Most AI systems aren't ready. Check yours in 15 min →
NE

Newsom’s Executive Order Moves California Toward AI Regulation

AuthorAndrew
Published on:
Published in:AI

This is the part where politicians try to sound responsible, and tech people roll their eyes. And honestly, both sides have a point. California Governor Gavin Newsom issuing an executive order to regulate AI sounds like grown-up leadership. It also sounds like a move that could easily turn into a messy patchwork of rules that mostly punishes the people who are trying to do things the right way.

Based on what’s been shared publicly, Newsom’s order is framed as a response to the federal government not doing enough. That framing matters. It’s basically California saying, “If Washington won’t act, we will.” That can be admirable. It can also be a power play. California has a long history of setting rules that end up shaping what everyone else does, because companies don’t want to build one version of a product for California and another for the rest of the country.

Here’s my take: state-level action on AI is better than pretending AI will regulate itself. But it’s also a risky way to govern something that doesn’t respect state borders. AI tools are built once and used everywhere. A rule in Sacramento can change what someone in Ohio can click on, whether anyone voted for that rule or not. If you like strong consumer protection, you might cheer. If you’re wary of one state steering the whole country, you should be nervous.

The other piece that’s hard to ignore is politics. The summary makes it clear this sits inside a bigger moment: Democratic leaders leaning into tech policy ahead of national elections, especially when federal action is limited. That doesn’t automatically make it bad. But it does change how I read it. When regulation becomes campaign material, there’s a temptation to go for bold gestures instead of boring details. Executive orders can be exactly that: fast, high-visibility, and not always built for the long grind of enforcement.

What’s at stake isn’t abstract. Imagine you run a small clinic and you’re using an AI tool to help sort patient messages. You’re not trying to “replace doctors.” You’re trying to keep up with volume. If the new rules are clear, you get confidence: you know what’s allowed, what needs human review, what you have to disclose. If the rules are vague, you end up doing what everyone does under uncertainty: you over-correct, you stop using the tool, and your patients wait longer.

Now flip it. Imagine you’re on the receiving end of AI decisions. You apply for an apartment and get screened out by a system you can’t understand. Or you get flagged by some automated fraud tool and your bank account gets frozen. This is where “move fast” stops being cute. If California forces more transparency and accountability, real people benefit. People who don’t have lawyers. People who can’t spend two months arguing with a customer support email address.

But there’s a consequence people don’t like to say out loud: regulation tends to favor the biggest players. Big companies can afford compliance teams, audits, paperwork, and legal reviews. Startups can’t. So if California sets a complicated bar, it may not “tame Big Tech.” It might lock in Big Tech, because only the giants can afford to jump.

And then there’s the cross-border chaos. If California builds one set of rules and other states build different ones, we get a weird reality where the same AI feature is legal in one place and not in another. Companies will respond in predictable ways. Either they build to the strictest standard and everyone lives with California’s choices, or they start limiting features by location, or they stop offering tools in certain states entirely. None of those outcomes are automatically good.

I’m also uneasy about how much depends on the details we haven’t seen. “Regulate AI” can mean a lot of things. Is the goal to protect consumers from harm? To set rules for government agencies buying AI? To force companies to test systems before releasing them? To control how AI is used in hiring, housing, health, education? Each choice creates winners and losers. And each choice can be enforced seriously, or just announced loudly.

The best-case version of this order is simple: clear expectations, realistic timelines, and a focus on the places where AI can wreck someone’s life quickly. The worst-case version is a glossy political signal that creates uncertainty, scares cautious organizations into freezing useful tools, and still doesn’t stop the most harmful uses because the bad actors ignore the rules anyway.

I don’t think the right answer is “wait for federal action,” because that can mean waiting forever. But I also don’t think “California goes first” is automatically leadership. Sometimes it’s just California exporting its preferences and calling it progress.

So here’s the real question I can’t shake: should one state be allowed to effectively set the rules for AI use across the whole country?

Frequently asked questions

What is AI agent governance?

AI agent governance is the set of policies, controls, and monitoring systems that ensure autonomous AI agents behave safely, comply with regulations, and remain auditable. It covers decision logging, policy enforcement, access controls, and incident response for AI systems that act on behalf of a business.

Does the EU AI Act apply to my company?

The EU AI Act applies to any organisation that develops, deploys, or uses AI systems in the EU, regardless of where the company is headquartered. High-risk AI systems face strict obligations starting 2 August 2026, including risk management, data governance, transparency, human oversight, and conformity assessments.

How do I test an AI agent for security vulnerabilities?

AI agent security testing evaluates agents for prompt injection, data exfiltration, policy bypass, jailbreaks, and compliance violations. Talan.tech's Talantir platform runs 500+ automated test scenarios across 11 categories and produces a certified security score with remediation guidance.

Where should I start with AI governance?

Start with a free AI Readiness Assessment to benchmark your current maturity across 10 dimensions (strategy, data, security, compliance, operations, and more). The assessment takes about 15 minutes and produces a prioritised roadmap you can act on immediately.

Ready to secure and govern your AI agents?

Start with a free AI Readiness Assessment to benchmark your maturity across 10 dimensions, or dive into the product that solves your specific problem.