AI Regulation Tracker · NY DFS · Statute

What does New York RAISE Act say about AI in banking?

Published Dec 19, 2025 · Last reviewed Oct 5, 2026

New York's Responsible AI Safety and Education (RAISE) Act, signed by Governor Hochul on December 19, 2025 and finalized by a chapter amendment signed March 27, 2026 (Chapter 96 of 2026), takes effect January 1, 2027. It requires large frontier developers to publish safety frameworks, report critical safety incidents within 72 hours, file quarterly assessments, and register with a new oversight office, the Office of Digital Innovation, Governance, Integrity and Trust (DIGIT), inside the Department of Financial Services. It binds frontier model developers, not banks as deployers; DFS announced on September 21, 2026 that large developers will be directed to register starting in November 2026. Its penalties are up to $1 million for a first violation and $3 million for subsequent ones, enforced by the Attorney General. For banks the effect is indirect, as the law gives vendor-risk teams new disclosures from frontier AI suppliers.

OFFICIAL TEXT: dfs.ny.gov ↗ · FINAL · APPLIES FROM JAN 1, 2027 · NY DFS

DocumentNew York RAISE Act — Responsible AI Safety and Education (RAISE) Act, General Business Law Article 44-B (Chapter 699 of the Laws of 2025, as amended by Chapter 96 of the Laws of 2026)
Issued byNew York State Department of Financial Services
TypeStatute
StatusFinal · applies from Jan 1, 2027
PublishedDec 19, 2025
EffectiveJan 1, 2027
Applies toFrontier models developed, deployed or operating in whole or in part in New York: all frontier developers (more than 10^26 operations of training compute) for transparency reports and incident reporting, and large frontier developers (over $500 million in annual revenue) for frameworks, registration and assessments. It does not regulate banks as users of AI, and bank-licensed entities are covered only if they train a frontier model. DFS houses the new oversight office, which is why DFS-regulated firms follow it
Official sourcedfs.ny.gov ↗
Use casesThird-party & vendor AI · Generative & agentic AI · AI governance (general) · Cybersecurity

What are the key points of New York RAISE Act?

  • Enacted as Chapter 699 of the Laws of 2025 (S6953B/A6453B), announced as signed by the Governor on December 19, 2025, and then replaced and finalized by chapter amendment S8828/A9449, signed March 27, 2026 as Chapter 96 of the Laws of 2026; the amendment moved the effective date to January 1, 2027.
  • Article 44-B §1420 definitions mirror California's SB 53: 'frontier model' means a foundation model trained using more than 10^26 operations; 'large frontier developer' means annual gross revenues above $500 million with affiliates; the 'office' is an office within the Department of Financial Services reporting to the Superintendent.
  • §1421: large frontier developers must publish and follow a frontier AI framework, review it at least annually and publish material changes within 30 days; every frontier developer must publish a transparency report with each new or substantially modified frontier model; no materially false or misleading statements about catastrophic risk.
  • §1422: critical safety incidents must be reported to the office within 72 hours of a determination or of learning facts sufficient to establish a reasonable belief that one occurred, or within 24 hours to an appropriate authority for imminent risk of death or serious injury; large developers file catastrophic-risk assessment summaries from internal use every three months.
  • §1428: no large frontier developer may develop, deploy or operate a frontier model in whole or in part in New York without a current disclosure statement filed with the office and payment of its pro rata assessment; the statement is renewed every two years or on a transfer of ownership or material change, and the office may levy $1,000 a day for failure to file.
  • §1427: the Attorney General may seek civil penalties up to $1 million for a first violation and $3 million for each subsequent violation by a large frontier developer; no private right of action. §1429 gives the office rulemaking authority and allows it to consider additional reporting requirements.
  • §1422(7): from January 1, 2028 the office must produce an annual public report with anonymized incident information, relevant frontier-model safety information and recommended changes to the Act.
  • §1425 limits the Act to frontier models developed, deployed or operating in whole or in part in New York; §1426 excludes accredited colleges and universities doing academic AI research and the Empire AI consortium.

What did New York RAISE Act change for banks?

The RAISE Act makes New York the second state, after California's SB 53, to impose binding transparency and incident-reporting duties on frontier AI developers, with a shorter 72-hour incident window, registration fees and a standing oversight office. For banks nothing changes directly, but it puts DFS, already the supervisor of the state's banks, in charge of a new office with rulemaking and information-gathering power over the AI labs that supply them. It also arrives alongside DFS's May 2026 industry letter on cyber risks of frontier AI models, which is guidance for DFS-regulated firms, not part of the Act.

What does the New York RAISE Act require, and does it apply to banks?

The New York RAISE Act (General Business Law Article 44-B), effective January 1, 2027, requires frontier model developers to publish transparency reports, and large frontier developers (more than $500 million in annual revenue) to publish and follow a frontier AI framework, report critical safety incidents within 72 hours, file quarterly assessments of catastrophic risk from internal use, and register with a new oversight office inside the Department of Financial Services before developing, deploying or operating a frontier model in New York. Penalties run to $1 million for a first violation and $3 million for later ones, enforced by the Attorney General. It does not regulate banks as users of AI; DFS-regulated banks are affected only indirectly, through the disclosures and incident reporting required of the frontier developers they buy models from.

RuleAuthorityWhat it requiresApplies
GBL §1420 and §1425 — Scope and thresholds ↗NY DFSApplies to frontier models (more than 10^26 operations) developed, deployed or operating in whole or in part in New York; large frontier developers have more than $500 million in annual gross revenue.From January 1, 2027
GBL §1421(1)–(2) — Frontier AI framework ↗NY DFSLarge frontier developers publish and follow a framework covering standards, thresholds, mitigations, third-party assessment, weight security, incident response and governance, review it annually and publish changes within 30 days.From January 1, 2027
GBL §1421(3)–(4) — Transparency report and truthful statements ↗NY DFSPublish a transparency report with each new or substantially modified frontier model; do not make materially false or misleading statements about catastrophic risk or framework compliance.From January 1, 2027
GBL §1422(3) — Critical safety incidents ↗NY DFSReport critical safety incidents to the office within 72 hours of a determination or of reasonable belief, and within 24 hours to an appropriate authority where there is imminent risk of death or serious injury.From January 1, 2027
GBL §1422(2) — Internal-use risk assessments ↗NY DFSLarge frontier developers send the office summaries of catastrophic-risk assessments from internal use every three months or on an agreed schedule.From January 1, 2027
GBL §1428 — Disclosure statement and assessments ↗NY DFSLarge frontier developers must have a current disclosure statement on file (identity, New York addresses, owners, contacts), renewed every two years, and pay pro rata assessments; the office can levy $1,000 a day for failure to file.Registration directed from November 2026; statements from January 1, 2027
GBL §1427 — Penalties ↗NY DFSAttorney General civil penalties up to $1 million for a first violation and $3 million per subsequent violation; no private right of action.From January 1, 2027
GBL §1429 and §1422(7) — Rulemaking and annual report ↗NY DFSThe office may adopt rules and consider additional reporting; from January 1, 2028 it publishes an annual report with anonymized incident data and recommended changes to the Act.Rulemaking authority from enactment; first annual report from January 1, 2028

The Act was enacted in two steps. The December 2025 law (Chapter 699 of 2025) was signed with a chapter amendment agreed in advance; the amendment, S8828/A9449, repealed and replaced Article 44-B, adopted the thresholds and duties above, and set the effective date at January 1, 2027. It was introduced January 8, 2026, passed the Senate January 28 and the Assembly March 11, and was signed March 27, 2026 as Chapter 96. The Governor's release described the result as building on California's framework.

DFS hosts the oversight office but the Act's duties fall on AI developers, not on the banks, insurers and licensees DFS supervises. DFS's September 21, 2026 announcement says New York will direct large frontier developers to register starting in November 2026 and that the DIGIT office will oversee implementation; the Act also lets that office adopt rules and consider additional reporting requirements, so the operative detail may change through rulemaking. Penalties for failing to file a disclosure are administrative, while the Attorney General brings the substantive civil actions.

For banks the Act matters as vendor intelligence. Large AI suppliers will publish frameworks and transparency reports, and report incidents to a regulator in the same state that licenses many banks, but banks will not receive those reports. DFS's separate May 2026 industry letter on frontier AI cybersecurity risk, and its 23 NYCRR Part 500 requirements on third-party service providers, remain the instruments that bind DFS-regulated banks.

WHAT THIS MEANS IN PRACTICE

  • Do not treat the RAISE Act as a bank compliance obligation; log it in the AI third-party risk file as a source of vendor disclosures from January 2027.
  • Request frontier AI frameworks and transparency reports from model vendors and compare them with those required under California SB 53.
  • Write 72-hour incident notification, audit rights and cooperation duties into AI vendor contracts; the Act sends incident reports to the DIGIT office, not to bank customers.
  • Watch DFS and the DIGIT office for registration notices, rulemaking and any additional reporting requirements, which the Act authorizes.
  • Read the Act alongside DFS's frontier-AI cyber industry letter, which is the guidance that applies to DFS-regulated banks.

Does the New York RAISE Act apply to banks?

Not as users of AI. The RAISE Act regulates frontier model developers; banks are covered only if they train a frontier model with more than 10^26 operations. DFS hosts the oversight office, but the Act is separate from DFS's supervision of banks, which continues under Part 500 and AI guidance.

When does the New York RAISE Act take effect?

January 1, 2027. The original law was signed December 19, 2025 and the chapter amendment signed March 27, 2026 set that effective date. DFS said on September 21, 2026 that large frontier developers will be directed to register starting in November 2026, with disclosure statements due starting January 1, 2027.

What are the penalties under the RAISE Act?

The Attorney General may seek civil penalties of up to $1 million for a first violation and up to $3 million per subsequent violation by a large frontier developer. The oversight office may also levy $1,000 per day for failure to file a required disclosure statement. The Act creates no private right of action.

What is the DIGIT office at DFS?

It is the Office of Digital Innovation, Governance, Integrity and Trust, established within the Department of Financial Services, which the Governor's office says will oversee RAISE Act implementation. It receives incident reports, registrations and quarterly assessments from large frontier developers and publishes an annual report from 2028.

How does the RAISE Act compare with California SB 53?

Both cover frontier developers using the same 10^26 and $500 million thresholds. New York requires incident reports within 72 hours (California: 15 days), requires large developers to register and pay assessments to a standing DFS office, and allows penalties up to $3 million for repeat violations (California: up to $1 million per violation).

DateDocumentStatus
May 21, 2026DFS Frontier AI Models Industry Letter (May 2026) — Heightened Cybersecurity Risks Associated with Frontier AI ModelsIn force
May 21, 2026DFS Heightened Threat Environment Guidance (May 2026) — Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat EnvironmentIn force
Dec 16, 2025Asrow Assembly Statement on AI in Insurance (Dec 2025) — Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and PricingFinal
Oct 16, 2024DFS AI Cybersecurity Industry Letter (Oct 2024) — Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related RisksIn force
Jul 11, 2024Insurance Circular Letter No. 7 (2024) — Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingIn force
May 30, 2024DFS Virtual Currency Customer Service Guidance (May 2024) — Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities)In force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning