TL;DR Between September 18 and 23, 2026, four governors issued AI executive orders: Newsom (California N-9-26), Spanberger (Virginia EO 22), Pritzker (Illinois EO 2026-07) and Kotek (Oregon EO 26-26). All four direct state agencies and none sets penalties on private companies. Two route AI safety through state procurement and two mention a kill switch or strict liability for study. This tracker compares them, lists the deadlines we can verify, and gives you a vendor safety attestation to prepare before a government customer asks.
In the two weeks before Washington announced voluntary AI commitments on September 29, four governors took a different route. None of them passed a law. Each signed an executive order, which is faster, binds only the state's own agencies, and is easy to reverse. That makes these orders weak as regulation and useful as a forecast: they show what state buyers are about to ask for, and what legislatures may be asked to pass in 2027.
This page tracks all four in one table, flags which claims we could verify against an official source and which we could not, and ends with something you can use: a safety attestation vendors can prepare before a state customer asks for one. If you want the California order in detail, see our Newsom N-9-26 contract clauses article.
The four orders side by side
| California | Virginia | Illinois | Oregon | |
|---|---|---|---|---|
| Governor | Gavin Newsom | Abigail Spanberger | JB Pritzker | Tina Kotek |
| Order | N-9-26 | Executive Order 22 | Executive Order 2026-07 | Executive Order 26-26 |
| Date | September 18, 2026 | September 18, 2026 | September 22, 2026 | September 23, 2026 (as reported) |
| Main subject | Independent AI oversight and a kill switch study | Data center accountability, plus a new AI task force | An AI Cabinet to advise on AI risk | State AI procurement standards |
| AI-specific directive | Speed up SB 813 and AB 1405 (independent verification and an auditor registry), with recommendations on onsite auditors and a frontier kill switch | Create an AI task force on workforce displacement, data privacy and cybersecurity | Advise on incidents, safeguards, procurement standards, data center incentives and strict liability | Develop criteria for third-party AI safety review and assess a kill switch for frontier models |
| Deadline we can verify | Report due November 16, 2026 | None stated for the task force | None stated | Proposal to the governor within 90 days |
| Binds private companies? | No | Not for the AI provisions | No | No |
Three things stand out when you read the rows together.
All four are directives to government. The Illinois cabinet advises. The Oregon order tells the state's chief information officer what to build. The California order tells the Government Operations Agency to move faster on a law that already exists. The Virginia order is mostly about data centers. Nothing here creates a duty or a penalty for an AI company.
Procurement is the lever. Oregon's order is entirely about procurement standards. Illinois lists "incorporating AI safety standards into state procurement and contracting" among the cabinet's tasks. A state can set conditions on the products it buys without passing a statute, and a vendor that wants the contract has to meet them.
The kill switch has crossed state lines. California's order points toward one, and Oregon's order asks for an assessment of whether a kill switch requirement for frontier models is workable. Congress has a House bill on the same idea, which we covered in our AI Kill Switch Act article.
What each order actually says
California: N-9-26
This is the order we already covered. It does not regulate AI companies directly. It tells the Government Operations Agency to speed up SB 813 (independent verification organizations) and AB 1405 (a registry of AI auditors), both signed September 9, and to deliver recommendations by November 16, 2026 on onsite auditors, verified safety filings, a kill switch and wider incident reporting. Newsom also signed a large batch of AI bills on September 30, which we summarize in our California September 30 signings article.
Illinois: Executive Order 2026-07
The governor's own press release is the best source here. It creates the Illinois Artificial Intelligence Cabinet, made up of outside experts from academia, law, ethics and governance, plus senior leaders from eight state agencies: the Department of Innovation and Technology, the Emergency Management Agency, the Department of Financial and Professional Regulation, the Commerce Commission, the State Police, the Department of Commerce and Economic Opportunity, the Environmental Protection Agency and the Department of Public Health.
Its listed tasks include:
- Advising on preparing for and responding to AI-related incidents
- Developing incident prevention and response policies
- Evaluating whether data center tax incentives, permits or approvals should be conditioned on meeting safety standards
- Addressing the energy burden of AI data centers
- Incorporating AI safety standards into state procurement and contracting
- Assessing strict-liability frameworks for AI-caused harm
The press release does not state any deadlines, and appointees had not been announced. Pritzker's quoted rationale was that when experts "sound the alarm bell and ask for guardrails, we should listen." Our Illinois SB 315 vendor risk article covers the state's separate frontier AI safety legislation.
Oregon: Executive Order 26-26
The order is titled "Establishing Responsible Artificial Intelligence Procurement Standards for State Government." Based on the reproduction of the governor's release we could read, it directs the state chief information officer to develop standards or criteria for third-party AI safety review and to assess whether a kill switch requirement for frontier AI models is workable. The implementation proposal goes to the governor within 90 days. One source also says the order is reassessed every three months.
Counting 90 days from September 23 gives roughly December 22, 2026. That date is our arithmetic, not a date stated in the order. The summary we read does not define "frontier AI models," describe how a kill switch would work, or list specific vendor requirements.
Virginia: Executive Order 22
Virginia's order is mostly about data centers. The official release describes a data center accountability framework: it bans state executive branch entities from entering or requiring nondisclosure agreements on data center projects, and it requires local approval for any data center using more than 25 megawatts. It also creates a new AI task force "to address growing concerns and risks posed by the rapid development of artificial intelligence," naming workforce displacement, data privacy and cybersecurity.
The official release gives no membership, deliverables or timeline for the task force, and says nothing about state AI procurement. Law firm summaries report 120-day and 180-day deadlines for agency action on engagement, noise, water and workforce measures. We did not find those deadlines in the official release we read, so treat them as reported, not confirmed. They concern data center measures, not the AI task force.
Deadlines you can plan around
| Date | Event | How sure we are |
|---|---|---|
| November 16, 2026 | California Government Operations Agency report on independent oversight and a kill switch | Stated in the governor's order, as covered in our earlier article |
| About December 22, 2026 | Oregon CIO proposal on AI procurement standards | Our count of 90 days from September 23 |
| Not announced | Illinois AI Cabinet appointments and deliverables | Press release says appointments come later |
| Not stated | Virginia AI task force output | Official release is silent |
Only the first row is firmly dated. If you run a calendar of AI compliance dates, enter the California date and set a reminder to check Oregon in December.
Why a vendor should care
If you sell AI to state or local government, or to a company that sells to them, these orders suggest the questions you will see in the next round of RFPs. Oregon is the most direct signal: its chief information officer has been told to define what a third-party safety review looks like. Illinois is a second: its cabinet is asked to put safety standards into procurement.
If you buy AI, the same orders are a free reference. A state's procurement standard is a ready-made list of questions to put to your own vendors, and state criteria tend to be copied by large private buyers.
Neither group should read these orders as law. They are study directives, they can be reversed by the next governor, and none of them has been tested in court. The federal government is also going in a different direction. Our write-up of the Super Intelligence executive order and the Joint Commitment covers the voluntary, no-enforcement approach announced on September 29.
A vendor safety attestation to prepare now
None of the four orders prescribes a form. This template is built from the topics the orders say they will study, so you have answers ready if a government customer asks. It is our own draft, not a state requirement, and it is not legal advice. Fill in the brackets and keep it under two pages.
AI safety attestation for [customer name]
1. Product and model. [Product name and version]. Underlying model provider(s): [names]. Date of last significant model change: [date].
2. Third-party safety review. Reviewed by: [independent reviewer name, or "none"]. Date: [date]. Scope: [what was tested]. Report available under NDA: [yes/no]. Findings still open: [number and severity, or "none"].
3. Shutdown capability. What we can suspend: [feature, tenant or whole product]. Time to suspend after a decision: [minutes or hours]. Who authorizes: [role]. Last tested: [date].
4. Incident notice. We will notify the customer within [72] hours of learning of an incident in which the product acted outside its authorized scope or exposed customer data. Contact: [role and email]. Covered events: [list].
5. Logs. We keep [action and access] logs for [24] months and will deliver them within [5] business days of a written request.
6. Data and training. Customer data is used to train models: [yes/no]. Retention period: [days]. Subprocessors: [names].
Signed: [name, title, date]
The numbers in brackets are starting positions. The most useful sections are the first three. A vendor that can fill them in honestly, including "none" for the third-party review, is ahead of most.
Five questions to ask your own AI vendors
Use these if you are the buyer, or if a state customer is about to ask them of you:
- Has an independent party reviewed this product's safety, and can we see the report?
- Can you suspend or limit the product for our account quickly, and has that been tested?
- What incidents have you had, and how long did it take to tell customers?
- Which model providers and subprocessors touch our data?
- What changed in the model since the last review?
For a fuller list, our AI vendor due diligence checklist goes into more depth, and our multi-state AI compliance strategy covers how to handle several states at once.
What we could not verify
- We did not read the full text of the Oregon or Virginia orders. Oregon's details come from a reproduction of the governor's release, and Virginia's from the governor's release and legal summaries that disagree on deadlines.
- Oregon's date of September 23 is the date of the report we read, not necessarily the signing date.
- The Oregon "reassessed every three months" detail comes from one source.
- Reports say governors in other states took related steps. We confirmed these four only, so this page is not a complete list.
- We found no verified tweet or social post from any of the governors about these orders that we could cite, so this page has no embed.

