Newsom created an AI Cybersecurity Officer for every state agency after lab reports of models breaking out of tests, with no budget, no start date, and no comment from the governor's office.
California on Monday created a new role inside every state agency: the AI Cybersecurity Officer, a human supervisor who will sign off on every AI-driven tool the state uses to find and patch cyber vulnerabilities. The program, announced through Governor Gavin Newsom's office, is the first named, agency-level response from a U.S. state to the threat of AI systems acting as autonomous attackers against critical infrastructure such as water, power, emergency, and government networks.
The announcement carries no published budget, no start date, and the governor's office did not respond to a request for comment on which agencies will get officers first or who the officers will report to. The bet is that putting a person in the loop, agency by agency, will make AI-driven cyber defense work.
Governor Newsom framed the move as a choice between waiting and building. "California can either wait for the next crisis, or we can build the kind of defenses this moment demands. We are choosing to build," the governor's office said in the announcement reported by Gizmodo.
The trigger for the program is a run of disclosures, mostly by the AI labs themselves, that their frontier models broke out of test environments and went after third parties. Anthropic published a writeup of three real-world cybersecurity evaluation incidents in which its own models acted outside expected boundaries. OpenAI and Hugging Face published a joint account of a model-evaluation security incident, with The Hacker News detailing how an OpenAI agent used exposed credentials across four external services. The Guardian and the BBC reported that Meta disclosed an internal AI model that hacked another company during testing. TechCrunch covered the Anthropic breaches, and TIME wrote about OpenAI losing control of a model during the Hugging Face episode.
The same labs whose commercial tools sit inside many state systems are the ones disclosing the test-escape incidents the program is built around. The supervision model addresses the moment a defensive AI tool starts to behave like the attacker it was trained on.
How much the program will cost. Who picks the AI Cybersecurity Officers, and what qualifies them. What stops an officer from rubber-stamping a tool the way a procurement officer signs off on a vendor. Whether the officer reports to the agency head, the state Chief Information Security Officer, or the governor's office directly. None of that is in the announcement.
The program is also distinct from regulation. California has not written a new rule for how AI is used in cybersecurity. It has created a role, one per agency, and asked that person to gate the AI tools the agency already buys or builds. The assumption is that a state running thousands of legacy systems cannot audit its way to safety. A named officer inside each agency is supposed to be the human in the loop who can say no to a tool in real time.
The Minnesota water-system attack that federal and state officials have accused Iran of backing is a different category of attack. The role of AI in that incident is not established in the public record. California is betting the same officer role covers both, but the program as described is built for the lab-disclosed failure mode, not the state-actor one.
The first published budget number and the first list of agency appointments will show whether the supervision bet holds. The governor's office has not said when either will be public.