New York’s RAISE Act takes effect on January 1, 2027, and the version that will apply is not the one Governor Kathy Hochul signed in December 2025. A chapter amendment signed on March 27, 2026 repealed the original text and replaced it with a transparency and incident-reporting regime run by a new office inside the Department of Financial Services. For anyone tracking what New York actually asks of frontier AI developers, the amended text is the one to read.
How the law got here
The Responsible AI Safety and Education Act started as S6953-B, sponsored by Senator Andrew Gounardes and passed by both chambers in June 2025. The governor signed it on December 19, 2025 as Chapter 699 of the Laws of 2025, with an approval memo. Her announcement that day described “agreed-upon chapter amendments” requiring large developers to publish safety information, report incidents within 72 hours and answer to an oversight office within DFS.
Those amendments arrived as S8828, introduced on January 8, 2026. The Senate passed it on January 28, the Assembly on March 11, and the governor signed it on March 27, 2026 as Chapter 96. Its sponsor memo calls it a negotiated change that repeals the underlying chapter and aligns the RAISE Act “more closely with California’s SB 53.” It also moves the effective date to January 1, 2027.
Who is covered
The amended law works with three nested definitions in new General Business Law Section 1420:
- Frontier model. A foundation model trained with more than 10^26 integer or floating-point operations. The count includes the original training run and any later fine-tuning, reinforcement learning or other material modification the developer applies to a preceding foundation model.
- Frontier developer. A person that has trained, or started training, a frontier model with at least that much computing power.
- Large frontier developer. A frontier developer that, together with its affiliates, had annual gross revenues above $500 million in the preceding calendar year.
Most of the heavier duties fall on large frontier developers only. The law applies only to frontier models “developed, deployed, or operating in whole or in part in New York state.” Accredited New York colleges and universities doing academic AI research, and the Empire AI consortium, are exempt.
Two other definitions set the threshold for harm. A catastrophic risk is a foreseeable and material risk that a frontier model will materially contribute to the death of or serious injury to more than 50 people, or more than $1 billion in property damage, from a single incident in which the model provides expert-level help with a chemical, biological, radiological or nuclear weapon, carries out a cyberattack or certain crimes without meaningful human oversight, or evades its developer’s or user’s control. A critical safety incident includes unauthorized access to model weights that results in death or bodily injury, harm from a catastrophic risk that materializes, loss of control causing death or injury, and a model using deception to subvert its developer’s controls outside of an evaluation designed to elicit that behavior.
What large frontier developers must publish
Under Section 1421, a large frontier developer must write, follow and publish on its website a frontier AI framework for its frontier models. The statute lists what it must describe, including:
- how the developer incorporates national and international standards and industry best practices;
- the thresholds it uses to judge whether a model has capabilities that could pose a catastrophic risk, and the mitigations it applies;
- how assessments feed into the decision to deploy a model or use it extensively inside the company;
- the use of third parties to assess risks and mitigations;
- cybersecurity practices protecting unreleased model weights;
- how it identifies and responds to critical safety incidents;
- internal governance, and risks from internal use, including a model circumventing oversight.
The framework must be reviewed at least once a year. A material change has to be published, with a justification, within 30 days.
Every frontier developer, large or not, must publish a transparency report before or at the same time as deploying a new or substantially modified frontier model: its website, a way for a person to contact it, the release date, supported languages and output modalities, intended uses and general restrictions on use. Large developers add summaries of their catastrophic-risk assessments and results, the extent of third-party evaluators’ involvement and other steps taken under the framework. Publishing this inside a system card or model card counts.
Developers may redact for trade secrets, security or public safety, but must keep the unredacted text for five years. The law also bars materially false or misleading statements about catastrophic risk or about compliance with the framework, unless made in good faith and reasonable under the circumstances.
Reporting to the state
Section 1422 sets the reporting duties:
- Critical safety incidents must be reported to the DFS office within 72 hours of determining one has occurred, or of learning facts that support a reasonable belief that one has.
- If an incident poses an imminent risk of death or serious physical injury, the developer must tell an appropriate authority, such as law enforcement, within 24 hours.
- Large frontier developers must send the office summaries of catastrophic-risk assessments from internal use of their models every three months, or on another schedule the office agrees to.
Members of the public can also report suspected incidents to the office, and incident reports are exempt from New York’s freedom of information law. A developer may instead follow a federal reporting standard the office designates as substantially equivalent or stricter, sending the office copies of its federal reports. Starting January 1, 2028, the office must publish an annual report with anonymized, aggregated incident information and any recommended changes to the law.
Registration, fees and penalties
Section 1428 adds a requirement with no counterpart in the transparency rules: a large frontier developer may not develop, deploy or operate a frontier model in New York without a current disclosure statement on file with the office. The statement names the company and its trade names, its principal and New York addresses, three points of contact and, depending on whether it is privately held or public, certain beneficial owners. It is renewed every two years, or sooner after an ownership transfer or material change. The office publishes a list of filers, without the contact details.
Large frontier developers also pay pro rata assessments to cover the office’s costs. Operating without a filing, filing false information or missing an assessment can bring a civil penalty of $1,000 a day plus the amounts owed.
Enforcement of the main duties sits with the Attorney General, who may seek civil penalties of up to $1 million for a first violation and up to $3 million for each later one when a large frontier developer fails to publish or send a required document, makes a prohibited statement, fails to report an incident or does not follow its own framework. The law creates no private right of action. The office also has rulemaking authority and may consider additional reporting or publication requirements.
What happened in September 2026
On September 21, 2026, the governor said the office is the Office of Digital Innovation, Governance, Integrity and Trust, or DIGIT, within DFS, and that starting in November the state will direct large frontier developers to register. She appointed Marc Gilman as Deputy Director for the RAISE Act, the office’s first full-time hire, and said compliance and regular reporting begin in January 2027. The release also said she is exploring ways to build on the law, so further changes are possible.
How this fits with other New York AI guidance
The RAISE Act regulates model developers. It is separate from DFS’s cybersecurity rules for licensed financial firms, which DFS has applied to AI risk through industry letters covered in our explainer on NYDFS AI cybersecurity guidance. Using a frontier model does not make a firm a frontier developer, but the compute count includes fine-tuning and other material modifications, so a company that heavily retrains a model should check where it stands.
This is a summary of the statute, not legal advice. Companies near the thresholds should read the text and follow DIGIT’s rules once they are published.
Sources
- New York State Senate: S8828 (2025-2026), bill text, sponsor memo and actions
- New York State Senate: S6953-B (2025-2026), the original RAISE Act
- Governor Hochul, December 19, 2025: Governor Hochul Signs Nation-Leading Legislation to Require AI Frameworks for AI Frontier Models
- Governor Hochul, September 21, 2026: AI Safety: Governor Hochul Announces Next Steps to Regulate Major AI Developers





