Cognitive Logic · International Watch · AI Governance
Italiano · English
An AI kill switch is not a switch: it is a decision that must remain verifiable
California is accelerating the construction of an independent AI verification system and has formally opened the path toward a continuously verified emergency shutdown capability for frontier models. The governance problem, however, begins before the switch is activated and continues after the model has stopped.
Executive summary
On 18 September 2026, California Governor Gavin Newsom issued Executive Order N-9-26, directing state agencies to accelerate implementation of California's new independent AI oversight framework.
The distinction between measures already in force and measures still under consideration is essential.
The accelerated implementation of independent verification organizations and the state AI auditor framework is an executive direction to the administration. Onsite independent verifiers, continuously verified shutdown capabilities and an expanded definition of critical safety incidents are proposals for potential further changes to state law.
1. What changes now
California is accelerating implementation of Senate Bill 813 and Assembly Bill 1405.
SB 813 establishes a framework for independent verification organizations capable of assessing AI systems and models. AB 1405 establishes a state registry for AI auditors and standards concerning their independence, transparency and integrity.
These measures establish an institutional layer between AI developers' own safety claims and independent assessment.
2. What is not yet a direct obligation on frontier AI labs
Executive Order N-9-26 does not itself impose a mandatory kill switch on frontier AI developers.
Instead, it directs the development of recommendations concerning potential changes to state law that could:
- require designated independent verification organizations onsite in frontier AI laboratories;
- subject safety frameworks, transparency reports and risk assessments to independent verification;
- advance an emergency shutdown capability for frontier models whose effectiveness is verified on an ongoing basis;
- expand critical safety incident definitions to include loss-of-control incidents.
Until additional legislation is enacted, these elements should therefore be treated as institutional proposals rather than existing direct duties for AI laboratories.
3. Why a kill switch is a governance problem
A shutdown mechanism can exist technically while remaining weakly governed.
The relevant question is not simply whether a model can be stopped. Governance must establish who has authority to order the intervention, what evidence is sufficient to cross the shutdown threshold, how execution is confirmed, and who can subsequently authorize a restart.
signal → classification → shutdown threshold → authority → decision → activation → technical confirmation → impact → residual risk → independent verification → restart authorization
The control is therefore not the switch itself. The control is the verifiable decision chain surrounding it.
4. Human oversight is not the same as human authority
A human may remain technically present in a process without possessing effective decision authority.
A governed intervention requires the identity, mandate and accountability of the decision-maker to remain reconstructable.
This distinction becomes particularly important when several actors are involved: frontier-model developers, independent verification organizations, cloud providers, cybersecurity teams, emergency authorities and external auditors.
5. Shutdown does not end the incident
Stopping a model creates a new operational state that must itself be verified.
The organization must determine which components were actually stopped, which dependencies remain active, what effects have already occurred and what residual risk persists.
Restart should therefore be treated as a new governed decision rather than as the automatic reversal of shutdown.
6. The QEN interpretation
Within QEN Sovereign, an emergency shutdown capability should not be represented as a binary control — present or absent.
It should be represented as a chain of evidence, authority and decisions whose integrity can be assessed independently.
- Signal: provenance, timestamp, integrity and operational context.
- Classification: the rule transforming a signal into a safety or security event.
- Threshold: the criterion that justifies escalation or shutdown.
- Authority: the identity and mandate of the authorized decision-maker.
- Activation: the decision record and confirmation of technical execution.
- Impact: affected components, dependencies and observed consequences.
- Residual risk: conditions remaining after shutdown.
- Independent verification: external confirmation that the intervention was effective.
- Restart authority: evidence, identity and reasoning supporting return to operation.
7. Operational Intervention & Restart Authority
The California case suggests a distinct assessment dimension for AI governance: Operational Intervention & Restart Authority.
An assessment should examine at least:
- decision authority;
- intervention triggers and thresholds;
- evidence provenance and integrity;
- segregation of duties;
- technical confirmation of execution;
- override mechanisms;
- independent verification;
- residual-risk assessment;
- restart criteria;
- traceability of the final decision.
8. From distributed incidents to intervention authority
This analysis extends a problem already examined by International Watch: distributed AI incidents may emerge as multiple anomalies that appear individually insufficient to cross a critical threshold.
Evidence correlation therefore precedes intervention authority.
Related analysis: Distributed AI incidents: governance, correlation and release integrity .
9. From Data Governance to Evidence Governance
Independent verification requires more than access to data. It requires the ability to reconstruct why an operational decision was made.
This connects the California case to Cognitive Logic's broader work on Evidence Governance and Industrial Cybersecurity & Evidence Governance .
See also QEN Sovereign, Validation Programme and Trust & Verification.
10. Current limits
As of 20 September 2026, the executive order does not itself define all technical requirements that would be necessary for a uniform operational shutdown framework.
Further legislative and administrative work would be required to determine, among other matters, the precise scope of covered models, technical requirements for shutdown capabilities, verifier access, testing frequency, responsibility for failed intervention and criteria for restart.
Primary sources
- Executive Order N-9-26 — signed text, 18 September 2026
- Office of Governor Gavin Newsom — executive order announcement, 18 September 2026
- Office of Governor Gavin Newsom — SB 813 and AB 1405, 9 September 2026
Independent reporting
QEN context: QEN Sovereign · QEN Framework · International Watch