California AI Executive Order N-9-26: What It Means for AI Governance
Jump to Section
California is accelerating a move from AI safety claims to independently verified evidence.
On September 18, 2026, Governor Gavin Newsom signed Executive Order N-9-26, directing state agencies to accelerate the development of California’s independent AI oversight framework and to evaluate potential additions to its AI safety laws.
The proposals include onsite independent verification at large frontier AI developers, third-party verification of safety disclosures, an independently tested emergency shutoff mechanism, and broader reporting of loss-of-control incidents.
The order does not immediately impose those four requirements on private companies. Instead, it directs state officials to assess their technical feasibility and potential effectiveness and recommend possible legislative changes by November 16, 2026.
For privacy, legal, security, and AI governance teams, the broader signal is important: organizations may increasingly need to demonstrate that AI safeguards operate as intended, supported by inventories, testing records, incident histories, accountable owners, and other verifiable evidence.
What Does California Executive Order N-9-26 Require?
Executive Order N-9-26 establishes three implementation deadlines:
- November 16, 2026: The California Government Operations Agency, working with the Governor’s Office of Emergency Services and national experts, must recommend potential amendments to California’s AI safety and security laws.
- May 1, 2027: The agency must complete and publicly post the application requirements, procedures, and criteria for independent verification organizations.
- December 1, 2027: The agency must complete the requirements specified in Government Code Section 11549.82(a) and begin the actions required under subsection (b).
The order builds on SB 813 and AB 1405, which Governor Newsom signed earlier in September.
SB 813 establishes a framework for certifying independent verification organizations that can assess AI systems and models. AB 1405 creates a state registry for AI auditors and establishes standards for independence, transparency, and integrity.
Together, the laws and executive order create infrastructure for more formal, evidence-based AI assurance. The four additional safeguards receiving the most attention remain proposals for possible legislative action.
What AI Safety Requirements Is California Considering?
California officials must evaluate at least four potential changes to state law.
Onsite Independent Verification
The order directs officials to consider requiring large frontier developers to embed designated independent verification organizations onsite to conduct periodic audits and evaluations.
This approach could give qualified reviewers more direct access to models, safeguards, testing processes, and supporting evidence. It would move oversight beyond periodic disclosures or reviews based primarily on information selected by the developer.
The operational lesson extends beyond frontier-model developers: independent assurance may become an ongoing governance function rather than a one-time certification exercise.
Third-Party Verification of Safety Disclosures
California will consider requiring independent verification of the safety frameworks, transparency reports, and risk assessments that frontier AI companies must file.
The distinction between disclosure and verification matters.
Disclosure asks an organization to describe its controls. Verification asks whether those controls are appropriately designed, consistently implemented, and supported by evidence.
This approach could increase expectations for documentation such as:
- Model and system inventories
- Testing and monitoring records
- Incident histories
- Control ownership
- Approval processes
- Remediation plans and status
- Evidence supporting safety and compliance assertions
Claims that cannot be traced to reliable evidence will be harder to defend.
A Verified Emergency Shutoff Mechanism
The order also directs officials to evaluate a potential requirement for frontier models to have an emergency shutoff mechanism whose effectiveness is independently verified on an ongoing basis.
Although the phrase “kill switch” attracts attention, the surrounding governance questions are equally important:
- What conditions would trigger the mechanism?
- Who would have authority to activate it?
- Which models, versions, integrations, and downstream services would it affect?
- How could the organization test it without introducing additional risk?
- How would the process preserve evidence needed for an investigation?
- What would happen if the model supported a critical business process?
A technical control is only as reliable as the governance surrounding it. Clear decision authority, escalation paths, testing procedures, documentation, and post-incident review would all be essential.
Broader Reporting of Loss-of-Control Incidents
California will consider expanding the definition of a reportable critical safety incident to include a broader range of loss-of-control events.
Organizations cannot consistently report AI incidents unless they first define what qualifies as an AI incident.
A workable incident process should distinguish among:
- Model performance failures
- Security events
- Privacy incidents
- Harmful or prohibited outputs
- Unauthorized autonomous activity
- Internal policy violations
- Events that cross multiple risk categories
The process should also establish when the organization became aware of an incident, who evaluates it, which legal or contractual obligations apply, and how the final decision is documented.
Does the Order Apply to Enterprise AI Users?
The proposed requirements are directed primarily at large frontier-model developers, independent verification organizations, and AI auditors. Most enterprises using third-party AI systems are not the direct target.
The order may still influence how organizations evaluate AI vendors and document their own governance. Procurement, legal, security, privacy, and risk teams may increasingly seek clearer answers to questions such as:
- Which AI systems and models does the organization use?
- Which vendors provide or support them?
- Who owns each system and its associated risks?
- What personal, confidential, or regulated data does the system process?
- What controls govern deployment and ongoing monitoring?
- What evidence supports vendor safety and compliance claims?
- How are AI-related incidents detected, escalated, investigated, and documented?
- Can access, integrations, or high-risk functionality be restricted quickly?
This broader enterprise impact is a likely governance implication, not a requirement created by the order. Organizations should continue monitoring California’s recommendations and any subsequent legislative action.
When answers and supporting evidence are spread across disconnected spreadsheets, policies, vendor files, and ticketing systems, demonstrating control effectiveness becomes more difficult.
What Should AI Governance Teams Do Now?
Organizations do not need to wait for California’s recommendations to strengthen their AI governance programs.
Build an Authoritative AI Inventory
Document each AI system’s models, owners, vendors, business purposes, affected individuals, data categories, integrations, and relevant jurisdictions.
The inventory should include approved systems and a defined process for identifying unapproved or “shadow” AI use.
Map Regulatory Obligations to Controls
Connect applicable laws, regulatory guidance, contracts, frameworks, and internal policies to specific operational controls.
Assign an accountable owner to each control and identify the evidence that demonstrates whether the control is operating as intended.
Integrate Verification Into the AI Lifecycle
Define when independent review is required, what reviewers may access, how conflicts of interest will be managed, and how findings will move through remediation.
Verification requirements should be incorporated into procurement, development, deployment, monitoring, incident response, and system retirement.
Prepare for AI-Related Incidents
Create an intake and investigation process capable of capturing:
- Model behavior and version
- Affected systems and integrations
- Data exposure
- Level of autonomy
- Safety, privacy, security, and business impact
- Detection and awareness times
- Containment actions
- Applicable notification or reporting obligations
Coordinate AI incident response with existing privacy, cybersecurity, legal, compliance, and enterprise-risk processes.
Test Intervention and Shutdown Procedures
For higher-risk systems, determine how the organization can restrict access, suspend integrations, disable functionality, or take a model out of service.
Document who has decision authority and test the procedure before an emergency occurs. Testing should also address business continuity, downstream dependencies, evidence preservation, and restoration criteria.
Preserve Evidence of Governance Decisions
Retain the facts considered, obligations evaluated, stakeholders involved, decisions made, controls tested, and remediation completed.
Effective governance requires more than reaching an appropriate outcome. It requires demonstrating how and why the organization reached that outcome.
Why AI Governance Is Moving From Disclosure to Proof
Executive Order N-9-26 points toward a more evidence-based model of AI governance.
Policies and principles remain important, but organizations may increasingly be asked to show how safeguards operate in practice:
- Who owns each control?
- How and when is it tested?
- What evidence demonstrates that it works?
- What happens when a system or control fails?
- Can the organization respond consistently and explain its decision?
Answering those questions requires continuity across AI inventories, assessments, controls, vendors, incidents, remediation, and reporting.
When those activities remain scattered across documents and disconnected systems, teams can struggle to respond quickly or demonstrate reasonable diligence.
Organizations will be better prepared when they can make consistent, risk-informed decisions and preserve a clear record of the facts, obligations, stakeholders, and actions behind each decision.
RadarFirst helps teams translate changing regulatory obligations into coordinated assessments, incident response workflows, and defensible records.
Explore how RadarFirst helps organizations operationalize AI governance and regulatory risk.
This article is provided for informational purposes and does not constitute legal advice.
Frequently Asked Questions About Executive Order N-9-26
Does Executive Order N-9-26 require companies to create an AI kill switch now?
No. The order directs California agencies to evaluate the technical feasibility and potential effectiveness of legislation requiring an emergency shutoff mechanism for frontier models. Any binding private-sector requirement would depend on subsequent legal action.
Which organizations are most directly affected?
The existing and proposed frameworks focus primarily on large frontier AI developers, independent verification organizations, and AI auditors. Enterprise users should continue to monitor developments, as evolving verification expectations may affect vendor diligence, procurement, contracting, insurance, and internal governance.
When will California issue its recommendations?
The Government Operations Agency must submit its recommendations by November 16, 2026. Those recommendations could inform future amendments to California law, but they will not automatically create new private-sector requirements.
What is independent AI verification?
Independent AI verification is an objective assessment of an AI system, model, control, disclosure, or risk analysis by a qualified organization with appropriate expertise and independence. Its purpose is to determine whether documented safeguards are supported by evidence and operate as represented.
Does the order apply to companies using third-party AI tools?
The order’s proposed requirements focus on large frontier developers and the organizations that verify or audit AI systems. Enterprise users are not the direct focus, but they should evaluate whether their vendors can provide reliable evidence about model governance, controls, incidents, and intervention procedures.
What should organizations prioritize first?
Begin with visibility. Establish an authoritative AI inventory, identify accountable owners, map legal and policy obligations to operational controls, and define a cross-functional AI incident process. Verification is difficult when an organization cannot reliably identify its AI systems, risks, decisions, and supporting evidence.
Let’s Get Started
Trusted by leading organizations, RadarFirst enables teams to manage incidents with speed, consistency, and defensibility by standardizing how incidents are captured, assessed, and actioned.