California Generative AI Procurement Order
California Executive Order N-5-26 — Responsible Procurement and Deployment of Generative Artificial Intelligence
United States • California
RAI-US-CA-PROCURE-2026California Executive Order N-5-26 establishes a framework for responsible GenAI procurement and deployment across state government, focusing on privacy, civil liberties, and ethical use.
Summary
Read full text ↗Plain English
Overview
California Executive Order N-5-26, signed by Governor Gavin Newsom on March 30, 2026, sets forth a strategic framework for the responsible procurement and deployment of Generative Artificial Intelligence (GenAI) within the California state government. This Executive Order aims to harness the benefits of GenAI for Californians while simultaneously ensuring these powerful tools are deployed transparently and in ways that rigorously protect privacy and civil liberties. It underscores California's commitment to leading in AI innovation responsibly, building on the foundation established by previous state initiatives, notably Executive Order N-12-23 issued in September 2023.
The Order directs state agencies to integrate new trust and safety obligations into their contracting processes for AI companies. This includes developing robust vendor certification standards, independently reviewing federal supply chain risk designations related to AI, and establishing guidelines for the ethical and secure use of GenAI within state operations. By leveraging its substantial purchasing power, California seeks to influence market behavior and encourage the development and deployment of AI technologies that align with the state's values of public safety, transparency, and the protection of fundamental rights. The directives outlined in N-5-26 are designed to address potential risks such as mass surveillance, manipulation of information, and violations of civil rights and civil liberties, while simultaneously exploring opportunities to enhance government services and efficiency.
Definitions
While Executive Order N-5-26 itself does not contain a dedicated, formal definitions section, it consistently refers to and operates under the understanding of several key terms critical to its implementation. The primary term, "Generative Artificial Intelligence" (GenAI), is used throughout the document to denote advanced AI systems capable of producing various forms of content, such as text, images, or code, often in response to prompts. The Order's focus is on the responsible interaction and integration of these generative capabilities within state governmental functions and procurement processes.
Other terms, while not explicitly defined, are used in contexts that imply their meaning within the framework of AI regulation. These include "harmful bias" in AI models, referring to systemic prejudices or unfairness embedded in or resulting from AI systems that can lead to discriminatory outcomes. "Civil rights and civil liberties" are invoked to emphasize protections against unlawful discrimination, surveillance, and infringements on fundamental freedoms like free speech and voting. The Order also addresses "supply chain risk designations" in the context of federal assessments of AI vendors, indicating concerns about security vulnerabilities or foreign influence in the technology supply chain. The absence of explicit definitions suggests reliance on commonly understood meanings within the legal and technological communities, or that more precise definitions will be developed by the tasked agencies as they formulate specific guidelines and certifications.
Governance and Institutional Framework
Executive Order N-5-26 establishes a multi-agency governance framework to oversee the responsible procurement and deployment of GenAI within California's state government. The California Department of Technology (CDT) and the Department of General Services (DGS) are central to this framework, jointly tasked with developing new certification criteria for AI vendors seeking to contract with the state. These criteria are designed to ensure that AI technologies procured by California agencies adhere to stringent standards regarding public safety, civil liberties, and ethical use. The CDT also plays a crucial role in identifying and developing opportunities for state government to leverage AI effectively.
Further strengthening the governance structure, the State Chief Information Security Officer (CISO) within the CDT is directed to independently review federal AI supply chain risk designations. This directive allows California to make its own informed decisions regarding procurement, potentially overriding federal restrictions if the CISO deems a designation improper. The Government Operations Agency (GovOps), in consultation with DGS and CDT, is responsible for recommending reforms to contractor responsibility provisions, including mechanisms for suspending or disqualifying vendors found to have unlawfully undermined privacy or civil liberties. This collaborative approach among key state agencies ensures a comprehensive and coordinated effort in managing the risks and maximizing the benefits of GenAI across the state.
Key Focus Areas
The Executive Order N-5-26 outlines several critical focus areas to ensure the responsible integration of GenAI into state operations and procurement. A primary focus is the development of new certification requirements for AI vendors. These certifications will mandate that companies contracting with the state attest to and explain their policies and safeguards across three priority areas: preventing the exploitation or distribution of illegal content (such as child sexual abuse material and non-consensual intimate imagery), mitigating harmful bias in AI models, and safeguarding civil rights and civil liberties, including free speech, voting rights, human autonomy, and protections against unlawful discrimination, detention, and surveillance.
Another significant area is the independent review of federal supply chain risk designations. The CDT's State Chief Information Security Officer (CISO) is authorized to assess federal AI supply chain risk determinations and, if deemed improper, facilitate continued procurement by California agencies, notwithstanding federal restrictions. This highlights California's intent to maintain autonomy in its procurement decisions. The Order also directs the development of best-practice guidance for watermarking AI-generated or significantly manipulated images and video, aligning with existing state laws on transparency. Furthermore, it emphasizes expanding responsible government use of AI through facilitating employee access to vetted tools, updating the State Digital Strategy to include GenAI use cases, and publishing a data minimization toolkit for agencies.
Implementation Framework
The implementation framework for Executive Order N-5-26 is structured around a series of directives to specific state agencies, with most actions mandated within 120 days of the Order's issuance. The Department of General Services (DGS) and the California Department of Technology (CDT) are tasked with developing the core certification criteria for AI vendors. These criteria will serve as a foundational element for all future state contracts involving AI, ensuring that vendors demonstrate adherence to state values concerning safety, ethics, and civil liberties. This involves a detailed process of defining what constitutes acceptable safeguards against harmful content, bias, and civil rights violations, and how vendors must attest to these.
Beyond procurement, the framework extends to the broader integration and management of GenAI within state government. The CDT, in collaboration with the Government Operations Agency (GovOps), is directed to issue guidance for departments on appropriately watermarking AI-generated content, consistent with industry best practices and existing California law. Furthermore, the Order mandates the development of a data minimization toolkit, providing state agencies with best practices, templates, and special contract provisions to ensure privacy and security in AI deployments. The State Digital Strategy will also be updated to incorporate GenAI use cases, aiming to enhance government transparency, accountability, and accessibility of services. These directives collectively form a robust framework designed to guide the responsible adoption and oversight of GenAI across all levels of California's state government.
Monitoring and Evaluation
Monitoring and evaluation under Executive Order N-5-26 are primarily embedded within the ongoing responsibilities assigned to various state agencies, rather than through a single, explicit monitoring body. The directives require the California Department of Technology (CDT), the Department of General Services (DGS), and the Government Operations Agency (GovOps) to develop, implement, and continuously refine policies, guidelines, and certification standards. This iterative process inherently involves a degree of monitoring as agencies work to meet the 120-day deadlines for recommendations and guidance, and subsequently integrate these into procurement and operational practices.
For instance, the requirement for AI vendors to attest to and explain their safeguards against harmful content, bias, and civil liberties violations implies an ongoing review process during contract negotiation and management. Similarly, the CDT State Chief Information Security Officer's (CISO) independent review of federal supply chain risk designations suggests a continuous assessment mechanism to ensure California's procurement strategies remain aligned with its independent security and policy objectives. While the Order does not detail specific metrics or a centralized audit function, the establishment of clear deliverables and the expectation for agencies to develop best practices, toolkits, and updated strategies will necessitate internal monitoring of progress and effectiveness in achieving the Order's objectives. The ongoing nature of these tasks ensures that the state's approach to GenAI remains adaptable and responsive to evolving technological landscapes and societal impacts.
Penalties, Liability, and Appeals
Executive Order N-5-26 itself does not directly establish new penalties or liability frameworks for AI misuse, nor does it detail an appeals process for affected parties. However, it lays the groundwork for future mechanisms to address non-compliance and accountability within the state's procurement ecosystem. Specifically, the Order directs the Government Operations Agency (GovOps), in consultation with the Department of General Services (DGS) and the California Department of Technology (CDT), to submit recommendations for reforms to contractor responsibility provisions.
These recommendations are intended to establish grounds for suspending or disqualifying vendors that have been judicially determined to have unlawfully undermined privacy or civil liberties. This includes violations related to freedom of speech, voting rights, and protections against unlawful discrimination and surveillance. While the Order itself states it is not intended to create new enforceable rights against the State of California, its directives aim to leverage the state's procurement power to enforce responsible AI practices among its contractors. The specific details of these reforms, including the nature of penalties, liability assignments, and any appeal mechanisms, are anticipated to be developed and proposed by the tasked agencies within the stipulated 120-day timeframe.
Relationship to Other Instruments
Executive Order N-5-26 is not an isolated policy but is strategically positioned within California's broader and evolving landscape of AI governance. It explicitly builds upon and expands the directives of Governor Newsom's earlier Executive Order N-12-23, issued in September 2023. While N-12-23 outlined how the state would safely learn, innovate, and use Generative AI, N-5-26 adds a procurement-focused layer, detailing how the state will ensure responsible AI practices through its contracting power. This continuity demonstrates a deliberate, phased approach to AI regulation in California.
Furthermore, N-5-26 complements other significant legislative measures recently enacted in California. It aligns with and reinforces the objectives of the Transparency in Frontier Artificial Intelligence Act (TFAIA), which became effective on January 1, 2026, requiring large AI model developers to adopt safety frameworks, report risk assessments, and disclose critical safety incidents. The Order's directives on watermarking AI-generated content also comport with California Business & Professions Code sections 22757.2 and 22757.3, which impose transparency and provenance obligations on GenAI providers. By focusing on procurement, the Executive Order strengthens the enforcement and practical application of these existing laws and policies, creating a cohesive regulatory environment for AI in the state.
National/Federal Alignment
Executive Order N-5-26 highlights a notable point of divergence and an assertive stance by California in the national conversation surrounding AI policy. While the federal government, particularly through initiatives like the White House's "AI Action Plan" and a December 2025 executive order, has emphasized deregulation and sought to establish a "minimally burdensome national standard" for AI, California's Order leverages its significant market power to impose distinct and robust AI governance requirements on state contractors. This approach positions California to potentially set de facto national benchmarks through its procurement standards, particularly in areas where federal regulatory efforts remain fragmented or contested.
A key aspect of this independent approach is the directive authorizing the CDT's State Chief Information Security Officer (CISO) to independently assess federal AI supply chain risk determinations. This allows California to make its own judgments regarding vendor restrictions, and in some circumstances, proceed with procurement despite federal designations. This move has been noted as a reaction to specific federal actions, such as the designation of certain AI companies as supply chain risks, and introduces a potential avenue for tension with federal national security frameworks. By exercising its procurement authority rather than enacting generally applicable regulatory mandates, California aims to insulate its requirements from potential federal preemption challenges, carving out its own path in AI regulation.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Executive Order Issued | 2026-03-30 | Governor Gavin Newsom signs Executive Order N-5-26. |
| Develop AI Vendor Certification Criteria | 2026-07-28 | DGS and CDT to develop certification criteria for AI vendors. |
| Develop Recommendations for Contractor Responsibility Reforms | 2026-07-28 | GovOps, in consultation with DGS and CDT, to submit recommendations on reforms to contractor responsibility provisions. |
| Issue Guidance on Watermarking AI-Generated Content | 2026-07-28 | CDT, in collaboration with GovOps, to issue best-practice guidance for watermarking AI-generated images/video. |
| Publish Data Minimization Toolkit | 2026-07-28 | CDT to publish a data minimization toolkit for departments and agencies. |
| Update State Digital Strategy | Ongoing | CDT to update the State Digital Strategy to include GenAI use cases. |
| Facilitate Employee Access to Vetted GenAI Tools | Ongoing | Agencies to facilitate employee access to vetted GenAI tools with appropriate safeguards. |
| Develop Pilot AI Application/Website | Ongoing | Agencies to develop a pilot application or website using GenAI for government services. |
| Expand Workforce Trainings | Ongoing | Agencies to expand trainings on emerging technologies. |
Compliance Checklist
| Check | Required Action |
|---|---|
| AI Vendor Certification | For vendors seeking state contracts: Attest to and explain policies and safeguards against illegal content, harmful bias, and civil liberties violations. |
| Procurement Process Integration | State agencies: Integrate new AI vendor certification standards into all relevant procurement processes. |
| Supply Chain Risk Assessment | CDT CISO: Review federal AI supply chain risk designations and issue guidance for state procurement, potentially overriding federal restrictions if deemed improper. |
| Content Watermarking | State agencies: Implement guidance for watermarking AI-generated or significantly manipulated images and video. |
| Data Minimization | State agencies: Utilize the data minimization toolkit and implement best practices for privacy and cybersecurity in AI deployments. |
| Responsible AI Use | State agencies: Facilitate employee access to vetted GenAI tools, update the State Digital Strategy, and explore GenAI use cases to improve government services. |
| Contractor Responsibility Review | GovOps, DGS, CDT: Develop and implement reforms to suspend or disqualify contractors judicially determined to have undermined privacy or civil liberties. |
| Workforce Training | State agencies: Expand trainings on emerging technologies for state employees. |
Sources and References
| Source | Type |
|---|---|
| California Executive Order N-5-26 — Responsible Procurement and Deployment of Generative Artificial Intelligence | official |
| Governor Newsom Issues Executive Order on Responsible Procurement and Deployment of Generative Artificial Intelligence | government |
| California Executive Order N-12-23 — Generative Artificial Intelligence | official |
California's Executive Order N-5-26 establishes a comprehensive framework for how the state government will responsibly procure and deploy Generative Artificial Intelligence (GenAI), directly impacting state agencies and any companies seeking to provide AI products or services to California.
Issued on March 30, 2026, this order aims to harness AI's benefits while rigorously protecting privacy, civil liberties, and public safety. It mandates that state agencies integrate new trust and safety obligations into their contracting processes. For companies, this means developing robust vendor certification standards. Specifically, vendors wishing to contract with California must attest to and explain their safeguards against: - the exploitation or distribution of illegal content (like child sexual abuse material) - harmful bias in AI models - violations of civil rights and civil liberties, including free speech, voting rights, and protections against unlawful discrimination or surveillance.
State agencies are also directed to issue guidance on watermarking AI-generated content and publish a data minimization toolkit to ensure privacy and security in AI deployments. A key aspect of the order is California's assertive stance on federal AI policy: the State Chief Information Security Officer can independently review federal AI supply chain risk designations and, if deemed improper, allow California agencies to proceed with procurement despite federal restrictions.
While the order itself doesn't create new penalties, it lays the groundwork for future reforms to contractor responsibility provisions. This means vendors found to have unlawfully undermined privacy or civil liberties could face suspension or disqualification from state contracts. Most of these new criteria and guidelines, including vendor certification standards and watermarking guidance, are expected to be developed and issued by July 28, 2026. A practical pitfall for companies is navigating California's independent assessment of AI supply chain risks, which could diverge from federal directives and add complexity for national operations.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
Read this article-by-article
Plain-English breakdown of 8 key articles, with cross-jurisdiction equivalents where applicable.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under California Generative AI Procurement Order. Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Before placing on market
Applies to: AI vendors seeking state contracts.
“Attest to and explain their policies and safeguards across three priority areas: preventing the exploitation or distribution of illegal content... mitigating harmful bias... and safeguarding civil rights and civil liberties”
- #2ImportantOverview⏰ After 2026-07-28
Applies to: California state agencies.
“The Order directs state agencies to integrate new trust and safety obligations into their contracting processes for AI companies.”
- #3ImportantGovernance and Institutional Framework
Applies to: California Department of Technology's State Chief Information Security Officer (CDT CISO).
“The State Chief Information Security Officer (CISO) within the CDT is directed to independently review federal AI supply chain risk designations.”
- #4ImportantImplementation Timeline⏰ Jul 28, 2026
Applies to: California Department of Technology (CDT) and Government Operations Agency (GovOps).
“CDT, in collaboration with GovOps, to issue best-practice guidance for watermarking AI-generated images/video.”
- #5ImportantCompliance Checklist⏰ After 2026-07-28
Applies to: California state agencies.
“State agencies: Implement guidance for watermarking AI-generated or significantly manipulated images and video.”
- #6ImportantImplementation Timeline⏰ Jul 28, 2026
Applies to: California Department of Technology (CDT).
“CDT to publish a data minimization toolkit for departments and agencies.”
- #7ImportantCompliance Checklist⏰ After 2026-07-28
Applies to: California state agencies.
“State agencies: Utilize the data minimization toolkit and implement best practices for privacy and cybersecurity in AI deployments.”
- #8ImportantImplementation Timeline⏰ Jul 28, 2026
Applies to: Government Operations Agency (GovOps), Department of General Services (DGS), and California Department of Technology (CDT).
“GovOps, in consultation with DGS and CDT, to submit recommendations on reforms to contractor responsibility provisions.”
- #9RecommendedImplementation Timeline
Applies to: California state agencies.
“Agencies to facilitate employee access to vetted GenAI tools with appropriate safeguards.”
- #10RecommendedImplementation Timeline
Applies to: California Department of Technology (CDT).
“CDT to update the State Digital Strategy to include GenAI use cases.”
- #11RecommendedImplementation Timeline
Applies to: California state agencies.
“Agencies to expand trainings on emerging technologies.”
- #12RecommendedImplementation Timeline
Applies to: California state agencies.
“Agencies to develop a pilot application or website using GenAI for government services.”
Related Regulations
California AI Transparency Act
California, United States91% similar
California SB 53 — Transparency in Frontier Artificial Intelligence Act (TFAIA)
United States91% similar
Georgia State AI Governance and Use Guidance
United States90% similar
California AB 2885 — Artificial Intelligence: Unified Definition and State Agency Inventory
United States90% similar
North Carolina State Government Responsible Use of Artificial Intelligence Framework
United States90% similar
© Regulations.AI — created on 05-May-2026 using Gemini 2.5 Flash