Regulatory Updates

California wants independent verifiers inside AI companies

Published
Read time3 min read
Regulatory Updates

On 18 September 2026 Governor Gavin Newsom signed an executive order directing California agencies to accelerate work on an independent AI oversight framework. On 23 September his office named four experts to guide it: Jason Goldman of the Center for Shared AI Prosperity, Gillian Hadfield of Johns Hopkins University, Alondra Nelson of the Institute for Advanced Study and Rob Reich of Stanford University. What is being explored is a meaningful departure from how AI has been regulated so far.

What is being proposed

The executive order directs state agencies to assess the technical feasibility and likely effectiveness of several measures, and to recommend possible legislative changes by 16 November 2026. The proposals include:

  • Onsite independent verification at large frontier AI developers — verification organisations embedded within the companies themselves
  • Third-party verification of safety disclosures, rather than relying on developer self-attestation
  • An independently tested emergency shutoff mechanism, described in the coverage as a "kill switch"
  • Broader reporting of loss-of-control incidents

The governor's office also referenced accelerating implementation timelines for existing legislation, SB 813 and AB 1405. Newsom's framing was pointed: the federal government's failure to create meaningful AI oversight, he said, should alarm every American, "especially when AI CEOs themselves are begging for regulation".

Key points
Status
An executive order directing assessment and recommendations — not enacted rules.
Next date
Recommendations on feasibility and legislative change due by 16 November 2026.
Who it targets
Large frontier model developers, not general deployers of AI.

Why this matters even if you are not a frontier lab

Very few organisations reading this build frontier models, and nothing here imposes an obligation on an ordinary AI deployer. The significance is in the regulatory model being tested.

Most AI regulation so far, the EU AI Act included, relies substantially on providers documenting and attesting to their own compliance, with authorities checking afterwards. California is exploring something closer to the model used in financial services and safety-critical manufacturing: independent verifiers with their own access, checking claims at source.

If that approach gains ground, the practical consequence for everyone downstream is a shift in what counts as adequate evidence. "The vendor told us it was tested" is weaker than "a verifier with access confirmed it", and procurement standards tend to follow the strongest available assurance rather than the minimum legal one.

The divergence problem is getting real

For organisations operating internationally, this is the more immediate issue. The EU is enforcing a comprehensive horizontal regime while simultaneously considering delays to parts of it. The US has no federal equivalent, and individual states are filling the gap at different speeds and with different instruments. California, as the home of most large AI developers and a very large market in its own right, sets a de facto standard whatever it does.

Planning for that does not mean tracking fifty regimes. It means building governance around the questions every regime asks, because they are strikingly consistent:

  • Which AI systems are in use, doing what, and who owns each one?
  • What evidence do you hold that each was tested, and by whom?
  • Who can intervene when a system behaves unexpectedly, and how quickly?
  • What gets reported, to whom, when something goes wrong?

An organisation that can answer those four from a live record adapts to a new regime by changing a report. One that cannot is starting a discovery project every time a jurisdiction moves — and on current evidence, they will keep moving.

A reasonable read

This is an executive order commissioning recommendations, not a rulebook. It may produce legislation, it may be narrowed, and the November date is for advice rather than obligations. Treat it as a signal about where assurance expectations are heading, note the 16 November milestone, and spend the intervening time on the inventory work that is useful under every version of the future.

Build AI governance that holds up whichever regime lands on you next.

Talk about AI governance

Common questions

Not directly, and not yet. It directs state agencies to assess measures aimed at large frontier AI developers and to recommend possible legislative changes by 16 November 2026. Ordinary deployers of AI are not the target, though procurement expectations tend to follow the strongest assurance standard available.

An independently tested emergency shutoff mechanism for frontier models. It is one of several measures the executive order asks state agencies to evaluate for technical feasibility and effectiveness, alongside onsite independent verification and third-party verification of safety disclosures.

Build the governance that every regime asks for rather than tracking each one separately: a live inventory of AI systems with named owners, evidence of testing and who performed it, a defined intervention path when a system misbehaves, and clear incident reporting routes. Those four hold up under the EU AI Act and under whatever California legislates.

Sources

  1. Governor Newsom announces world-leading experts to deliver on his AI executive order, including advancing creation of a “kill switch” — Governor of California, 23 September 2026
  2. Governor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch — Governor of California, 18 September 2026
  3. California Gov. Newsom issues executive order to rein in AI 'before it's too late' — CNBC, 18 September 2026