AI Regulation Tracker · NY DFS · Letter

What does DFS AI Cybersecurity Industry Letter (Oct 2024) say about AI in banking?

Published Oct 16, 2024 · Last reviewed Aug 26, 2026

On October 16, 2024, DFS issued an Industry Letter telling every DFS-regulated entity how to address AI-related cyber risk under 23 NYCRR Part 500. It identifies four risks — AI-enabled social engineering (deepfake voice, video, and text), AI-enhanced cyberattacks, exposure or theft of the large volumes of nonpublic information (including biometrics) used by AI, and AI supply-chain and vendor dependencies — and maps each to existing Part 500 obligations. It creates no new rule, but it states DFS's expectation that AI threats appear in risk assessments, training, MFA design, vendor diligence, and data-minimization programs.

DocumentDFS AI Cybersecurity Industry Letter (Oct 2024)Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks
Issued byNew York State Department of Financial Services
TypeLetter
StatusIn force
PublishedOct 16, 2024
EffectiveOct 16, 2024
Applies toAll entities regulated by DFS under the Banking, Insurance, or Financial Services Law ('Covered Entities' under Part 500)
Official sourcedfs.ny.gov
Use casesCybersecurity · Third-party & vendor AI · Fraud detection · Data & privacy · Generative & agentic AI

What are the key points of DFS AI Cybersecurity Industry Letter (Oct 2024)?

  • Four risks: two from attackers' use of AI (deepfake-driven social engineering; faster vulnerability discovery, malware variants, and lower skill barriers) and two from a firm's own AI use (concentration of NPI and biometric data; third-party and vendor dependencies).
  • Risk assessments (§§500.2, 500.3, 500.9) must address AI-specific threats, including the firm's own AI deployments and the AI tools its vendors use, and be updated at least annually or on material change.
  • Third-party service providers (§500.11): diligence on how vendors secure AI and NPI, contractual protections, and timely notice of cybersecurity events.
  • Access controls and MFA (§§500.7, 500.12): limit privileges by job function; DFS says SMS, voice, and video-based authentication are vulnerable to AI manipulation and points to digital certificates or physical security keys; universal MFA became mandatory Nov 1, 2025.
  • Training (§§500.10, 500.14): annual awareness training must cover deepfakes and AI social engineering, with procedures such as out-of-band verification of unusual requests; cybersecurity staff need training on AI-enhanced attacks and on deploying AI defensively.
  • Monitoring (§§500.5, 500.14): monitor for unauthorized access and, where AI tools such as chatbots or copilots are deployed, monitor queries and outputs for unusual behaviour and NPI leakage.
  • Data management (§500.13): minimize NPI retained for AI, maintain the asset and data inventory required by Nov 1, 2025, and secure biometric data that can be used to build deepfakes.

What did DFS AI Cybersecurity Industry Letter (Oct 2024) change for banks?

This was the first formal statement by a US financial regulator translating AI risk into a specific, examinable control set. It did not add obligations, but it converted 'AI risk' from a strategy topic into a Part 500 examination item: a bank with a New York presence now needs its documented risk assessment, training records, MFA architecture, and vendor contracts to show that AI-enabled threats were considered — and DFS has since layered its May 2026 frontier-AI letter on the same foundation.

Does the NYDFS AI letter impose new requirements?

No. It states that it does not impose new requirements beyond 23 NYCRR Part 500; it explains how DFS expects existing Part 500 obligations — risk assessment, vendor management, access controls, MFA, training, monitoring, data management — to be applied to AI-related risks.

What MFA does NYDFS recommend against AI deepfakes?

Forms that cannot be defeated by AI-generated audio or video: the letter flags SMS, voice, and video verification as vulnerable and suggests digital-certificate or physical security-key approaches, with MFA required for all authorized users from November 1, 2025.

DateDocumentStatus
May 21, 2026DFS Frontier AI Models Industry Letter (May 2026)Heightened Cybersecurity Risks Associated with Frontier AI ModelsIn force
May 21, 2026DFS Heightened Threat Environment Guidance (May 2026)Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat EnvironmentIn force
Dec 16, 2025Asrow Assembly Statement on AI in Insurance (Dec 2025)Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and PricingFinal
Jul 11, 2024Insurance Circular Letter No. 7 (2024)Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingIn force
May 30, 2024DFS Virtual Currency Customer Service Guidance (May 2024)Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities)In force
Jan 17, 2024DFS Proposed AI Insurance Circular Letter (Jan 2024)Proposed Insurance Circular Letter on the Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingSuperseded

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →