Back to Blog
Policy & Regulation April 1, 2026 5 min read

California Mandates AI Safety Checks for State Contractors in First-of-Its-Kind Order

Governor Gavin Newsom signed an executive order on March 30 requiring AI vendors that sell to California to certify safeguards against bias, illegal content, and civil rights violations. The move puts California directly at odds with the Trump administration's push to deregulate AI at the federal level.

California Mandates AI Safety Checks for State Contractors in First-of-Its-Kind Order

California Governor Gavin Newsom signed an executive order on March 30, 2026 that gives the state a meaningful new lever over the AI industry: any company that wants to sell AI technology to California government agencies must now certify their systems have working safeguards against a specific list of harms.

The order is calibrated precisely around the gap left by the Trump administration’s retreat from federal AI oversight. Where Washington has moved to consolidate regulation under a single national framework — one that critics say benefits incumbents — Sacramento is building its own vetting layer.

What the Order Requires

Companies seeking state contracts must attest, in writing, that their AI tools prevent:

  • Distribution of CSAM (child sexual abuse material) and other illegal content
  • Harmful bias that produces discriminatory outputs affecting protected classes
  • Civil rights violations through automated decision-making

State agencies have 120 days to develop formal certification frameworks. The Government Operations Agency is leading the process and must produce new procurement guidelines — essentially a checklist AI vendors will have to clear before appearing on approved vendor lists.

The California Department of Technology will also issue best-practice guidance on AI watermarking: requirements for labeling AI-generated or significantly manipulated images and video, consistent with existing state law.

The Federal Dimension

One of the more politically pointed clauses grants California’s State Chief Information Security Officer explicit authority to review federal supply chain risk designations. Where the state CISO concludes a federal ban is improperly applied, the Department of General Services and the California Department of Technology must “jointly issue guidance ensuring that departments and agencies can continue to easily procure from that company.”

This is a direct override mechanism. If the federal government bans a foreign AI product for geopolitical reasons that California considers insufficient, the state can route around that designation for its own procurement.

It also works the other way: California can bar vendors that the federal government hasn’t flagged.

Scope and Limits

The order applies to AI companies seeking state government contracts — not to all companies operating in California or selling to private customers. That’s a narrower scope than the sweeping SB 1047 framework Newsom vetoed in 2024, and deliberately so.

By attaching requirements to procurement rather than licensing, Newsom avoids the constitutional friction that comes with regulating interstate commerce. The state can impose whatever conditions it wants on its own purchasing decisions. The result is softer than a law, but the California government market is large enough that procurement conditions function as de facto industry standards.

The Bigger Picture

California has historically been the most consequential subnational technology regulator in the world. The CCPA became the de facto U.S. privacy baseline. Automotive emissions standards spread globally. AI procurement standards follow the same playbook.

AI vendors should expect this certification framework to be operational by late July 2026. The requirements are not technically demanding — they are process demands. Companies that already have responsible AI programs will adapt quickly. Those that don’t have the documentation will need to build it.

The 120-day clock is running.

AI policy California Newsom regulation AI safety