California’s AI Oversight Order and the Verification-First Bet: What Executive Order N-9-26 Actually Does

Governor Newsom’s Executive Order N-9-26 requires nobody else’s agreement — and the instrument it reached for is verification, not restraint.

Key Timeline — September 2026

17 September 2026

Anthropic publishes self-measured figures on automation and oversight, and states a plan to embed independent third-party evaluators with access comparable to internal risk assessment teams — a stated plan, not yet implemented.

18 September 2026

Governor Newsom signs Executive Order N-9-26, directing the Government Operations Agency to accelerate AI safety oversight under SB 813 and AB 1405, and directing that recommendations on four proposals — including onsite embedding of verifiers — be developed within two months.

Existing Law — SB 813 (McNerney)

Establishes a framework for independent verification organizations to assess AI systems for safety and risk. Implementation now accelerated by EO N-9-26.

Existing Law — AB 1405 (Bauer-Kahan)

Creates a state registry for AI auditors and sets independence and transparency standards. Implementation now accelerated by EO N-9-26.

What Happened

On 18 September 2026, Governor Gavin Newsom signed Executive Order N-9-26, directing California’s Government Operations Agency to accelerate implementation of AI safety oversight. The order works through two existing laws already on the books: SB 813, authored by Senator McNerney, which establishes a framework for independent verification organizations to assess AI systems for safety and risk; and AB 1405, authored by Assemblymember Bauer-Kahan, which creates a state registry for AI auditors and sets independence and transparency standards. The implementation of both laws is being accelerated — the laws themselves are not new.

Separately, the order directs that recommendations on four proposals be developed within two months. Those four proposals are under consideration, not enacted, and none is a requirement in force. They are: requiring frontier AI companies to embed designated independent verification organizations onsite for regular audits; requiring AI safety frameworks, transparency reports, and risk assessments to be verified by independent verification organizations; advancing the creation of an emergency kill switch for frontier models with ongoing efficacy verification — a proposal under consideration, not implemented and not mandated; and updating critical safety incident definitions to include loss-of-control incidents. No company is named, no threshold or definition of “frontier” is provided, no penalty or enforcement mechanism exists in this order, no effective date is stated, and no named verification organization appears.

Newsom stated: “We’re not waiting to act — we’re going to speed up our work on substantial and responsible AI oversight.” He also called on Congress and President Trump to “review and adopt the state’s framework” or use it “as a floor, not a ceiling.” Those are the only quotations from the order reported here; nothing is attributed to any legislator.

The key insight: For two weeks, every proposed mechanism for pacing frontier AI required somebody else’s agreement — an antitrust waiver, an auditing profession that doesn’t have the staff, a jurisdiction sitting outside the arrangement. A state governor signing an executive order requires nobody’s. That is the first structural fact here, and it is about the actor before it is about the content.

A regime that regulates verification does not have to decide how fast is too fast. It only has to decide who i
A regime that regulates verification does not have to decide how fast is too fast. It only has to decide who is entitled to look.

The Structural Read

The more consequential choice is in the content, not the act of signing. The instrument California reached for is verification, not restraint. Three of the four proposals under consideration concern who checks: independent verifiers embedded onsite, safety frameworks and risk assessments verified to an external standard, and a registry of auditors with independence requirements already embedded in law. Only one — the kill switch proposal under consideration — concerns an intervention capability, and that remains a future proposal, not a mandate.

This is the structural distinction worth holding. A regime that regulates verification rather than capability never has to answer the question the pacing debate could not answer: how fast is too fast? It only has to decide who is entitled to look. That is a far easier question to legislate and a far harder one to route around. This is an observation about two kinds of rule — not a claim that either is effective, desirable, or likely to work.

Permission Layer — Business Engineer Framework

Regulating who looks vs. regulating how fast

Capability regulation requires answering an unanswerable question: what speed is safe? Verification regulation sidesteps that entirely. It establishes entitlement to observe — which is a procedural claim, not a technical one — and builds the infrastructure of accountability before the question of limits has to be resolved. The Permission Layer here is not a gate on capability. It is a gate on opacity.

The sequence around the onsite-embedding proposal reads differently once that frame is clear. On 17 September, Anthropic published self-measured figures on automation and oversight and stated a plan — a stated plan, not yet implemented — to embed independent third-party evaluators with access comparable to internal risk assessment teams. The following day, a state proposes requiring essentially that arrangement. Nothing establishes that either prompted the other. Convergence is not evidence of coordination, and no causation is claimed in either direction. The observation worth making is narrower: when a voluntary commitment and a proposed requirement describe the same arrangement, the difference between them is not the activity but who is able to end it.

The quietest line in the order may carry the most durable structural weight. Updating critical safety incident definitions to include loss-of-control incidents takes a category that has until now lived in essays and position papers and converts it into a reportable event with a legal definition — if the proposal is adopted. Definitions determine what gets counted. What gets counted determines what can later be measured, disclosed, and regulated. This is the ordinary mechanics of how a regulatory regime acquires teeth, and it typically happens well before anything visible does. No past event is described here as a loss-of-control incident; no incident is named; no claim is made that any such incident has occurred or would qualify under any definition.

Governor Newsom — EO N-9-26, 18 September 2026

“We’re not waiting to act — we’re going to speed up our work on substantial and responsible AI oversight.”

The federal ask is an admission about the limits of the instrument, and that admission clarifies the architecture. A state can bind conduct within its own jurisdiction without anyone’s permission — which is precisely why this executive order exists at all. It cannot bind conduct outside it — which is precisely why the request to Congress and the President exists. Both halves belong together; neither cancels the other. No prediction is made here about whether Congress or the President acts, and no federal actor’s position is characterized.

Three Implications

IMPLICATION 1 — THE AUDITOR BECOMES STRUCTURAL INFRASTRUCTURE

SB 813 and AB 1405 are already law. What EO N-9-26 accelerates is their implementation — meaning the registry of AI auditors and the framework for independent verification organizations move from enacted-but-pending to operationally urgent. If the onsite-embedding proposal under consideration is later adopted, the auditor role shifts from periodic reviewer to continuous embedded presence. That changes the economics, staffing requirements, and professional standards of an industry that does not yet have the scale to staff the role. The bottleneck is not legal authority; it is human capital.

IMPLICATION 2 — “LOSS OF CONTROL” AS A LEGAL CATEGORY CHANGES THE DISCLOSURE CALCULUS

A proposal under consideration would add loss-of-control incidents to the definition of critical safety incidents. If adopted, this converts a conceptual category into a reportable event. Organizations operating frontier systems would face a definitional question on any anomalous behavior: does this qualify? That question — and the legal exposure that attaches to the answer — reshapes internal documentation practices, incident review protocols, and the relationship between technical teams and legal counsel, well before any enforcement action is ever taken. Definitions do work before regulators do.

IMPLICATION 3 — VOLUNTARY COMMITMENTS AND PROPOSED REQUIREMENTS NOW SHARE AN ADDRESS

When a voluntary commitment and a proposed regulatory requirement describe the same arrangement — independent evaluators embedded with access comparable to internal teams — the policy distance between them collapses to a single variable: who controls termination. Voluntary arrangements can be ended by the party that made them. Required arrangements cannot. That distinction, once it becomes visible in regulatory drafts, changes the strategic value of making the voluntary commitment in the first place — and changes it for every organization watching, not only the one that made the original statement.

Business Engineer Framework

The Permission Layer

EO N-9-26 is a Permission Layer move — but one that regulates the right to observe rather than the right to deploy. The Map of AI tracks all nine layers of the stack where this kind of structural intervention lands: from infrastructure through model providers to the governance layer that determines which systems ship, at what pace, and under whose watch. Understanding where verification fits in that stack — and where it doesn’t reach — is the analytical foundation for reading every policy move that follows.

Explore the Map of AI →

The Bottom Line

Executive Order N-9-26 is not a capability ceiling and not yet an enforcement regime — it is the construction of an observation architecture, built on two existing laws, pointing toward four proposals that remain under consideration, including a kill switch proposal under consideration that is not implemented and not mandated. The structural move is to make opacity harder before making speed illegal; to establish who is entitled to look before legislating how fast is too fast. Whether that is sufficient, whether it is the right instrument, and whether it produces the outcomes it seeks are open questions this analysis does not answer. What it does is establish the terms on which those questions will eventually be asked — and that work, done quietly in definitions and registries and independence standards, is how regulatory teeth grow.

This article is business analysis only. It is not legal advice and not investment advice. No view is expressed on any security and no recommendation is made.


Sources:
Executive Order N-9-26 — Office of Governor Gavin Newsom, 18 September 2026

91,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.

All four measures described above are proposals under consideration, not requirements in force. The emergency shutoff in particular is something the order advances the creation of; it is not implemented and not mandated, and nothing above should be read as saying California has created, required or implemented one. SB 813 and AB 1405 are existing laws whose implementation the order accelerates; they are distinct from the proposals. The two-month period is for developing recommendations, not for implementing anything. No company is named as subject to this order, and no threshold, compute level or definition of “frontier”, penalty, fine, enforcement mechanism, effective date, cost or named verification organisation is stated — none appears in the material relied on here. Nothing above describes any past event as a loss-of-control incident, names any incident, or claims that any such incident has occurred or would qualify under any definition. Anthropic’s statement that it plans to embed independent third-party evaluators is a stated plan rather than an existing arrangement. No causation is claimed in either direction between that statement and this order; convergence is not evidence of coordination. Nothing here predicts whether Congress or the President acts, characterises any federal actor’s position, or takes a position on preemption or on state versus federal authority. Nothing here takes a position on whether this regulation is good, bad, sufficient or excessive, or characterises anyone’s motives. No effect is claimed on any company’s costs, operations, location decisions or competitiveness, and nothing is predicted about enactment, adoption, compliance or industry response. This is business analysis. It is not legal advice and not investment advice, no view is expressed on any security, and no recommendation is made.

Scroll to Top

Discover more from FourWeekMBA

Subscribe now to keep reading and get access to the full archive.

Continue reading

FourWeekMBA