United States - New York - AI Safety Act (RAISE Act)
Responsible AI Safety & Education Act
United States • New York
RAI-US-NY-S6953B0-2025S6953B
New York's RAISE Act, enacted in 2025, creates a framework for overseeing advanced AI frontier models, mandating safety protocols and transparency to prevent critical harm.
Summary
Read full text ↗Plain English
Overview
The Responsible AI Safety & Education Act (RAISE Act), enacted in New York State, represents a landmark legislative effort to establish a comprehensive framework for the oversight of advanced artificial intelligence (AI) models, specifically targeting "frontier models" developed by large entities. Signed into law by Governor Kathy Hochul on December 19, 2025, the Act aims to safeguard New Yorkers from the potential risks associated with rapidly evolving AI technologies while simultaneously fostering innovation and economic growth within the state. It establishes nation-leading standards for AI transparency and safety, building upon and aligning with frameworks adopted by other leading tech states, notably California's Transparency in Frontier Artificial Intelligence Act (TFAIA). The RAISE Act addresses critical concerns such as the potential for AI systems to cause "critical harm," including catastrophic risks like the creation of bioweapons or large-scale automated criminal activity. By focusing on the largest developers of powerful AI models, the legislation seeks to ensure accountability and proactive risk mitigation, requiring developers to implement robust safety protocols and report incidents transparently.
While signed in late 2025, the substantive provisions of the RAISE Act are scheduled to take effect on January 1, 2027, allowing developers and the newly established oversight body sufficient time to prepare for compliance and implementation. This phased approach underscores the complexity of regulating cutting-edge technology and the need for careful preparation. The Act's passage highlights a growing trend of state-level AI regulation in the United States, often in response to perceived federal inaction, and sets New York apart as a proactive leader in establishing guardrails for AI development and deployment. It mandates transparency, reporting, and safety requirements for developers of "frontier AI models," which are defined by specific computational power and financial investment thresholds. The legislation is designed to strike a balance between promoting technological advancement and protecting public safety, ensuring that AI innovation serves the public good responsibly.
Definitions
The RAISE Act introduces several key definitions crucial for understanding its scope and application. A "Large Developer" is generally defined as an entity that develops "frontier models" and meets specific financial or computational thresholds. While earlier legislative versions considered developers who spent over $100 million in compute costs to train frontier models, the final version signed by Governor Hochul aligns with California's TFAIA, defining "large developers" as those with more than $500 million in revenue. This revenue-based threshold aims to focus the regulatory burden on the largest and most impactful AI developers operating in New York. The Act specifically targets "Frontier Models," which are advanced AI models characterized by significant computational power and financial investment during their training phase, or smaller models derived from them with similar capabilities. These models are identified as having the capacity to cause significant societal impact, necessitating specialized oversight.
A central concept in the Act is "Critical Harm," which delineates the severe risks the legislation seeks to prevent. Critical harm is broadly defined to include instances where AI technology could lead to the death or serious injury of a significant number of people (e.g., 100 or more), result in substantial financial damage (e.g., over $1 billion in theft or damage), or facilitate the creation of chemical, biological, radioactive, or nuclear weapons. It also encompasses scenarios where AI systems act without meaningful human intervention or assist in committing foreseeable crimes. Relatedly, a "Safety Incident" is defined as any known or suspected occurrence of critical harm or an increased risk thereof. This includes autonomous model behavior, unauthorized access or release of model weights, control failures, or unauthorized use of the AI system. These definitions are fundamental to triggering the Act's reporting obligations and enforcement mechanisms, ensuring that regulatory attention is directed towards the most potent and potentially dangerous AI systems and their developers.
Governance and Institutional Framework
The RAISE Act establishes a robust governance structure to oversee the development and deployment of frontier AI models within New York State. A cornerstone of this framework is the creation of a new, dedicated oversight office within the New York Department of Financial Services (NYDFS). This office is endowed with significant responsibilities, including enforcing the provisions of the RAISE Act, issuing rules and regulations to clarify and implement the law, assessing fees on developers to fund its operations, and publishing an annual report on AI safety. The choice of NYDFS as the host agency is notable, as it already possesses expertise in regulating complex financial technologies and cybersecurity, providing a foundation for addressing the sophisticated challenges posed by AI. The office's mandate for rule-making authority is crucial, as it allows for the development of detailed, adaptable guidelines that can keep pace with the rapid evolution of AI technology, ensuring the Act remains relevant and effective over time.
The oversight office's role extends beyond mere enforcement to include proactive monitoring and assessment of large frontier developers. It is tasked with evaluating these developers' adherence to safety and transparency protocols, thereby promoting a culture of responsible AI innovation. The annual reports published by this office are intended to provide transparency to the public and policymakers regarding the state of AI safety in New York, highlighting emerging risks, compliance trends, and the effectiveness of the regulatory framework. This institutional setup reflects a commitment to a comprehensive and dynamic approach to AI governance, recognizing that effective regulation requires both clear statutory mandates and flexible administrative oversight. The funding mechanism, based on fees from developers, is designed to ensure the office has the necessary resources to fulfill its mandate without relying solely on general taxpayer funds, aligning the cost of regulation with the entities that derive commercial benefit from AI development.
Key Focus Areas
The RAISE Act is primarily focused on several critical areas to ensure the safe and transparent development and deployment of frontier AI models. A central requirement is the implementation of comprehensive "safety and security protocols" by large developers. These protocols must be in writing, publicly published (with appropriate redactions for sensitive information), and subject to annual review and compliance. The protocols are expected to detail the developer's procedures for assessing and mitigating safety risks, including catastrophic risk potential, applying risk-reduction techniques, implementing robust cybersecurity measures to prevent unauthorized access or model theft, and establishing frameworks for ensuring best practices are consistently followed. This proactive approach aims to embed safety considerations throughout the AI development lifecycle, rather than addressing harms retrospectively.
Another key focus is mandatory "incident reporting." Large developers are required to report any "safety incidents" – defined as known or suspected occurrences of critical harm or increased risk thereof – to the Attorney General and the Division of Homeland Security and Emergency Services within 72 hours of discovery or reasonable belief that an incident has occurred. This rapid reporting mechanism is intended to enable swift governmental response to potential AI-related harms. The Act also places a strong emphasis on "transparency and disclosure." Beyond publishing safety protocols, the new oversight office within the NYDFS is mandated to issue annual reports on AI safety, contributing to public understanding and accountability. Furthermore, the Act explicitly prohibits large developers from deploying a frontier model "if doing so would create an unreasonable risk of critical harm." This forward-looking prohibition places a significant burden on developers to conduct thorough risk assessments and ensure their models do not pose unacceptable dangers, thereby establishing a legal standard for responsible AI deployment.
Implementation Framework
The implementation framework for the RAISE Act is designed to be comprehensive, ensuring that the legislative intent translates into practical, enforceable measures for AI safety and transparency. At its core, the Act mandates that large developers of frontier AI models establish and adhere to rigorous internal processes. This includes the development of detailed written safety and security protocols that outline how risks are assessed, mitigated, and managed throughout the AI lifecycle. These protocols must not only be created but also continuously reviewed and updated on an annual basis to reflect evolving risks and technological advancements. The requirement for public publication of these protocols (with necessary redactions) serves to foster transparency and allow for external scrutiny, contributing to public trust and accountability in AI development. The Act's framework also necessitates robust internal cybersecurity measures to protect AI models from unauthorized access, misuse, or theft, recognizing the critical importance of model integrity in preventing potential harms.
Central to the implementation is the role of the newly established oversight office within the New York Department of Financial Services (NYDFS). This office is not merely a reactive enforcement body but is empowered to develop and issue further rules and regulations. This rule-making authority is vital for providing granular details and practical guidance on how developers can comply with the Act's broad mandates, ensuring consistency and clarity across the industry. The office will also be responsible for monitoring compliance, conducting assessments of large frontier developers, and collecting fees to sustain its operations. The framework emphasizes a proactive approach to risk management, requiring developers to anticipate and address potential harms before deployment. This includes a prohibition on deploying models that pose an "unreasonable risk of critical harm," placing the onus on developers to demonstrate the safety of their systems. The entire framework is underpinned by the principle that innovation must proceed hand-in-hand with robust safety measures and transparent accountability.
Monitoring and Evaluation
Effective monitoring and evaluation are integral to the long-term success of the RAISE Act in achieving its objectives of AI safety and transparency. The legislation places a direct responsibility on large developers of frontier AI models to engage in continuous self-assessment and review. Specifically, developers are required to review their written safety and security protocols annually. This annual review process is crucial for ensuring that the protocols remain current and effective in addressing the dynamic risks associated with AI technology. Any changes made to these protocols must be justified and published within 30 days, promoting ongoing transparency and allowing stakeholders to track how developers are adapting their safety measures. This continuous internal monitoring by developers forms the first line of defense in identifying and mitigating potential harms, fostering a culture of perpetual vigilance and improvement in AI safety practices.
Complementing the developers' internal monitoring, the newly established oversight office within the New York Department of Financial Services (NYDFS) plays a critical external monitoring and evaluation role. This office is mandated to issue annual reports on AI safety. These reports are expected to provide a comprehensive overview of the state of AI safety in New York, including an assessment of compliance trends among large frontier developers, identification of emerging risks, and an evaluation of the effectiveness of the regulatory framework. The annual reports serve as a vital mechanism for public accountability and informed policymaking, allowing the legislature and the public to gauge the impact of the RAISE Act and identify areas where further intervention or refinement might be necessary. Through this dual approach of internal developer review and external governmental oversight, the RAISE Act aims to create a responsive and adaptive regulatory environment for AI.
Penalties, Liability, and Appeals
The RAISE Act establishes clear provisions for penalties and enforcement to ensure compliance with its mandates. The primary enforcement authority rests with the New York Attorney General, who is empowered to bring civil actions against large frontier developers for violations of the Act. Specifically, penalties can be levied for failures to submit required reporting, such as incident disclosures, or for making false statements in their submissions. The Act sets forth a tiered penalty structure: initial violations can incur civil penalties of up to $1 million, while subsequent violations may result in fines of up to $3 million. It is important to note that these penalty amounts were adjusted during the legislative process; earlier versions of the bill had proposed significantly higher fines, up to $10 million for first violations and $30 million for subsequent ones. The final, reduced penalties reflect a negotiated outcome, aiming to impose substantial deterrence without unduly stifling innovation.
A notable aspect of the RAISE Act's enforcement framework is the absence of a private right of action. This means that individuals or private entities cannot directly sue developers under the provisions of this Act for alleged harms or non-compliance. Instead, enforcement is exclusively reserved for the Attorney General's office, centralizing legal actions and ensuring a consistent application of the law. While the Act outlines penalties for non-compliance, it does not extensively detail mechanisms for appeals against enforcement decisions or liability frameworks beyond the civil penalties. However, standard administrative law procedures for challenging agency decisions and judicial review of civil penalties would generally apply. The focus of the Act's penalty regime is on compelling adherence to safety, transparency, and reporting obligations, rather than establishing a broad liability scheme for AI-induced harms, which often fall under existing tort law or other specific sector regulations.
Relationship to Other Instruments
The RAISE Act operates within a complex landscape of existing and emerging AI regulations, both at the state and federal levels. A significant aspect of its design is its deliberate alignment with California's Transparency in Frontier Artificial Intelligence Act (TFAIA), also known as SB 53. New York's legislation consciously builds on and mirrors elements of California's framework, aiming to create a unified benchmark among leading tech states in the absence of comprehensive federal regulation. This harmonization is intended to reduce potential compliance burdens for large AI developers operating across state lines, fostering a more coherent regulatory environment. By adopting similar definitions, reporting requirements, and oversight principles, the RAISE Act and TFAIA collectively represent a growing trend of state-level leadership in AI governance, particularly concerning frontier models and their associated risks.
However, the RAISE Act's passage also highlights a burgeoning conflict between state and federal authority in AI regulation. Following the signing of the RAISE Act, a federal Executive Order, reportedly signed by President Trump on December 11, 2025, aimed at establishing a national policy framework for AI and potentially limiting state AI laws deemed to impede a "minimally burdensome national standard." This federal directive signals a potential for preemption debates, as the Department of Commerce, empowered by the Executive Order, may consider state laws like the RAISE Act as "burdensome" or creating a "patchwork" of regulations that could stifle innovation. Despite this federal pushback, New York, alongside California, continues to advance its own regulatory agenda, asserting state-level responsibility for AI safety. The RAISE Act is also distinct from other New York AI-related bills, such as those concerning AI in advertising or the "New York Artificial Intelligence Bill of Rights," focusing specifically on frontier model developers and critical harm.
International Alignment
The RAISE Act, while primarily a state-level initiative within the United States, positions New York as a significant player in the global conversation surrounding AI regulation. Governor Hochul explicitly characterized the Act as setting a "nation-leading standard for AI transparency and safety," underscoring its ambition to influence broader regulatory approaches. The legislation's deliberate alignment with California's AI framework, as noted in its development, suggests an emerging regional consensus within the U.S. on how to approach frontier AI models. This state-level leadership is particularly relevant given the perceived lag in comprehensive federal AI regulation in the United States, creating a de facto American standard that could, in turn, inform international discussions. While the Act does not explicitly reference international AI governance frameworks like the EU AI Act or OECD recommendations, its focus on risk management, transparency, and accountability for high-impact AI systems resonates with principles advocated by these global bodies.
The Act's emphasis on preventing "critical harm" and mandating safety protocols for powerful AI systems reflects a global concern about the potential societal risks of advanced AI, including misuse in areas like bioweapons or autonomous criminal activity. By establishing clear requirements for incident reporting and oversight, New York contributes to a growing international trend of demanding greater accountability from AI developers. While the RAISE Act does not directly seek to align with specific international treaties or cross-border cooperation agreements, its robust regulatory stance could serve as a model for other jurisdictions grappling with similar challenges. The creation of a dedicated oversight office within the NYDFS, with its mandate to issue rules and annual reports, mirrors the institutional approaches seen in other advanced regulatory regimes globally, fostering a framework that, while locally enacted, has implications for the broader international discourse on responsible AI development.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| RAISE Act passed by New York Legislature (S6953B/A6453B) | 2025-06-12 | Passed by the New York Senate and Assembly, sending the bill to the Governor's desk. |
| Governor Kathy Hochul signs RAISE Act into law | 2025-12-19 | Governor Hochul signed the legislation, with agreed-upon chapter amendments to align more closely with California's AI law. |
| Effective Date of RAISE Act | 2027-01-01 | The substantive provisions of the Act are scheduled to take effect. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Safety & Security Protocol Implementation | Develop, implement, and maintain a written safety and security protocol detailing procedures for risk assessment, mitigation, cybersecurity, and testing of frontier AI models. |
| Protocol Publication | Conspicuously publish a copy of the safety and security protocol (with appropriate redactions) and transmit it to the Division of Homeland Security and Emergency Services. |
| Annual Protocol Review | Annually review and, if necessary, update the safety and security protocol, publishing justifications for any changes within 30 days. |
| Incident Reporting | Report any known or suspected "safety incidents" (occurrences of critical harm or increased risk) to the Attorney General and Division of Homeland Security and Emergency Services within 72 hours of discovery or reasonable belief. |
| Prohibition of Unreasonable Risk | Ensure that the deployment of any frontier AI model does not create an "unreasonable risk of critical harm" as defined by the Act. |
| Compliance with DFS Regulations | Adhere to any further rules and regulations issued by the new oversight office within the New York Department of Financial Services (NYDFS). |
Sources and References
| Source | Type |
|---|---|
| Governor Hochul Signs Nation-Leading Legislation to Require AI Frameworks for AI Frontier Models | government |
| Landmark AI Safety Bill Signed Into Law - The New York State Senate | government |
| New York State Senate Bill S6953B (RAISE Act) | legal |
| New York State Assembly Bill A6453B (RAISE Act) | legal |
The New York Responsible AI Safety & Education (RAISE) Act, signed into law in December 2025, establishes a framework for overseeing advanced AI "frontier models" developed by large entities, mandating safety protocols and transparency to prevent severe harm.
This landmark legislation applies to "Large Developers" – companies with over $500 million in revenue that create "frontier models." These are advanced AI systems with significant computational power, or smaller models derived from them, capable of causing "critical harm." This includes risks like: - widespread death or injury (100 or more people) - massive financial damage (over $1 billion) - creating chemical, biological, radioactive, or nuclear weapons - facilitating large-scale automated criminal activity
Key obligations for these developers include: developing and publicly publishing written safety and security protocols, detailing how they assess, mitigate, and manage risks, including cybersecurity. These protocols must be reviewed annually. Developers must also report any known or suspected "safety incidents" – occurrences or increased risks of critical harm – to the Attorney General and Division of Homeland Security within 72 hours. A strict prohibition exists against deploying a frontier model if it creates an "unreasonable risk of critical harm." Furthermore, developers must comply with additional rules issued by a new oversight office within the New York Department of Financial Services (NYDFS).
The substantive provisions of the RAISE Act take effect on January 1, 2027. Enforcement falls to the New York Attorney General, who can levy civil penalties of up to $1 million for initial violations and $3 million for subsequent ones. A crucial point for businesses is that the Act does not create a "private right of action," meaning individuals cannot directly sue developers under this law; enforcement is solely governmental. While this law aligns with California's AI framework, its existence highlights a growing state-level regulatory landscape that could conflict with future federal efforts to establish a uniform national standard.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under United States - New York - AI Safety Act (RAISE Act). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Jan 1, 2027
Applies to: Large developers of frontier AI models in New York.
“Develop, implement, and maintain a written safety and security protocol detailing procedures for risk assessment, mitigation, cybersecurity, and testing of frontier AI models.”
- #2Critical⏰ Jan 1, 2027
Applies to: Large developers of frontier AI models in New York.
“Conspicuously publish a copy of the safety and security protocol (with appropriate redactions)...”
- #3Critical⏰ Jan 1, 2027
Applies to: Large developers of frontier AI models in New York.
“...and transmit it to the Division of Homeland Security and Emergency Services.”
- #4Critical⏰ Annually, starting 2027-01-01
Applies to: Large developers of frontier AI models in New York.
“Annually review and, if necessary, update the safety and security protocol...”
- #5Critical⏰ Within 30 days of change
Applies to: Large developers of frontier AI models in New York.
“...publishing justifications for any changes within 30 days.”
- #6Critical⏰ Within 72 hours of discovery
Applies to: Large developers of frontier AI models in New York.
“Report any known or suspected 'safety incidents'... to the Attorney General and the Division of Homeland Security and Emergency Services within 72 hours of discovery...”
- #7Critical⏰ Before deployment
Applies to: Large developers of frontier AI models in New York.
“...prohibits large developers from deploying a frontier model 'if doing so would create an unreasonable risk of critical harm.'”
- #8Critical
Applies to: Large developers of frontier AI models in New York.
“Adhere to any further rules and regulations issued by the new oversight office within the New York Department of Financial Services (NYDFS).”
Related Regulations
Responsible AI Safety & Education Act
New York, United States100% similar
An act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models; to amend a chapter of the laws of 2025 amending the general business law relating to the training and use of artificial intelligence frontier models, as proposed in legislative bills numbers S. 6953-B and A. 6453-B, in relation to the effectiveness thereof; and to repeal certain provisions of the general business law, relating thereto
United States96% similar
An act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models; to amend a chapter of the laws of 2025 amending the general business law relating to the training and use of artificial intelligence frontier models, as proposed in legislative bills numbers S. 6953-B and A. 6453-B, in relation to the effectiveness thereof; and to repeal certain provisions of the general business law, relating thereto
United States96% similar
An Act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models
United States94% similar
An Act to amend the general business law, in relation to transparency and safety requirements for developers of artificial intelligence frontier models
United States94% similar
© Regulations.AI — created on 05-Aug-2026 using Gemini 2.5 Flash