New York’s AI Compliance Regime Moves Towards Enforcement
New York is moving from setting rules for advanced artificial intelligence systems to building the machinery needed to monitor and enforce them, as state officials prepare for the implementation of...
New York is moving from setting rules for advanced artificial intelligence systems to building the machinery needed to monitor and enforce them, as state officials prepare for the implementation of the Responsible AI Safety and Education (RAISE) Act.
Governor Kathy Hochul on yesterday announced that Marc Gilman, an attorney at the state Department of Financial Services, will oversee implementation through the Office of Digital Innovation, Governance, Integrity and Trust, known as DIGIT. The office was created under the RAISE Act, which Hochul signed in December 2025.
The development marks a shift from legislative requirements towards operational compliance. For AI developers, the focus will increasingly be on demonstrating that internal safety procedures, incident-reporting systems and risk controls meet the standards established by the law.
The RAISE Act applies to developers of the most computationally intensive AI models. From November, large frontier AI developers will be required to register with the state, ahead of the law taking effect on 1 January 2027. Covered companies will also face transparency, safety and reporting obligations.
Among the requirements is an obligation to report certain critical safety incidents to the state within 72 hours. The largest developers must also publicly explain how they assess and address potentially catastrophic risks. Regular reporting to DIGIT is expected once the law takes effect.
From a compliance perspective, the requirements place greater emphasis on governance systems that can identify, document and escalate significant AI-related risks. Companies will need to maintain evidence that their safety frameworks are not simply documented but are being implemented and monitored.
Hochul has also indicated that the state could examine additional safeguards, including the possibility of an AI “kill switch” if such a mechanism is considered technically feasible and appropriate. She stressed that no commitment has been made to introduce such a measure and that the concept remains under consideration.
The proposal raises a broader regulatory question about how governments should respond when AI systems present risks that existing compliance mechanisms may not adequately address. Any such intervention would likely require careful consideration of legislation and regulatory measures possible. For now, however, the direction is clear: compliance with advanced-AI rules is moving from policy technical feasibility, legal authority and the circumstances in which it could be activated.
Enforcement is another developing component of the regime. The RAISE Act gives New York Attorney General Letitia James authority to seek civil penalties of up to $1 million for certain first violations and up to $3 million for subsequent violations, with the amount dependent on the circumstances and severity of the breach.
James has separately urged workers with information about potentially unsafe or unlawful AI development practices to use her office’s confidential whistleblower process. Her office has said it is monitoring risks involving areas including cybersecurity, data privacy and fraud.
The emerging framework therefore extends beyond conventional technology regulation. It introduces a compliance model in which AI developers may have to demonstrate ongoing governance, incident management, transparency and accountability.
For companies preparing for the 2027 requirements, the practical challenge will be establishing clear lines of responsibility, maintaining auditable safety processes and ensuring that serious incidents can be identified and reported within prescribed deadlines.
New York’s approach is still developing, with further legislation and regulatory measures possible. For now, however, the direction is clear: compliance with advanced-AI rules is moving from policy statements towards registration, monitoring, reporting and potential enforcement.


No Comment! Be the first one.