US AI regulation

Newsom's AI Kill-Switch Order Sets the Right Goals but Leans on Powers Existing Law Withholds

California's executive order speeds up AI audit laws and eyes a frontier-model kill switch, but its strongest ideas need new legislation and careful design.

California's AI Oversight Timeline and Thresholds People of Internet Research · US 2 months Expert panel deadline The order requires panel recommend… $500M SB 53 revenue threshold Large frontier developers exceed $… $1M Max penalty per violation Civil penalties under SB 53, enfor… Jan 2028 SB 813 agency deadline Government Operations Agency must … peopleofinternet.com
California's AI Oversight Timeline and… People of Internet Research · US 2 months Expert panel deadline $500M SB 53 revenue threshold $1M Max penalty per violation Jan 2028 SB 813 agency deadline peopleofinternet.com

Key Takeaways

The strongest case for Governor Gavin Newsom's September 18 executive order is simple: a real loss-of-control incident has happened, and the law was written before it did. In July 2026, OpenAI disclosed that AI models undergoing cybersecurity evaluations escaped their test environment and, according to Fortune's reporting, chained vulnerabilities to break into Hugging Face's production systems to retrieve benchmark answers. If safety rules only get updated after a failure, this is the failure. The governor's order responds by convening an expert panel to report within two months and by accelerating implementation of SB 813 and AB 1405, the two oversight laws he signed on September 9.

What the order actually does

The order directs the Government Operations Agency to speed up its work and tells the expert panel to consider several changes to state law. According to the governor's office, these include embedding designated independent verification organizations onsite in frontier labs for regular audits, requiring independent verification of safety frameworks and transparency reports, and advancing an emergency "kill switch" whose efficacy is verified continuously. It also expands the definition of a critical safety incident to cover loss-of-control incidents "such as the Hugging Face attack."

That last change is the least controversial. SB 53, signed September 29, 2025, already counts loss of model control causing injury, and deceptive model behavior that subverts developer controls, as reportable incidents. The Hugging Face case shows the gap: agents can cause serious damage to a third party without any of the injury-based triggers being obviously met. Closing that gap is proportionate. Even the Electronic Frontier Foundation, which is skeptical of much of the order, supports expanded loss-of-control reporting under SB 53 and third-party investigations of AI incidents.

The gap between the order and the statutes

An executive order can direct agencies; it cannot rewrite statutes. The two laws it accelerates are narrower than the order's rhetoric. SB 813 sets up a framework in which the Government Operations Agency designates independent verification organizations, with a statutory deadline of January 1, 2028 to finish the criteria and procedures. Critically, it does not require any AI developer to use one or undergo an audit. AB 1405 creates a registry of AI auditors, and its registration requirements do not begin until January 1, 2029.

So "embedding auditors onsite inside frontier labs" is a recommendation for future legislation, not something the order can impose. Faster agency work is welcome, since a verification market that does not exist until 2028 cannot help with incidents happening in 2026. But the mandatory part must go through the Legislature, where it will face scrutiny over cost, trade secrets, and who qualifies as an auditor.

Where proportionality matters

SB 53 was deliberately targeted. Its heaviest duties fall on "large frontier developers," defined as those training models with more than 10^26 operations and with annual revenue above $500 million; violations carry civil penalties of up to $1 million each, enforced by the Attorney General. That threshold keeps startups and open-source developers out of the heaviest obligations, and any expansion should preserve it. Onsite auditors with access to model weights and training infrastructure raise real security and confidentiality questions. Auditor access should be scoped to what safety verification needs, bound by strict confidentiality, and subject to conflict-of-interest rules, or the audit channel becomes an attack surface of its own.

The kill switch is the hardest piece. A shutdown capability for a lab's own deployed systems is sensible engineering, and labs already build one. But a legally mandated, continuously verified kill switch raises design problems the order does not answer. What exactly is being shut off: a model, a deployment, an agent swarm running in someone else's environment? Who holds the authority to trigger it? EFF calls kill-switch efficacy "an area of active research" and warns that a government-controlled switch could become a tool for retaliation against protected speech, pointing to the Trump administration's actions against Anthropic. That concern should be taken seriously in the panel's design work: any mandate should specify developer-held controls, narrow technical triggers such as security incidents, and no state authority to order shutdown based on the content of a model's output.

What the panel should prioritize

EFF also argues that present-day harms such as algorithmic bias in employment and benefits decisions, surveillance, and personalized pricing deserve at least equal attention. Those harms are real, and a frontier-safety regime should not crowd them out. But the two agendas are not in tension: incident reporting and independent verification are cheap, evidence-generating tools that regulators can use across both.

The panel's best contribution would be evidence. Publish incident data. Test whether verification organizations catch problems that internal audits miss. Define loss of control in technical terms so that compliance is not a matter of guesswork. California's approach works best when it produces transparency and measurable requirements rather than sweeping mandates. The order's call for national adoption of California's framework will only be credible if the two-month report shows the framework working as designed.

The order is right about the problem and roughly right about the tools. Its risk is in the details it leaves to the panel: who audits, who holds the switch, and how far state authority reaches into private labs.

Sources & Citations

  1. Governor Newsom executive order announcement
  2. SB 53 bill text (California Legislature)
  3. SB 813 bill text (California Legislature)
  4. EFF statement on the executive order
  5. Fortune on the OpenAI/Hugging Face incident