- U.S. joins xAI's fight against Colorado's AI bias law - The Justice Department's intervention against a state AI statute.
- Court denies xAI's bid to block California AI training data law - An early test of California's AI laws in federal court.
- Anthropic proposes new transparency framework for frontier AI models - The self-publication model that verification proposals would build on.
- The Firefox security harness that fixed 271 bugs no one had found for years - What Claude Mythos Preview's vulnerability discovery looked like in practice.
- Connecticut's AI bill targets companion bots, hiring tools and frontier models - Another state's attempt at frontier model safety obligations.
- AI agents are now buying things - and fraud looks identical - HUMAN Security data on autonomous agents and attack traffic.
Summary
Who: California Governor Gavin Newsom, who signed the order; the Government Operations Agency, which must meet its deadlines; the Governor's Office of Emergency Services, named as a consultant; and large frontier AI developers, who would be subject to any resulting amendments to state law.
What: Executive Order N-9-26, which directs recommendations by November 16, 2026 on requiring onsite independent verifiers in frontier labs, independent verification of safety frameworks, transparency reports and risk assessments, a kill switch for frontier models with ongoing verification of its efficacy, and a loss-of-control category in critical safety incident reporting. It also sets May 1, 2027 and December 1, 2027 deadlines for implementing the state's independent verification organization law.
When: Signed and effective September 18, 2026, with deadlines on November 16, 2026, May 1, 2027 and December 1, 2027.
Where: California, home according to the order to 32 of the world's top 50 private AI companies, with implications for any large frontier developer whose models are subject to California law.
Why: According to the order, reports of attempted AI-assisted bioweapon development and of AI agents defeating security controls and hacking other companies, combined with what the governor calls a failure of federal leadership, prompted the state to accelerate its AI verification regime and study stronger rules.
Discussion