California on Sept. 18, 2026 took a formal step toward an AI “kill switch,” but the order does not create a working emergency shutoff. Governor Gavin Newsom’s executive order tells state agencies to speed up implementation of California’s new AI oversight laws and convene outside experts within two months to recommend stronger rules. In the state’s own description, those recommendations could include requiring frontier AI companies to build an emergency shutoff and to have its effectiveness verified by an independent verification organization.

That verification requirement is the story. California is not just asking whether frontier models should be stoppable; it is asking who can prove, continuously, that the stop works. The state already says it has a legal framework for independent verification organizations under SB 813 and a separate registry for AI auditors under AB 1405, both signed earlier this month. The new order tries to turn those oversight structures into something operational: a third party would not only review safety plans and risk assessments, but also assess whether a shutdown mechanism behaves as promised in a real deployment context.

CNBC reported the same order as part of Newsom’s broader effort to tighten AI guardrails after rising concern in Washington and the industry. Its account said the governor’s team wants experts to produce recommendations for stronger state law, including the possibility of independent third parties writing safety plans for frontier AI companies or requiring a kill switch for emergency shutdowns. That reporting matters because it confirms the executive order is a policy-opening move, not a completed technical standard.

What changed

The immediate change is procedural. California has moved from general AI safety legislation into a second layer of control: how to verify that a company can actually intervene when a model misbehaves. Newsom’s office said the order also asks experts to consider expanding the definition of a critical safety incident to include loss-of-control events, such as the Hugging Face attack cited in the state’s announcement. That signals the state is trying to bring fast-moving, high-consequence failures into the reporting regime, not just classic data breaches or compliance violations.

For frontier-model developers, that is a meaningful shift in burden. A future rule built on this order would likely force companies to show more than internal documentation. They may need to show that an emergency stop can be tested, audited and independently judged against a standard that regulators accept. For verification firms and AI auditors, the opportunity is also different: the work moves from paper compliance to live assessment of the systems and controls around model operation. For enterprises buying AI services, the practical implication is that a vendor’s safety claims may eventually need outside validation, not just a policy statement.

How it works, and why that is hard

California’s logic is straightforward: if a frontier model can create serious harm, a deployer should have a way to interrupt it. The hard part is turning that idea into an auditable requirement. The order does not define what counts as an adequate kill switch, how fast it must work, whether it needs to cut off model weights, API access or downstream integrations, or how a verifier would test it without creating new security risks. Those are not details at the margin; they are the core technical questions.

That is why the proposed role for an independent verification organization matters. The state is effectively trying to separate the model from the safety claim: the company builds and operates the system, while an outside body judges whether the emergency control is sufficiently real. If California succeeds, it could produce a compliance model that is more like an operational safety certification than a disclosure regime. If it fails, the kill-switch idea may remain rhetorically powerful but technically vague.

Who should care

Frontier AI labs have the most direct exposure, because they would be the ones building and documenting the stop mechanism. Regulators and policymakers will care because California is trying to make oversight legible in a domain where the state says federal action is absent. AI auditors, safety researchers and infrastructure teams should care because the order is an early sign that verification may become a distinct market function rather than an internal review step. And buyers of AI systems should care because a future procurement or vendor-review process could ask not only whether a model is powerful, but whether its failure modes are independently checkable.

The limitation is equally important: nothing in the order proves that a kill switch can be made reliable across all frontier systems, or that an independent verifier can test it meaningfully without seeing the full deployment stack. California has launched a rulemaking direction, not a solved engineering standard. The next substantive question is whether the expert group can translate “emergency shutoff” into measurable criteria instead of a symbolic requirement.

Watch the experts’ two-month recommendations for measurable verification standards; that is the clearest signal of whether California is turning an AI kill switch from a slogan into an auditable requirement.