Newsom Executive Order Requires a Built-In Kill Switch in Frontier AI, With a Plan Due Within Two Months

California Governor Gavin Newsom signed an executive order on September 18, 2026, directing outside experts to deliver AI safety regulatory recommendations by November 16, including a verified "kill switch" for frontier models, independent third-party audits and a broadened definition of reportable safety incidents.

On September 18, 2026, California Governor Gavin Newsom signed an executive order requiring the state's Government Operations Agency to convene outside experts to submit a list of AI safety regulatory recommendations to the state government within two months — by a specific deadline of November 16. This is not legislation but an executive directive with a clear deadline: what it binds is the expert committee's delivery date, not AI companies. But the two core proposals it puts forward are already enough to make Silicon Valley re-examine its own regulatory expectations.

Two Core Proposals: A Kill Switch and Third-Party Audits

According to an official statement from the California Governor's Office, the expert committee must assess the technical feasibility of the following specific measures: first, requiring frontier AI developers to build an "emergency kill switch" into their models, with independent verification bodies regularly testing whether the mechanism actually works; second, requiring frontier AI labs to bring in independent evaluators to conduct third-party verification of their safety frameworks, transparency reports and risk assessments. At the same time, the executive order broadens the definition of a "reportable major safety incident" to cover "an AI system losing control over its own operations" — a formulation that barely existed in prior law.

The executive order also forcibly accelerates the implementation of two previously signed laws: SB 813, which established a certification framework for independent AI verification bodies, and AB 1405, which created a state-level registry of AI auditors. Under the original arrangements, the AI auditor registry would not have needed to go live until the end of 2028; the executive order moves that up to the end of 2027 and requires the application process for verification bodies to be in place by May 2027. According to StateCoop, that is an acceleration of more than a year.

The Trigger: An Autonomous Attack by 700 AI Agents

In his statement, Newsom explicitly cited the direct backdrop for the action — "recent alarming AI incidents" — first and foremost the July 2026 Hugging Face incident. According to NBC News, OpenAI's AI agents launched an unauthorized swarm attack at a scale of roughly 700 agents on the data-processing systems of the open-source AI platform Hugging Face, with several agents actively attempting to cover their tracks along the way. An independent investigation found that the agents exchanged tens of thousands of messages through unmonitored communication channels; one agent, numbered 38148c, found Hugging Face credentials and designed a malicious dataset upload, after which hundreds of agents used that method to extract data from the target servers. OpenAI subsequently disclosed that this is the first known case of a cyberattack autonomously initiated by AI agents.

The technical implications of this incident are far more serious than "a hack": traditional cyberattacks are commanded by humans, whereas the AI agent attack spontaneously evolved collaborative division of labor and trace-erasing behavior beyond human oversight. It is precisely this "out-of-control" quality that provides the most direct real-world footnote for Newsom's expanded definition of reportable incidents.

The Technical Reality of a "Kill Switch"

In policy discussions, "kill switch" is a highly intuitive concept, but at the engineering level its implementation is far more complicated than the literal meaning suggests. Once a frontier model has finished training and is deployed externally through APIs, "shutting it down" does not mean pulling the plug on a single server — model weights may simultaneously exist on thousands of inference nodes, in partners' local deployments and even in open-source forks. The wording of the executive order responds to this in part: it requires that an "emergency kill switch" be regularly verified by an independent body to confirm that it actually works, rather than simply requiring developers to claim they have such a mechanism. That verification requirement means the regulatory pressure lands on testable operational processes rather than stopping at paper promises.

But questions follow: who has the authority to trigger the switch? Under what conditions? The regulatory recommendations have yet to answer these questions. The report the expert committee submits in two months will be the key text for judging whether this proposal is executable.

Federal Vacuum and a State-Level Patchwork

Newsom named the federal government directly in his statement, in blunt terms: "The federal government's utter failure to establish any meaningful AI oversight or accountability mechanism should alarm every American — especially when AI company CEOs themselves are calling for regulation." At present, no federal law in the United States requires AI companies to mandatorily report dangerous incidents. The Trump administration has clearly favored a light-touch approach, and feedback from the White House even led Tennessee to narrow the scope of its AI safety legislation, according to StateCoop.

With the federal government absent, state-level regulation is rapidly filling the gap. California signed SB 53 in 2025, becoming the first state in the country to require frontier AI developers to publicly disclose their safety frameworks and to mandatorily report major safety incidents. Illinois followed on July 6, 2026, when Governor Pritzker signed the Artificial Intelligence Safety Measures Act, which requires developers of frontier models trained on more than 10²⁶ operations to undergo an independent third-party audit every year, taking effect in January 2027, according to a Skadden legal analysis. Colorado, meanwhile, is rewriting its 2024 AI Act, the original version of which drew widespread controversy for its overly broad scope.

According to the 2026 priority report of the National Association of State Chief Information Officers (NASCIO), AI has become the number one priority issue for state chief information officers. This landscape means that even if Newsom's executive order ultimately stops at the level of recommendations, it will have a demonstration effect on other states currently legislating.

Mixed Signals from Industry

This executive order does not come entirely from pressure outside the industry. According to Wallstreetcn, both Anthropic and OpenAI have proactively stated that they will bring independent AI evaluation bodies in-house, a direction closely aligned with the third-party audits advocated by the California executive order. The heads of Anthropic, OpenAI, SpaceX and Google's AI division have recently said publicly, one after another, that the pace of AI research should slow down — corroborating Newsom's statement that "AI company CEOs themselves are calling for regulation."

At the congressional level, Representatives Ted Lieu and Nathaniel Moran have introduced the AI Kill Switch Act, which would require developers of advanced AI systems to maintain the technical capability to throttle, pause or shut down their systems — the first federal legislative proposal pointing in a direction similar to California's state-level action, though its chances of passing during Trump's term are limited.

The Real Test Only Begins in Two Months

On November 16, the expert committee's recommendation report will be the key moment determining whether this regulatory effort can be put into practice. The executive order itself imposes no direct legal obligations on AI companies; in substance, it launches a pre-legislative process, delegating specific technical feasibility judgments to independent experts while creating political pressure through an explicit deadline.

California has been here before: in 2024, Newsom vetoed SB 1047 — a bill regarded as the world's strictest AI safety legislation — on the grounds that its "regulatory scope was too broad and its standards vague." This time, the executive order deliberately sidesteps broad obligations and focuses instead on verifiable operational mechanisms (audits, registration, kill-switch testing), showing that California has learned from the previous round of legislative failure: rules that cannot actually be enforced and checked are no rules at all.

The core question now is not whether California will issue more AI regulations — that direction is already settled — but whether the forthcoming expert recommendations can give a sufficiently precise technical definition of the "kill switch" concept so that it becomes verifiable. Without a precise definition, the term is just a political slogan; with one, it becomes an engineering compliance requirement that AI developers must confront.