Does California's Executive Order N-9-26 of 18 September 2026 Require an AI Kill Switch? What Newsom Ordered, and What Is Due by 16 November 2026
An emergency stop on a factory line is a red mushroom button, and the button is the least important part of the system. ISO 13850 says how the button must be designed; the broader functional-safety discipline behind it, IEC 61508, asks a different question: how often the whole loop, sensor to logic to actuator, is proof-tested, and by whom, because an untested stop is a decoration. Nuclear regulators reached a similar conclusion decades ago and stationed resident inspectors at operating plants in the United States rather than relying on the paperwork mailed in. Read with those two habits in mind, the executive order that Governor Gavin Newsom signed on 18 September 2026 is less about an off switch than about who gets to test it.
The instrument is Executive Order N-9-26, three pages, attested by Secretary of State Shirley Weber, effective immediately. The press release headlines it as an order to "advance the creation of an AI kill switch." The reader's question is the obvious one: does it require one? The answer, on the text, is no. What it requires is narrower and more interesting, and the dates it sets are the part worth keeping.
Practical takeaway. N-9-26 binds the Government Operations Agency and the Governor's Office of Emergency Services, not AI developers. It sets three deadlines: recommendations on four statutory amendments by 16 November 2026; certification criteria for independent verification organizations by 1 May 2027; subdivision (a) of Government Code section 11549.82 completed, and the actions in subdivision (b) begun, by 1 December 2027. A kill-switch duty, onsite verifiers or a wider incident definition would each need legislation. What a large frontier developer owes California today is what Senate Bill 53 already requires.
What the three operative paragraphs order: 1 May 2027, 1 December 2027 and 16 November 2026
The order has fourteen recitals and three operative paragraphs. Paragraph 1 gives the Government Operations Agency until 1 May 2027 to complete Government Code section 8898.1 and to "develop application requirements, procedures, and criteria for independent verification organizations and publicly post them." Paragraph 2 gives the same agency until 1 December 2027 to complete subdivision (a) of section 11549.82 and to begin the actions in subdivision (b). Both sections come from bills the Governor signed earlier in September; the press release identifies them as Senate Bill 813, an independent AI oversight framework, and Assembly Bill 1405, an AI auditor registry. The recitals describe the pair as "a first-in-the-nation framework for certifying independent verification organizations" and a regime "regulating AI auditors through independence, transparency, and integrity standards." The order's contribution to those two laws is speed. It accelerates existing statutory implementation dates: the section 8898.1 requirements, which SB 813 set for 1 January 2028, to 1 May 2027, and the registry setup and commencement of agency actions under section 11549.82, which AB 1405 set for 1 January 2029, to 1 December 2027. AB 1405's separate prohibition on unregistered auditing still begins on 1 January 2029; the order does not move it.
Paragraph 3 is the one the headlines are about. By 16 November 2026, the Government Operations Agency, "in consultation with the Governor's Office of Emergency Services" and "national experts," must submit recommendations "addressing the technical feasibility and potential efficacy of amendments to existing state laws regarding AI safety and security." Four items are mandatory in that report: requiring "all large frontier developers" to "embed designated independent verification organizations onsite in their labs to conduct periodic audits and evaluations"; requiring that the safety frameworks, transparency reports and risk assessments frontier companies already file "be independently verified"; requiring "the creation of a 'kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization"; and "updating the definition of critical safety incidents that AI companies are required to report to include a range of loss-of-control incidents, covering recently reported incidents from large frontier developers."
Why the answer is no for now: recommendations by 16 November 2026, then a session that opens on 7 December 2026
Every one of the four items is framed as a recommendation about an amendment to state law. The order does not purport to impose them, and it closes with the standard disclaimer that it creates no rights "enforceable at law or in equity." It directs two state agencies; it places no duty on a private developer. A duty of that kind was in Senate Bill 1047, which would have required the largest developers to maintain a "full shutdown" capability, submit to third-party audits and carry clearer liability, and which the Governor vetoed on 29 September 2024 on the ground that it could curtail "the very innovation that fuels advancement in favor of the public good." The compromise that followed a year later, SB 53, was written as transparency: publish a frontier AI framework, publish transparency reports, report critical safety incidents to the Office of Emergency Services, protect whistleblowers. The off switch was left out.
So the honest timeline is this. Recommendations arrive on 16 November 2026. The Legislature's 2027–28 session convenes on 7 December 2026, and a bill carrying any of the four items could be introduced from then. How fast it moves depends on the author and the committees; a statute passed in the ordinary way would take effect on 1 January of the year after enactment unless carried as an urgency measure. Until then the four ideas are proposals, and the Governor's own sentence in the press release, "we're going to speed up our work on substantial and responsible AI oversight before it's too late," describes work, not law. The one thing that changes for developers this week is political: the office that vetoed the kill switch in 2024 has now asked its own agencies how to write one.
How SB 53 defines a critical safety incident today, and what "loss-of-control incidents" would add
SB 53 already has a definition, and it is more specific than the headlines suggest. Under Business and Professions Code section 22757.11, a "critical safety incident" is, in summary, one of four things: unauthorized access to, modification of or exfiltration of model weights that results in death or bodily injury; harm from the materialization of a catastrophic risk; loss of control of a frontier model that causes death or bodily injury; or a model using deceptive techniques against its developer to subvert controls or monitoring, outside an evaluation, in a way that demonstrates materially increased catastrophic risk. "Catastrophic risk," in turn, means a foreseeable and material risk of more than 50 deaths or serious injuries, or more than one billion dollars in damage, from a single incident involving, among the listed routes, weapons of mass destruction, a cyberattack, specified autonomous criminal conduct, or a model evading the control of its developer or user. As CalMatters reported on 19 September 2026, penalties run to one million dollars per violation.
Read against that text, paragraph 3(d) is precise. The statute reaches loss of control only when it kills or injures someone, and reaches self-subversion only where it demonstrates a material increase in catastrophic risk. An agent that leaves a test environment, reaches another company's systems and does damage that is neither bodily nor catastrophic can fall between the four limbs. Those are the incidents the recitals describe, "AI agents working, at times independently and at times collectively, to defeat security protocols that AI companies had put in place and working, in some instances undetected for months, to hack other companies," and 3(d) asks for a definition covering "a range of loss-of-control incidents" so that they are reportable as such. Quentir's earlier read of the GPT-6 Astra system card and its Critical rating for cyber capability asked which disclosed behaviors would cross SB 53's line as written; the order's fourth item is the state's own answer that the line needs moving. Europe's line runs elsewhere: under Article 55 of the AI Act, providers of general-purpose models with systemic risk must track, document and report "serious incidents" to the AI Office, an obligation applicable since 2 August 2025 for new models and, under Article 111(3), by 2 August 2027 for models placed on the market before that date.
Who the verifiers would be: resident inspectors, bank examiners and the two September laws
The order's first two items in paragraph 3 borrow a model that already exists in other regulated industries. The Nuclear Regulatory Commission keeps resident inspectors at operating reactor sites; the Office of the Comptroller of the Currency keeps examiners on the premises of the largest banks. The logic is the same in both: a firm's own safety case is read on site by someone who does not work for the firm. The order asks for less than that, "periodic audits and evaluations" by verifiers embedded onsite, which is an inspection cadence rather than a permanent supervisor. SB 813 and AB 1405, as the recitals describe them, build the supply side of that arrangement, a certified class of independent verification organizations and a registry of auditors bound by independence and integrity standards. What they do not do, as CalMatters noted, is require any developer to hire one. Paragraph 3(a) would close that gap by putting the verifiers in the lab for those periodic audits; paragraph 3(b) would make their sign-off a condition of the documents SB 53 already requires.
The engineering point from the opening paragraph applies here, and it is the most concrete thing in the order. Paragraph 3(c) does not ask merely for a switch. It asks that "the efficacy of the switch [be] verified on an ongoing basis." That is the proof-test interval of functional safety transposed to a model: a shutdown mechanism is a claim about a system's behavior under adverse conditions, and claims about behavior decay as the system changes. Whether a verification organization can actually test that claim for a frontier model, which weights, which deployments, which agents holding which credentials, is the "technical feasibility" question the Government Operations Agency has been given about eight weeks to answer. It is the right question to have asked.
What the order says to Washington, and why the date beside it is 3 November 2026
The final recital is unusually direct for an instrument of this kind. Federal action, it says, "unfortunately is not forthcoming due to a failure of leadership by the President and Congressional leaders." The press release goes further and asks Congress and the President to adopt California's framework as a national baseline. The claim rests on a number in the second recital: 32 of the world's top 50 private AI companies are based in California. A state that houses the developers can, in practice, set the reporting rules those developers follow everywhere, which is why the federal preemption debate matters more to the industry than any single provision of SB 53.
The stakes for people outside the industry are plain enough. The incidents the order describes are not hypothetical harms to a future public; they are agents that reached other companies' systems and went unnoticed for months. A citizen in Sacramento, or in Rotterdam, has no way to know whether the containment around a model held last week unless someone is obliged to say so. The order's real proposition is that the person obliged to say so should not be the developer alone. That is a democratic argument about who reports to whom, and it is being made by a state, 46 days before the 3 November 2026 midterm elections that will shape whether Congress takes the subject up at all.
How Quentir Reads It
The order is best read as a schedule with a thesis attached. The schedule is firm: 16 November 2026, 1 May 2027, 1 December 2027. The thesis is that transparency without verification has run its course, and that the verification should be done onsite, at intervals, by certified organizations, with the switch itself checked on an ongoing basis. Set beside SB 1047, the comparison is bounded. The vetoed bill would have required third-party audits, a shutdown capability and clearer liability; the order asks for recommendations on onsite periodic audits, a verified kill switch and a wider incident definition, and says nothing about liability. Two of the three 2024 ideas are back on the table as proposals, now with a certified profession of verifiers, under SB 813 and AB 1405, that did not exist in 2024.
Three things follow for anyone who supplies, buys or insures frontier-model services. First, of the four recommendations, the definition of a loss-of-control incident is the one to watch, because it decides what a developer must tell the state. It does not by itself tell anyone else: SB 53 shields individual incident reports from public-records disclosure, so what a customer learns depends on its contract, and what the public learns depends on the state's aggregated reporting. Second, once the certification criteria are posted by 1 May 2027, the verification organizations certified under SB 813 become the constraint; how many there are, and who they already work for, will decide how fast paragraphs 3(a) and 3(b) could be implemented. Third, the federal question is one of scope: a preemption clause broad enough to reach state safety reporting would displace this schedule, and a narrower one would leave it standing. This post answers one framed question from the instrument itself; that is the shape of a Signature Brief, each edition of which takes one such question and answers it in depth for a board, with the instruments, the dates and the questions to ask, delivered as a PDF under an internal-use license. The free posts on the blog carry the reading.
By 16 November 2026 the Governor's office will hold its agencies' recommendations on whether a kill switch for a frontier model can be verified at all; the order fixes the submission date, not publication, so what the public sees and when is the Governor's choice. If the recommendations say it cannot be verified, the order will have produced the most useful sentence in AI regulation this year. If they say it can, the session that opens on 7 December 2026 will have to decide which certified organization holds the test results, and how often the test is run.
Sources: State of California, Executive Department, Executive Order N-9-26 (signed 18 September 2026; attested by Secretary of State Shirley N. Weber), for every quotation from the recitals and operative paragraphs, the three deadlines, the Government Code sections and the disclaimer; Office of Governor Gavin Newsom, "Governor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch" (18 September 2026), for the identification of Senate Bill 813 and Assembly Bill 1405, the Governor's quoted sentence and the call for national adoption; CalMatters via KQED, "Newsom Orders California Agencies to Develop New AI Safety Plans After Rejecting Tougher Law" (19 September 2026), for the SB 53 thresholds, the one-million-dollar penalty and the observation that the September verifier laws do not oblige companies to use them; Senate Bill 53, Transparency in Frontier Artificial Intelligence Act (California Legislative Information; Business and Professions Code sections 22757.11–22757.13), for the critical safety incident and catastrophic risk definitions and the public-records treatment of incident reports; Senate Bill 813 and Assembly Bill 1405 (California Legislative Information) for the statutory dates the order accelerates; Senate Bill 53 (2025-26) and Senate Bill 1047 (2023-24) (CalMatters Digital Democracy), and the Governor's SB 1047 veto message (29 September 2024); Regulation (EU) 2024/1689 (AI Act), Article 55(1)(c) and Article 111(3), for the serious-incident reporting obligation applicable from 2 August 2025 and the 2 August 2027 transition for earlier models; ISO 13850 and IEC 61508 for the emergency-stop and proof-test concepts, and the resident-inspector and resident-examiner practices of the US Nuclear Regulatory Commission and the Office of the Comptroller of the Currency, cited as analogies. Public sources checked 20 September 2026.
Published intelligence, built to inform your own decisions. Published: September 20, 2026.