✕

IE11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

The Question Every California Agency Will Be Asked About AI

...in 2027 (and Why Most Can't Answer It Yet)

ae32505f78b7-6a3b791cd4ca847d713c2905_image__15___1_.png
Which AI tools are running in your department today, who is using them, for what, and under which policy?

Most California IT leaders can answer some of that. Very few can answer all of it, and almost none can answer it for last month as well as this one. That has been a manageable problem for three years. As of September 18, it is a problem with a deadline.

What Sacramento already expects from you


Before the new order, California agencies were already carrying more AI obligations than most realize, and every one of them assumes the agency knows its own AI footprint.

The 2023 generative AI executive order and the CDT guidelines that followed set the baseline: risk assessment, procurement review, and an inventory of high-risk generative AI uses reported to CDT. AB 302 turned the inventory into statute and widened it to high-risk automated decision systems, reported annually to the Legislature.

Then in March came Executive Order N-5-26, which gave DGS and CDT 120 days to develop vendor certification criteria on bias, civil rights, and content safety, and directed the state to expand employee access to vetted generative AI tools. That 120 days ran out in late July. Vendor attestations are now a live procurement question, and so is the flip side: the state is putting sanctioned AI in more employees’ hands, which means more use to govern, not less.

Local governments are not bound by every line of that, but county boards and city councils read the same headlines, and public records law applies to AI output regardless of what tool produced it. The question “are we using AI, and how” is already being asked in council chambers up and down the state.

Why the first answer is usually wrong


The state’s own experience with AB 302 is instructive. The first inventory, collected by survey in 2024, came back reporting no high-risk automated decision systems in use across state government. The 2025 round surveyed 182 agencies and four reported them, including the Employment Development Department and the Department of Corrections and Rehabilitation. The systems did not appear in a year. The method of finding them changed.

That is the pattern with every survey-based AI inventory. People report what they procured. They do not report the AI features that switched on inside the Microsoft 365 or Google Workspace tenant the agency already pays for. They do not report the browser extension a caseworker installed to summarize documents. They do not report the drift from the enterprise ChatGPT tenant to a personal account when the login got annoying. And nobody reports an agent, because most staff do not yet think of one as a tool.

In every agency deployment Darwin AI has done, the sanctioned inventory turned out to be a fraction of what was actually running. That is not a California problem or a small-agency problem. It is what happens when the inventory is a document and the environment is not.

What changed on September 18


Executive Order N-9-26 pulls forward two laws the Legislature passed this session. SB 813 created a framework for independent verification organizations that assess AI systems for safety and risk. AB 1405 created a state registry for AI auditors with standards for their independence and integrity. The order moves the IVO application requirements from January 2028 to May 2027, the auditor registry from January 2029 to December 2027, and gives GovOps and Cal OES until November 16 to recommend the next round, including on-site audits at frontier developers and an emergency shutoff for the most advanced models.

The direct targets are AI companies, not agencies. But California is building a licensed audit profession for AI, and audit professions do not stay pointed at one target. Once registered auditors exist with state-defined methods, they become the default answer to every “who checks this?” question that follows: vendor certifications under N-5-26, legislative oversight of AB 302 inventories, records disputes, grant conditions. The infrastructure being stood up for frontier models is the infrastructure that will eventually look at how AI is used inside government.
When that happens, the auditor will not ask whether you have a policy. They will ask for the record.

Can your agency produce the record? A five-line self-check


The agencies across the West that are ready did not get there by predicting Sacramento. They built governance that does not have to be rebuilt every time Sacramento moves. It comes down to five things, and each is a yes-or-no question you can answer today.
  • Is the inventory continuous or annual? Every AI tool in use, sanctioned or not, across local, embedded, and browser-based AI, discovered automatically and kept current. Darwin Govern maintains a continuously updated repository of government, enterprise, and consumer AI models so a new tool is recognized the day it shows up, not the next survey cycle.
  • Is policy enforced where AI is used, or only published? Darwin’s endpoint agent applies the agency’s own policy at the point of use: sensitive data protection, access controls by identity group, and enforcement of state-mandated application bans. The policy stops depending on every employee having read the memo.
  • Is risk classified as a by-product of operation, or as a project? Use-case and risk classification happen as people work, so the risk register reflects this week, not last quarter’s self-report.
  • Is there a retained, auditable record? Records retention aligned to the agency’s own schedule, with reporting on applications, use cases, and risks that can go to an auditor, a records officer, or a board without a scramble.
  • Does public transparency update itself? A public AI inventory that reflects the live record rather than a webpage someone has to remember to edit.
  • This is how the City of Corona built its governance program here in California, and it is the same platform Texas DIR uses at state scale: one baseline, established in the first 90 days, that keeps itself current as the tools, the policies, and the rules change underneath it.

The window is between now and November 16


Until GovOps delivers its recommendations, agencies have a rare quiet period where the direction is clear and the specifics are not fixed. That is the moment to establish the baseline, including the tools nobody sanctioned, and match each one to a policy.

For agencies that have not written that policy yet, Darwin offers a free AI Policy Wizard at policy.darwingov.com, aligned to the NIST AI Risk Management Framework and the GovAI Coalition framework. It is the fastest path to a defensible starting point. For agencies ready to move from paper to enforcement, Darwin Govern turns that policy into a living compliance record.

California has said what it plans to do about AI oversight and when. It will get there sooner than the statutes promised, because that is how the state operates on this subject now. The only choice left to an agency is whether the record exists before the auditors are registered, or gets reconstructed after.

Shelley Ballard, Western US Sales Lead, Darwin AI

About Darwin AI
Darwin AI builds AI governance and agentic workflow automation for state and local government. Darwin Govern gives agencies continuous visibility into every AI tool in use, enforces policy at the point of use, assesses risk, and maintains the auditable record that emerging state and federal requirements expect agencies to produce. Darwin LaunchPad delivers governed agentic workflows so agencies can put AI to work inside existing processes with the same controls in place. Darwin is backed by Insight Partners and works with agencies including Texas DIR, the Georgia Technology Authority, and the City of Corona. Learn more at darwingov.com.
AI Visibility, Control, and Compliance for State & Local Government