Back to News
PolicyAI Understanding briefing

New York sets compliance dates for RAISE Act AI safety rules

Governor Kathy Hochul announced a specific implementation schedule for New York's RAISE Act, requiring large AI developers to register in November and begin safety reporting in January.

4 min readRead the linked source
Source-provided image accompanying New York sets compliance dates for RAISE Act AI safety rules
Source referenceSource recorded
Publisher
pymnts.com
Source link
pymnts.comhttps://www.pymnts.com/news/artificial-intelligence/2026/new-yorks-ai-safety-law-puts-banks-vendor-plans-to-the-test/
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Start here

Key terms

AI Safety
A field focused on reducing harmful behavior, failures, and misuse risks in AI systems.
Weight
A learned numeric value that scales signals passing through a neural network.
Test yourselfAI Ethics Quiz

What happened

New York State has established a concrete compliance timeline for its Responsible and Security (RAISE) Act. Governor Kathy Hochul announced on September 21 that large frontier AI model developers must register with the state's new Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) starting in November. Full requirements, including public safety protocols, quarterly risk assessments, and 72-hour incident reporting, take effect in January. The state also appointed Marc Gilman as deputy director for the RAISE Act within DIGIT, which operates under the Department of Financial Services.

Governor Kathy Hochul announced the implementation schedule for New York's RAISE Act on September 21, 2026. The schedule mandates that large frontier AI model developers register with the state's Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) beginning in November 2026. In January 2027, these developers must begin publishing safety and transparency frameworks, submitting quarterly assessments of catastrophic risks, and reporting critical safety incidents to DIGIT within 72 hours.

The state appointed Marc Gilman as the deputy director for the RAISE Act within DIGIT, a new office housed in the Department of Financial Services. The law imposes civil penalties for non-compliance, with fines up to $1 million for a first violation and $3 million for subsequent violations, enforced by the state attorney general. These obligations apply specifically to large frontier-model developers rather than all AI users, but they create a regulatory chain that affects downstream customers.

The announcement highlights a practical challenge for banks and fintechs that use these models for customer service, fraud detection, or payments. If an AI provider reports a serious incident, the developer may need to investigate, change access, or alter model behavior, potentially disrupting the financial institution's operations. The law does not currently mandate 'kill switches,' though Governor Hochul has discussed the concept as an exploratory idea.

Source details: pymnts.com

Why it matters

This development transforms the RAISE Act from a signed statute into an operational regulatory framework with enforceable deadlines. The 72-hour incident reporting requirement and potential civil penalties of up to $3 million for violations create immediate operational risks for financial institutions relying on these AI vendors. Banks and fintechs must now assess their dependency on specific AI providers and prepare fallback procedures, as a reportable incident by a vendor could disrupt critical services like fraud detection or payments. The law specifically targets large frontier model developers, but the downstream impact on their enterprise customers is significant, forcing a re-evaluation of vendor risk management strategies in the AI sector.

The RAISE Act's implementation schedule provides New York with a mechanism to track serious model risks in real-time. The 72-hour incident reporting window is a significant operational constraint for AI developers, requiring rapid response to safety issues. For financial institutions, this creates a new layer of vendor risk that must be integrated into existing compliance and operational resilience frameworks.

The distinction between developers and users is critical. While banks are not directly subject to the RAISE Act's registration requirements, their reliance on specific AI vendors makes them vulnerable to the consequences of a vendor's non-compliance or a reportable incident. The potential for civil penalties adds to the developers' obligations, potentially influencing their risk management practices and, by extension, the stability of the services they provide to financial clients.

This policy action forces financial institutions to proactively assess their AI dependencies. They must determine how quickly they would be notified of a vendor incident, which services would be affected, and whether they can suspend the model's access to sensitive data or its authority to take actions. This shift from passive reliance to active risk management is a major change in how the financial sector approaches AI adoption.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Ethics Quiz

Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?

What to watch next

Monitor the registration process for large AI developers in November to see which firms comply and how they structure their safety frameworks. Watch for the first quarterly catastrophic risk assessments due in early 2027. Additionally, track whether Governor Hochul's exploratory discussions about AI 'kill switches' evolve into formal regulatory requirements or remain voluntary best practices for financial institutions.

The November registration deadline will reveal which large AI developers are subject to the RAISE Act and how they interpret the 'frontier model' definition. Compliance efforts may vary, with some firms potentially challenging the scope of the law or seeking clarifications from DIGIT.

The first quarterly catastrophic risk assessments, due in early 2027, will provide the first public insight into how developers evaluate and report on their models' potential for harm. These reports may highlight specific risks in areas like financial services, where AI is increasingly used for decision-making.

Governor Hochul's discussions about AI 'kill switches' could lead to further regulatory guidance or voluntary standards for financial institutions. While not currently required, the concept of being able to quickly disable an AI tool in an emergency is becoming a key focus for risk managers in the banking sector.

Related guides & quizzes

AI EthicsAI Models ExplainedFuture of AITest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?