AI Regulation Tracker · New York State (state-chartered banks, foreign bank branches and agencies, insurers, money transmitters, virtual-currency licensees, and other DFS-licensed entities)

How does the NY DFS regulate AI in banking?

Last updated Aug 26, 2026 · Updated as rules change

The New York State Department of Financial Services regulates AI in banking mainly through its cybersecurity regulation, 23 NYCRR Part 500, rather than a standalone AI rule. Its October 16, 2024 Industry Letter tells every DFS-regulated entity to fold AI-specific threats — deepfake social engineering, AI-accelerated attacks, exposure of data used to train AI, and AI supply-chain risk — into the Part 500 risk assessments, MFA, training, and third-party controls they already run, and its May 21, 2026 letter on frontier AI models tells CISOs to compress patching timelines and review AI-generated code before the next generation of vulnerability-finding models becomes widely available. For AI in underwriting and pricing, DFS's Insurance Circular Letter No. 7 (2024) requires disparate-impact testing, board-level governance, and specific adverse-action reasons — binding on insurers, including bank-owned ones, but not on bank lending.

Full nameNew York State Department of Financial Services
RoleState prudential, insurance, and cybersecurity regulator
Force on banksSupervisory guidance
Applies toRoughly 3,000 DFS-licensed or -chartered entities: New York state-chartered banks and trust companies, New York branches and agencies of foreign banks, licensed lenders, mortgage companies, money transmitters, virtual-currency (BitLicense) firms, and every insurer authorized in New York — including bank-owned insurers and agencies
Key document23 NYCRR Part 500 (Second Amendment effective Nov 1, 2023; fully phased in Nov 1, 2025) as applied to AI by the Oct 16, 2024 Industry Letter
Latest moveMay 21, 2026: two Industry Letters on frontier AI model cyber risk and measures to take in a heightened threat environment
Documents tracked8 · all documents →

DFS is the most consequential state financial regulator in the United States because almost every large bank has a New York charter, branch, or agency, and because Part 500 — first effective March 1, 2017 and substantially amended on November 1, 2023 — is the template other state and federal cyber rules have borrowed from. DFS has chosen to regulate AI by interpretation of Part 500 rather than by writing an AI rule: the October 2024 Industry Letter and the two May 21, 2026 Industry Letters each state that they create no new legal requirements, yet each maps AI risks onto specific Part 500 sections that DFS examines against and has enforced with seven- and eight-figure penalties.

On the conduct side, DFS's Insurance Circular Letter No. 7 (2024) is one of the most detailed US supervisory statements on algorithmic fairness: it defines 'artificial intelligence systems' and 'external consumer data and information sources', requires a three-step disparate-impact analysis with an annual search for less discriminatory alternatives, holds insurers fully responsible for vendor models, and requires that adverse-action reasons name the actual data relied on. Its scope is insurers, not banks, but bank holding companies with insurance subsidiaries and bank-affiliated agencies are directly caught, and the analysis closely tracks what the CFPB expects under ECOA. Acting Superintendent Kaitlin Asrow, who took over on October 18, 2025, told the New York Assembly in December 2025 that DFS intends to keep applying technology-neutral law through guidance and examinations rather than write bespoke AI rules unless new risks require it.

What has the NY DFS actually published on AI?

DateDocumentStatus
May 21, 2026DFS Frontier AI Models Industry Letter (May 2026)Heightened Cybersecurity Risks Associated with Frontier AI ModelsIn force
May 21, 2026DFS Heightened Threat Environment Guidance (May 2026)Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat EnvironmentIn force
Dec 16, 2025Asrow Assembly Statement on AI in Insurance (Dec 2025)Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and PricingFinal
Oct 16, 2024DFS AI Cybersecurity Industry Letter (Oct 2024)Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related RisksIn force
Jul 11, 2024Insurance Circular Letter No. 7 (2024)Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingIn force
May 30, 2024DFS Virtual Currency Customer Service Guidance (May 2024)Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities)In force
Jan 17, 2024DFS Proposed AI Insurance Circular Letter (Jan 2024)Proposed Insurance Circular Letter on the Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and PricingSuperseded
Nov 1, 202323 NYCRR Part 500Cybersecurity Requirements for Financial Services Companies (Second Amendment)In force
DateTypeDocument / event
May 21, 2026LetterDFS Frontier AI Models Industry Letter (May 2026) — Heightened Cybersecurity Risks Associated with Frontier AI Models. On May 21, 2026, DFS issued an Industry Letter warning that 'frontier AI models' able to identify vulnerabilities and build exploits at unprecedented speed and scale will soon become widely available, and directing regulated entities to prepare before they do. source ↗
May 21, 2026GuidanceDFS Heightened Threat Environment Guidance (May 2026) — Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment. Issued May 21, 2026 as the companion to DFS's frontier-AI letter, this guidance defines a 'heightened cybersecurity threat environment' as one where risks are significantly elevated with a high likelihood of impacting information systems, nonpublic information, or operations — expressly including the arrival of frontier AI models — and lists the measures DFS expects firms to consider in three areas: reducing the attack surface, improving threat detection and readiness, and improving resilience and response. source ↗
Dec 22, 2025MilestoneRAISE Act signed; DFS to house frontier-AI oversight office. Governor Hochul signs the Responsible AI Safety and Education Act, which requires large frontier-model developers to publish safety protocols and report critical harm incidents within 72 hours, and places a new oversight office inside DFS to assess developers and issue annual transparency reports.
Dec 16, 2025SpeechAsrow Assembly Statement on AI in Insurance (Dec 2025) — Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and Pricing. On December 16, 2025, Acting Superintendent Kaitlin Asrow told the New York Assembly's Insurance and Science and Technology committees that DFS applies existing, technology-neutral law to AI — 'the core regulatory obligations are the same for manual processes as they are for AI models' — and that it has integrated review of new AI systems and datasets into its examinations. source ↗
Nov 1, 2025MilestoneFinal Part 500 Second Amendment provisions take effect. Universal multi-factor authentication (§500.12) and the asset-inventory requirement (§500.13(a)) — the two controls the October 2024 AI letter leans on most — become mandatory for all covered entities.
Oct 18, 2025MilestoneKaitlin Asrow becomes Acting Superintendent. Adrienne Harris departs after four years; Asrow, a former Federal Reserve supervisor of bank technology use, takes over and later tells the Assembly DFS will apply technology-neutral law to AI through guidance and exams rather than new AI-specific rules.
Oct 16, 2024LetterDFS AI Cybersecurity Industry Letter (Oct 2024) — Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks. On October 16, 2024, DFS issued an Industry Letter telling every DFS-regulated entity how to address AI-related cyber risk under 23 NYCRR Part 500. source ↗
Jul 11, 2024CircularInsurance Circular Letter No. 7 (2024) — Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing. Insurance Circular Letter No. source ↗
May 30, 2024LetterDFS Virtual Currency Customer Service Guidance (May 2024) — Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities). DFS's May 30, 2024 Industry Letter to virtual currency entities is its only guidance so far that sets rules for AI chatbots in customer service. source ↗
Jan 17, 2024ConsultationDFS Proposed AI Insurance Circular Letter (Jan 2024) — Proposed Insurance Circular Letter on the Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing. On January 17, 2024, DFS published for comment a proposed insurance circular letter on AI systems and external consumer data in underwriting and pricing, with comments due March 17, 2024. source ↗
Nov 1, 2023Regulation23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies (Second Amendment). 23 NYCRR Part 500 is the New York cybersecurity regulation that all of DFS's AI guidance hangs on. source ↗
  • Whether the new RAISE Act oversight office inside DFS produces any spillover expectations for banks that deploy frontier models through vendors
  • Part 500 examinations and enforcement in 2026–27 testing whether firms actually documented AI-enabled social engineering, deepfake-resistant MFA, and AI-vendor risk in their §500.9 risk assessments
  • Any move by DFS to extend Circular Letter No. 7-style disparate-impact testing beyond insurance to lenders, or to write AI-specific requirements — which Asrow said in December 2025 remains possible 'as new risks arise'
  • Follow-up to the May 2026 frontier-AI letter once vulnerability-finding models are broadly available, including any expected patching timelines

Does NYDFS have an AI regulation for banks?

No standalone rule. DFS regulates AI in banks through 23 NYCRR Part 500, its cybersecurity regulation, as interpreted by the October 16, 2024 Industry Letter on AI cyber risks and the May 21, 2026 Industry Letter on frontier AI models. Both say they create no new requirements but map AI risks onto sections DFS examines and enforces.

Does Insurance Circular Letter No. 7 (2024) apply to banks?

Only to insurers authorized in New York, Article 43 corporations, HMOs, fraternal benefit societies, and the State Insurance Fund. A bank's insurance subsidiary is covered for its underwriting and pricing; the bank's lending is not. The letter also does not cover marketing or claims handling.

What does NYDFS expect banks to do about AI deepfakes?

Treat AI-enabled social engineering as a Part 500 risk: include it in the annual risk assessment, train all staff on deepfake voice/video/text attacks, verify unusual requests through separate channels, and use MFA that is resistant to AI manipulation — DFS specifically discourages SMS, voice, and video-based authentication in favor of digital certificates or hardware keys.

Follow every move these regulators make

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →