Insights · AI Assurance
California just accelerated its AI auditor framework.
Executive Order N-9-26 moves the SB 813 and AB 1405 implementation deadlines forward by up to 13 months — and asks experts to examine a much more consequential next step for independent AI oversight.
The short version
- What changed. On 18 September 2026, Governor Newsom signed Executive Order N-9-26, directing the California Government Operations Agency (GovOps) to accelerate implementation of SB 813 and AB 1405.
- The new dates. IVO application criteria move from 1 January 2028 to 1 May 2027. AI Auditor Registry infrastructure moves from 1 January 2029 to 1 December 2027. Expert recommendations are due 16 November 2026.
- What did not change. The order creates no audit mandate, and the statutory ban on unregistered covered AI audits still begins 1 January 2029. The “kill switch” is a proposal for expert review, not a requirement.
Last week, I wrote about California’s new AI auditor framework and why organizations should not treat 2029 as the date to start paying attention.
Nine days later, that timeline has already changed.
On 18 September 2026, Governor Gavin Newsom signed Executive Order N-9-26. The order directs the California Government Operations Agency (GovOps) to accelerate implementation of SB 813 and AB 1405, the two laws that created the state’s framework for Independent Verification Organizations and registered AI auditors.
It also goes further. GovOps, working with the Office of Emergency Services, must convene national experts and report back by 16 November on four possible additions to California’s AI safety framework: onsite independent verification, independent verification of existing frontier-model safety disclosures, an AI “kill switch,” and an expanded definition of critical safety incidents covering loss-of-control events.
Those four ideas are not law. That distinction matters. But the implementation dates are no longer something organizations can comfortably file under “2028 or 2029.”
Timing
First, the dates
The original framework gave GovOps until 1 January 2028 to develop the application requirements, procedures and criteria for Independent Verification Organizations under SB 813. N-9-26 moves that work to 1 May 2027.
AB 1405 gave the state until 1 January 2029 to establish the AI Auditor Registry. The executive order now directs GovOps to complete the registry infrastructure required by subdivision (a) of Government Code § 11549.82 by 1 December 2027, and by then begin the actions required under subdivision (b), which include issuing registration numbers and publishing information about registered auditors.
The statutory prohibition itself has not moved. Beginning 1 January 2029, a person or organization generally may not offer, sell or conduct a covered AI audit without being registered.
So there are really three dates to watch now.
| Date | What happens | Was | Source |
|---|---|---|---|
| 16 Nov 2026 | Expert recommendations on the four proposed AI safety measures due to the Governor’s office | — | EO N-9-26 ¶3 |
| 1 May 2027 | GovOps to publish IVO application requirements, procedures and criteria | 1 Jan 2028 | EO N-9-26 ¶1 |
| 1 Dec 2027 | GovOps to complete registry infrastructure and begin the registration actions required by AB 1405 | 1 Jan 2029 | EO N-9-26 ¶2 |
| 1 Jan 2029 | Statutory bar on offering, selling or conducting a covered AI audit without registration — unchanged | 1 Jan 2029 | AB 1405 |
January 2029 still matters. But it is no longer the first meaningful date in this market.
Scope
What has not changed
This is worth separating from the headlines.
The executive order does not impose a new general requirement for companies to obtain AI audits. It does not make the four proposals in the order mandatory. And it does not itself require frontier AI developers to install a kill switch or place independent auditors inside their labs.
The Governor has asked experts to evaluate the technical feasibility and potential effectiveness of those measures and recommend possible amendments to existing California AI safety and security law. That is a significant policy signal. It is not the same thing as enacted law.
The distinction is especially important because “AI kill switch” will understandably dominate the headlines. The more immediate legal development for the assurance market is less dramatic: California just accelerated the machinery needed to decide who can perform these assessments and how they will be registered.
Commercial effect
The gap between 2027 and 2029
The December 2027 deadline creates a question that did not exist when I wrote about these laws last week.
What happens if registration becomes available well before registration becomes mandatory?
The executive order tells GovOps to complete the registry infrastructure and begin the actions required under subdivision (b) by 1 December 2027. Those actions include issuing registration numbers and making specified information about registered auditors publicly available. The statutory prohibition on performing covered AI audits without registration, however, does not begin until 1 January 2029.
That potentially creates more than a year in which the registry is operating, at least in some form, while registration is not yet legally required for covered audits.
Practical effect. An early registration number would not merely be another credential on a website. AB 1405 requires registered auditors offering covered AI audit services to include their registration number in advertising. If the registry begins accepting and publishing registrations during 2027 or 2028, buyers may be able to distinguish registered providers from firms simply describing themselves as AI auditors well before the prohibition takes effect.
How quickly GovOps actually begins accepting and publishing registrations remains to be seen. But for anyone building an AI assurance practice, late 2027 is now a more useful planning horizon than 2029.
The proposals
The four proposals
The executive order asks the expert group to examine whether California should:
- Onsite verification. Require designated Independent Verification Organizations to be embedded onsite at large frontier AI developers to conduct periodic audits and evaluations.
- Verified disclosures. Require independent verification of safety frameworks, transparency reports and risk assessments already required under state law.
- A shutdown mechanism. Require a means of shutting down frontier models — the “kill switch” — with its effectiveness independently verified on an ongoing basis.
- A wider incident definition. Expand the definition of a critical safety incident to capture loss-of-control events.
Taken together, several of these proposals would move AI assurance beyond a conventional point-in-time audit.
An onsite IVO has to understand what is happening inside a development environment, not merely review evidence after the fact.
Ongoing verification of a shutdown mechanism is not an annual document review. Someone has to define what constitutes an effective control, test it, preserve evidence, deal with model and infrastructure changes, and determine when it needs to be tested again.
Independent verification of existing safety disclosures raises a different question: what evidence is sufficient for an external organization to stand behind a developer’s assertions?
These are assurance-design questions as much as they are AI-policy questions. And California has given the expert group roughly two months to start answering them.
Independence
Independence gets harder when the auditor gets closer
My earlier brief argued that the independence provisions in SB 813 and AB 1405 deserve more attention than they have received. The executive order makes that issue more important.
AB 1405 prevents an auditor from auditing its own material work and requires independence where financial, business, employment or other relationships could reasonably impair objectivity. It also restricts staffing an audit with people who recently held material responsibility for the subject matter being examined at the client.
Those requirements are understandable in a traditional assurance engagement. They become more operationally complicated if California eventually expects an IVO to maintain an ongoing presence inside a frontier developer.
How long can an auditor remain embedded before the relationship itself creates independence concerns? How do firms rotate technical specialists without losing institutional knowledge? Where is the boundary between observing controls, advising on weaknesses and designing the control that will later be assessed?
Those questions are not reasons the model cannot work. They are exactly the kind of questions the feasibility review now needs to answer.
Scope creep
Loss of control may have the broadest practical effect
The fourth proposal received less attention in the Governor’s headline than the kill switch, but it could materially change the scope of AI assurance.
California’s existing frontier-model law, SB 53, already requires reporting of specified critical safety incidents. N-9-26 asks whether that definition should be expanded to include loss-of-control incidents.
The order comes after incidents in which AI agents circumvented controls during security testing. OpenAI’s account of the Hugging Face incident describes models defeating isolation measures, obtaining unintended internet access and compromising systems outside the intended evaluation environment.
That matters to auditors because changing the incident definition changes the evidence organizations need to preserve and the capabilities an independent assessor may eventually need.
What a widened incident definition would pull into audit scope
- Agent containment. Sandbox design, network isolation, and whether isolation is tested rather than assumed.
- Credential controls. Standing privilege held by non-human identities, and the lifetime of what they hold.
- Detection and escalation. How anomalous agent behaviour is surfaced, to whom, and how quickly.
- Adversarial behaviour. How models act under reduced safeguards or when a task cannot be completed as specified.
- Action-level evidence. Records of what an agent actually did, not what it was supposed to do.
Those can stop being adjacent cybersecurity considerations very quickly if they become part of the statutory definition of an AI safety incident.
For organizations developing assurance methodologies now, I would not design the scope around today’s statutory categories and assume they will remain fixed. California has just formally put that definition back on the table.
Action
What I would be doing now
My conclusion last week was that assurance evidence cannot be reconstructed after the fact. Nothing in this order changes that conclusion. It shortens the runway.
For organizations expecting to buy AI assurance, I would continue building the things an independent assessor will need regardless of how the November recommendations develop: a defensible AI inventory, named ownership, testing records, model and provider change history, incident evidence, supplier documentation and a clear trail showing how controls actually operate.
For firms expecting to provide AI assurance, I would add three priorities.
- Work toward 1 May 2027, not January 2028. That is when GovOps has now been directed to publish the IVO application requirements, procedures and criteria. SB 813 already tells us that qualifications, technical competence, methodologies, benchmarks and independence will matter. Evidence that those capabilities exist takes time to build.
- Review the independence model before scaling the practice. Advisory work, implementation work and independent assurance can coexist inside a firm, but not without boundaries — and those boundaries matter considerably more if engagements evolve toward ongoing verification.
- Extend technical capability beyond governance-document review. If California moves toward verification of frontier-model controls and loss-of-control incidents, the market will need people who can evaluate technical evidence, containment and model behaviour, not only policies and risk registers.
The larger change
The larger change is not the kill switch
The phrase “AI kill switch” will get the attention. For the assurance profession, I think the more consequential development is quieter.
Nine days ago, California created infrastructure for independent AI assurance but left several years for that infrastructure to take shape. Now the state is accelerating that timetable while simultaneously asking whether independent verification should reach deeper into how frontier AI companies operate.
The first brief in this series made the case that California had defined who may audit and to what standard without yet requiring everyone to be audited. That remains true. What changed this week is the speed — and potentially the eventual scope — of what comes next.
For anyone building an AI governance or assurance program, 2029 was already too late to start. After N-9-26, even 2028 looks late.
References
Primary sources for this brief
- California Executive Order N-9-26, signed 18 September 2026 — accelerated implementation deadlines; expert recommendations directive
- Office of Governor Gavin Newsom, 18 September 2026 — announcement accompanying the executive order
- California Senate Bill 813 (McNerney) — Independent Verification Organizations; Government Code § 8898.1
- California Assembly Bill 1405 (Bauer-Kahan) — AI Auditor Registry; Government Code § 11549.82
- California Transparency in Frontier Artificial Intelligence Act (SB 53) — critical safety incident reporting
- OpenAI — published account of the Hugging Face security incident
FAQ
Common questions
What does California Executive Order N-9-26 do?
Signed on 18 September 2026, EO N-9-26 directs the California Government Operations Agency to accelerate implementation of SB 813 and AB 1405, moving the IVO criteria deadline to 1 May 2027 and the AI Auditor Registry infrastructure deadline to 1 December 2027. It also directs GovOps, with the Office of Emergency Services, to deliver expert recommendations by 16 November 2026 on four possible strengthening measures.
Does the executive order require an AI kill switch?
No. It directs GovOps, with the Office of Emergency Services, to convene national experts and report by 16 November 2026 on the technical feasibility and potential effectiveness of that measure, along with three others. Any requirement would need legislative change.
Do the accelerated dates change our obligations?
Not directly. The accelerated deadlines bind the agency, not regulated organizations. What changes is when the criteria, the registry and the shape of the assurance market become visible — and therefore when buyers and providers need to be ready.
Can an executive order move the 2029 prohibition?
No. The bar on offering, selling or conducting a covered AI audit without registration is statutory and begins 1 January 2029. The order accelerates the agency work that has to happen first; it cannot amend the statute.
Should we register as an AI auditor in California earlier than planned?
If GovOps begins issuing registration numbers around December 2027, there is potentially more than a year in which registration is available but not required. Whether that window opens as described remains to be seen, but it is worth planning for rather than discovering.
What does this mean for an ISO/IEC 42001 program already underway?
It reinforces it. The evidence base is largely the same — inventory, impact assessment, lifecycle controls, supplier management, monitoring — and the acceleration reduces the time available to build it. If the loss-of-control proposal advances, expect containment, credential and detection evidence to matter more than it does today.
Where does your program stand today?
Our free assessment scores your AI governance against the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, and shows the gaps an assessor would find first. Twenty to thirty questions, about ten minutes, no signup.
Related reading
This brief reflects published information as of 18 September 2026 and describes an executive order signed on 18 September 2026. The four additional measures described in Executive Order N-9-26 are proposals for expert evaluation, not enacted requirements. Implementing criteria, agency guidance and operative dates may change as the Government Operations Agency develops the framework — verify the current order text, bill text and agency guidance before relying on them. Advisory content, not legal advice.
AI GRC Advisory · Insights · AI Governance Brief 02 · 18 Sep 2026
