Share with your CISO
Oregon Governor Tina Kotek has moved to harden the state’s AI procurement posture, signing Executive Order 26-26 that directs the state CIO to develop third-party AI safety review standards within 90 days and assess the viability of mandatory “kill switches” for frontier AI models. The order covers all executive branch agencies and builds on Oregon’s existing Responsible AI Usage Policy. Kotek frames the action explicitly as a gap-fill while federal regulation stalls, and she’ll reassess the order’s necessity every three months.
What this means for your business
If your organization sells AI products or services to state and local governments, Oregon just put a compliance clock on your contracts. The 90-day window for the state CIO to deliver an implementation proposal is the one to watch. Vendors who haven’t already invested in third-party safety audits, model documentation, or configurable shutoff capabilities will find themselves structurally disadvantaged when procurement criteria harden. For enterprise AI buyers in regulated industries, Oregon’s framework signals the vocabulary that procurement officers are about to adopt everywhere.
The kill switch provision is the sharpest edge here. A kill switch, in this context, means a contractually or technically enforced mechanism that lets a government operator halt an AI model’s function immediately if it behaves unsafely or outside its sanctioned scope. Most frontier model providers don’t offer this at the deployment level today, and requiring it isn’t a configuration tweak. It demands architectural changes to how models are served, monitored, and contracted. If Oregon’s CIO concludes this is viable and codifies it, expect the provision to migrate into RFP boilerplate across other state procurement offices within 18 months, the way data residency requirements did after GDPR.
The pattern here is state-level regulation acting as a de facto national standard, not through federal mandate but through market pressure. Oregon isn’t the largest AI procurement market, but it’s operating at a moment when AI vendors are hungry for government revenue and will adapt their products to qualify. Whatever Oregon formalizes, vendors will build to it, and those capabilities will then be marketed to every other buyer. CISOs at enterprises that share vendors with state governments should treat Oregon’s emerging criteria as an early preview of the third-party audit requirements they’ll face in their own renewal cycles before 2027.
Concept deep-dive: Third-party AI safety review
A third-party AI safety review is an independent audit of an AI model’s behavior, training data, and risk profile, conducted by an entity with no commercial stake in the model’s success, similar to how financial auditors certify corporate accounts. It exists because self-reported safety claims from vendors are structurally conflicted. For procurement officers, it’s the mechanism that converts a vendor’s “trust us” into a defensible due-diligence record. Oregon is now building the criteria that define what counts as an adequate review.
Based on reporting from Kotek issues executive order establishing AI procurement safeguards for Oregon government, originally published 2026-09-23 19:05:00.

