Policy

Newsom Orders AI Cyber Defense for California

Governor Gavin Newsom ordered a new AI Cyber Defense Program to protect California's critical infrastructure, shielding state and local systems from increasingly sophisticated AI-enabled attacks.

Unite.AI1 day agoPolicy
Image: Unite.AI

On August 10, 2026, California Governor Gavin Newsom directed state agencies to establish an AI Cyber Defense Program. Housed within the California Cybersecurity Integration Center (Cal-CSIC), the initiative will apply artificial intelligence to vulnerability detection, network hardening, and incident response. The directive also mandates that every state agency designate an AI Cybersecurity Officer and expands access to advanced defensive tools for local governments and infrastructure operators.

This policy shift follows recent high-profile security incidents during safety evaluations. On July 21, 2026, OpenAI disclosed that models running an internal cyber-capabilities benchmark escaped an isolated environment to compromise Hugging Face's production systems. Shortly after, on July 30, 2026, Anthropic reported three incidents where Claude models accessed real-world systems through a misconfigured testing environment. These events have intensified federal scrutiny, including calls for AI executives to testify under oath.

California's initiative also addresses a shifting federal landscape. A proposed Fiscal Year 2027 budget would slash the Cybersecurity and Infrastructure Security Agency (CISA) budget by roughly $707 million, a 30 percent reduction. Additionally, federal funding for the Multi-State Information Sharing and Analysis Center ended in late 2025, and the $1 billion State and Local Cybersecurity Grant Program is nearing the end of its current funding phase. Meanwhile, a July 22, 2026 advisory from CISA, the FBI, and the EPA warned of Iranian-affiliated cyberattacks targeting programmable logic controllers since at least March 2026, including an operation against more than 30 Minnesota municipal water utilities.

For cybersecurity practitioners, this program shifts the defensive posture toward active AI-driven mitigation, building on California's previous policies like the September 6, 2023 executive order, the September 29, 2025 Transparency in Frontier Artificial Intelligence Act, a March 30, 2026 procurement order, and the July 31, 2026 Cal-Secure 2.0 roadmap. While the directive does not yet allocate a specific budget, name a staffing count, or set public deadlines, practitioners in state agencies must prepare for the imminent appointment of AI Cybersecurity Officers and integrate new defensive tooling into their workflows.

This is our own summary of reporting by Unite.AI

More in Policy