AI Regulation Tracker · NY DFS · Regulation

What does 23 NYCRR Part 500 say about AI in banking?

Published Nov 1, 2023 · Last reviewed Sep 2, 2026

23 NYCRR Part 500 is the New York cybersecurity regulation that all of DFS's AI guidance hangs on. First effective March 1, 2017, it was substantially amended by a Second Amendment effective November 1, 2023, with the last provisions — universal multi-factor authentication (§500.12) and asset inventories (§500.13(a)) — mandatory from November 1, 2025. It requires a written cybersecurity program based on a documented risk assessment, a CISO, 72-hour incident notice, 24-hour notice of any extortion payment, and an annual certification signed by the CEO and CISO by April 15.

OFFICIAL TEXT: dfs.ny.gov · IN FORCE · NY DFS

Document23 NYCRR Part 500Cybersecurity Requirements for Financial Services Companies (Second Amendment)
Issued byNew York State Department of Financial Services
TypeRegulation
StatusIn force
PublishedNov 1, 2023
EffectiveNov 1, 2023
Applies toEvery person or entity operating under a DFS license, registration, charter, certificate, permit, or accreditation under the Banking Law, Insurance Law, or Financial Services Law; heightened 'Class A' duties for large companies; limited exemptions for small entities
Official sourcedfs.ny.gov
Use casesCybersecurity · Third-party & vendor AI · AI governance (general) · Data & privacy

What are the key points of 23 NYCRR Part 500?

  • Second Amendment effective Nov 1, 2023; §500.17 notice changes at 30 days; governance, incident response, BCDR at one year (Nov 1, 2024); vulnerability management, access privileges, and training at 18 months (May 1, 2025); MFA and asset inventory at two years (Nov 1, 2025).
  • Creates 'Class A companies' (at least $20 million in NY gross annual revenue in each of the last two years plus either 2,000+ employees or $1 billion+ global gross revenue) with added duties: independent audits, privileged-access management, and endpoint detection and response.
  • §500.17: notify the Superintendent within 72 hours of determining a cybersecurity incident at the entity, an affiliate, or a third-party service provider; notify within 24 hours of any extortion payment and explain it within 30 days.
  • §500.9 risk assessment must be documented, updated at least annually and on material change, and drive the entire program — the hook DFS uses to require AI-specific threats to be assessed.
  • §500.11 third-party service provider policy, §500.12 MFA, §500.13 data retention and asset inventory, §500.14 monitoring and annual training — the sections DFS's AI letters cite by number.
  • §500.17(b) annual certification of material compliance (or acknowledgment of non-compliance with a remediation plan) signed by the highest-ranking executive and the CISO by April 15.
  • §500.20 enforcement: DFS has imposed multi-million-dollar penalties, including a $2.25 million consent order against Delta Dental in April 2026, its first cyber enforcement of the year.

What did 23 NYCRR Part 500 change for banks?

Before the Second Amendment, Part 500 already required a risk-based program, but the 2023 rewrite added board-level oversight, Class A tiering, 24-hour ransom-payment notice, universal MFA, and CEO/CISO certification — turning it from a policy requirement into a control set DFS examines line by line. Because DFS regulates AI by reading these sections rather than writing new ones, Part 500 compliance is in practice the AI-cyber compliance standard for any bank with a New York charter, branch, or agency.

What does 23 NYCRR Part 500 require, who does it apply to, and what are the deadlines?

23 NYCRR Part 500 is the New York Department of Financial Services cybersecurity regulation. It applies to every 'covered entity' — any person operating under, or required to operate under, a DFS license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, Insurance Law or Financial Services Law, which includes New York-chartered banks, DFS-licensed branches and agencies of foreign banks, insurers, mortgage lenders and money transmitters. It requires a written cybersecurity program built on a risk assessment that is updated at least annually, a chief information security officer who reports to the board, multi-factor authentication for anyone accessing the entity's information systems, notice to the Superintendent within 72 hours of a cybersecurity incident and within 24 hours of any extortion payment, and an annual certification of material compliance filed by April 15. The Second Amendment took effect November 1, 2023 and its last provisions — universal MFA and asset inventories — became mandatory on November 1, 2025, so every requirement is now in force.

RuleAuthorityWhat it requiresApplies
§500.2 — Cybersecurity programNY DFSA written program based on the §500.9 risk assessment, designed to identify, protect against, detect, respond to and recover from cybersecurity events; Class A companies must also have it independently audited annually.In force
§500.3 — Cybersecurity policyNY DFSWritten policies and procedures approved at least annually by the senior governing body or a senior officer, covering the listed areas from data governance to vendor management.In force
§500.4 — CISO and senior governing bodyNY DFSA qualified CISO with adequate authority who reports in writing to the board at least annually; the board must have sufficient understanding of cybersecurity to exercise oversight.Since Nov 1, 2024
§500.5 — Vulnerability managementNY DFSAnnual penetration testing from inside and outside the network, automated scans plus manual review where scans cannot reach, and timely remediation prioritised by risk.Since May 1, 2025
§500.7 — Access privilegesNY DFSLeast-privilege access, privileged accounts limited and reviewed at least annually, prompt removal of unneeded access; Class A companies need privileged access management and automated blocking of common passwords.Since May 1, 2025
§500.9 — Risk assessmentNY DFSA documented risk assessment, reviewed and updated at least annually and whenever a change in business or technology materially affects cyber risk — the hook DFS uses to require AI-specific threats to be assessed.In force
§500.11 — Third-party service providersNY DFSWritten policies for identifying, assessing and contractually binding third parties that access systems or nonpublic information, with periodic reassessment.In force
§500.12 — Multi-factor authenticationNY DFSMFA for any individual accessing any information system of the covered entity; limited-exemption entities need it for remote access, privileged accounts and third-party application access.Since Nov 1, 2025
§500.13 — Asset inventory and data retentionNY DFSA complete, accurate inventory of information systems with owner, location, classification, support expiration and recovery objectives, plus policies for disposing of nonpublic information no longer needed.Since Nov 1, 2025
§500.14 — Monitoring and trainingNY DFSRisk-based monitoring of user activity, protection against malicious code, and at least annual cybersecurity awareness training that includes social engineering; Class A companies add endpoint detection and response and centralised logging.Since May 1, 2025
§500.15 — EncryptionNY DFSEncryption of nonpublic information in transit over external networks and at rest, with compensating controls for at-rest data only where encryption is infeasible and the CISO approves them.Since Nov 1, 2024
§500.16 — Incident response and business continuityNY DFSWritten incident response and business continuity and disaster recovery plans, tested at least annually, with backups isolated from network connections.Since Nov 1, 2024
§500.17 — Notices and annual certificationNY DFSNotice to the Superintendent within 72 hours of a cybersecurity incident (including at affiliates and third-party providers), within 24 hours of an extortion payment and a written explanation within 30 days; by April 15 each year, a certification of material compliance or an acknowledgment of non-compliance with a remediation plan, signed by the highest-ranking executive and the CISO.Since Dec 1, 2023
§500.19 — Limited exemptionsNY DFSReduced obligations for entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue from New York operations in each of the last three fiscal years, or less than $15 million in year-end total assets — still subject to the program, policy, access, risk assessment, third-party, MFA, retention, training, incident response and notice requirements.In force
Class A company (§500.1(d))NY DFSA covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from New York operations (including affiliates' New York operations) and either more than 2,000 employees averaged over the last two fiscal years or more than $1 billion in gross annual revenue from all operations, worldwide, including affiliates.In force
DFS industry letter on AI cybersecurity risksNY DFSDFS's October 16, 2024 letter maps AI-enabled threats (deepfake social engineering, AI-enhanced attacks, exposure of nonpublic information, vendor AI) onto existing Part 500 sections — risk assessments, third-party policies, MFA, monitoring and training — rather than adding new rules.Oct 2024
DFS industry letter on frontier AI modelsNY DFSMay 21, 2026 guidance on the cyber risks from frontier AI models, again framed as Part 500 obligations.May 2026

The compliance calendar comes from §500.22. The Second Amendment took effect November 1, 2023; new §500.17 notice requirements applied 30 days later (December 1, 2023); most other new requirements 180 days later (April 29, 2024); governance, encryption, incident response and the revised limited-exemption thresholds at one year (November 1, 2024); vulnerability scanning, access privileges, malicious-code protection and training at 18 months (May 1, 2025); and universal multi-factor authentication under §500.12 together with the asset inventory under §500.13(a) at two years (November 1, 2025). The first annual certification under the amended rule was due April 15, 2024. Nothing is still phasing in.

'Class A' is the tier that matters for large banks. The test is New York revenue of at least $20 million in each of the last two fiscal years (counting affiliates' New York operations) plus either more than 2,000 employees or more than $1 billion in global revenue, both averaged over the last two fiscal years and both counting affiliates wherever located. Class A companies must commission independent audits of their cybersecurity program, implement privileged access management with automated blocking of commonly used passwords, and deploy endpoint detection and response with centralised logging. Foreign banks with a DFS-licensed New York branch are commonly caught because the employee and revenue tests look at the whole group.

DFS regulates AI in cybersecurity by reading Part 500 rather than by writing AI rules. The October 2024 industry letter and the May 2026 letters on frontier AI models and the heightened threat environment each take a threat — deepfake voice and video social engineering, AI-accelerated vulnerability discovery, data exposure through AI tools, dependence on AI vendors — and point to the section that already covers it: §500.9 for assessing it, §500.11 for vendors, §500.12 for authentication that resists AI-generated impersonation, §500.14 for monitoring and training, §500.15 for encryption. That is why the annual §500.17 certification is, in practice, also a certification that AI-era threats have been assessed.

WHAT THIS MEANS IN PRACTICE

  • The annual certification signed on April 15 by the CEO and CISO is personal: it attests material compliance with every section, so the §500.9 risk assessment it rests on must have been updated within the year and must address the AI threats DFS has named.
  • Universal MFA has been mandatory since November 1, 2025 — the limited-exemption carve-outs (remote access, privileged accounts, third-party applications) apply only to §500.19 entities.
  • The 72-hour clock runs from determining that an incident has occurred, including at an affiliate or a third-party service provider; the 24-hour clock runs from an extortion payment, followed by the 30-day written explanation.
  • Test the Class A thresholds at group level every fiscal year; crossing them adds the independent audit, privileged access management and EDR duties for the following period.
  • Small covered entities lose the §500.19 exemption once they exceed any one of the three thresholds and then have 180 days to comply in full.

What are the key Part 500 compliance dates from the 2023 amendment?

Nov 1, 2023 effective; Dec 1, 2023 for new §500.17 notices; Nov 1, 2024 for governance, incident response, and business continuity; May 1, 2025 for vulnerability management, access privileges, malicious-code controls, and training; Nov 1, 2025 for universal MFA and asset inventory.

Who is a Class A company under Part 500?

A covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from New York operations (including affiliates' NY operations) and either more than 2,000 employees or over $1 billion in global gross annual revenue, averaged over the last two years.

DateDocumentStatus
May 21, 2026DFS Frontier AI Models Industry Letter (May 2026)Heightened Cybersecurity Risks Associated with Frontier AI ModelsIn force
May 21, 2026DFS Heightened Threat Environment Guidance (May 2026)Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat EnvironmentIn force
Dec 16, 2025Asrow Assembly Statement on AI in Insurance (Dec 2025)Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and PricingFinal
Oct 16, 2024DFS AI Cybersecurity Industry Letter (Oct 2024)Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related RisksIn force
Jul 11, 2024Insurance Circular Letter No. 7 (2024)Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingIn force
May 30, 2024DFS Virtual Currency Customer Service Guidance (May 2024)Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities)In force

Which banks' AI programmes does 23 NYCRR Part 500 reach?

10 of the 100 largest US banks profiled on this site cite 23 NYCRR Part 500 among the documents their AI work answers to.

Follow every document these regulators publish

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning