# How does the NY DFS regulate AI in banking?

Source: https://www.bankingnewsai.com/ai-regulation/ny-dfs
Last updated: Oct 5, 2026

The New York State Department of Financial Services regulates AI in banking mainly through its cybersecurity regulation, 23 NYCRR Part 500, rather than a standalone AI rule. Its October 16, 2024 Industry Letter tells every DFS-regulated entity to fold AI-specific threats — deepfake social engineering, AI-accelerated attacks, exposure of data used to train AI, and AI supply-chain risk — into the Part 500 risk assessments, MFA, training, and third-party controls they already run, and its May 21, 2026 letter on frontier AI models tells CISOs to compress patching timelines and review AI-generated code before the next generation of vulnerability-finding models becomes widely available. For AI in underwriting and pricing, DFS's Insurance Circular Letter No. 7 (2024) requires disparate-impact testing, board-level governance, and specific adverse-action reasons — binding on insurers, including bank-owned ones, but not on bank lending.

## At a glance

| Field | Value |
| --- | --- |
| Full name | New York State Department of Financial Services |
| Jurisdiction | New York State (state-chartered banks, foreign bank branches and agencies, insurers, money transmitters, virtual-currency licensees, and other DFS-licensed entities) |
| Role | State prudential, insurance, and cybersecurity regulator |
| How binding | Supervisory guidance |
| Applies to | Roughly 3,000 DFS-licensed or -chartered entities: New York state-chartered banks and trust companies, New York branches and agencies of foreign banks, licensed lenders, mortgage companies, money transmitters, virtual-currency (BitLicense) firms, and every insurer authorized in New York — including bank-owned insurers and agencies |
| Key document | 23 NYCRR Part 500 (Second Amendment effective Nov 1, 2023; fully phased in Nov 1, 2025) as applied to AI by the Oct 16, 2024 Industry Letter |
| Latest move | Sep 21, 2026: Governor Hochul announces RAISE Act implementation next steps — frontier AI developer registration opens November 2026, full compliance from January 2027, and Marc Gilman named Deputy Director of DFS's new DIGIT office |

## Overview

DFS is the most consequential state financial regulator in the United States because almost every large bank has a New York charter, branch, or agency, and because Part 500 — first effective March 1, 2017 and substantially amended on November 1, 2023 — is the template other state and federal cyber rules have borrowed from. DFS has chosen to regulate AI by interpretation of Part 500 rather than by writing an AI rule: the October 2024 Industry Letter and the two May 21, 2026 Industry Letters each state that they create no new legal requirements, yet each maps AI risks onto specific Part 500 sections that DFS examines against and has enforced with seven- and eight-figure penalties.

On the conduct side, DFS's Insurance Circular Letter No. 7 (2024) is one of the most detailed US supervisory statements on algorithmic fairness: it defines 'artificial intelligence systems' and 'external consumer data and information sources', requires a three-step disparate-impact analysis with an annual search for less discriminatory alternatives, holds insurers fully responsible for vendor models, and requires that adverse-action reasons name the actual data relied on. Its scope is insurers, not banks, but bank holding companies with insurance subsidiaries and bank-affiliated agencies are directly caught, and the analysis closely tracks what the CFPB expects under ECOA. Acting Superintendent Kaitlin Asrow, who took over on October 18, 2025, told the New York Assembly in December 2025 that DFS intends to keep applying technology-neutral law through guidance and examinations rather than write bespoke AI rules unless new risks require it.

## What AI guidance has the New York DFS issued for regulated banks and insurers?

The New York State Department of Financial Services has not written an AI rule; it regulates AI through five pieces of guidance that hang on existing law. For every regulated entity — state-chartered banks, foreign-bank branches, licensed lenders, money transmitters, virtual-currency firms and insurers — the October 16, 2024 Industry Letter on cybersecurity risks arising from AI maps deepfake social engineering, AI-enhanced attacks, exposure of the data AI consumes, and AI supply-chain risk onto the obligations of the cybersecurity regulation 23 NYCRR Part 500. The May 21, 2026 Industry Letter on frontier AI models tells the same firms to shorten vulnerability remediation, map third-party dependencies, put human review on AI-generated code before deployment, strengthen logging and test resilience more often, with a companion letter on measures for a heightened threat environment. For insurers, Insurance Circular Letter No. 7 of July 11, 2024 requires disparate-impact testing, board-level governance, vendor accountability and specific adverse-action reasons for AI systems and external consumer data used in underwriting and pricing. For virtual-currency entities, the May 30, 2024 customer-service letter sets the three chatbot conditions: disclose the AI at the start, allow escalation to a human, and test the tool for accuracy. Acting Superintendent Kaitlin Asrow told the Assembly on December 16, 2025 that these, applied through technology-neutral examination, are DFS's AI framework and that no further AI rule is planned for now.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| 23 NYCRR Part 500 (Second Amendment) | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | The cybersecurity regulation every AI letter attaches to: risk-based programme, documented annual risk assessment, CISO, MFA, asset inventory, 72-hour incident notice, annual CEO/CISO certification; Class A companies add independent audits and privileged-access controls. | Effective Nov 1, 2023; last provisions Nov 1, 2025 | [23 NYCRR Part 500](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-23-nycrr-part-500) |
| Industry Letter: Cybersecurity Risks Arising from AI | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | AI threats must appear in Part 500 risk assessments, training, MFA design (SMS, voice and video factors are vulnerable to AI manipulation), vendor diligence and data-minimisation; covers the firm's own AI deployments and its vendors' AI. | Oct 16, 2024 | [DFS AI Cybersecurity Industry Letter (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-10-16-ai-cyber-risks) |
| Industry Letter: Heightened Cybersecurity Risks Associated with Frontier AI Models | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Shorter remediation timelines for firmware, hardware and software vulnerabilities; mapped third-party dependencies with coordinated patching; human oversight of AI-generated code before deployment; stronger logging and alerting; more frequent resilience testing. | May 21, 2026 | [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models) |
| Guidance on measures in a heightened cybersecurity threat environment | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Reduce the attack surface (known exploited vulnerabilities, phishing-resistant MFA, segmentation), improve detection and readiness, and improve resilience and response — with the arrival of frontier AI models expressly named as a trigger. | May 21, 2026 | [DFS Heightened Threat Environment Guidance (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-heightened-threat-environment) |
| Insurance Circular Letter No. 7 (2024) | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Insurers must show AI systems and external consumer data do not proxy protected classes, run a documented three-step disparate-impact analysis at least annually, place AI governance with the board and senior management, remain responsible for vendor models, and give specific reasons within 15 days of an adverse decision. | Jul 11, 2024 | [Insurance Circular Letter No. 7 (2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-insurance-circular-letter-2024-07) |
| Proposed insurance circular letter (Jan 2024) | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | The consultation draft that introduced the AIS and ECDIS definitions and the disparate-impact framework; finalised with clarifications as Circular Letter No. 7. | Jan 17, 2024 (comments to Mar 17, 2024) | [DFS Proposed AI Insurance Circular Letter (Jan 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-proposed-insurance-circular-letter-2024-01) |
| Industry Letter: Customer service requests and complaints (virtual-currency entities) | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Where AI is used in customer service: disclose it at the start of the interaction, allow escalation to a human for any request or complaint, and test and monitor the tool for accuracy; quarterly complaint tabulation by channel. | May 30, 2024 | [DFS Virtual Currency Customer Service Guidance (May 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-05-30-vce-customer-service) |
| Acting Superintendent Asrow, Assembly hearing statement | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | DFS applies existing, technology-neutral law to AI, reviews new AI systems and datasets in examinations, cites the three letters above as its framework, and sees no immediate need for additional AI rules. | Dec 16, 2025 | [Asrow Assembly Statement on AI in Insurance (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-asrow-assembly-statement-2025-12-16-ai-insurance) |
| CFPB issue spotlight on chatbots | [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb) | The federal counterpart to DFS's chatbot conditions: institutions stay responsible for accurate answers, dispute recognition and access to a human whatever technology is used. | Jun 2023 | [CFPB Chatbots in Consumer Finance (issue spotlight, 2023)](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-chatbots-in-consumer-finance-2023) |

DFS is unusual among US financial regulators in having said, in writing and in testimony, exactly what its AI framework is. Asrow's December 2025 statement to the Assembly's Insurance and Science and Technology committees listed three pillars — the insurance circular letter, the virtual-currency chatbot guidance and the AI cybersecurity letter — and described the method: 'the core regulatory obligations are the same for manual processes as they are for AI models', enforced through examinations that now include review of new AI systems and external data sources. The two May 2026 letters extended the cyber pillar to frontier models. None of the five documents creates a new legal requirement; each tells regulated entities how DFS will read an existing one.

The reach is wider than New York. Roughly 3,000 entities are DFS-licensed or -chartered, including the New York branches and agencies of foreign banks and every insurer authorised in the state, so a large bank's insurance affiliate can be bound by Circular Letter No. 7 even though the bank's own lending is not. Part 500's annual certification, signed by the CEO and CISO by April 15, is the mechanism that turns the AI cyber letters into personal accountability: a firm certifying compliance is certifying that AI threats are in its risk assessment and that AI-generated code is reviewed before deployment. Part 500 was also the template that the NAIC's insurance data-security model law and several state regulations copied, which is why DFS guidance tends to travel.

What DFS has not done is as telling as what it has. There is no AI rule for bank lending, no algorithmic-underwriting guidance for banks equivalent to the insurance circular, and no supervisory statement on generative or agentic AI use inside banks beyond the code-review expectation in the frontier-models letter. Asrow left the door open to 'specific AI requirements as new risks arise'. For a bank the practical position is that DFS examines AI through Part 500 and through the technology-neutral consumer-protection and safety-and-soundness law it already enforces, and that the fastest-moving expectations are on the cyber side.

### What this means in practice

- Confirm the Part 500 risk assessment names AI threats explicitly — deepfake social engineering, AI-accelerated exploitation, the firm's own AI deployments and vendors' AI — before the next annual certification.
- Retire SMS, voice and video-based authentication factors where DFS says they are vulnerable to AI manipulation; the October 2024 letter points to digital certificates and hardware keys.
- Stand up the frontier-models controls now: a code-review gate for AI-generated code, a dependency map of critical providers with coordinated patching, and shorter remediation targets, all documented for the examiner.
- If the group has a New York-authorised insurer, run Circular Letter No. 7's three-step disparate-impact analysis on every AI underwriting or pricing model and keep the annual less-discriminatory-alternative search on file.
- Apply the chatbot conditions from the virtual-currency letter — disclosure, human escalation, accuracy testing — to any customer-facing AI, since DFS has cited them as its expectation and the CFPB says the same.

## What AI governance framework does New York require of regulated banks?

New York requires AI governance through 23 NYCRR Part 500 rather than through an AI statute: a DFS-regulated bank's cybersecurity programme must be based on a documented risk assessment that, since the October 16, 2024 Industry Letter, has to address AI-specific threats and the bank's own and its vendors' AI; the programme is owned by a CISO who reports to the board, and the CEO and CISO certify compliance every year by April 15. The May 21, 2026 frontier-AI letter adds the governance mechanics DFS expects around AI in the software supply chain — human review of AI-generated code before deployment, mapped third-party dependencies, shortened remediation timelines and more frequent resilience testing. Insurers in the group face the more explicit governance rule: Circular Letter No. 7 places responsibility for AI systems with the board and senior management, requires a documented disparate-impact analysis and keeps insurers accountable for vendor models. Around that state layer sit the federal and international expectations a New York bank meets at the same time — board-owned model risk management under SR 26-2 for banks above about $30 billion, third-party lifecycle controls under SR 23-4, and the FSB's twelve sound practices, whose first three (strategic oversight, accountability, AI inside the risk framework) are the governance structure regulators on every side now describe.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| 23 NYCRR Part 500 §§500.2–500.4, 500.9, 500.17 | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Written cybersecurity programme and policy approved by the senior governing body; a CISO who reports to the board at least annually; documented risk assessment updated at least annually and on material change; annual CEO/CISO certification of compliance. | In force; certification due Apr 15 each year | [23 NYCRR Part 500](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-23-nycrr-part-500) |
| DFS Industry Letter on AI cybersecurity risks | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | The risk assessment must address AI threats and AI use — the firm's own deployments and its vendors' — and drive training, access controls, MFA design, third-party diligence and data minimisation. | Oct 16, 2024 | [DFS AI Cybersecurity Industry Letter (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-10-16-ai-cyber-risks) |
| DFS Industry Letter on frontier AI models | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | Governance of AI in the software supply chain: human oversight of AI-generated code before deployment, input validation and restricted script execution, dependency mapping, faster remediation, stronger logging, more frequent resilience testing. | May 21, 2026 | [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models) |
| Insurance Circular Letter No. 7 (2024), governance section | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | For New York-authorised insurers: board and senior management responsible for the AI framework, written policies and procedures, documented disparate-impact analysis, full responsibility for third-party models, and adverse-action transparency. | Jul 11, 2024 | [Insurance Circular Letter No. 7 (2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-insurance-circular-letter-2024-07) |
| Interagency model risk guidance (SR 26-2 / OCC 2026-13 / FIL-15-2026) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Board and senior-management governance of model risk, independent validation and effective challenge for quantitative models, scaled to materiality; generative and agentic AI managed through broader governance. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| SR 23-4 / OCC Bulletin 2023-17 / FIL-29-2023 | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Third-party AI — vendor models, foundation-model access, AI embedded in platforms — through the full relationship lifecycle; the bank stays accountable. | In force | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |
| FSB Sound Practices 1–3 | [FSB](https://www.bankingnewsai.com/ai-regulation/fsb) | Board-set strategic direction and oversight, clear accountability for AI, and AI risks incorporated into the enterprise risk-management framework. | Final report due Oct 2026 | [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) |
| NIST AI RMF 1.0, Govern function | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Policies, roles, accountability and culture for AI risk; the voluntary vocabulary Treasury's FS AI RMF adapts for financial services. | Since Jan 2023 | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) |
| Treasury FS AI RMF and AI Lexicon | [U.S. Treasury](https://www.bankingnewsai.com/ai-regulation/treasury) | A financial-services adaptation of the NIST framework for evaluating AI use cases across the lifecycle, scalable by institution size. | Feb 19, 2026 | [Treasury FS AI RMF and AI Lexicon (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fs-ai-rmf-and-ai-lexicon-2026) |
| EU AI Act, Arts. 9–15 and 26 (for New York banks with EU operations) | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Risk-management system, data governance, logging, human oversight and deployer obligations for high-risk uses such as consumer credit scoring. | Stand-alone Annex III obligations from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |

The New York framework is best understood as a cybersecurity regulation that has been asked to carry AI governance. Part 500 already required the structures a governance framework needs — a senior governing body that approves the programme, a CISO with a board reporting line, a risk assessment that drives every control, and an annual certification that puts named executives' signatures on compliance. The October 2024 letter did not add a structure; it added AI to the risk assessment and therefore to everything downstream of it. The May 2026 letters did the same for the software supply chain, and the code-review expectation is the first time a US financial regulator has said in guidance that AI-generated code needs a human before it ships.

The insurance side is where New York is explicit about governance in the sense a board would recognise. Circular Letter No. 7 names the board and senior management as responsible for the AI framework, asks for written policies and procedures, and demands documented evidence — the three-step disparate-impact test repeated annually — that the framework works. It does not apply to bank lending, but bank holding companies with New York-authorised insurers run it alongside their bank-side model risk programme, and DFS examiners now review new AI systems and data sources in both.

For a New York-regulated bank the practical framework is therefore three layers that must agree with each other: DFS's Part 500 programme with AI threats and AI-generated code inside it; the federal model-risk and third-party guidance that governs the models and vendors; and the FSB's sound practices, which supervisors on both sides of the Atlantic are converging on as the description of good governance. None conflicts with the others, and a single AI inventory tagged by materiality, owner, vendor and human-oversight point satisfies most of what all three ask to see.

### What this means in practice

- Give the CISO's annual board report an AI section: which AI systems the bank runs, which vendors' AI it depends on, and what the risk assessment says about each — the October 2024 letter makes this the expected content.
- Write the code-review gate for AI-generated code into the secure-development standard and keep the evidence; it is the one AI-specific control DFS has asked for by name.
- Run one AI inventory that serves Part 500, SR 26-2 and SR 23-4 at once: materiality tier, owner, validation status, vendor, human-oversight point, and the risk-assessment entry that covers it.
- If the group owns a New York-authorised insurer, align its Circular Letter No. 7 governance with the bank's model-risk governance so the board sees one AI framework, not two.
- Use the FSB's first three sound practices as the board-level summary; they are what DFS, the federal agencies and European supervisors all describe when they say 'governance'.

## Documents (9)

- May 21, 2026 — [DFS Heightened Threat Environment Guidance (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-heightened-threat-environment): Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (In force)
- May 21, 2026 — [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models): Heightened Cybersecurity Risks Associated with Frontier AI Models (In force)
- Dec 19, 2025 — [New York RAISE Act](https://www.bankingnewsai.com/ai-regulation/documents/ny-raise-act): Responsible AI Safety and Education (RAISE) Act, General Business Law Article 44-B (Chapter 699 of the Laws of 2025, as amended by Chapter 96 of the Laws of 2026) (Final · applies from Jan 1, 2027)
- Dec 16, 2025 — [Asrow Assembly Statement on AI in Insurance (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-asrow-assembly-statement-2025-12-16-ai-insurance): Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and Pricing (Final)
- Oct 16, 2024 — [DFS AI Cybersecurity Industry Letter (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-10-16-ai-cyber-risks): Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks (In force)
- Jul 11, 2024 — [Insurance Circular Letter No. 7 (2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-insurance-circular-letter-2024-07): Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing (In force)
- May 30, 2024 — [DFS Virtual Currency Customer Service Guidance (May 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-05-30-vce-customer-service): Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities) (In force)
- Jan 17, 2024 — [DFS Proposed AI Insurance Circular Letter (Jan 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-proposed-insurance-circular-letter-2024-01): Proposed Insurance Circular Letter on the Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing (Superseded)
- Nov 1, 2023 — [23 NYCRR Part 500](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-23-nycrr-part-500): Cybersecurity Requirements for Financial Services Companies (Second Amendment) (In force)

## Timeline

- Jan 1, 2027 — [New York RAISE Act](https://www.bankingnewsai.com/ai-regulation/documents/ny-raise-act): RAISE Act takes effect — The New York RAISE Act, as amended by the 2026 chapter amendment, takes effect; large frontier developers' disclosure obligations apply from this date.
- Nov 2026 — [New York RAISE Act](https://www.bankingnewsai.com/ai-regulation/documents/ny-raise-act): RAISE Act: DFS begins directing large frontier developers to register — DFS said on 21 September 2026 that its Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) will begin directing large frontier AI developers to register starting November 2026.
- Sep 21, 2026 — [RAISE Act implementation: registration opens November 2026, DIGIT office staffed](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260921) — Governor Hochul announces large frontier AI developers must register with the state starting November 2026 and directs full RAISE Act compliance (72-hour critical-incident reporting, transparency requirements) from January 2027; DFS's new Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) gets its first full-time hire, Marc Gilman, as Deputy Director for RAISE Act implementation.
- May 21, 2026 — [DFS Heightened Threat Environment Guidance (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-heightened-threat-environment): DFS Heightened Threat Environment Guidance (May 2026) — Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment — Issued May 21, 2026 as the companion to DFS's frontier-AI letter, this guidance defines a 'heightened cybersecurity threat environment' as one where risks are significantly elevated with a high likelihood of impacting information systems, nonpublic information, or operations — expressly including the arrival of frontier AI models — and lists the measures DFS expects firms to consider in three areas: reducing the attack surface, improving threat detection and readiness, and improving resilience and response.
- May 21, 2026 — [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models): DFS Frontier AI Models Industry Letter (May 2026) — Heightened Cybersecurity Risks Associated with Frontier AI Models — On May 21, 2026, DFS issued an Industry Letter warning that 'frontier AI models' able to identify vulnerabilities and build exploits at unprecedented speed and scale will soon become widely available, and directing regulated entities to prepare before they do.
- Dec 22, 2025 — [RAISE Act signed; DFS to house frontier-AI oversight office](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20251222) — Governor Hochul signs the Responsible AI Safety and Education Act, which requires large frontier-model developers to publish safety protocols and report critical harm incidents within 72 hours, and places a new oversight office inside DFS to assess developers and issue annual transparency reports.
- Dec 19, 2025 — [New York RAISE Act](https://www.bankingnewsai.com/ai-regulation/documents/ny-raise-act): New York RAISE Act — Responsible AI Safety and Education (RAISE) Act, General Business Law Article 44-B (Chapter 699 of the Laws of 2025, as amended by Chapter 96 of the Laws of 2026) — New York's Responsible AI Safety and Education (RAISE) Act, signed by Governor Hochul on December 19, 2025 and finalized by a chapter amendment signed March 27, 2026 (Chapter 96 of 2026), takes effect January 1, 2027.
- Dec 16, 2025 — [Asrow Assembly Statement on AI in Insurance (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-asrow-assembly-statement-2025-12-16-ai-insurance): Asrow Assembly Statement on AI in Insurance (Dec 2025) — Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and Pricing — On December 16, 2025, Acting Superintendent Kaitlin Asrow told the New York Assembly's Insurance and Science and Technology committees that DFS applies existing, technology-neutral law to AI — 'the core regulatory obligations are the same for manual processes as they are for AI models' — and that it has integrated review of new AI systems and datasets into its examinations.
- Nov 1, 2025 — [Final Part 500 Second Amendment provisions take effect](https://www.dfs.ny.gov/industry_guidance/regulations/final_adoptions_fs/rf_fs_2amend23NYCRR500_text_20231101_alt) — Universal multi-factor authentication (§500.12) and the asset-inventory requirement (§500.13(a)) — the two controls the October 2024 AI letter leans on most — become mandatory for all covered entities.
- Oct 18, 2025 — [Kaitlin Asrow becomes Acting Superintendent](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202509291) — Adrienne Harris departs after four years; Asrow, a former Federal Reserve supervisor of bank technology use, takes over and later tells the Assembly DFS will apply technology-neutral law to AI through guidance and exams rather than new AI-specific rules.
- Oct 16, 2024 — [DFS AI Cybersecurity Industry Letter (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-10-16-ai-cyber-risks): DFS AI Cybersecurity Industry Letter (Oct 2024) — Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks — On October 16, 2024, DFS issued an Industry Letter telling every DFS-regulated entity how to address AI-related cyber risk under 23 NYCRR Part 500.
- Jul 11, 2024 — [Insurance Circular Letter No. 7 (2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-insurance-circular-letter-2024-07): Insurance Circular Letter No. 7 (2024) — Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing — Insurance Circular Letter No.
- May 30, 2024 — [DFS Virtual Currency Customer Service Guidance (May 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-05-30-vce-customer-service): DFS Virtual Currency Customer Service Guidance (May 2024) — Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities) — DFS's May 30, 2024 Industry Letter to virtual currency entities is its only guidance so far that sets rules for AI chatbots in customer service.
- Jan 17, 2024 — [DFS Proposed AI Insurance Circular Letter (Jan 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-proposed-insurance-circular-letter-2024-01): DFS Proposed AI Insurance Circular Letter (Jan 2024) — Proposed Insurance Circular Letter on the Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing — On January 17, 2024, DFS published for comment a proposed insurance circular letter on AI systems and external consumer data in underwriting and pricing, with comments due March 17, 2024.
- Nov 1, 2023 — [23 NYCRR Part 500](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-23-nycrr-part-500): 23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies (Second Amendment) — 23 NYCRR Part 500 is the New York cybersecurity regulation that all of DFS's AI guidance hangs on.

## What to watch next

- Frontier AI developer registration opening with DIGIT in November 2026, and whether DFS publishes any bank-facing guidance alongside it
- Whether the RAISE Act oversight office produces any spillover expectations for banks that deploy frontier models through vendors, once DIGIT is fully staffed
- Part 500 examinations and enforcement in 2026–27 testing whether firms actually documented AI-enabled social engineering, deepfake-resistant MFA, and AI-vendor risk in their §500.9 risk assessments
- Any move by DFS to extend Circular Letter No. 7-style disparate-impact testing beyond insurance to lenders, or to write AI-specific requirements — which Asrow said in December 2025 remains possible 'as new risks arise'

## FAQ

### Does NYDFS have an AI regulation for banks?

No standalone rule. DFS regulates AI in banks through 23 NYCRR Part 500, its cybersecurity regulation, as interpreted by the October 16, 2024 Industry Letter on AI cyber risks and the May 21, 2026 Industry Letter on frontier AI models. Both say they create no new requirements but map AI risks onto sections DFS examines and enforces.

### Does Insurance Circular Letter No. 7 (2024) apply to banks?

Only to insurers authorized in New York, Article 43 corporations, HMOs, fraternal benefit societies, and the State Insurance Fund. A bank's insurance subsidiary is covered for its underwriting and pricing; the bank's lending is not. The letter also does not cover marketing or claims handling.

### What does NYDFS expect banks to do about AI deepfakes?

Treat AI-enabled social engineering as a Part 500 risk: include it in the annual risk assessment, train all staff on deepfake voice/video/text attacks, verify unusual requests through separate channels, and use MFA that is resistant to AI manipulation — DFS specifically discourages SMS, voice, and video-based authentication in favor of digital certificates or hardware keys.
## Which fintechs does the NY DFS supervise or license?

[PayPal](https://www.bankingnewsai.com/fintech/paypal) · [Block](https://www.bankingnewsai.com/fintech/block) · [Stripe](https://www.bankingnewsai.com/fintech/stripe) · [Robinhood](https://www.bankingnewsai.com/fintech/robinhood)


Related authorities: [OCC](https://www.bankingnewsai.com/ai-regulation/occ), [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve), [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb), [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic), [NIST](https://www.bankingnewsai.com/ai-regulation/nist), [Colorado AI Act](https://www.bankingnewsai.com/ai-regulation/colorado-ai-act).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/ny-dfs
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
