A PYMNTS Company

New York Joins California in Setting AI Regulation Benchmarks

 |  January 6, 2026
AI regulations, legislation, education

Barely more than a week after President Trump issued his executive order seeking to wrest control of AI regulation away from the states, New York Governor Kathy Hochul signed the Responsible AI Safety and Education (RAISE) Act, one of the most detailed state-level AI safety regimes to date. The law imposes a series of binding obligations on developers of frontier AI models with more than $500 million in annual revenue and vests enforcement and oversight authority in the state attorney general and a newly created office within the Department of Financial Services, respectively.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The requirements are slated to take effect January 1, 2027.

    As enacted, the RAISE Act will apply to developers with more than $500 million in annual revenue that develop, deploy, or operate “frontier models” in whole or in part in New York. Frontier models are defined as AI systems trained using more than 10²⁶ floating-point operations per second (FLOPS) and more than $100 million in compute costs. It also covers models created through so-called distillation techniques that transfer capabilities from larger models to smaller ones. Academic research institutions are exempt, but only if their work is not later transferred to commercial entities.

    “This law builds on California’s recently adopted framework, creating a unified benchmark among the country’s leading tech states as the federal government lags behind,” Hochul said in a statement accompanying the bill’s signing.

    At the core of the statute is a requirement that covered developers adopt formal, written safety and security protocols before deploying a frontier model. According to a summary and analysis of the law by Jones Walker, the protocols must be sufficiently detailed to allow regulators to determine whether they have been followed and must address both risk mitigation and cybersecurity controls.

    Developers are required to describe how they reduce the risk of “critical harm,” prevent unauthorized access or misuse, test models for unreasonable risk, and designate senior personnel responsible for compliance.

    The Act defines critical harm narrowly but strictly. It includes the death or serious injury of at least 100 people or at least $1 billion in damage to property or monetary rights, when such harm is “caused or materially enabled” by a model. Examples listed include the creation or use of chemical, biological, radiological, or nuclear weapons, as well as autonomous AI conduct that would constitute a serious crime if performed by a human with intent, recklessness, or gross negligence.

    Related: EU Plans to Step Up Enforcement of Digital Rules in the Face of US Opposition

    Developers must publish redacted versions of their safety protocols and submit them to New York’s Division of Homeland Security and Emergency Services and the Attorney General, while retaining unredacted copies for the duration of model deployment plus five years. The statute expressly prohibits deploying a frontier model if doing so would create an unreasonable risk of critical harm.

    Compliance obligations do not end at deployment, per Jones Walker. The RAISE Act requires annual reviews of safety and security protocols to reflect evolving model capabilities and industry best practices, along with detailed annual testing and recordkeeping designed to allow third-party replication of safety assessments.

    The law also imposes a strict 72-hour incident reporting requirement. Developers must notify state authorities of any “safety incident,” including known instances of critical harm, theft or unauthorized access to model weights, critical control failures, or autonomous model behavior outside user requests.

    Oversight will fall in part to the new AI-focused office within the Financial Services Department, an agency with a track record of aggressive cybersecurity examinations. Developers should expect document-intensive reviews and the possibility of consent orders mandating operational changes.

    Enforcement authority rests with the attorney general, with civil penalties of up to $1 million for an initial violation and up to $3 million for subsequent violations, along with injunctive relief. Although federal preemption challenges are widely anticipated, the RAISE Act will take effect unless and until courts invalidate it. For covered AI developers, the statute signals that compliance planning cannot wait for federal resolution and must begin well in advance of the 2027 effective date.