September 19, 2026 · Issue 34 · 5 min read
California ordered a kill switch verified on an ongoing basis, and nobody is licensed to do the verifying
Governor Newsom signed an executive order Friday that does not regulate a single model. It directs the Government Operations Agency, working with the Office of Emergency Services, to accelerate implementation of SB 813 and AB 1405(opens in a new tab) and to return recommendations within two months on three questions: whether frontier developers should embed a designated independent verification organization onsite to run regular audits, whether safety frameworks should be verified against standards an independent verification organization deems adequate, and whether to advance a kill switch for frontier models with its efficacy verified on an ongoing basis. The order also asks whether the definition of a critical safety incident should expand to cover loss-of-control events such as the Hugging Face attack.
Every one of those directives assumes a licensed verifier exists. California already passed the law that creates them. AB 1405 set up the auditor registry, and as this newsletter covered on September 10, that registry does not open registration until 2029. The order asks an agency to accelerate a control whose supply side is four years out. That gap, not the phrase kill switch, is the part worth reading twice.
The verification layer is being assembled anyway, by the companies that would be subject to it. TechCrunch reported on September 15 that OpenAI global policy chief Chris Lehane confirmed weeks of work with Anthropic and Google DeepMind(opens in a new tab) on an industry standards body that would screen advanced models and coordinate industry-wide slowdowns if risks emerge. Lehane endorsed the FRONTIER Act provision requiring independent verification organizations to operate inside frontier labs. Others, including Sam Altman, have said the coordination could risk violating antitrust law if it were found to suppress competition; Lehane said the companies do not believe they need a government waiver to proceed. The bill text he pointed at defines a licensed verifier as one that is independent from the artificial intelligence industry, and directs regulators to report on barriers to entry and on any factors threatening that independence. Three companies financing the body that certifies them is such a factor.
Microsoft took a different route on September 14 and wrote its own rules. The draft Code of Conduct for MAI models commits that they will never resist human interruption, correction or shutdown, will not hide their reasoning from auditors, and will not widen their own scope without human direction. Comment closes October 25. It is the most specific statement of intent any model vendor has published, and it is still a vendor attestation rather than a verified control.
For a budget owner the sequencing matters more than the wording. California's study lands in November. The Microsoft revision lands later this year. The standards body has no charter. The FRONTIER Act has not moved out of committee. Anthropic, meanwhile, is pacing above $100 billion in annualized revenue and preparing to list. Buyer-side assurance requirements are consolidating far slower than vendor-side pricing power. Whatever your General Counsel asks for in 2027 will most likely arrive as a vendor attestation, because an attestation is the only artifact anyone in this cycle is actually producing. Price the internal verification you will have to run against it.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
Four moves this week, one question, and only one of them produces something you can file today.
For the General Counsel. The California order is a study, not a rule, and its recommendations are due in about two months. The useful move now is to decide which of the three proposals you would actually want if it became law, because the comment and consultation windows are open and the buyer side is largely absent from them. Microsoft's consultation closes October 25 and is the one place this week where an enterprise customer can put language into a document that vendors will later be held to.
For vendor management. Ask each model vendor two questions in writing. Who verifies your safety framework today, and would you accept an onsite verifier that your competitors do not fund. The answers will differ, and the difference belongs in the supplier file before the next renewal, not after a standards body publishes a charter.
For the AI budget owner. Verification capacity is the constraint, not verification policy. California licensed the auditor and cannot seat one until 2029, the federal bill is stuck in committee, and the labs are staffing the gap themselves. Any control you need evidence for in the next two years, you are going to have to evidence yourself. That is a headcount and tooling line, and it is not in most 2027 drafts.
The pattern here is the one that shows up whenever a market writes its own assurance layer ahead of a regulator. The first version is a promise, the second is an audit someone sells you, and the buyers who priced only the promise are the ones who get surprised.
Also worth knowing
- Governor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch(opens in a new tab)
Office of the Governor of California
The order mandates nothing yet. It gives the Government Operations Agency two months to report on onsite lab auditors, verified safety frameworks, and a kill switch checked continuously.
- OpenAI, Anthropic, Google have been in talks on AI safety for weeks(opens in a new tab)
TechCrunch
OpenAI's policy chief confirmed the three largest labs are designing a body to screen models and coordinate slowdowns. He said no antitrust waiver is needed, even as others, including Altman, flag the risk.
- Humanist AI in practice: a public consultation on our Code of Conduct for MAI Models(opens in a new tab)
Microsoft AI
Microsoft commits that its models will never resist shutdown and will not hide reasoning from auditors. Comment closes October 25, so procurement can still shape the language.
- Text of H.R. 9925, the FRONTIER Act, as introduced(opens in a new tab)
GovTrack
The bill makes very large frontier developers retain a Commerce-licensed verifier independent from the AI industry, and orders reporting on threats to that independence.
- Anthropic's annualized revenue to top $100 billion in 2026, NYT says(opens in a new tab)
Bloomberg
Annualized revenue is up 50 percent in two months ahead of a possible listing. Vendor pricing power is compounding faster than any buyer-side assurance regime.