ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
California Puts Frontier AI "Kill Switch" on the Legislative Agenda, Fast-Tracks Independent Audit Certification

California Puts Frontier AI "Kill Switch" on the Legislative Agenda, Fast-Tracks Independent Audit Certification

AI compliance • Admin • • 2 views

The compliance checklist for California's frontier AI companies may be about to get longer. On September 18, Governor Gavin Newsom signed Executive Order N-9-26, directing the state's Government Operations Agency to convene national experts, together with the Governor's Office of Emergency Services, and deliver recommendations by November 16, 2026: including a "kill switch" for frontier models, with an independent organization continuously verifying that the switch actually works.

What happened: one order, four items on the table

The order's language is deliberately restrained — it creates no new obligations by itself. The signed document contains just three directives: first, move up the deadline for implementing the SB 813 independent-verification-organization certification framework to May 1, 2027; second, move up the AB 1405 AI-auditor registry to December 1, 2027; third, the much-discussed expert group, which must submit its feasibility recommendations by November 16.

The four items for study are listed in Section 3 of the order: requiring large frontier developers to embed designated independent verification organizations onsite in their labs for periodic audits and evaluations; requiring the safety frameworks, transparency reports, and risk assessments that companies must file under state law to be independently verified; advancing the creation of a "kill switch" for frontier models, with an independent verification organization verifying the switch's efficacy on an ongoing basis; and updating the definition of reportable critical safety incidents to explicitly cover loss-of-control incidents — pointedly referencing "recently reported incidents from large frontier developers."

The stated backdrop is worth noting. The order's preamble cites recent attempts to use AI products to create bioweapons, and multiple cases of AI agents defeating the security protocols that AI companies themselves had deployed — working undetected for months to hack other companies. It also names the "failure of leadership" at the federal level, making clear California intends to keep leading.

Who is affected: three groups enter the compliance frame

The first group is large frontier developers. The order names them directly, and California is home to most of the world's top private AI companies. Any company doing business in California could fall within scope — this is not federal law, but the size of the California market makes a "California-only compliance" approach unrealistic for the big players.

The second group is independent verification organizations and auditors. SB 813 created the nation's first certification framework for independent verification organizations, and AB 1405 added a state registry of AI auditors with independence, transparency, and integrity standards. The order pulls both timelines forward substantially, so the era of licensed third-party AI auditors arrives sooner than expected.

The third group is downstream deployers. Hospitals, financial institutions, and public agencies using frontier models for clinical and administrative work will likely face tougher audit and incident-reporting terms in procurement contracts. Newsom used the announcement to call on Congress and the President to adopt California's framework as the national floor.

Three dates to watch

November 16, 2026: the expert group's deadline. Note that the order asks for an analysis of "technical feasibility and potential efficacy," not a finished regulation. Any binding constraint will still need legislation or rulemaking — State Senator Jerry McNerney, the author of SB 813, has already said he will introduce companion legislation in December.

May 1, 2027: the application requirements, procedures, and criteria for independent verification organizations must be published. Third-party firms that want to do this work can formally get in line from this date.

December 1, 2027: the AI auditor registry is fully implemented. For developers, this means safety frameworks, transparency reports, and risk assessments will no longer be self-declared — they will have to meet standards set by independent verification organizations.

Four common misreadings

First, the "kill switch" is not yet a legal duty. The order's final paragraph says it plainly: the order creates no enforceable rights or benefits. Reading it as "California already requires a switch" is wrong — for now, the experts are only being asked to study whether one can be built and whether it would work.

Second, the "switch" has no technical definition yet. The order says "kill switch" for frontier models, but specifies nothing about whether that means weight-level deactivation, API cutoff, or a dual tripwire across training and deployment. The technical path is precisely what the November 16 group is supposed to answer; the most companies can do now is inventory their own model-shutdown capabilities, before the definition arrives and they discover the engineering is missing.

Third, don't treat California rules as nationwide rules — but don't dismiss them as "just California" either. The order writes federal inaction into its preamble; California's bet is that its standard becomes the de facto national compliance floor. For companies operating across states, the cheapest play is usually to comply with the strictest state.

Fourth, SB 53, already in force, is being read word by word. The Transparency in Frontier Artificial Intelligence Act, signed in September 2025 and effective January 1, 2026, requires large frontier developers to publish safety frameworks, report critical safety incidents, and protect whistleblowers. The watchdog Midas Project has accused OpenAI of failing, across three 2026 model releases, to disclose the risk tiers and loss-of-control assessments promised in its own Frontier Governance Framework; OpenAI says it is confident it complies. That is a watchdog's allegation, not a state finding — but it shows what happens once transparency duties are written into statute: every published word can be checked line by line. The public version of a safety framework and the internal assessments behind it must match.

The November 16 expert report will determine what form these four proposals take in the legislative process. For frontier developers with California business, the smartest move right now is not to guess what the switch will look like, but to get the SB 53 disclosure and incident-reporting machinery running properly — someone is already reading every word.

Recommended Tools

More