A symbolic AI governance scene shows California’s Capitol, a kill switch, feasibility study, audits, and data servers.
California Gov. Gavin Newsom’s Executive Order N-9-26 puts an AI “kill switch” on the state’s legislative agenda, but it does not require OpenAI, Anthropic, Google, Microsoft, or any other AI developer to install one today. The order, signed September 18, directs California agencies to report by November 16 on the technical feasibility and likely effectiveness of such a requirement for frontier models, alongside onsite third-party audits and expanded incident reporting.

That distinction is central. The Verge reported the order as a move toward a possible mandated shutdown mechanism, and California’s own announcement uses similarly forceful language about advancing a kill switch. But the signed order itself directs the Government Operations Agency and Governor’s Office of Emergency Services to develop recommendations for possible amendments to state law. The immediate obligations fall on state agencies; the obligations on AI labs would require another legal step.

For Windows administrators and enterprise IT teams, the practical implication is not a new setting in Copilot, Azure AI Foundry, Windows, or Microsoft 365. It is a warning that the largest AI suppliers may soon face California-specific requirements around emergency response, independent assurance, and disclosure of serious control failures—and those requirements could influence the contracts, incident notices, service controls, and audit evidence enterprise customers receive nationwide.

What Newsom actually ordered​

The executive order accelerates implementation of two California laws Newsom signed only nine days earlier: SB 813, which establishes a framework for independent verification organizations, and AB 1405, which creates a state registry for AI auditors.

The order moves the deadline for the Government Operations Agency to establish procedures for independent verification organizations to May 1, 2027. It also directs the agency to begin actions related to the AI auditor registry by December 1, 2027. Those dates matter because California is not merely convening another advisory panel; it is bringing forward infrastructure intended to support third-party review of AI systems.

The more consequential portion is due much sooner. By November 16, state officials must submit recommendations on whether California law could require large frontier-model developers to:

  • Place a designated independent verification organization onsite for periodic lab audits and evaluations.
  • Have their safety frameworks, transparency reports, and risk assessments independently verified.
  • Create a kill switch whose effectiveness is continually verified by an independent organization.
  • Expand reportable critical safety incidents to include a range of loss-of-control events.

California’s public statement frames these measures as a response to recent AI security incidents. The order does not identify named companies in its binding provisions, nor does it define how an emergency shutdown would work in a cloud service, a model-hosting platform, a downloadable model-weight release, or a customer-managed deployment.

That missing implementation detail is more important than the phrase “kill switch.” A shutdown control that pauses an API is materially different from one that disables autonomous agents, revokes credentials, halts model training, withdraws model weights, blocks inference clusters, or attempts to isolate systems already operating in a customer environment. California has asked whether such a mechanism is feasible; it has not answered that question.


The order is narrower than the headlines suggest​

Some coverage has described Newsom’s action as requiring AI labs to create kill switches. Bloomberg Law, for example, characterized the order as requiring companies to implement emergency shutoffs. The signed executive order says something more limited: agencies must study the feasibility and potential efficacy of requiring the creation of a kill switch through amendments to existing law.

That is not a semantic quibble. It changes the compliance status from “build this now” to “prepare for a regulatory proposal within two months.” No company has yet been given a statutory design standard, a testing protocol, an enforcement process, a definition of failure, or a deadline to deploy a shutdown mechanism.

The order also expressly asks independent verifiers to assess the efficacy of a future control on an ongoing basis. California therefore appears to be moving toward an assurance regime rather than accepting an AI lab’s internal attestation that a red button exists somewhere in its operations center.

That could prove far more demanding than a nominal kill switch. A meaningful independent verification program would need to establish what components count as the model, which systems the control can reach, whether personnel can activate it under pressure, how quickly it takes effect, whether it works across replicas and providers, and whether it can be bypassed by an agent with access to credentials or external infrastructure.

A vendor could plausibly demonstrate that it can suspend an API while still being unable to recover model weights already distributed to customers or open-source repositories. The state’s order does not resolve that gap, and it should not be assumed that one technical control can cover both hosted proprietary models and models that have already left a developer’s control.

California is building on SB 53, not replacing it​

Newsom’s new order sits on top of California’s Transparency in Frontier Artificial Intelligence Act, SB 53, which he signed in September 2025. That law already requires qualifying frontier AI developers to publish safety frameworks, report specified critical safety incidents to the state, and protect whistleblowers who disclose serious risks.

SB 53 was designed around large frontier developers, rather than ordinary software makers or organizations deploying a commercial chatbot. The law’s scope is aimed at well-resourced developers training models at the highest end of the capability scale. It is not a blanket rule for every company that uses generative AI, every Windows application with an assistant feature, or every IT department experimenting with an LLM.

The executive order’s proposed changes would add teeth to that existing framework in two ways. First, they could turn company-produced safety and risk documents into independently checked submissions. Second, they could make certain loss-of-control incidents reportable even when they do not fit the catastrophic-harm categories that dominated earlier frontier-AI legislation.

CalMatters reported that the recommendations could form the basis of a special legislative session, which Newsom had floated publicly before issuing the order. That provides a plausible route from policy study to enforceable obligations, but it remains a political possibility rather than a scheduled legislative outcome.

There is a notable change in Newsom’s posture. In 2024, he vetoed SB 1047, a more sweeping frontier-model safety proposal, arguing that it could regulate based on computing thresholds without adequately accounting for a system’s actual risk profile. The current order revisits several concepts associated with that earlier debate—third-party oversight, safety planning, emergency shutdowns—but routes them through a new verification structure and a feasibility review.

Why this matters to enterprise buyers​

The first organizations likely to feel the effects are frontier-model developers and their cloud partners, not desktop users. But regulations aimed at the largest model suppliers routinely travel downstream through enterprise contracts, security questionnaires, procurement policies, compliance reporting, and incident-notification terms.

For IT leaders, the useful question is not whether California can physically “turn off AI.” It is whether major providers begin offering verifiable evidence that they can contain a severe model or agent incident. That evidence could eventually cover emergency access revocation, workload suspension, audit logs, model version traceability, incident escalation paths, and notification commitments.

Enterprise customers should distinguish those provider-level controls from controls they retain themselves. A Microsoft 365 tenant administrator can disable a feature, restrict access, change conditional-access policies, revoke sessions, or remove an enterprise application. Those are tenant and identity controls. They are not a verified mechanism for shutting down the underlying model service, and they may not stop data or instructions already sent to an external model endpoint.

Organizations using AI agents should also avoid treating a vendor’s emergency shutoff promise as a substitute for basic security architecture. Least-privilege service accounts, narrowly scoped API permissions, network segmentation, approval gates for consequential actions, immutable logging, and rehearsed credential-revocation procedures remain the controls an enterprise can actually operate when an agent behaves unexpectedly.

The order’s focus on “loss-of-control” reporting could be particularly relevant for autonomous systems that can use browsers, call APIs, write code, access cloud resources, or act through delegated identities. A capability failure is not necessarily a catastrophe, but it can become an ordinary enterprise incident: an exposed token, an unintended bulk data action, unauthorized cloud changes, or persistent access established through an agent’s tools.


November 16 is the date to watch​

Newsom has set a short clock: California agencies must deliver their recommendations by November 16, 2026. The report should reveal whether the state believes a frontier-model kill switch can be defined and tested in a way that has legal and technical meaning, rather than serving as a reassuring label for a narrow service pause.

Until then, California has initiated an accelerated regulatory design process—not imposed an AI off switch. The first concrete compliance milestones are state deadlines in 2027, while the private-sector requirements that generated the headlines remain proposals awaiting technical recommendations and, likely, legislation.