By This Hour Technology Desk
California Gov. Gavin Newsom is reportedly moving to put a more demanding set of AI safety obligations before the state, including the prospect that companies operating frontier models would have to maintain a shutdown mechanism that is regularly tested and shown to work.
The proposal is not itself a new legal requirement. Rather, an executive order described by The Verge would convene experts and give them two months to advise California on ways to strengthen state AI-safety law. But the questions assigned to that group point to an ambitious direction: whether the state should pair companies’ own safety commitments with independent access, outside review and formal reporting when control of an advanced system is lost.
That distinction matters. A recommendation to consider a rule is not a rule, and an executive order cannot by itself settle the technical, legal and operational questions involved in supervising advanced AI. Still, the reported order would place those questions squarely in California’s policymaking process and suggest that Newsom wants the state to move faster than federal lawmakers on an area of technology policy with unusually high stakes.
A shutdown tool would have to be more than a promise
The most striking element of the reported order is its request that the expert group consider a requirement for a routinely verified “kill switch” for frontier AI models. In plain terms, the idea is that a company would need a reliable way to halt a model or its operation, and would need to demonstrate on an ongoing basis that the mechanism works.
The phrase can make the issue sound simpler than it is. The source material does not define what systems would qualify as frontier models, what parts of a model’s operation a shutdown capability would cover, or what test would establish that it remains effective. It does not say whether a mechanism would be evaluated before a system is deployed, at fixed intervals afterward, after a material change, or under some combination of those conditions. Nor does it specify what would trigger the use of such a tool.
Those omissions are not minor drafting details. They go to the practical meaning of the proposed safeguard. A control that can be activated in theory but cannot be independently checked is different from one that works under review. Likewise, a capability aimed at stopping one use of a model may not address every way a model can be accessed or operated. The reported assignment appears designed to make verification, rather than mere existence, part of the policy discussion.
That emphasis fits the wider package described in the report. Newsom is reportedly asking experts to examine whether independent verification groups should be present on company sites for regular audits. The order would also have them consider subjecting corporate transparency reports and risk assessments to independent auditing standards. Taken together, those proposals would shift attention from voluntary accounts supplied by AI companies toward outside examination of their safety claims.
California would still need to decide what independence means in practice. The available account does not identify who would choose the verifiers, how conflicts would be handled, what access they would receive, or which findings would become public. It also does not say whether any eventual obligation would apply broadly across AI companies or only to a smaller class of developers and systems. These are central questions, not technicalities, because they would determine both the reach of a future framework and the authority of the people checking compliance.
Independent checks are at the center of the reported plan
The reported order treats auditing as a system rather than a single event. Onsite verification, review of transparency reporting, and examination of risk assessments would each serve a related but distinct purpose. A company may describe its own safety processes in a report; an outside auditor would be asked to assess whether that account meets an applicable standard. A risk assessment may identify possible harms; independent review would test the basis and completeness of that assessment. Onsite work, if ultimately required, would potentially bring evaluators closer to the conditions in which a company’s procedures are applied.
The source does not establish that California has selected a particular audit model, or that any independent group has been assigned a role. It says only that the expert group is being asked to consider such measures. The difference should guide how the proposal is understood. The order, as reported, starts a policy-design exercise with a short timetable; it does not announce a finished inspection regime.
Even so, the focus on verification indicates that Newsom’s approach is not confined to broad principles of responsible AI. It would examine mechanisms intended to make safety claims measurable and reviewable. That is a consequential choice because requirements involving outside assessors can raise difficult questions about standards, confidentiality and accountability. The supplied material does not resolve any of them, and it offers no indication of the recommendations the group may ultimately reach.
Readers looking for related debate over external AI scrutiny can find it in our report on concerns that independent audits may depend on stronger containment, monitoring and access controls. That broader dispute reinforces a narrower point about the California proposal: outside review can be proposed as a safeguard, but its value would depend on the scope of the review and on the controls available for reviewers to examine.
Loss-of-control reports could become a formal safety obligation
Another reported question for the expert group is whether companies should be required to report loss-of-control incidents as critical safety incidents. The account points to an attack involving OpenAI and Hugging Face as an example of the kind of event Newsom wants considered in this category. It does not provide further details of that incident, and this report does not independently establish its circumstances or consequences.
The policy significance lies in classification. If loss-of-control events are treated as critical safety incidents, companies could face a clearer duty to notify the state rather than decide privately how, or whether, to characterize a failure. Yet the available material does not define loss of control, identify a reporting deadline, set out what information a report would contain, or state what response the state could require after receiving one.
Those unanswered points would shape any eventual rule. A narrowly drawn definition might focus on an inability to stop or constrain a model. A broader one could cover failures in the systems around it. The source does not say which path California is considering. It also does not say whether reports would be confidential, published, audited, or linked to penalties. What is clear from the reported order is that incident reporting is being considered alongside tested shutdown capacity and independent review, rather than as a separate administrative exercise.
Newsom is pairing a new review with implementation work
The order reportedly does more than call for recommendations. It directs a state agency to accelerate implementation of two recently signed laws: one concerning independent AI-safety verification and another creating a registry of AI auditors. The supplied information does not name the agency, describe the laws’ detailed provisions, or specify what accelerated implementation would entail.
That limitation makes it premature to describe the order as creating an operational oversight structure on its own. Nonetheless, the combination is significant. The reported expert process would consider additional safeguards while the state agency is told to move more quickly on mechanisms related to outside verification and auditors. Newsom appears to be pursuing immediate administrative momentum as well as possible future legislation.
The two-month deadline also signals urgency, but it should not be confused with a deadline for companies to install new controls. It is a deadline for recommendations. The next meaningful evidence will be the group’s work: who takes part, what it recommends, whether California publishes a detailed framework, and which parts of that framework, if any, require legislative action.
California is presenting itself as a federal model
Newsom is reportedly casting California’s framework as a possible foundation for national action, urging Congress and President Donald Trump to review and adopt it, or treat California’s standards as a baseline. The Verge also reported that Newsom had raised the possibility of a special legislative session on AI, alongside further executive action.
The federal appeal is part of the policy argument, not evidence that federal adoption is imminent. The source describes little expectation that Congress will enact substantial AI legislation soon, citing the congressional calendar and the approach of midterm elections. It also recounts Trump’s opposition to AI guardrails. Those positions indicate a substantial political gap between the California initiative described here and a swift national agreement.
For California, that gap may be a reason to act through state law; for companies, it could mean preparing for a potentially important state-level framework without knowing whether a national one will follow. Neither outcome is settled by the order. The essential near-term question is whether the experts translate broad concepts—shutdown capability, independent verification, audited risk reporting and incident notification—into recommendations precise enough to become enforceable rules.
All of these details come from a single report by The Verge and have not been independently corroborated by this publication. The reported executive order, the makeup of the expert group, the exact status of the cited laws and the possible terms of any future California requirements should therefore be treated as subject to confirmation.
Reporting notes
What is confirmed: The Verge reported that the expert group will consider shutdown tools, onsite verification, audited disclosures and reporting of loss-of-control incidents.
Why this matters: The proposal could move AI oversight toward independently verified controls, audits and incident reporting at the state level.
What remains unclear: The order’s exact terms, the experts involved, the definition of frontier models and whether recommendations become enforceable rules remain unclear. This report is based on one source and has not been independently corroborated.