California just wrote the AI rulebook. And before you ask — yes, the same California where Anthropic, OpenAI, Google, and Meta all have their headquarters. The state looked at the industry operating within its own borders, squinted, and said: "Someone should really regulate you guys." Then looked around, realized nobody else was volunteering, and grabbed the pen.
Governor Newsom signed an executive order this week establishing mandatory AI safety disclosures, transparency requirements for foundation models, and procurement standards for any AI system touching state government. It's the most comprehensive state-level AI regulation in the country. And the part that matters isn't what's in it — it's that thirty-seven other states are going to copy-paste it within eighteen months because writing original legislation is hard and California already did the homework.
This is the Brussels Effect, but for Sacramento. The European Union figured this out years ago with GDPR: regulate the biggest market and everyone else adopts your rules, because maintaining two compliance systems costs more than following the stricter one. California did the same thing with car emissions. Now they're doing it with AI.
And the timing. Oh, the timing.
This executive order drops the same week Anthropic is privately telling governments its newest model makes large-scale cyberattacks significantly more likely. The same week a hundred Baidu robotaxis froze on a highway in Wuhan and trapped passengers for two hours while the screen cheerfully suggested they keep their seatbelts fastened. The same week we discovered OpenAI was burning fifteen million dollars a day on a video product that earned in its entire lifetime what it spent in three and a half hours.
The rulebook showed up to a party where someone already set the kitchen on fire, someone else locked the guests in the car, and a third person was feeding the household budget directly into a paper shredder.
But here's the thing I keep coming back to: the rules aren't the interesting part. The interesting part is the admission. When a state writes regulation, it is officially saying: "We do not trust you to handle this yourselves." And based on this week? That is the most reasonable sentence anyone in government has produced all year.
The executive order requires AI companies to disclose training data sources, report safety incidents within 72 hours, and submit to third-party audits for systems deployed in critical infrastructure. None of this is radical. This is seatbelts. This is "wash your hands before returning to work." This is the absolute bare minimum, packaged as groundbreaking policy because the bar was on the floor.
And other states will copy it. Not because it's brilliant — because it exists. In a landscape where nobody has rules, the first set of rules becomes the default. Not by being good. By being first.
California didn't write the best AI rulebook. California wrote the only AI rulebook. And in regulation, "only" beats "best" every single time. ⚙️





