From AI safety plans to verifiable control

A control-evidence map for independent AI verification

California’s Executive Order N-9-26, signed September 18, 2026, directs the Government Operations Agency, in consultation with the Governor’s Office of Emergency Services, to recommend — by November 16, 2026 — whether to require independent verification organizations onsite in frontier AI labs; independent verification of required safety frameworks, transparency reports, and risk assessments; an independently tested “kill switch” for frontier models; and an expanded definition of reportable loss-of-control incidents.

The order doesn’t yet define what verification will require. But it names the shift: from AI companies self-reporting on safety, to independent organizations verifying that controls actually held when a system attempted to act.

That is an engineering problem, not a paperwork problem. It requires evidence — produced continuously, outside the AI system itself — that isolation held, actions were evaluated, unauthorized actions were blocked, and authority could be withdrawn.

Control evidence map

What must be verified Evidence an independent reviewer needs Manetu capability
The agent remains within its operating boundary Isolation status, containment events, and attempted boundary violations AgentVisor™ containment
The agent acts under identifiable authority Agent identity, execution context, and the authority attached to each request Agent identity & context
Every external action is evaluated before it executes The attempted action, the applicable policy, and the decision made before execution Policy Engine evaluation
Unauthorized actions are prevented, not just logged Recorded allow/deny decisions and evidence that denied actions did not execute Runtime enforcement
Authority can be withdrawn, not just documented A revocation event and evidence that subsequent actions were denied Policy-based revocation
A control failure can be reconstructed after the fact Time-stamped activity, policy decisions, identities, and system context Auditable decision history
Controls operate independently of the AI system Evidence that the system requesting authority could not set or override its own limits External authorization boundary

Where the kill switch ends

A kill switch is an emergency measure — used when loss of control is imminent or suspected. Enterprise-grade control starts earlier: contain the agent, evaluate every attempted action, enforce policy before execution, and revoke authority the moment conditions change.

The goal is not merely to stop an AI system after control is lost. It is to prevent unauthorized action before emergency shutdown becomes necessary.


SCOPE NOTE

This map does not claim compliance with standards that have not yet been written. It identifies the operational evidence any credible independent-verification regime will need to see.

SOURCE

California Executive Order N-9-26 (signed September 18, 2026) directs the Government Operations Agency, in consultation with the Governor’s Office of Emergency Services, to recommend, by November 16, 2026, whether to require onsite independent verification organizations, independently verified safety frameworks, an independently tested frontier-model kill switch, and an expanded definition of reportable loss-of-control incidents.