From the journal

California Governor Newsom Issues Executive Order N-5-26 on AI Procurement Standards, March 2026

California Governor Gavin Newsom issued Executive Order N-5-26 on 30 March 2026. The order is in effect immediately upon issuance and directs the California Government Operations Agency (GovOps) to develop a plan for new state contracting processes and best practices for AI companies seeking state contracts. The order is at the executive direction stage: GovOps must produce the procurement plan within a specified period, and no statutory changes are required. The California Department of

3 min read

California Governor Gavin Newsom issued Executive Order N-5-26 on 30 March 2026. The order is in effect immediately upon issuance and directs the California Government Operations Agency (GovOps) to develop a plan for new state contracting processes and best practices for AI companies seeking state contracts. The order is at the executive direction stage: GovOps must produce the procurement plan within a specified period, and no statutory changes are required. The California Department of Technology is separately directed to produce recommendations and best practices for watermarking AI-generated images or manipulated video, consistent with existing state law.

Executive Order N-5-26 does not cite a specific statute as its primary authority. It operates under the Governor's general executive power under the California Constitution, Article V, Section 1. The order requires AI vendors that contract with the state to attest to, and explain, their policies and safeguards against: (a) exploitation or distribution of illegal content; (b) model bias or the absence of technology to prevent bias; and (c) violations of civil rights and free speech. The order also directs the state to separate its procurement authorization process from the federal government's process if necessary, and to use AI tools to improve state service delivery, increase transparency, and strengthen accountability.

AI companies seeking California state contracts must now prepare to comply with attestation and disclosure requirements under the forthcoming GovOps procurement plan. The order applies to companies doing business with any California state agency. Private-sector AI developers not seeking state contracts are not directly bound, but the order signals that California will use its purchasing power to set standards across the AI market. Companies will need to document their content safety policies, bias-prevention measures, and civil rights compliance in formats acceptable to state procurement offices once the GovOps plan is finalized.

The order explicitly enables the state to separate its AI procurement authorization from the federal government's processes if federal requirements conflict with California standards. This creates a potential bifurcated compliance path for AI vendors operating under both federal and California state contracts. The GovOps plan has not yet been published; the timelines for vendor attestation requirements will become clearer once GovOps delivers its recommendations. The watermarking directive to the California Department of Technology addresses AI-generated or manipulated audio-visual content and is framed as guidance consistent with existing California deepfake legislation.

Our firm advises AI companies on government contracting compliance, procurement policy, and regulatory readiness across U.S. state and federal markets. We maintain a partner network with California-licensed counsel and government affairs practitioners. We invite AI developers and technology vendors engaging with California public agencies to contact us for compliance assessment. We advise on: AI procurement compliance, government contracting attestation, AI bias and fairness documentation, deepfake and watermarking regulation, and state-federal regulatory divergence strategies.

Source: Executive Order N-5-26, Governor Gavin Newsom, State of California, signed 30 March 2026; available at https://www.gov.ca.gov/2026/03/30/as-trump-rolls-back-protections-governor-newsom-signs-first-of-its-kind-executive-order-to-strengthen-ai-protections-and-responsible-use/; confirmed current 1 May 2026.

The information provided is not legal, tax, investment, or accounting advice and should not be used as such. It is for discussion purposes only. Seek guidance from your own legal counsel and advisors on any matters. The views presented are those of the author and not any other individual or organization. Some parts of the text may be automatically generated. The author of this material makes no guarantees or warranties about the accuracy or completeness of the information.

AI Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.