New York AI Frontier Model Transparency and Safety Act
An act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models; to amend a chapter of the laws of 2025 amending the general business law relating to the training and use of artificial intelligence frontier models, as proposed in legislative bills numbers S. 6953-B and A. 6453-B, in relation to the effectiveness thereof; and to repeal certain provisions of the general business law, relating thereto
United States
RAI-US-NY-A9449S8-2026A9449/S8828
New York's A9449/S8828 amends the RAISE Act, establishing transparency and safety requirements for AI frontier model developers in the state.
Summary
Read full text ↗Plain English
Overview
New York Assembly Bill A9449, which was substituted by Senate Bill S8828, constitutes significant chapter amendments to the Responsible AI Safety and Education (RAISE) Act, originally passed as Chapter 699 of the Laws of 2025. The RAISE Act itself was signed into law by Governor Kathy Hochul on December 19, 2025, marking New York as a leader in state-level AI regulation alongside California. These subsequent amendments, as embodied in A9449/S8828, are the result of negotiations between the Governor and legislative sponsors, aimed at refining the initial framework and ensuring its effective implementation. The core purpose of these amendments is to enhance transparency and safety requirements specifically for developers of advanced artificial intelligence frontier models operating within the state of New York.
The legislation introduces a robust regulatory structure designed to address the potential risks associated with rapidly evolving AI technologies while simultaneously fostering innovation. It mandates that large frontier AI developers adhere to specific protocols, including the development and disclosure of safety measures and the timely reporting of critical safety incidents. Furthermore, the amendments establish a new oversight mechanism, centralizing regulatory authority and enforcement responsibilities within a state agency. By doing so, New York aims to create a predictable and accountable environment for AI development, protecting consumers and the broader public from potential harms while supporting the state's position as a hub for technological advancement.
Definitions
The amended RAISE Act introduces and clarifies several key definitions crucial for determining the scope and applicability of its provisions. Central to the legislation are the terms "large frontier developer" and "frontier model." A "large frontier developer" is generally defined as an entity that has trained at least one frontier model and has incurred significant compute costs in doing so, though reports indicate that agreed-upon amendments might shift this threshold to be based on developer revenue to align more closely with other state frameworks. This focus ensures that the regulations target the most powerful and potentially impactful AI systems and their creators.
A "frontier model" refers to advanced artificial intelligence systems that possess or could acquire capabilities that pose significant risks. The legislation also introduces the concept of "unreasonable risk of critical harm," which serves as a threshold for prohibiting the deployment of certain models. These definitions are critical for delineating which AI systems and developers fall under the purview of the Act's transparency, safety, and reporting obligations, thereby allowing for targeted regulation without stifling the broader AI ecosystem. The oversight office established by the Act is expected to provide further guidance and potentially promulgate rules to elaborate on these definitions as technology evolves.
Governance and Institutional Framework
A cornerstone of the amended RAISE Act is the establishment of a dedicated oversight office to manage and enforce the new AI regulations. This office is to be situated within the New York State Department of Financial Services (DFS). Its primary mandate includes assessing large frontier developers, promoting transparency, and ensuring compliance with the Act's provisions. The creation of such a specialized body underscores New York's commitment to proactive AI governance, providing a central authority for monitoring AI development and deployment within the state. This contrasts with approaches that might rely solely on existing agencies without specific AI expertise.
The oversight office is granted significant powers, including the authority to issue rules and regulations necessary for the effective implementation of the Act. It is also tasked with receiving disclosure statements from large frontier developers, maintaining a public list of compliant entities (excluding sensitive contact information), and issuing annual reports on the state of AI development and safety. This institutional framework is designed to be dynamic, allowing the state to adapt its regulatory approach as AI technology advances and new challenges emerge. The office's ability to determine developer fees for funding its operations further solidifies its capacity for independent and sustained oversight.
Key Focus Areas
The amended RAISE Act zeroes in on several critical areas to ensure responsible AI development and deployment. A primary focus is on transparency requirements, mandating that large frontier developers disclose crucial information regarding their AI models. This includes publishing appropriately redacted safety protocols and transmitting copies to relevant state authorities, such as the Division of Homeland Security and Emergency Services (DHSES) and the New York Attorney General. The intent is to provide regulators and the public with insight into how these powerful AI systems are being developed and managed, fostering trust and accountability.
Another vital area is safety protocols and risk management. Developers are required to establish and maintain robust safety and security protocols for their frontier models. The Act explicitly prohibits the deployment of a frontier model if it would create an "unreasonable risk of critical harm." This proactive measure aims to prevent catastrophic outcomes by placing a direct responsibility on developers to assess and mitigate potential dangers. Furthermore, the legislation mandates incident reporting, requiring developers to notify the State within 72 hours of identifying a qualifying safety incident. This ensures that authorities are promptly informed of significant issues, enabling timely intervention and learning from real-world events. Finally, annual reviews and testing of safety and security protocols are required, ensuring that developers continuously adapt their measures to account for evolving model capabilities and industry best practices.
Implementation Framework
The implementation of the amended RAISE Act is structured with a clear timeline and designated responsibilities to ensure its effective rollout. While the original RAISE Act was signed in December 2025, the chapter amendments, as represented by A9449/S8828, are slated to take effect on January 1, 2027. This delayed effective date provides developers and the newly established oversight office within the Department of Financial Services (DFS) ample time to prepare for compliance and establish necessary operational frameworks. The transition period is crucial for developing the detailed rules and regulations that will underpin the Act's broad provisions.
The DFS oversight office is explicitly authorized to adopt rules and regulations to implement the provisions of the Act. This rulemaking authority is essential for translating the legislative intent into actionable compliance requirements, covering aspects such as the specific format and content of disclosure statements, detailed criteria for identifying "qualifying safety incidents," and the procedures for annual protocol reviews and testing. The office will also be responsible for prescribing the form and manner in which disclosure statements are filed and for determining any associated assessment fees. This phased approach, with a future effective date and subsequent rulemaking, aims to ensure a smooth and well-defined implementation process for all stakeholders.
Monitoring and Evaluation
Effective monitoring and evaluation mechanisms are integral to the amended RAISE Act, ensuring that the regulatory framework remains relevant and impactful in the face of rapidly evolving AI technologies. A core component of this is the requirement for large frontier developers to conduct annual reviews of their safety and security protocols. These reviews must account for changes in model capabilities and advancements in industry best practices, with modified protocols to be published if changes are made. This continuous assessment ensures that developers are proactively adapting their risk mitigation strategies.
The oversight office within the Department of Financial Services (DFS) plays a central role in state-level monitoring. It is mandated to assess large frontier developers and is expected to issue annual reports on the state of AI development and compliance within New York. Furthermore, the Act's requirement for developers to establish incident reporting systems facilitates ongoing understanding and monitoring of the post-deployment impacts of artificial intelligence. This data, collected through mandatory disclosures and incident reports, will enable the DFS office to evaluate the effectiveness of the regulations, identify emerging risks, and inform future policy adjustments, thereby fostering a responsive and adaptive regulatory environment.
Penalties, Liability, and Appeals
To ensure compliance and deter violations, the amended RAISE Act establishes a clear framework for penalties and enforcement. The Attorney General is authorized to bring civil actions against large frontier developers who fail to comply with their reporting obligations or make false statements in their disclosures. This empowers the state's chief legal officer to pursue enforcement against non-compliant entities, underscoring the seriousness with which these regulations are to be taken.
The Act specifies significant civil penalties for violations. An initial violation can incur a civil penalty of up to $1 million, while subsequent violations can lead to penalties of up to $3 million. These substantial fines are intended to serve as a strong deterrent, encouraging developers to invest adequately in compliance measures. Additionally, for failing to file a current disclosure or submitting false information, the oversight office may levy civil penalties of $1,000 for each day of non-compliance, along with an amount equal to any owed assessments. Notably, the Act does not authorize a private right of action, meaning individuals cannot directly sue developers under this law; enforcement is reserved for state authorities. The Act also includes whistleblower protections for employees, encouraging internal reporting of concerns without fear of retaliation.
Relationship to Other Instruments
The New York RAISE Act, as amended, is designed with an awareness of the broader regulatory landscape, particularly in relation to other pioneering state-level AI legislation. It explicitly builds upon and aims for alignment with California's Transparency in Frontier Artificial Intelligence Act (TFAIA), also known as SB-53. This strategic convergence between two major tech-centric states aims to create a de facto national standard for frontier AI developer transparency and safety, potentially reducing the burden of conflicting regulations for companies operating across state lines. While there are minor differences, the overwhelming convergence is a key feature of New York's approach.
Furthermore, the Act includes provisions that attempt to mitigate the risk of duplicative or conflicting burdens should federal AI regulations emerge. It allows New York to designate a federal rule or standard as equivalent to the state's transparency standard. If such an equivalency is established, companies can comply with New York's requirements by simply meeting the federal rule. This forward-looking provision demonstrates an intent to harmonize state and potential federal efforts, ensuring a streamlined compliance pathway for developers. The amendments also relate to Chapter 699 of the Laws of 2025, which was the original RAISE Act, by refining its provisions and adjusting its effective date.
International Alignment
While the New York RAISE Act is a state-level initiative within the United States, its design and stated objectives implicitly contribute to broader discussions on international AI governance and alignment. By establishing robust transparency and safety requirements for frontier AI models, New York aims to set a "strong and sensible standard" that can serve as a benchmark. The Act's deliberate alignment with California's similar legislation, the Transparency in Frontier Artificial Intelligence Act (TFAIA), creates a "unified benchmark among the country's leading tech states." This bicoastal approach can influence national conversations and potentially inform future federal policies, which in turn could impact international regulatory dialogues.
The principles embedded in the RAISE Act, such as mandatory safety protocols, incident reporting, and the establishment of an oversight body, resonate with themes found in emerging AI regulations globally, including discussions within the European Union and other international bodies. Although the Act does not directly address international treaties or cross-border data flows, its focus on responsible AI development and risk mitigation aligns with a growing global consensus on the need for effective AI governance. By demonstrating a functional regulatory model at the state level, New York contributes to the practical experience and best practices that can inform more comprehensive international alignment efforts in the future.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Original RAISE Act (S6953B/A6453B) signed into law | 2025-12-19 | Established initial framework for AI safety and transparency. |
| Assembly Bill A9449 introduced | 2026-01-06 | Proposed chapter amendments to the RAISE Act. |
| Senate Bill S8828 (substituting A9449) passed Senate | 2026-01-28 | Advanced the chapter amendments through the Senate. |
| Senate Bill S8828 (substituting A9449) passed Assembly | 2026-03-11 | Completed legislative passage of the chapter amendments. |
| Senate Bill S8828 (substituting A9449) delivered to Governor | 2026-03-20 | Awaiting gubernatorial action to become law. |
| Amended RAISE Act (including A9449/S8828 provisions) effective date | 2027-01-01 | Full implementation of transparency and safety requirements begins. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Develop Safety Protocols | Establish and maintain comprehensive safety and security protocols for all frontier models. |
| Publish Redacted Protocols | Publish appropriately redacted versions of safety protocols. |
| Transmit Protocols to Authorities | Transmit copies of safety protocols to the Division of Homeland Security and Emergency Services (DHSES) and the NY Attorney General. |
| Retain Unredacted Protocols | Retain unredacted copies of protocols for the deployment period plus five years. |
| Prohibit Unreasonable Risk Deployment | Ensure no frontier model is developed, deployed, or operated if it creates an "unreasonable risk of critical harm." |
| Conduct Annual Protocol Reviews | Perform annual reviews of safety and security protocols, updating for model changes and best practices. |
| Report Safety Incidents | Notify the State within 72 hours of identifying a qualifying safety incident. |
| File Disclosure Statement | File a current disclosure statement with the DFS oversight office in the prescribed form and manner. |
| Pay Required Assessments | Pay any required fees or assessments determined by the DFS oversight office. |
| Comply with Rulemaking | Adhere to rules and regulations adopted by the DFS oversight office for implementation. |
Sources and References
| Source | Type |
|---|---|
| NY Senate - S8828 | government |
New York's amended RAISE Act sets new transparency and safety rules for developers of advanced artificial intelligence models operating in the state. This law applies to "large frontier developers," generally defined as entities that have trained powerful AI systems, known as "frontier models," which could pose significant risks. While the original law was signed in late 2025, these amendments, passed in March 2026, will fully take effect on January 1, 2027.
Under the new rules, these developers must uphold several key obligations. They are required to: - Establish and maintain robust safety and security protocols for their AI models. - Publish appropriately redacted versions of these safety protocols and share them with state authorities like the Division of Homeland Security and the Attorney General. - Promptly report "qualifying safety incidents" to the state within 72 hours of identification. - Conduct annual reviews of their safety measures, adapting them to evolving AI capabilities. Crucially, the law prohibits deploying any frontier model that would create an "unreasonable risk of critical harm."
Enforcement falls to the New York State Attorney General, who can bring civil actions against non-compliant developers. Penalties are substantial, with initial violations potentially costing up to $1 million, and subsequent violations up to $3 million. Failing to file required disclosures or submitting false information can also lead to daily fines of $1,000. A key point for developers to note is that this law does not allow individuals to sue directly; enforcement is solely handled by state authorities. The Act does, however, include protections for whistleblowers. This framework, aligning closely with California's similar AI legislation, aims to create a consistent regulatory standard across leading tech states.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 10 marked completePlain-English obligations under New York AI Frontier Model Transparency and Safety Act. Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Before placing on market
Applies to: Large frontier developers operating in New York.
“The Act explicitly prohibits the deployment of a frontier model if it would create an 'unreasonable risk of critical harm.'”
- #2CriticalKey Focus Areas⏰ Before placing on market
Applies to: Large frontier developers operating in New York.
“Developers are required to establish and maintain robust safety and security protocols for their frontier models.”
- #3CriticalKey Focus Areas⏰ Before placing on market
Applies to: Large frontier developers operating in New York.
“transmitting copies to relevant state authorities, such as the Division of Homeland Security and Emergency Services (DHSES) and the New York Attorney General.”
- #4CriticalKey Focus Areas⏰ Before placing on market
Applies to: Large frontier developers operating in New York.
“publishing appropriately redacted safety protocols”
- #5CriticalKey Focus Areas⏰ 72 hours after identification
Applies to: Large frontier developers operating in New York.
“requiring developers to notify the State within 72 hours of identifying a qualifying safety incident.”
- #6CriticalGovernance and Institutional Framework⏰ As prescribed by the DFS oversight office
Applies to: Large frontier developers operating in New York.
“It is also tasked with receiving disclosure statements from large frontier developers”
- #7CriticalGovernance and Institutional Framework⏰ As determined by the DFS oversight office
Applies to: Large frontier developers operating in New York.
“The office's ability to determine developer fees for funding its operations further solidifies its capacity for independent and sustained oversight.”
- #8CriticalImplementation Framework⏰ Ongoing, as rules are adopted
Applies to: Large frontier developers operating in New York.
“The DFS oversight office is explicitly authorized to adopt rules and regulations to implement the provisions of the Act.”
- #9ImportantKey Focus Areas⏰ Annually
Applies to: Large frontier developers operating in New York.
“annual reviews and testing of safety and security protocols are required”
- #10ImportantCompliance Checklist⏰ Ongoing
Applies to: Large frontier developers operating in New York.
“Retain unredacted copies of protocols for the deployment period plus five years.”
Related Regulations
An act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models; to amend a chapter of the laws of 2025 amending the general business law relating to the training and use of artificial intelligence frontier models, as proposed in legislative bills numbers S. 6953-B and A. 6453-B, in relation to the effectiveness thereof; and to repeal certain provisions of the general business law, relating thereto
United States100% similar
An Act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models
United States97% similar
An Act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models
United States97% similar
Responsible AI Safety & Education Act
New York, United States96% similar
Responsible AI Safety & Education Act
New York, United States96% similar
© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash