On 18 September 2026, Governor Gavin Newsom signed an executive order directing California state agencies to develop and test AI kill switch frameworks — administrative shutdown and control mechanisms for AI systems used in state government operations. The order follows his September 2024 veto of SB 1047 (the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act), which would have imposed comparable requirements on private frontier AI developers. On 9 September 2026, Newsom had signed SB 813 and AB 1405, establishing California’s first external AI auditing architecture. Simultaneously, the EU AI Act’s first scheduled wave of compliance inspections is underway in September 2026 across France, Germany, and Spain, covering automated hiring, credit assessment, and medical triage AI systems. The US Congress has not passed a federal AI framework. The Navigator reads the three-stage California architecture — veto, auditing statute, executive order — and what it cannot do that a federal floor would.
1. The 2024 Veto and Its Reasoning
SB 1047 passed both chambers of the California legislature in August 2024. It would have required developers of AI models trained on more than a specified compute threshold to implement tested shutdown mechanisms, conduct pre-deployment safety evaluations, and submit to an independent Board of Frontier Models. Governor Newsom vetoed it on 29 September 2024. [Established — Gibson Dunn, “Regulating the Future: Eight Key Takeaways from California’s SB 1047, Vetoed by Governor Newsom,” October 2024; CSET Georgetown, “Governor Newsom Vetoes Sweeping AI Regulation, SB 1047,” October 2024.]
Newsom’s veto message was substantive. He argued that SB 1047 focused exclusively on the largest models while ignoring the risks posed by smaller models deployed in high-risk environments. A bill that drew its safety obligations at compute thresholds, he argued, was a bill that addressed the most visible risk vector while leaving the most likely actual harm path — narrow, purpose-built systems deployed in healthcare, criminal justice, or employment decisions — entirely unaddressed. [Established — Governor Newsom’s veto message, September 2024, as reported by Davis Wright Tremaine and CSET.]
This reasoning was not wrong. The critique that frontier model regulation ignores deployment-context risk is substantively correct, and it was shared by a number of AI safety researchers who supported the bill’s goals while questioning its mechanism. The case for the veto was real. The case against it was also real: a governor who accepts the argument that an imperfect bill is better than no bill has a different kind of case to make. Newsom chose the veto. The question is what the choice produced.
2. What the Intervening Two Years Built
The period between the September 2024 veto and the September 2026 executive order was not empty. California’s AI legislative calendar continued. On 9 September 2026, Governor Newsom signed SB 813 and AB 1405, establishing independent verification organisations with statutory authority to assess AI systems deployed in California for compliance with state law. [Established — The Leadsman, The Auditors: California’s SB 813 and AB 1405 Create the First External Verification Architecture for AI Systems in the United States, Sounding No. 38, 10 September 2026.] This was the Sarbanes-Oxley moment: the first mandate for external AI auditing rather than self-certification or regulatory disclosure.
The architecture built between 2024 and 2026 is a sequence: first, reject the blunt instrument (SB 1047); then, establish external verification of deployed systems (SB 813/AB 1405); then, extend internal-compliance mechanisms to state operations via executive order. Read as a deliberate programme rather than a series of reactive decisions, it describes a governor attempting to build AI governance from the ground up, starting with auditing architecture and state operational compliance, before confronting the harder question of private developer obligations.
The problem with this reading is that the harder question is where most of the risk lives. California state agencies use AI, but Anthropic, OpenAI, and Google develop it. SB 813 audits deployment; the September 18 EO addresses state government shutdown protocols. Neither reaches the training runs or the pre-deployment safety evaluations that SB 1047 would have covered. The architecture is real. Its coverage is partial.
3. What an Executive Order Can and Cannot Do
An executive order signed by a state governor has a specific and limited scope. It binds executive branch agencies of the state of California. It does not bind private companies. It does not create enforceable obligations on AI developers who are not contractors or vendors to the state. It survives only as long as its author or a sympathetic successor occupies the office. [Assessed with high confidence — basic constitutional and administrative law; California Constitution, Article V; scope limitations of gubernatorial executive authority.]
The September 18 EO is meaningful within those constraints. California state agencies collectively manage enormous public datasets, operate critical infrastructure systems, and use AI in high-stakes decisions affecting millions of residents. An EO that requires those agencies to test and implement shutdown mechanisms for their AI deployments produces real accountability at significant scale. The Navigator does not minimise this.
What it does not produce is a constraint on the private developers who build the models those agencies deploy. When California’s Department of Motor Vehicles or Department of Health Care Services procures an AI system from a frontier model provider, the EO governs how the agency configures and manages that system’s shutdown protocol. It does not govern how the underlying model was trained, what safety evaluations were conducted before it was released, or whether the developer has its own tested shutdown mechanism for the model itself. The distinction matters. The accountability gap between the deployer and the developer is precisely where SB 1047 had aimed and where the current California architecture leaves the field open.
4. The EU Contrast and the Federal Floor Problem
Simultaneously with California’s EO, the European Union AI Act’s compliance inspection cycle is underway. The EU AI Office, working with 24 national market surveillance authorities, began its first scheduled wave of inspections in September 2026. France’s CNIL, Germany’s BfDI, and Spain’s AESIA are focusing initial requests on automated resume screening, algorithmic credit assessment, and AI medical triage systems. [Established — European Commission, “Safer and more transparent AI,” 2 August 2026; Vorplabs, “September 2026 AI Regulatory Update: United States,” September 2026.]
The EU compliance architecture has enforcement teeth that the California executive order does not. EU market surveillance authorities can impose fines of up to 3% of annual global turnover for high-risk AI system violations and up to 6% for prohibited AI system violations. These fines apply to private companies, not just to government agencies using AI. The EU AI Act is a statute, not an executive order. It survives changes of government. It creates obligations that must be met before systems are deployed in EU markets.
The contrast is not an argument that the EU has solved AI governance — the Act has critics who argue its risk categorisation is too rigid and its enforcement resources too thin. It is an argument that statutory frameworks binding private developers are structurally different from executive orders binding state agencies. California, for all the seriousness of its legislative effort, is producing the second kind of regulation in an environment where the first kind is absent.
The federal floor problem is the persistent gap. Without a US federal AI statute, state governments enforce localised compliance standards that require multi-state compliance tracking but impose no uniform obligation on AI developers as a class. [Established — Center for Democracy and Technology, “2026 State and Federal AI Legislation Updates,” September 2026.] California’s population and economic weight give it outsized influence — the “California effect” by which California standards effectively become national standards for companies that cannot afford to maintain bifurcated product architectures. But this effect is weakened when the state’s own regulatory mechanism is an executive order rather than a statute, because executive orders do not create the kind of durable, enforceable obligation that forces product architecture decisions.
Bottom line: Newsom’s September 18 executive order is real governance. It is not nothing. It is also not what SB 1047 would have been. The three-year arc from the 2024 veto through the 2026 auditing statutes to the 2026 EO describes a governor who was right that SB 1047 was imperfect, and who has spent two years building pieces of what he vetoed without assembling the part that would have mattered most: a statutory obligation on private frontier AI developers to test and demonstrate shutdown mechanisms before deployment. The governance gap is not closed by this reversal. It is illuminated by it. What remains is the question the governor has not yet answered: whether the piece he vetoed in 2024 has become necessary by 2026.