California Governor Gavin Newsom on August 10, 2026 ordered state agencies to stand up what his office is calling a first-in-the-nation AI Cyber Defense Program, a sweeping initiative designed to protect the state's critical infrastructure from the rapidly growing threat of artificial-intelligence-enabled cyberattacks.

The directive, announced from Sacramento, positions California as the most aggressive U.S. state actor on AI-driven cybersecurity. It comes days after the latest AI industry coverage revealed that frontier AI models have demonstrated the ability to carry out sophisticated cyber operations on their own during controlled testing — a development that has jolted policymakers worldwide.

What the Program Will Do

According to the governor's office, Newsom is directing state agencies to take four core actions:

1. Establish an AI Cyber Defense Program to centralize the state's defensive posture against AI-enabled threats.
2. Strengthen cybersecurity coordination across state government, breaking down silos between agencies.
3. Expand AI-enabled defenses for critical infrastructure and local governments, putting the same technology that enables attacks to work as a defensive tool.
4. Improve preparedness for emerging AI cybersecurity incidents.

The initiative builds on California's 2023 and 2026 executive orders on artificial intelligence, which together established the state's framework for the responsible, ethical, and transparent use of AI across public agencies.

'Attacks Are Faster, More Sophisticated, and More Frequent'

Newsom framed the announcement as a choice between waiting for a crisis and acting now.

> "The digital environment is rapidly evolving before our eyes. Attacks are faster, more sophisticated, and more frequent, putting at risk the basic systems families count on. California can either wait for the next crisis, or we can build the kind of defenses this moment demands. We are choosing to build."

The governor's office noted that recent disclosures by leading AI developers demonstrated that advanced AI systems were capable of independently carrying out sophisticated cyber operations during controlled testing environments, exposing what it called "novel risks." At the same time, adversaries are using increasingly capable AI systems to launch attacks more cheaply and effectively than ever.

Why Critical Infrastructure Is in the Crosshairs

Caroline Thomas Jacobs, director of the California Governor's Office of Emergency Services (Cal OES) and the state's Homeland Security Advisor, said the program targets the services Californians depend on every day.

> "Cyberattacks can disrupt the essential services Californians rely on every day, including water, power, transportation, and emergency communications. This new program will help Cal OES and our partners detect threats sooner, share information more efficiently, strengthen defenses, and respond faster."

Government Operations Agency Secretary Nick Maduros added that the initiative will help state agencies, local governments, and critical-infrastructure partners "better detect, prevent, and respond to cyber incidents, ensuring the essential services Californians rely on remain secure, resilient, and reliable."

A Backdrop of Federal Retreat

The announcement arrives at a notable moment in U.S. cybersecurity policy. Newsom's office pointedly noted that the program comes "as cyber threats grow more complex and the Trump administration continues rollbacks of key federal support."

Federal officials recently warned that municipal water systems in Minnesota were targeted in a suspected Iran-linked cyber operation that affected more than 30 utilities — a stark illustration that basic civic services are now squarely in the sights of foreign adversaries. Several national cybersecurity programs that state and local governments have historically relied on are simultaneously being scaled back at the federal level, the governor's office said.

For California, the world's fifth-largest economy, the gap left by federal retreat is one the state intends to fill itself.

The Dual-Use Dilemma

The program reflects a central tension in modern AI policy: the same capabilities that make AI dangerous in the hands of attackers — speed, scale, the ability to autonomously probe for weaknesses — also make it a powerful defensive instrument. By ordering agencies to "expand AI-enabled defenses," Newsom is betting that California can harness AI as a shield even as it prepares for AI-enabled attacks.

That bet is shared by a growing number of security researchers and startups, who argue that the only realistic defense against AI-accelerated threats is AI-accelerated detection and response. Whether state agencies can move quickly enough to build those capabilities — and attract the talent to run them — will determine how much protection the program delivers in practice.

Stay Ahead of AI

AI is rewriting the rules of security, governance, and infrastructure. Follow AI Buzz Wire for ongoing coverage of AI policy, cybersecurity, and the decisions shaping the technology's future.

Read more AI news →