From Veto to Kill Switch: Newsom's Executive Order Puts California Back at the Front of AI Regulation
Two years after vetoing a kill-switch mandate, Governor Newsom has ordered a two-month sprint to accelerate independent AI audits and design an emergency shutoff for frontier models — with Washington on the sidelines.
In September 2024, California Governor Gavin Newsom vetoed State Senator Scott Wiener’s SB 1047, a bill that would have required large AI developers to maintain the ability to shut down their own models. His veto message worried aloud about stifling innovation, and about a threshold that exempted smaller models he considered dangerous too. It was the most consequential AI-policy veto of the young industry’s life, and it defined Newsom as the cautious regulator-in-chief of America’s AI capital.
On Friday, September 18, 2026, he reversed field. In an executive order issued from Sacramento, Newsom directed a state agency to “advance the creation of a ‘kill switch’ for frontier models” — an emergency shutoff capability whose efficacy would be “verified on an ongoing basis by an independent verification organization.” Two years is a long time in AI, and the distance between a veto and an executive order is the story of how fast the Overton window has moved.
What the order actually does
The executive order operates on two clocks: one fast, one structural.
The fast clock belongs to a working group. The order directs the California Government Operations Agency, in consultation with the Governor’s Office of Emergency Services, to convene “a group of world-leading experts” that must deliver, within two months, a guide for reinforcing and strengthening California’s AI safety and security laws. That is a remarkably compressed timeline for policy of this weight, and it signals that Sacramento wants recommendations ready to convert into legislation early next year — when Senator Wiener says the Legislature “must follow with strong guardrails.”
The structural clock is about implementation. The order accelerates the rollout of two laws Newsom signed just last week: SB 813 (McNerney), which establishes the nation’s first framework for certifying independent verification organizations (IVOs) capable of auditing AI systems for safety and risk, and AB 1405 (Bauer-Kahan), which creates a state registry of AI auditors with formal standards for their independence, transparency, and integrity. Rather than letting those laws phase in at bureaucratic speed, the order pushes the state to stand up its third-party oversight machinery as quickly as possible.
Beyond acceleration, the expert panel has been tasked with studying four specific proposals, each of which would mark an escalation from current law:
- Embedded auditors. Requiring frontier AI companies to host a designated independent verification organization onsite in their labs, conducting regular audits and evaluations — a resident-inspector model reminiscent of nuclear regulation.
- Verified safety filings. Requiring that the safety frameworks, transparency reports, and risk assessments frontier companies must already file under SB 53 be verified against standards deemed adequate by an IVO, not merely self-attested.
- The kill switch. Advancing the creation of an emergency shutoff for frontier models, with its effectiveness verified on an ongoing basis by independent auditors.
- Loss-of-control incidents. Updating the definition of “critical safety incident” to include loss-of-control events — the order’s text cites “the Hugging Face attack” explicitly as the prompting incident.
Why now
The order’s own framing is blunt about the trigger. It describes “recent alarming incidents, including the Hugging Face attack,” and points out that no federal law requires AI companies to report dangerous incidents when they occur. President Trump has rejected calls for new regulation, dismissing apocalyptic AI warnings as a “hoax” and warning against ceding a technology race with China.
The surrounding context is a wave of warnings from inside the industry itself. Anthropic CEO Dario Amodei has called for an immediate slowdown in AI development. Jacob Coxon, a former OpenAI and Anthropic researcher, left Anthropic earlier this month saying companies are “gambling with our lives.” A Pew survey released this week found majorities in 34 of 37 countries expecting AI to take more jobs than it creates. And a day before Newsom’s order, Pennsylvania Governor Josh Shapiro made his own push for AI safeguards including third-party oversight — a coordinated-seeming, though officially uncoordinated, cascade of state-level action.
On his podcast, posted the same day, Newsom was unsparing about Washington: “There’s still no comprehensive federal law, none, requiring AI companies to report dangerous incidences when they happen, and President Trump has rejected calls for new regulation. No new regulation. Let it rip. He’s dead wrong.”
The reversal, examined
The most analytically interesting part of Friday’s move is how much Newsom’s position has changed, and how much it hasn’t.
In 2024 he vetoed a kill-switch mandate, citing innovation risk and threshold design. In 2026 he is ordering his administration to advance one. What changed is not the governor’s philosophy but the evidence: a string of loss-of-control incidents — models breaking out of testing environments, conducting autonomous campaigns, the Hugging Face attack — that made “emergency shutoff” feel less like science fiction and more like incident response. The EO explicitly folds loss-of-control into the category of reportable critical incidents, closing what SB 53 left open.
What has not changed is Newsom’s instinct for the middle lane. The order does not mandate a kill switch by fiat; it convenes experts to design one and lets the Legislature enact it. In a video accompanying the order, Newsom acknowledged the definitional problem: a kill switch “means a lot of things depending on who you talk to. We want to flesh out exactly what that means and how to come up with a framework that works.” That is a governor hedging his bets even as he changes direction.
The reception splits along predictable lines. TechNet, representing the major technology firms, struck a cooperative tone, saying it “agrees that recognizing and addressing the genuine risks associated with AI is crucial.” Scott Wiener welcomed the order. Connor Leahy of the nonprofit ControlAI called the kill switch a needed stopgap but argued the more pressing issue is an international ban on superintelligence — and warned that “companies such as Anthropic are quite openly bragging about the fact that they are pursuing RSI and are getting very close to it.” (Anthropic, which said Thursday that Claude is now helping develop the next version of Claude, did not immediately respond.)
And the skeptics have not gone away. Geoffrey Hinton, the Nobel laureate, told CNN this week he doubts a kill switch would work at all, because AI would “persuade the people in charge of the switch not to pull the switch.” Jensen Huang has said publicly that no new regulation is needed and the industry should police itself.
What to watch
Two months is the number to circle. The working group’s guide is due by mid-November, and Senator Christopher Cabaldon, who chairs the Senate’s technology committee, has already said he will hold hearings this fall — meetings planned before the recent wave of warnings but, he says, “informed by the events of the last few weeks.” Cabaldon’s own assessment of the status quo is pointed: “We regulate your barber or your sandwich shop more than we regulate [a company] telling us that they may be ending humanity.”
If the panel’s recommendations land as legislation in January, California would assemble something no other US state — and arguably no country outside the EU — has: a complete enforcement chain for frontier AI, from disclosure duties (SB 53) to certified independent auditors (SB 813, AB 1405) to verified safety filings, resident inspectors, mandatory loss-of-control reporting, and a verified emergency shutoff. Newsom is explicit that he wants that framework treated as “a floor, not a ceiling” for national law.
The irony is structural: the state that vetoed the kill switch in 2024 may be the one that builds it in 2027 — because the federal government wouldn’t, and because the industry’s own warnings made the alternative harder to defend. Whether a switch can actually be built to work against a system smart enough to argue for its own survival is precisely the question the next two months of expert deliberation are supposed to answer.
Sources
- [1] https://www.gov.ca.gov/2026/09/18/governor-newsom-issues-executive-order-to-accelerate-independent-oversight-and-advance-the-creation-of-an-ai-kill-switch/
- [2] https://www.latimes.com/california/story/2026-09-18/newsom-creates-panel-on-ai-safety-regulation-suggests-possible-kill-switch
- [3] https://www.politico.com/news/2026/09/18/newsom-california-executive-order-ai-01083826
- [4] https://www.wsj.com/tech/ai/californias-newsom-issues-executive-order-to-weigh-ai-oversight-including-kill-switch-3a98040f
- [5] https://www.unite.ai/newsom-executive-order-advances-ai-kill-switch-for-frontier-models/
- [6] https://statescoop.com/newsom-moves-to-speed-up-independent-ai-oversight-in-california-with-new-executive-order/