California Proposes a Kill Switch for Powerful AI, Enforced by Outside Auditors

California Gov. Gavin Newsom issued an executive order on Friday, September 18, 2026, to position California to lead on AI oversight and start work on a possible kill switch mandate for frontier models, the most capable general-purpose systems. The Verge
The order directs the state to convene experts and deliver recommendations within two months on stronger AI safety measures in state law. The timeline is two months. The charge covers enforceable oversight tools, not voluntary principles.
What the order puts on the table
The expert group will consider requiring AI companies to host independent verification teams on site for regular audits, much like outside safety inspectors with building access.
It will also consider making company transparency reports and risk assessments follow standards set by independent auditors, rather than company-chosen formats.
A third item is the kill switch itself. The proposal would create a kill switch for AI models that is routinely tested to show it works. As described in state coverage, the switch would require AI developers to shut off certain programs in emergencies. CalMatters
A fourth proposal would require independent third parties to write safety plans for frontier AI companies, according to the Governor's Office release. Governor's Office
The order also directs a state agency to speed up two recent laws. One creates a framework for independent verifiers to assess AI safety. The other creates a state registry of AI auditors. Those laws supply the administrative base for any wider mandate.
The Governor's Office published the action on September 18, 2026, under the title "Governor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch."
Newsom called on Congress and President Donald Trump to review California's framework and adopt it as a model for federal action.
Two days before the order, on Wednesday, Newsom floated calling California lawmakers into a special legislative session on AI in an interview with Politico.
The broader context here is a sequence of state moves. On September 9, 2026, Newsom signed SB 813, described as first-in-the-nation AI safeguards to protect Californians. A separate California AI order requires firms seeking state contracts to have safeguards against abuse. Reuters In September 2024, Newsom vetoed a hotly contested AI safety bill after objections raised by the tech industry.
Why verification will decide this
The operative word in the order is independent. On-site verification teams, auditor-set reporting standards, and third-party safety plans point to the same design choice.
Compliance would no longer rest on internal evaluations and self-attested system cards, the company-written summaries of model behavior. It would depend on external parties with defined access, a defined audit surface, and authority to test shutdown controls.
In my view, that shift matters more than the phrase kill switch. A shutdown rule is easy to state and hard to implement. Models run across many servers and services, a process called inference. Copies spread as fine-tuned derivatives adapted from a base model, and weights, the numerical settings that define a model, can already be replicated. Agentic systems that use tools and keep persistent state add further complications.
The broader context here is that the two-month expert process must settle definitions before any statute. Routine checks would need to cover deployment controls, API cutoffs, hosted weights, and customer-managed copies. The scope of "shut off certain programs" will decide whether this means a deployment stop, a training halt, withdrawal of inference endpoints, or a combination. Standards are still needed for auditor qualifications, access to eval harnesses and incident logs, re-verification timing, and liability for failed shutdown. The auditor registry and verifier framework give the state a place to lodge those standards. Without them, transparency reports risk becoming paperwork rather than useful inputs.
In my experience watching security rules spread, the near-term signal for enterprise buyers and platform teams is procurement leverage. California already ties state contracts to safeguards against abuse. If auditor-graded risk assessments become normal, they will move into vendor due diligence, model buying checklists, and contract terms for shutdown and incident response. That pattern is familiar from SOC 2, FedRAMP, and zero-trust mandates, which began as narrow requirements before becoming baseline expectations.
In my view, after covering cycles from client-server to cloud to mobile to AI, this approach can work if it stays narrow and technical. Independent audit succeeds when auditors can inspect, reproduce results, and interrupt service. It fails when oversight means forms review. California is framing the question correctly around on-site presence and verified interruptibility. If the group defines testable shutdown criteria and access rights with precision, builders will have something concrete to engineer against, which would allow faster deployment under clearer guardrails.


