Oregon’s AI order is a drafting mandate; procurement still needs an evidence gate
Executive Order 26-26 tells Oregon’s CIO to propose frontier-AI procurement standards and assess a kill-switch requirement within 90 days. Agencies still need measurable review criteria, exceptions and operating evidence.

What happened
On 23 September Governor Tina Kotek issued EO 26-26, effective immediately. It sets a policy preference for frontier models with independent third-party safety review, directs the state CIO to propose implementation within 90 days and requires assessment of a possible kill-switch requirement.
Why it matters
The order establishes direction, not a complete supplier test. Procurement teams must define eligible systems, acceptable reviewer independence, evidence freshness, deployment-specific controls, exceptions and what suspending a model means in a live service.
Oregon Executive Order 26-26, issued on 23 September, makes responsible procurement of frontier AI an immediate state policy and gives the state chief information officer 90 days to propose implementation. The proposal must develop standards or criteria for adequate independent third-party AI-safety review. The order also directs the state to assess whether a kill-switch requirement is viable.
The order takes effect immediately and is to be reassessed every three months, but its operational rules do not yet exist. Oregon already requires executive-branch AI tools to pass normal technology-investment and procurement review, including security, privacy and data-handling terms. The new act adds a frontier-model safety direction rather than replacing those controls.
Translate policy words into admissible evidence
The first drafting task is scope. Define frontier model using observable properties relevant to procurement: capability, autonomy, access to sensitive systems, tool authority and deployment scale. Avoid a vendor label that can be changed without changing risk. State whether the gate applies to a base model, a hosted service, a fine-tuned version and a system that adds retrieval or agents around the model.
Next define independent review. A usable criterion identifies reviewer conflicts, methods, model and system version, test environment, limitations, disclosure rights and the date after which evidence expires. A safety card or provider-funded evaluation can contribute evidence; it should not automatically satisfy independence. Require suppliers to state what was not tested and which results are not portable to the state's deployment.
The procurement file should map each material risk to evidence and an owner. For cybersecurity, that might include tool permissions, egress, secrets handling, prompt-injection tests and incident response. For public decisions, add data provenance, human authority, explanation, accessibility and appeal. A single composite safety score cannot substitute for this map.
Make the stop control a service contract
A kill switch is not one button inside a model. The state needs a documented sequence that can revoke credentials, disable integrations, block traffic, preserve records, notify service owners and switch to a safe manual or degraded mode. Test the sequence in the actual service. Measure detection-to-freeze time and ensure the supplier cannot silently restore access.
The counterargument is that stringent requirements could exclude smaller suppliers or lock the state into incumbents with expensive assurance programmes. Proportional tiers can reduce that risk. Low-authority pilots may use lighter evidence and strict isolation; systems affecting rights, money, safety or critical services need stronger review. Publish the rubric and allow equivalent evidence rather than naming one certification.
Exceptions require the same discipline. Record the statutory or operational need, unavailable alternatives, compensating controls, duration, approving official and exit date. Emergency acquisition should narrow authority and time, not erase auditability. Vendor confidentiality may limit publication of exploit details, but it should not prevent the state from publishing the review scope, conclusion, limitations and accountability route.
Oregon's direction is meaningful because procurement can convert abstract safety claims into contractual evidence. Yet the order itself does not prove any model safe and is not the final procurement rule. The Skills Intelligence glossary can support consistent terminology, while the decisive artefact is an additions-and-exceptions ledger linking each deployed version to current review and a tested stop path.
Set a change trigger as well as an initial gate. A new model version, tool connection, fine-tune, material prompt policy, data source or authority level should reopen the relevant evidence rather than inherit approval automatically. This prevents a procurement decision about one system from becoming permanent permission for a changing service.
The immediate decision is to draft the 90-day proposal as a testable admission gate. No frontier system should receive production authority merely because a review exists; it should pass a deployment-specific evidence map, named exception process and full interruption exercise.