California is requiring every state agency to name a specific person responsible for defending against AI-related cyber threats.
On August 10, 2026, Gov. Gavin Newsom announced a statewide AI Cyber Defense Program with three directives. One directs state agencies to designate an AI Cybersecurity Officer. The other two establish the program within the California Cybersecurity Integration Center and expand AI-enabled defense access for local governments and critical infrastructure partners. The order builds on Newsom’s 2023 and March 30, 2026 AI executive orders.
The release frames the move against a federal warning, attributed to unnamed officials, that municipal water systems in Minnesota were targeted in a suspected Iran-linked operation affecting more than 30 utilities. The state also cites a proposed FY2027 federal budget that would cut CISA by roughly $707 million, about 30 percent, plus the end of federal funding for MS-ISAC, as reasons to act on its own.
For security leaders, the value is the org-design signal. California is pairing an operational program with a per-agency accountability role, a structure enterprise CISOs and governance officers can benchmark when deciding who owns AI-threat defense internally. However, the release specifies no timeline, budget, reporting lines, or required qualifications for the officers, so this is directional rather than operational. State CISOs should also watch the precedent of states filling gaps left by proposed federal cuts.



Leave a Reply