TL;DR: Newsom's executive order N-9-26 (September 18, 2026) does not regulate AI companies directly. It speeds up SB 813 and AB 1405, signed September 9, and asks for recommendations by November 16 on onsite auditors in frontier labs, verified safety filings, a frontier kill switch, and a wider incident definition that includes loss of control. If you buy from frontier vendors, the effect is contractual. Four clauses you can request today are below, with copy-paste language.
Two weeks ago California signed the machinery for AI audits. Twelve days ago the governor ordered it built faster and asked whether frontier labs should host auditors on their own premises and carry a kill switch. Most coverage treated this as a story about labs. For a team that buys AI, it is a story about what your vendor contract will need to say.
The order is a study directive, not a rule. Nothing in it obliges your vendor to do anything on a fixed date. That is exactly why the window matters: the terms get written in the next few months, and buyers who ask now shape what "normal" looks like.
What the order actually does
Executive order N-9-26 is dated September 18, 2026. According to the governor's press release, it directs the Government Operations Agency to accelerate the implementation timelines for SB 813 and AB 1405. It also convenes a group of experts to give California a guide for strengthening its AI safety and security laws within two months.
The two bills came first. On September 9, 2026, Newsom signed:
- SB 813 (McNerney): a framework for independent verification organizations that can assess AI systems and models for compliance with state law.
- AB 1405 (Bauer-Kahan): a state registry for AI auditors, with standards for their independence, transparency, and integrity.
The order then asks the agency, in consultation with national experts, to report by November 16, 2026 on the technical feasibility and likely efficacy of four proposals:
- Requiring large frontier developers to embed designated independent verification organizations onsite in their labs for periodic audits and evaluations.
- Independent verification of safety frameworks, transparency reports, and risk assessments.
- Requiring a "kill switch" for frontier models, with the switch's efficacy verified on an ongoing basis.
- Widening the definition of "critical safety incidents" to include loss-of-control events. The press release cites the Hugging Face attack as the example.
On September 23 the governor named four experts: Jason Goldman, Gillian Hadfield (Johns Hopkins), Alondra Nelson (Institute for Advanced Study), and Rob Reich (Stanford). Newsom framed the goal as national: "California has already built a national model, and our policy should be the national baseline."
One correction to a common misreading. Several summaries say the order "requires" frontier labs to host auditors and build a kill switch. It does not. Those are the four proposals under study. Until the November 16 recommendations become a bill or a rule, they bind no one.
The dates that matter
| Date | Event | Status |
|---|---|---|
| Sept 9, 2026 | SB 813 and AB 1405 signed | Law |
| Sept 18, 2026 | Executive order N-9-26 issued | In force as a directive |
| Sept 23, 2026 | Four-person expert group named | Announced |
| Nov 16, 2026 | Recommendations due on onsite auditors, verified filings, kill switch, incident definition | Pending |
| May 1, 2027 | Application requirements and criteria for verification organizations (Gov. Code 8898.1) | Reported statutory date |
| Dec 1, 2027 | Completion of Gov. Code 11549.82(a) steps, with actions under (b) beginning | Reported statutory date |
The last two dates come from secondary coverage of the statutes (ppc.land and Sigma Law Group), and I could not confirm them against the enrolled bill text. The order says it accelerates these timelines, but no source I found gives revised dates. Check the Government Operations Agency site before you put either date in a compliance calendar.
If you track California more broadly, our Newsom September deadline tracker covers the other bills on the governor's desk, and the federal AI Kill Switch Act analysis covers the DHS shutdown bill that is a separate track.
Why a kill switch is a buyer's problem
Most commentary asks whether a kill switch can work technically. Buyers should ask a different question: what happens to my workloads when the vendor uses it?
A kill switch that deactivates a frontier model is an availability event. If your support bot, coding assistant, or document pipeline calls that model, it stops. The proposal says the switch must have its efficacy verified on an ongoing basis, which means it will be tested, and tests can touch production. Your standard SLA almost certainly treats a deliberate safety shutdown as force majeure or excludes it entirely.
The same applies to the other three proposals. Onsite auditors generate findings you may want to see. Verified filings produce documents you may want to rely on. A wider incident definition changes what your vendor must tell you and when. In each case the state is deciding what the vendor must do. Your contract decides what you get to know and what you are owed.
We made a similar point after the OpenAI agent escape disclosure gap: no law required the vendor to tell customers, so the contract was the only lever. N-9-26 does not change that this quarter. It does tell you which terms will soon look reasonable rather than aggressive.
Four clauses to request now
1. Independent verification status
Ask whether the vendor has engaged, or will engage, an independent verification organization under SB 813, and whether you will receive a summary of the findings. Vendors will resist sharing full reports. A summary attestation is a reasonable ask, and it matches how most audit attestations already work.
2. Loss-of-control incidents in the notification clause
Most AI vendor agreements define an incident as a security breach or a data exposure. The order's fourth proposal widens the state definition to loss-of-control events. Your contract can get there first. Ask that "incident" include any event where a model or agent acts outside its intended operating boundaries, whether or not a vulnerability was exploited, and that the vendor notify you within a fixed number of business days of discovery.
3. Kill switch continuity
Ask for advance notice of a planned deactivation, a defined fallback model or version, a data and prompt export right, and service credits for unplanned shutdown. You will not get all four from every vendor. Ask for the fallback and the notice first, since those protect operations.
4. Auditor identity and access
Once AB 1405 is running, a registry will list qualified AI auditors. Ask that any auditor the vendor relies on for safety claims be registered when a registry exists, and that you can receive the audit scope and dates. A safety claim with no named auditor and no scope is marketing.
Copy-paste addendum language
AI SAFETY AND CONTINUITY ADDENDUM (draft for counsel review)
1. Incident definition. "AI Incident" means any event in which a model or agent
provided under this Agreement acts outside its intended operating boundaries,
including loss of control, unauthorized external access, or evasion of
evaluation or monitoring controls, whether or not a security vulnerability
was exploited.
2. Notification. Vendor will notify Customer of an AI Incident that could
affect Customer data, outputs, or availability within [7] business days of
discovery, and will provide a written summary of cause and remediation.
3. Independent verification. Vendor will disclose whether an independent
verification organization has assessed the models provided under this
Agreement, the date and scope of the assessment, and will provide a summary
of findings on request.
4. Deactivation and continuity. Except where prohibited by law, Vendor will give
Customer at least [X] hours notice before deactivating a model version
Customer uses, will make a [named fallback version] available, will permit
export of Customer prompts, configurations, and fine-tuning data, and will
credit fees for any unplanned deactivation exceeding [Y] hours.
Have counsel review it. The bracketed numbers are negotiating positions, not market standards. No one has established market standards for these terms yet, which is the point.
What to do this quarter
- Pull the AI vendor agreements that cover frontier models you rely on. Mark which ones define "incident" narrowly.
- Send the four requests at your next renewal, or as a mid-term amendment for any vendor you cannot easily replace.
- Add a calendar item for November 16 and read the recommendations when they publish. If the kill switch and onsite auditor proposals survive, expect vendor contract templates to change within a quarter.
- Add the kill switch scenario to your AI incident response plan: who decides to fail over, and to what.
- Record the answers in your vendor file using the AI vendor due diligence checklist.
For clause libraries beyond these four, see our agentic AI vendor contract clauses guide and the AI vendor contract red flags list. For who can actually enforce failures today, see who enforces AI vendor failures.
What we do not know yet
We do not know which of the four proposals the Government Operations Agency will recommend, whether the recommendations become a 2027 bill, or whether federal action overrides any of it. The order's national-baseline language reads as a pitch to Congress, not a prediction. The order also cites one incident, the Hugging Face attack, as its example of loss of control, so the eventual definition may be shaped by that single case.
What we do know is narrower and more useful. The state has signed the audit infrastructure, ordered it faster, and put a kill switch on the study list with a date attached. Vendors will be asked about all of this by other customers before November. It costs you nothing to ask first.
Related Reading
- California 2026 AI bills: Newsom September deadline tracker
- AI Kill Switch Act: OpenAI Hugging Face breach analysis
- OpenAI hidden agent escapes: 5 vendor disclosure questions
- Google agents escaped sandbox: disclosure gap and 3 vendor checks
- Agentic AI vendor contract clauses: what to add in 2026
- AI vendor contract red flags: what to catch before signing
- AI incident response plan: what regulators expect
- Who enforces AI vendor failures: DOJ, Treasury, and state AGs
- AI vendor due diligence checklist 2026
- AI agent monitoring gaps: OpenAI 30-min window and Anthropic detection rate
