Three Orders, Three Models of Obligation
The three orders differ in structure, but each one transfers work to the CIO's office that wasn't there before.
California EO N-5-26 (signed March 30, 2026) directed the Department of General Services and the California Department of Technology to submit recommendations for new AI vendor certification requirements within 120 days. The deadline was July 28, 2026. The certification framework requires vendors to attest to their AI governance policies in three areas; the order also directed GovOps to propose reforms to contractor responsibility provisions, including suspension authority for vendors judicially determined to have unlawfully undermined privacy or civil liberties. Separately, state agencies were directed to facilitate employee access to vetted generative AI tools and publish a data minimization toolkit. California's primary control surface is the contract: governance flows through what the state requires vendors to certify before an award.
Oregon EO 26-26 (signed September 23, 2026) placed obligations on the state's Chief Information Officer directly. The CIO has 90 days to propose a working definition of "frontier AI" for state government purposes, establish criteria for what constitutes adequate third-party safety review of those systems, and assess the viability of requiring kill-switch capability on frontier AI systems under state contracts. Governor Kotek cited the absence of adequate federal oversight as the reason for state action. The order also directs the Governor's office to reassess the necessity of the EO every three months — a built-in sunset review that gives the administration flexibility but also means this framework could be extended or narrowed depending on what federal action materializes.
Illinois EO 2026-07 (signed September 22, 2026) established the Illinois Artificial Intelligence Cabinet, a cross-agency advisory body including the heads of the Department of Innovation and Technology, the Illinois Emergency Management Agency, the Department of Financial and Professional Regulation, the Commerce Commission, the State Police, the Department of Commerce and Economic Opportunity, the Environmental Protection Agency, and the Department of Public Health. Governor Pritzker has 30 days to appoint members. The Cabinet is charged with assessing AI-related risks, advising on procurement safeguards, and developing guidance on AI incident response. Illinois chose a deliberative model rather than a deadline model: it convened the governance structure first, with substantive recommendations to follow.
These are not equivalent levels of urgency. Oregon's CIO faces a December 2026 deadline to produce something specific. California's deadline has passed; the question for state agencies is now whether the recommendations produced since July have been incorporated into procurement templates. Illinois is still standing up its cabinet.
The Definition Problem Oregon Gave Its CIO
Oregon's most technically demanding assignment is the definition of "frontier AI." The term originated in AI safety research to describe models with novel, emergent capabilities that are difficult to predict before deployment. For a state CIO, the definition must be operationally actionable — specific enough that a procurement officer can determine whether a given contract falls inside it.
A workable framework for state purposes might categorize AI systems along two dimensions: consequence level and reversibility. A model that scores unemployment claims, ranks child welfare referrals, or generates real-time recommended actions for emergency dispatch is both high-consequence and low-reversibility — an error cannot easily be undone, and the affected person may not have a meaningful review mechanism before harm occurs. These systems warrant the oversight Oregon envisions regardless of their technical sophistication. A model that summarizes public comments on a proposed regulation is high-volume but low-consequence; errors are caught in the editorial process.
A capability-based threshold — such as the compute thresholds used in some federal and international AI governance frameworks — may also apply, particularly for general-purpose models procured on a subscription basis rather than purpose-built systems. But for state government, the operational consequence framework captures the relevant risk better than capability metrics alone: a highly capable general-purpose model used for scheduling has a different risk profile than a narrower model used for risk-scoring children.
Oregon's CIO will need to inventory current state AI systems against whatever definition emerges. Building that inventory from scratch after the proposal is drafted will compress the subsequent procurement revision work into an impossible window. The inventory should be underway now, in parallel with the definitional work.
Kill-Switch Requirements: What the Assessment Must Address
The kill-switch provision in Oregon EO 26-26 is the most operationally novel element in any current state AI order. Oregon's CIO must assess viability, not mandate implementation — but the assessment requires understanding what implementation would actually entail, since a kill switch that can't be exercised in practice is not a governance control.
Viable kill-switch capability on a frontier AI system under a state contract would require at least four things:
Unilateral suspension authority in the contract. Current state IT master services agreements were not designed with this in mind. A kill-switch provision needs to specify: who in the state organization has authority to invoke it, what notice (if any) the vendor receives, the timeframe within which the system must be suspended, and what the vendor's obligations are during suspension. These are novel terms. Procurement offices need to draft them before vendors have leverage in negotiations over a specific system.
An operational continuity plan without the AI. A kill switch is only a governance control if the underlying function can continue when the AI is suspended. For AI systems embedded in eligibility determinations, case management, real-time dispatch, or infrastructure monitoring, this requires a documented manual or automated fallback. If no fallback exists, then the choice is not "use the AI or don't" — it's "use the AI or suspend the function." That's a different risk calculus, and it means the kill switch is a crisis measure rather than a routine governance tool. Identifying which programs have this gap is part of the assessment.
Audit trail and incident documentation requirements. The decision to invoke a kill switch is a significant event. Contracts need to specify what records must be maintained, what the handoff process looks like, and what post-suspension review the vendor owes. Without these terms, the kill switch has no accountability structure.
A jurisdictional scope question. If the frontier AI system is a general-purpose model procured from a major vendor on a subscription basis, the "kill switch" question is really a contract termination question — the state can stop using the service. If it's a custom model integrated into state systems, suspension has technical dependencies that must be planned for. The assessment Oregon requires will need to distinguish these cases.
None of this is impossible to build. But it requires procurement templates, legal review, and technical architecture decisions that take months. Oregon's CIO has until late December. Starting with the inventory of what systems would fall under the requirement is the right first move.
How These Mandates Should Change Procurement Templates
All three orders converge on procurement contracts as the implementation vehicle. This is logical: most AI systems in state government arrive through a vendor agreement, and the contract is the most durable governance instrument a state has over vendor behavior after award.
Taken together, the three orders point toward a set of contract provisions that state procurement offices should begin developing:
- Vendor attestation requirements: vendors must attest to training data governance, bias testing protocols, and performance monitoring practices before award — not just describe their AI governance policies at a general level. California's framework requires attestation in three specific areas; Oregon's will add third-party review to the required scope.
- Third-party review terms: once Oregon's criteria are published, contracts for systems meeting the frontier definition will need to require an independent review before the system is deployed in production, with findings disclosed to the state.
- Suspension authority clauses: unilateral suspension rights with defined timelines, notice requirements, and handoff procedures — distinct from termination-for-cause provisions, which require a legal finding.
- Incident response obligations: what constitutes a reportable AI incident, how quickly the vendor must notify the state, what documentation must follow, and what remediation is required.
- Performance benchmarking: measurable performance floors tied to the specific operational context (eligibility accuracy, decision consistency, appellate reversal rate) rather than generic model benchmarks.
None of these terms is standard in current state IT procurement. The states with published AI EOs will need to develop model contract language through their procurement agencies; the states without them will need to develop it themselves or wait for a peer state's template to emerge. California's process, being the most advanced, is the most likely source of a practical template that other states can adapt.
A Practical Sequence for CIO Offices
For CIOs responding to an existing order, or preparing for one:
1. Inventory current AI systems against a working frontier-AI definition. Don't wait for the official definition. Categorize deployed and contracted AI systems by consequence level and reversibility. Systems making or recommending irreversible decisions affecting residents — benefits, custody, criminal justice, public safety dispatch — are the priority tier regardless of how the official definition resolves.
2. Audit existing contracts for suspension and termination provisions. Review AI vendor contracts for unilateral suspension authority. Most will not have it. Identify which contracts are up for renewal within 18 months — those are the near-term revision opportunities.
3. Identify which programs lack an operational fallback. Map the gap between "we could suspend this AI system" and "we could continue operations if we did." Where the fallback is missing or undocumented, that's a program risk independent of the procurement requirement.
4. Begin building model contract language now. Third-party review criteria, kill-switch provisions, incident response obligations, and performance benchmarking are all drafting tasks that can start before an official standard is published. Using the NIST AI Risk Management Framework (NIST AI 100-1) and IEEE Standard 3119-2025 as scaffolding gives procurement offices a principled starting point that can be refined as state guidance matures.
5. Track California's vendor certification framework. California's 120-day process produced specific recommendations. Once those are public, they represent the most detailed state AI procurement standard in the country. Adapting California's framework to your state's context is faster and more defensible than drafting from scratch.
The pattern established in 2026 — multiple states acting independently, in rapid succession, on AI governance — is not going to reverse. State CIOs who invest in the procurement infrastructure now will be managing known risk. Those who wait will be managing the compressed timeline that comes with an EO they didn't see coming.
Spartan X has worked directly with state government executives and technology leaders on AI program design and delivery, including building platforms that incorporate the kind of governance architecture these orders are now mandating. That operational experience — understanding where AI governance lives in contracts, in operational procedures, and in system architecture — is what separates compliance plans that hold up from ones that don't.
Sources and further reading
- Oregon EO 26-26 (September 23, 2026): Governor Kotek Issues Executive Order to Advance AI Safety and Oversight
- Illinois EO 2026-07 (September 22, 2026): Gov. Pritzker Establishes Illinois Artificial Intelligence Cabinet
- California EO N-5-26 (March 30, 2026): 3.30 FINAL Trusted AI Procurement EO N-5-26
- NIST AI Risk Management Framework (NIST AI 100-1): nist.gov/artificial-intelligence
- IEEE Standard 3119-2025, Standard for the Procurement of Artificial Intelligence and Automated Decision Systems
- Four State Governors Issued AI Executive Orders in One Week — TechJack Solutions analysis



