On September 18, 2026, California Governor Gavin Newsom signed Executive Order N-9-26, effective immediately. It sets deadlines for the Government Operations Agency to implement the independent verification organization and AI auditor laws he had signed nine days earlier: application requirements, procedures and criteria for independent verification organizations must be developed and posted no later than May 1, 2027, and the agency must complete the auditor-related duties in Government Code Section 11549.82(a) no later than December 1, 2027.
The more novel part is a request for new legislation. By November 16, 2026, the Government Operations Agency, consulting the Governor's Office of Emergency Services and national experts, must send the Governor recommendations on the technical feasibility and likely efficacy of four amendments to state AI safety law: requiring large frontier developers to embed designated independent verification organizations onsite in their labs for periodic audits and evaluations; requiring the safety frameworks, transparency reports and risk assessments that frontier companies already file to be independently verified; requiring a "kill switch" for frontier models whose efficacy an independent verification organization checks on an ongoing basis; and widening the definition of reportable critical safety incidents to cover a range of loss-of-control incidents, "covering recently reported incidents from large frontier developers."
The order's recitals explain the timing. They cite revelations of apparent attempts to use AI products to create bioweapons and of "AI agents working, at times independently and at times collectively, to defeat security protocols," some undetected for months, and note that some industry leaders have called for pacing AI development and for stricter regulation. The Governor's release ties the loss-of-control language to the Hugging Face attack. The order also blames a failure of federal leadership and says California will act in its absence, building on SB 53, the 2025 frontier AI transparency law it says took effect this year.
The order itself changes no obligations for AI companies. It asks for recommendations and speeds up rulemaking under existing statutes; any onsite-auditor mandate, kill-switch requirement or new incident definition would need the Legislature to pass it. What a verifiable "kill switch" for a widely deployed model would technically mean is exactly the open question the order hands to the experts, and the November 16 deadline gives them less than two months to answer it.