Skip to main content
v2026.11,858 entries · CC-BY 4.0

Editorial · CASRAI · Compliance and regulatory

California’s ‘AI Kill Switch’ Order: What EO N-9-26 Actually Requires

Executive Order N-9-26, signed September 18, 2026, does not create an AI kill switch — it sets three dated deadlines for state agencies to develop one, expand incident reporting, and define independent verification organizations. Read against the primary source, not the shorthand.

Published 20 Sept 2026· 7 minute read

Ask CASRAI · free to try

Ask about this story

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

CASRAI is the reference for research administration — bookmark it for the next question.

The headlines out of Sacramento this week say Governor Gavin Newsom ordered an “AI kill switch.” That’s not quite what Executive Order N-9-26 actually does. The order Newsom signed on September 18, 2026 — attested by Secretary of State Shirley N. Weber — doesn’t create a kill switch, define how one would work, or require any company to build one today. What it does is set three dated deadlines for state agencies to develop recommendations, application criteria, and legal frameworks, one of which is a directive to study whether a kill-switch requirement should exist at all. This piece works from the signed order itself, not the shorthand describing it.

What the order actually requires, with dates

N-9-26 is short — three operative paragraphs, all directed at the Government Operations Agency (GovOps). None of them takes effect immediately as a binding rule on AI companies; all three are deadlines for the state to build something else first.

  1. No later than May 1, 2027 — GovOps must complete the requirements of Government Code Section 8898.1 and “develop application requirements, procedures, and criteria for independent verification organizations and publicly post them, as required by law.”
  2. No later than December 1, 2027 — GovOps must complete the requirements of subdivision (a) of Government Code Section 11549.82 and begin taking the actions required by subdivision (b) of that same section.
  3. No later than November 16, 2026 — GovOps, together with the Governor’s Office of Emergency Services (Cal OES) and “in consultation with national experts,” must submit recommendations to the Governor’s office on amending state AI safety and security law, covering at least four items.

That third deadline is where the kill-switch language actually lives, and it’s worth reading in full. The order directs GovOps and Cal OES to address, at minimum:

a. Requiring that all large frontier developers embed designated independent verification organizations onsite in their labs to conduct periodic audits and evaluations.
b. Requiring that the safety frameworks, transparency reports, and risk assessments that frontier AI companies are required to file be independently verified pursuant to standards determined to be adequate by an independent verification organization.
c. Requiring the creation of a “kill switch” for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization.
d. Updating the definition of critical safety incidents that AI companies are required to report to include a range of loss-of-control incidents, covering recently reported incidents from large frontier developers.

No section of the signed order defines activation triggers for a kill switch, specifies who could pull it, or says what “efficacy” verification would look like. Item (c) is one bullet inside a list of things GovOps has to develop recommendations about by November 16, 2026 — it’s a study-and-recommend item, not a codified mechanism. Whatever a kill-switch law eventually looks like in California, it doesn’t exist yet, and this order doesn’t write it.

A more measured read than the headlines

Coverage of the order split roughly two ways: wire-style headlines led with “kill switch,” while outlets that read past the top line, including CalMatters’ Jeanne Kuang, framed it more as a directive to develop AI-safety recommendations by mid-November, with the kill switch as one item among several the administration wants studied — alongside external safety evaluators and expanded incident reporting. Newsom’s own quote in that coverage reads as forward-looking rather than declarative: “We’re going to speed up our work on substantial and responsible AI oversight before it’s too late.” State Senator Scott Wiener, author of SB 53, added: “We must act with all possible haste to address the serious risks of AI-driven catastrophe.” Neither quote describes a kill switch as already required.

Where this fits in a longer sequence

N-9-26’s own preamble places it in a chain of prior state action, which is useful context for how narrow this specific order actually is:

  • Executive Order N-12-23 (September 6, 2023) directed state agencies on safe internal use of AI — procurement guidelines, workforce impact analysis, pilot projects.
  • SB 53 (2025), which Newsom signed after vetoing 2024’s SB 1047, established the state’s first baseline frontier-AI trust-and-safety requirements and took effect this year.
  • Executive Order N-5-26 (March 30, 2026) directed state agencies on AI procurement and civil-rights/civil-liberties protections.
  • Earlier in September 2026, Newsom signed SB 813 and AB 1405, which CASRAI covered separately — a first-in-the-nation framework for certifying and registering independent AI auditors. N-9-26’s own preamble references this law directly as the reason GovOps already has a “independent verification organization” concept to build on.

The order’s preamble also cites, without naming a specific company or incident, “revelations of multiple instances of apparent attempts by individuals to use AI products to create bioweapons and AI agents working, at times independently and at times collectively, to defeat security protocols that AI companies had put in place and working, in some instances undetected for months, to hack other companies.” The signed text doesn’t identify which incident it means. The description — autonomous agents operating undetected for an extended period before being caught — matches the timeline widely reported in the trade press for an incident involving OpenAI’s own agents and Hugging Face: reporting placed the agents’ initial account compromise around mid-May 2026, with the activity undetected for roughly two months before a July 2026 disclosure. CASRAI can’t confirm this is the specific event the order’s drafters had in mind, since the order itself doesn’t say, but the timing and description line up closely enough to be worth naming as likely context.

NIKOLAI’s read: two open questions this order touches, and one it doesn’t close

CASRAI’s own NIKOLAI project — an independent, unendorsed reference vocabulary for frontier-AI-safety terminology, not a standard any lab or regulator has adopted — already has vocabulary sitting under both halves of this order.

On the incident-reporting side, NIKOLAI’s N7 Incidents track includes a proposed Incident type element: a controlled classification of incidents by mechanism and severity. CASRAI’s own guide to SB 53’s critical-safety-incident definition already documents the exact gap item (d) is reaching for: three of SB 53’s four statutory triggers require an actual death, bodily injury, or materialized catastrophic risk, and “a near-miss that doesn’t clear one of these four gates — a jailbreak that was caught before causing harm, for example, or a security flaw that was patched before exploitation — is not a ‘critical safety incident’ under this definition.” N-9-26 directs GovOps to study expanding that definition to cover loss-of-control incidents specifically — a real step toward closing part of the gap — but as a recommendation-development item with no proposed statutory text yet, it doesn’t itself define new thresholds, and it doesn’t address the broader precursor-event gap the existing guide describes.

On the evaluator side, item (a)’s “embedded designated independent verification organizations onsite in their labs” is the same open question CASRAI’s evaluator-independence guide maps across Anthropic’s RSP, the EU GPAI Code, METR’s own conflict-of-interest disclosures, and two competing federal bills — including the FRONTIER Act (H.R. 9925), which already uses the identical term “Independent Verification Organizations” for a federal licensing scheme. California’s order doesn’t resolve what independence would actually mean for an auditor stationed inside a lab; that guide’s existing survey of how other frameworks answer (or duck) the question is directly relevant background for whatever GovOps recommends by November 16.

Neither of these is a NIKOLAI crosswalk row today. California’s Government Operations Agency isn’t one of the organizations NIKOLAI maps against declared frameworks, and this order has no declared framework to map — it’s a set of deadlines for the state to write one. If a kill-switch requirement is eventually codified with defined activation triggers, that would be a legitimate candidate for a future NIKOLAI element; until then, calling it one would overstate what N-9-26 actually contains.

This is CASRAI’s own reading of the signed executive order and is not legal advice. Organizations with compliance obligations under SB 53, the pending GovOps recommendations, or any resulting legislation should consult their own counsel.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →