Article-by-article breakdown

California Generative AI Procurement Order

California Executive Order N-5-26 — Responsible Procurement and Deployment of Generative Artificial Intelligence

Overview and Scope

Directive 1Responsible Procurement and Deployment of GenAI

Applies from: 2026-03-30

Applies to

  • California State Government
  • State Agencies
  • AI Vendors contracting with the State

Plain English

This Executive Order (EO) establishes a framework for how California's state government will responsibly acquire and use Generative Artificial Intelligence (GenAI). Its core purpose is to leverage the benefits of GenAI for Californians while rigorously protecting privacy and civil liberties. The EO aims to influence the broader AI market by setting high standards for vendors who wish to contract with the state, building upon previous state initiatives like Executive Order N-12-23.

Key points

  • Sets a strategic framework for GenAI procurement and deployment.
  • Prioritizes privacy, civil liberties, and ethical use of AI.
  • Leverages state purchasing power to influence AI market behavior.
  • Addresses risks like mass surveillance, manipulation, and civil rights violations.

What you need to do

  1. 1.State agencies must align GenAI initiatives with these overarching principles.
  2. 2.AI vendors should anticipate stringent requirements when engaging with California.
  3. 3.Compliance officers need to understand the state's values guiding AI adoption.
Procurement Standards

Directive 2Establishing AI Vendor Certification Criteria

Applies from: 2026-07-28

Applies to

  • California Department of Technology (CDT)
  • Department of General Services (DGS)
  • AI Vendors seeking state contracts

Plain English

The Department of General Services (DGS) and the California Department of Technology (CDT) are jointly tasked with developing new certification criteria for AI vendors. These criteria will be mandatory for companies seeking to contract with the state for AI technologies. Vendors will need to attest to and explain their policies and safeguards in three critical areas: preventing the exploitation or distribution of illegal content (e.g., child sexual abuse material), mitigating harmful bias in AI models, and safeguarding civil rights and civil liberties, including free speech, voting rights, human autonomy, and protections against unlawful discrimination, detention, and surveillance.

Key points

  • Mandatory certification for AI vendors contracting with the state.
  • Criteria focus on preventing illegal content, mitigating bias, and protecting civil liberties.
  • Vendors must attest to and explain their safeguards.
  • Developed jointly by DGS and CDT.

What you need to do

  1. 1.AI vendors must develop robust internal policies and technical safeguards for their models.
  2. 2.Vendors need to prepare documentation and explanations of their compliance measures.
  3. 3.State agencies must integrate these new certification standards into all AI procurement processes.
Procurement Standards

Directive 3Independent Review of Federal AI Supply Chain Risks

Applies from: 2026-03-30

Applies to

  • State Chief Information Security Officer (CISO) within CDT
  • California State Agencies

Plain English

The State Chief Information Security Officer (CISO) within the California Department of Technology (CDT) is directed to independently review federal AI supply chain risk designations. This means California will make its own informed decisions regarding AI procurement, and the CISO has the authority to facilitate continued procurement by California agencies even if federal restrictions exist, should the CISO deem a federal designation improper. This highlights California's intent to maintain autonomy in its technology procurement decisions.

Key points

  • State CISO to independently assess federal AI supply chain risk designations.
  • California can potentially override federal restrictions on AI procurement.
  • Ensures state autonomy in technology sourcing decisions.
  • Aims to prevent undue federal influence on state AI adoption.

What you need to do

  1. 1.State agencies should consult the CISO regarding any federal AI vendor restrictions.
  2. 2.AI vendors previously impacted by federal designations may find new opportunities in California.
  3. 3.Compliance officers need to monitor both federal and state risk assessments for AI vendors.
Accountability

Directive 4Reforming Contractor Accountability for AI Misuse

Applies from: 2026-07-28

Applies to

  • Government Operations Agency (GovOps)
  • Department of General Services (DGS)
  • California Department of Technology (CDT)
  • AI Contractors

Plain English

The Government Operations Agency (GovOps), in consultation with DGS and CDT, is tasked with submitting recommendations for reforms to contractor responsibility provisions. These reforms are intended to establish clear grounds for suspending or disqualifying vendors who have been judicially determined to have unlawfully undermined privacy or civil liberties. This includes violations related to freedom of speech, voting rights, and protections against unlawful discrimination and surveillance, ensuring that AI contractors are held accountable for their actions.

Key points

  • Recommendations for new contractor responsibility provisions are due.
  • Focus on suspending/disqualifying vendors for unlawful privacy/civil liberties violations.
  • Applies to violations like free speech, voting rights, discrimination, and surveillance.
  • Aims to strengthen accountability for AI misuse by contractors.

What you need to do

  1. 1.AI contractors face potential suspension or disqualification for civil liberties violations.
  2. 2.State agencies will gain stronger tools for vendor oversight and enforcement.
  3. 3.Compliance officers should prepare for new contractual terms and potential penalties related to AI misuse.
Transparency and Trust

Directive 5Guidance on Watermarking AI-Generated Content

Applies from: 2026-07-28

Applies to

  • California Department of Technology (CDT)
  • Government Operations Agency (GovOps)
  • State Agencies deploying GenAI

Plain English

The California Department of Technology (CDT), in collaboration with the Government Operations Agency (GovOps), must issue best-practice guidance for watermarking AI-generated or significantly manipulated images and video. This directive aims to enhance transparency and aligns with existing state laws that impose transparency and provenance obligations on GenAI providers. The guidance will help state agencies ensure that content created or altered by AI is clearly identifiable.

Key points

  • CDT and GovOps to issue watermarking guidance for AI-generated images/video.
  • Aims to increase transparency and identify AI-created content.
  • Aligns with existing California laws on GenAI transparency.
  • Guidance to be based on industry best practices.

What you need to do

  1. 1.State agencies using GenAI for visual content must implement watermarking practices.
  2. 2.Product leads for GenAI tools used by the state need to ensure watermarking capabilities.
  3. 3.Compliance officers should integrate watermarking requirements into content creation workflows.
Privacy and Security

Directive 6Publishing a Data Minimization Toolkit

Applies from: 2026-07-28

Applies to

  • California Department of Technology (CDT)
  • State Agencies deploying GenAI

Plain English

The California Department of Technology (CDT) is directed to publish a data minimization toolkit for state agencies. This toolkit will provide essential resources, including best practices, templates, and special contract provisions, designed to ensure privacy and security in all AI deployments. The goal is to help agencies reduce the collection and use of personal data to only what is strictly necessary, thereby mitigating privacy risks associated with AI systems.

Key points

  • CDT to publish a data minimization toolkit for state agencies.
  • Toolkit includes best practices, templates, and contract provisions.
  • Focuses on enhancing privacy and security in AI deployments.
  • Aims to reduce unnecessary data collection and use by AI systems.

What you need to do

  1. 1.State agencies must adopt data minimization principles when designing and deploying AI solutions.
  2. 2.Product leads for AI systems should prioritize privacy-by-design and data minimization features.
  3. 3.Compliance officers need to integrate toolkit guidelines into data governance and AI project planning.
Operational Integration

Directive 7Integrating GenAI into State Operations and Strategy

Applies from: Ongoing

Applies to

  • California Department of Technology (CDT)
  • State Agencies

Plain English

This directive encourages and guides the broader integration of GenAI within state government operations. State agencies are instructed to facilitate employee access to vetted GenAI tools, ensuring appropriate safeguards are in place. The California Department of Technology (CDT) will update the State Digital Strategy to incorporate GenAI use cases, aiming to enhance government transparency, accountability, and accessibility of services. Agencies are also encouraged to develop pilot AI applications and expand workforce training on emerging technologies to build internal capacity.

Key points

  • Facilitate employee access to vetted GenAI tools with safeguards.
  • Update the State Digital Strategy to include GenAI use cases.
  • Explore pilot AI applications for government services.
  • Expand workforce training on emerging technologies.

What you need to do

  1. 1.Agencies need to identify, vet, and procure appropriate GenAI tools for internal use.
  2. 2.Internal policies for responsible GenAI use by employees must be developed.
  3. 3.Investment in employee training and skill development for AI technologies is crucial.
  4. 4.Product leads should identify opportunities for GenAI to improve government services.
Context and Precedent

Directive 8Alignment with California's AI Regulatory Landscape

Applies from: 2026-03-30

Applies to

  • California State Government
  • AI Vendors

Plain English

Executive Order N-5-26 is not a standalone policy but is strategically integrated into California's existing and evolving AI governance framework. It explicitly builds upon and expands directives from Governor Newsom's earlier Executive Order N-12-23 (September 2023), which focused on safe AI learning and innovation. Furthermore, this Order complements other significant state laws, such as the Transparency in Frontier Artificial Intelligence Act (TFAIA), effective January 1, 2026, and California Business & Professions Code sections 22757.2 and 22757.3, which mandate transparency and provenance for GenAI providers. By focusing on procurement, the EO strengthens the practical application and enforcement of these existing laws.

Key points

  • Builds upon and expands previous Executive Order N-12-23.
  • Complements the Transparency in Frontier Artificial Intelligence Act (TFAIA).
  • Reinforces existing state laws on GenAI transparency and provenance.
  • Integrates procurement power to enforce broader state AI policies.

What you need to do

  1. 1.Understand that this EO is part of a comprehensive and consistent regulatory approach in California.
  2. 2.Ensure compliance with all relevant state AI laws, not just this Executive Order.
  3. 3.AI vendors should be aware of the cumulative effect of California's AI regulations.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →