A control-evidence map for independent AI verification
California’s Executive Order N-9-26, signed September 18, 2026, directs the Government Operations Agency, in consultation with the Governor’s Office of Emergency Services, to recommend — by November 16, 2026 — whether to require independent verification organizations onsite in frontier AI labs; independent verification of required safety frameworks, transparency reports, and risk assessments; an independently tested “kill switch” for frontier models; and an expanded definition of reportable loss-of-control incidents.
The order doesn’t yet define what verification will require. But it names the shift: from AI companies self-reporting on safety, to independent organizations verifying that controls actually held when a system attempted to act.
That is an engineering problem, not a paperwork problem. It requires evidence — produced continuously, outside the AI system itself — that isolation held, actions were evaluated, unauthorized actions were blocked, and authority could be withdrawn.
| What must be verified | Evidence an independent reviewer needs | Manetu capability |
|---|---|---|
| The agent remains within its operating boundary | Isolation status, containment events, and attempted boundary violations | AgentVisor™ containment |
| The agent acts under identifiable authority | Agent identity, execution context, and the authority attached to each request | Agent identity & context |
| Every external action is evaluated before it executes | The attempted action, the applicable policy, and the decision made before execution | Policy Engine evaluation |
| Unauthorized actions are prevented, not just logged | Recorded allow/deny decisions and evidence that denied actions did not execute | Runtime enforcement |
| Authority can be withdrawn, not just documented | A revocation event and evidence that subsequent actions were denied | Policy-based revocation |
| A control failure can be reconstructed after the fact | Time-stamped activity, policy decisions, identities, and system context | Auditable decision history |
| Controls operate independently of the AI system | Evidence that the system requesting authority could not set or override its own limits | External authorization boundary |
A kill switch is an emergency measure — used when loss of control is imminent or suspected. Enterprise-grade control starts earlier: contain the agent, evaluate every attempted action, enforce policy before execution, and revoke authority the moment conditions change.
The goal is not merely to stop an AI system after control is lost. It is to prevent unauthorized action before emergency shutdown becomes necessary.
SCOPE NOTE
This map does not claim compliance with standards that have not yet been written. It identifies the operational evidence any credible independent-verification regime will need to see.
SOURCE
California Executive Order N-9-26 (signed September 18, 2026) directs the Government Operations Agency, in consultation with the Governor’s Office of Emergency Services, to recommend, by November 16, 2026, whether to require onsite independent verification organizations, independently verified safety frameworks, an independently tested frontier-model kill switch, and an expanded definition of reportable loss-of-control incidents.