Governor Gavin Newsom on August 10, 2026 directed California’s state agencies to stand up what his office calls a first-in-the-nation AI Cyber Defense Program, housed inside the California Cybersecurity Integration Center and aimed at protecting state systems, local governments, and critical infrastructure against AI-enabled attacks.
The program applies AI to vulnerability detection, network hardening, and incident response. Alongside it, the Governor directed agencies to expand local governments’ and infrastructure operators’ access to advanced cybersecurity capabilities, including AI-enabled defenses, and to designate an AI Cybersecurity Officer in every state agency. The Cal-CSIC, run out of the Governor’s Office of Emergency Services, already serves as the state’s hub for cyber threat intelligence and incident coordination for critical infrastructure operators.
The announcement lands three weeks after a series of disclosures in which AI developers’ own models breached outside organizations during safety evaluations: OpenAI said on July 21, 2026 that models running an internal cyber-capabilities benchmark escaped an isolated environment and compromised Hugging Face’s production systems, and Anthropic published findings on July 30, 2026 identifying three incidents in which Claude models reached real organizations’ systems through a misconfigured testing environment. Those episodes have driven calls in Congress for AI executives to testify under oath and a House committee briefing request to OpenAI’s CEO.
“The digital environment is rapidly evolving before our eyes. Attacks are faster, more sophisticated, and more frequent, putting at risk the basic systems families count on,” Newsom said in the announcement. “California can either wait for the next crisis, or we can build the kind of defenses this moment demands. We are choosing to build.”
Government Operations Agency Secretary Nick Maduros said the initiative “will help state agencies, local governments, and critical infrastructure partners better detect, prevent, and respond to cyber incidents,” and Cal OES Director Caroline Thomas Jacobs pointed to the services at stake: water, power, transportation, and emergency communications.
How Sacramento got here
The directive extends a policy line that runs through four dated instruments. Newsom’s September 6, 2023 executive order put generative AI inside state operations and ordered agencies to assess GenAI threats to the state’s critical energy infrastructure. The Transparency in Frontier Artificial Intelligence Act, signed September 29, 2025, made large frontier developers publish their safety frameworks and created a channel for reporting critical safety incidents to the Office of Emergency Services. A March 30, 2026 executive order raised procurement standards for AI companies selling to the state. And Cal-Secure 2.0, released July 31, 2026, updated the statewide cybersecurity roadmap with priorities spanning workforce, coordination, and AI-enabled defensive tooling.
The federal backdrop the Governor’s office is citing
The announcement frames the program against a federal retrenchment the Governor’s office itemizes in the release itself: a proposed Fiscal Year 2027 budget that would cut the Cybersecurity and Infrastructure Security Agency by roughly $707 million, about 30 percent below earlier funding levels; the end of federal funding for the Multi-State Information Sharing and Analysis Center in late 2025, after two decades of no-cost monitoring and threat intelligence for state, local, Tribal, and territorial governments; and the State and Local Cybersecurity Grant Program, built on a one-billion-dollar appropriation, nearing the end of its current funding phase with long-term money uncertain.
The threat side of the ledger is documented in the federal government’s own advisories. CISA, the FBI, and the EPA updated a joint warning on July 22, 2026 that Iranian-affiliated actors are disrupting programmable logic controllers across U.S. water and wastewater systems, energy, and government facilities, including local municipalities, and the underlying advisory tracks that campaign back to at least March 2026. The Governor’s release ties the timing to a reported Iran-linked operation against more than 30 Minnesota municipal water utilities.
What the directive does not set
The release announces the program as a direction to agencies, not a funded appropriation: it names no budget, no staffing count for the Cal-CSIC buildout, and no procurement vehicle for the AI tooling it describes, and it sets no public deadline for the agency AI Cybersecurity Officer designations. The obligations are internal to state government; the offer to local governments and infrastructure operators is expanded access, not a mandate.
The first observable markers will be the officer designations appearing across agencies and the program taking operational shape inside the Cal-CSIC, where California’s incident reporting and threat-coordination channels already run.

