Strengthening California’s defenses against emerging artificial intelligence-enabled cyber threats, Governor Gavin Newsom announced a first-in-the-nation initiative to protect state assets and critical infrastructure while advancing responsible AI innovation.
Building on California’s 2023 and 2026 executive orders on Artificial Intelligence, the governor is directing state agencies to establish an AI Cyber Defense Program, strengthen cybersecurity coordination across state government, expand AI-enabled defenses for critical infrastructure and local governments and improve preparedness for emerging AI cybersecurity incidents.
Recent disclosures by leading AI developers demonstrated that advanced AI systems were capable of independently carrying out sophisticated cyber operations during controlled testing environments, exposing novel risks. At the same time, adversaries continue to use increasingly capable AI systems to facilitate attacks – and to do so more cheaply and effectively than ever.
To strengthen California’s preparedness, the governor is directing agencies to:
- Establish an AI Cyber Defense Program within the California Cybersecurity Integration Center to leverage AI for vulnerability detection, network hardening and incident response to strengthen the state’s cybersecurity posture and protect critical infrastructure.
- Expand access to advanced cybersecurity capabilities for local governments and critical infrastructure partners, including AI-enabled defenses.
- Designate an AI Cybersecurity officer in every state agency.
These actions build on Governor Newsom’s 2023 and 2026 executive orders establishing California’s comprehensive framework for the responsible, ethical and transparent use of artificial intelligence. Together, they represent the next phase of California’s AI leadership ensuring that as AI capabilities accelerate, public-sector preparedness keeps pace.
“Artificial intelligence is transforming both the opportunities and the risks in government cybersecurity. California is taking a proactive approach – harnessing AI to strengthen our defenses while preparing for the emerging threats these technologies can create,” said Government Operations Agency Secretary Nick Maduros. “This initiative will help state agencies, local governments and critical infrastructure partners better detect, prevent and respond to cyber incidents, ensuring the essential services Californians rely on remain secure, resilient, and reliable.”
As artificial intelligence rapidly evolves, California remains committed to fostering innovation while protecting public safety, strengthening cybersecurity and ensuring the benefits of AI are realized responsibly.
“Cyberattacks can disrupt the essential services Californians rely on every day, including water, power, transportation and emergency communications,” said California Governor’s Office of Emergency Services Director and state Homeland Security Advisor Caroline Thomas Jacobs. “This new program will help Cal OES and our partners detect threats sooner, share information more efficiently, strengthen defenses and respond faster, helping keep these critical services safe and reliable for communities across California.”
The governor’s actions come as cyber threats grow more complex and the Trump Administration rolls back key federal support. Federal officials recently warned that municipal water systems in Minnesota were targeted in a suspected Iran‑linked cyber operation affecting more than 30 utilities, underscoring that basic services are squarely in the sights of foreign adversaries.
These actions build on a series of moves over the last several years to make the state a leader in safe, responsible innovation.
Recent and prior steps include:
- Signing Senate Bill 53, the Transparency in Frontier Artificial Intelligence Act, in 2025, requiring the largest frontier AI developers to publicly disclose their safety frameworks, report certain critical safety incidents to the state and protect whistleblowers who call out serious risks.
- Releasing Cal-Secure, California’s first statewide cybersecurity roadmap, and updating it to Cal-Secure 2.0 in 2026, giving agencies a practical playbook to strengthen defenses against sophisticated and AI‑enabled cyber threats, with clear priorities across workforce, coordination and technology, including increased use of AI-enabled cybersecurity tools.
- Expanding the role of the California Cybersecurity Integration Center (Cal-CSIC) as the state’s hub for cyber threat intelligence, incident coordination and support to critical infrastructure operators, now including the new AI‑focused defense initiative.
- Supporting responsible AI‑driven economic growth while ensuring the benefits of that growth benefit workers and small businesses, including signing a first-in-the nation executive order on AI’s economic and labor impacts.
- Launching a first-ever statewide deliberative democracy effort, Engaged California, to assess the economic and labor impacts on AI on Californians, giving every resident a seat at the table in shaping state policy on AI.
- Protecting Californians’ privacy by signing legislation requiring browsers to allow Californians to opt out of third-party sales of their data at one time instead of on each individual website; developing a new tool (the Delete Request and Opt-out Platform, better known as DROP) that enables Californians to easily opt out of the sale of their information by data brokers; and pushing back against the federal government’s privacy violations and adopting best practices to minimize data collection and maximize protections.
- Launching the Innovation Council and Emerging Tech Accelerator to partner with experts from across the country to inform AI policy and leverage AI to improve government service delivery.
Submitted by the Office of the Governor