Insight

California’s New Executive Order Establishes New AI Vendor Certification and Procurement Requirements

Client Alerts

On March 30, 2026, California Governor Gavin Newsom signed Executive Order N-5-26 (the “Order”), directing state agencies to develop new artificial intelligence (“AI”) vendor certification standards, implement enhanced procurement safeguards, and expand AI governance infrastructure within state government. Companies that provide, or are considering providing, AI systems or services to California state agencies should evaluate the Order’s requirements and prepare for changes to vendor qualification standards expected to take shape by late July 2026. Given California’s role as the world’s fourth-largest economy and home to a significant concentration of AI companies, its procurement policies often influence broader market practices beyond state government contracting.

The Order is the latest step in California’s evolving AI governance framework, building on California’s Executive Order N-12-23 (September 2023), which directed state agencies to develop responsible processes for generative AI adoption, and the Transparency in Frontier AI Act (SB 53) (effective January 1, 2026),  requiring large AI developers to establish safety frameworks, publish transparency reports, and report critical incidents to state authorities.

The Order comes amid active federal efforts to define a parallel AI regulatory approach: a July 2025 executive order directed federal agencies to avoid AI systems incorporating certain social or political value frameworks; a December 2025 executive order directed the Department of Justice to establish a task force focused on evaluating state AI laws; a National AI Legislative Framework that was released in March 2026; and the Pentagon’s recent supply-chain risk designations affecting certain AI companies. How federal and state requirements will interact as both continue to develop remains an open question.

Key Provisions

New AI Vendor Certification Framework

Within 120 days, California’s Department of General Services (“DGS”) and Department of Technology (“CDT”) must submit recommendations for new AI vendor certification standards covering measures to protect public safety and prevent misuse of AI technology. The Order identifies areas that certifications must address, including prevention of illegal content distribution, harmful bias governance, and risks of civil rights or civil liberties violations such as unlawful surveillance. Once adopted, these standards will apply to vendors seeking to contract with California state agencies.

Independent Review of Federal Supply-Chain Risk Designations

CDT’s Chief Information Security Officer (“CISO”) must independently evaluate any federal supply-chain risk designations affecting AI companies. If the CISO concludes a designation lacks adequate justification, DGS and CDT will issue guidance permitting continued state procurement from the affected vendor. The legal boundaries between state procurement authority and federal national security determinations remain unsettled, and the Order does not address how California would respond if federal authorities assert grounds that preclude state override — an open question for affected companies.

Enhanced Contractor Responsibility Provisions

The California Government Operations Agency (“GovOps”)  must recommend reforms within 120 days to establish grounds for disqualifying vendors judicially determined to have unlawfully undermined privacy rights or civil liberties. The focus on judicial determinations sets a comparatively high threshold. The Order does not create new private rights of action; enforcement is expected to rely on existing procurement law authorities, including suspension and debarment processes.

AI Adoption and Governance Infrastructure

Multiple agencies, including GovOps, CDT, the Office of Data and Innovation, DGS, and California Department of Human Resources, must within 120 days facilitate state employee access to vetted generative AI tools, update the State Digital Strategy, develop a life-events-based AI government services portal, expand AI training programs, and publish a data minimization toolkit for departments handling sensitive data.

Watermarking Guidance for AI-Generated Content

CDT must issue guidance within 120 days on watermarking AI-generated or AI-manipulated images and video, consistent with California Business and Professions Code sections 22757.2 and 22757.3, covering technical standards, applicability, and compliance verification.

Implications

The Order creates immediate planning obligations and medium-term compliance requirements for companies operating in California’s AI vendor ecosystem. The 120-day timeline means draft certification standards, contractor responsibility reforms, and watermarking guidance should emerge by late July 2026.

Companies currently under contract with California state agencies are not immediately subject to new certification requirements as existing contracts are governed by their current terms. However, companies with contract renewals, pending bids, or anticipated opportunities in the California market should assess whether their current AI governance frameworks, bias testing protocols, and content moderation policies are likely to satisfy the certification criteria being developed.

Out-of-state vendors contracting with California agencies also fall within the Order’s scope. The certification framework applies to entities seeking to do business with the state, regardless of where they are headquartered.

The independent review mechanism for federal supply-chain designations introduces a novel procurement dynamic. If California and federal authorities reach conflicting conclusions about the same vendor’s risk profile, affected companies may find themselves navigating inconsistent procurement eligibility determinations across government customers. The legal authority supporting California’s ability to disregard federal national security-based designations has not been tested and may be subject to challenge.

More broadly, the simultaneous development of federal and state AI regulatory frameworks creates potential for tension that companies should monitor and questions as to whether federal action would preempt state procurement requirements.

For companies subject to SB 53’s transparency and safety framework requirements, the Order adds a procurement dimension to existing compliance obligations. Demonstrating robust safety frameworks and transparency practices under SB 53 may position companies favorably in the forthcoming certification process, though the two frameworks operate independently.

Recommended Actions

Inventory California Government Contracts and Pipeline Opportunities. Companies should identify current contracts with California state agencies, anticipated renewals, and active bids. Understanding the scope of California government exposure is a prerequisite to assessing compliance obligations under forthcoming certification standards.

Review Existing AI Governance Frameworks. The Order identifies illegal content, harmful bias, and civil liberties risks as among the areas certification must address, though the final certification structure has not yet been determined. These enumerated examples provide a useful starting point for self-assessment. Companies can begin evaluating existing bias testing methodologies, content moderation policies, and civil rights risk assessments against these criteria and identify gaps before draft standards are released.

Monitor Agency Proceedings and Comment Opportunities. DGS, CDT, and GovOps will develop certification recommendations and contractor responsibility reforms over the coming months. Monitoring agency proceedings and considering participation during public comment periods can help shape standards before they are finalized.

Assess Exposure to Federal Supply-Chain Risk Designations. Companies currently subject to or at risk of federal supply-chain designations should evaluate how California’s independent review mechanism may affect their state procurement eligibility and monitor developments in the federal-state dynamic on this issue. In addition, Companies engaged in both federal and California state government contracting should monitor how evolving federal AI requirements (e.g., the National AI Legislative Framework) create compliance considerations that interact with California’s forthcoming certification standards.

Evaluate Watermarking Capabilities. Companies that generate or process AI-generated images or video as part of services provided to California agencies should assess current watermarking capabilities relative to the requirements of California Business and Professions Code sections 22757.2 and 22757.3 and anticipate the forthcoming CDT guidance.

Incorporate Regulatory Developments into AI Governance. Boards and compliance teams should treat the Order as part of a broader California AI regulatory framework that now includes SB 53 and is likely to expand. Incorporating these developments into ongoing AI governance and risk oversight discussions, rather than on an ad hoc basis, will improve readiness as standards are finalized.

Conclusion

Executive Order N-5-26 reflects California’s continued effort to shape AI governance through the levers of public procurement and contractor qualification. Its immediate legal effect is limited, as implementing standards will take months to develop, but the Order establishes a framework and timeline that affected companies should begin preparing for now. The intersection of state procurement requirements, existing AI legislation, and evolving federal-state dynamics makes this an area requiring close attention.


This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.

Discover our latest:

Insights

CLE Events

Texas Reincorporation 101: Recent Developments and Key Considerations for Boards

Join Vinson & Elkins and FTI Consulting for a webinar on the growing trend of companies reincorporating to Texas.

October 1, 2026

October 1, 2026 • 1-minute read

CLE Events

Financing and Bankability of Data Center Projects

This program will examine the key legal and commercial considerations for financing data center projects, with a focus on what makes these projects bankable for lenders and investors.

September 29, 2026

September 29, 2026 • 1-minute read

Events

Paige Anderson to Speak on BARBRI Webinar

Partner Paige Anderson will speak on BARBRI’s live video CLE program, “Mastering Public and Private REITs: Key Tax, Structuring, Financing, …

September 22, 2026

September 22, 2026 • 1-minute read

Events

Paige Anderson and Vinay Prabhakar to Present on REIT Tax and Data Centers in Upcoming myLawCLE Webinar

Partners Paige Anderson and Vinay Prabhakar will present on myLawCLE’s live CLE program, “REIT Tax in the Data Center Era: …

September 18, 2026

September 18, 2026 • 1-minute read

Articles

Four Antitrust Pathways to AI Lab Coordination

The debate over AI lab coordination has collapsed into a false binary. There are at least four paths forward. In …

September 17, 2026

September 17, 2026 • 8-minute read

News & Achievements
V&E

Get in Touch

Thoughts or questions? Send us a note, and we’ll connect you with the right person.

The ESG GC: How Your Role as Chief Legal Officer is Integral To Your Company’s ESG Efforts Background Image