New York’s Department of Financial Services has not written an AI rule for the firms it supervises. It has done something narrower: in three industry letters since October 2024, it has explained how its existing cybersecurity regulation, 23 NYCRR Part 500, applies when attackers use AI and when regulated firms deploy it themselves.

Each letter says the same thing about its legal weight. None imposes new requirements. Each tells covered entities how DFS reads obligations they already have, and that reading is what a firm’s risk assessment, vendor contracts and training plan should reflect.

The October 2024 letter: four risks, six control areas

The first letter, dated October 16, 2024, was addressed to executives and information security staff at every DFS-regulated entity. DFS said it was responding to inquiries about how AI changes cyber risk.

It names four risks. Two come from threat actors using AI:

  • AI-enabled social engineering. DFS calls this one of the most significant threats to the financial sector: realistic, interactive audio, video and text, or deepfakes, used to get employees to share credentials, disclose information or take actions such as wiring funds. The letter also notes deepfakes used to imitate a person and get past biometric verification.
  • AI-enhanced attacks. AI can help attackers find and exploit vulnerabilities faster, run reconnaissance once inside, and speed up new malware and ransomware variants. DFS adds that publicly available AI tools may lower the skill needed to launch an attack.

Two come from a firm’s own use of AI:

  • Exposure of large volumes of nonpublic information. AI products usually need a lot of data, often including nonpublic information, so the firm has more to protect. Stored biometric data is singled out because it can be used to imitate authorized users and bypass multi-factor authentication.
  • Supply chain dependencies. Gathering and processing that data often runs through vendors and third-party service providers, and each one is a possible entry point.

The letter then walks through controls Part 500 already requires and says how DFS expects them to account for AI.

Risk assessments. They must take AI threats, including deepfakes, into account, and DFS says they should cover the firm’s own use of AI, the AI used by its vendors and weaknesses in AI applications. The regulation already requires the assessment to be updated at least annually and whenever a change in business or technology materially changes cyber risk. Incident response, business continuity and disaster recovery plans should cover AI-related disruptions, and the senior governing body is expected to understand AI-related risk well enough to oversee it.

Vendor management. DFS “strongly recommends” that due diligence on a third-party service provider consider the AI threats that provider faces and how it protects itself. Where a provider uses AI, the letter suggests extra representations and warranties on the secure use of the firm’s nonpublic information.

Access controls. The letter recalls that, from November 2025, Part 500 requires MFA for all authorized users accessing a covered entity’s information systems or nonpublic information. Firms keep discretion over which factors to use, but DFS suggests avoiding SMS, voice and video authentication, which deepfakes can imitate, in favor of digital certificates and physical security keys. For biometrics it points to liveness detection or texture analysis.

Training. Annual awareness training must cover social engineering, and DFS wants that to include deepfakes, for example through simulated phishing and voice or video impersonation exercises. Staff should know to verify an unexpected request for credentials or an urgent money transfer. Personnel allowed to use AI applications should be trained to write queries that do not disclose nonpublic information.

Monitoring. Firms that use AI products, or let staff use tools such as ChatGPT, should consider watching for unusual queries that may signal an attempt to extract nonpublic information, and blocking queries that would expose it to a public AI system.

Data management. Data minimization applies to information used for AI. DFS also asks firms to identify the information systems that use or rely on AI and keep an inventory of them, prioritizing those critical to operations.

The October 2025 letter: AI in vendor contracts

DFS’s October 21, 2025 guidance on third-party service providers is not an AI letter, but it names AI among the technologies, alongside cloud computing, file transfer systems and fintech products, that are increasing firms’ reliance on outside providers.

For AI specifically, it suggests that contracts with providers include, where relevant, a clause on acceptable use of AI and on whether the firm’s data may be used to train AI models or be disclosed to other parties. The same letter says firms may not delegate responsibility for Part 500 compliance to a provider, and that DFS considers weak third-party risk management in examinations, investigations and enforcement.

The May 2026 advisory: frontier models

On May 21, 2026, DFS sent CISOs of regulated entities an advisory about “frontier AI models” that can speed up the discovery and exploitation of vulnerabilities. DFS said some such models were not yet broadly available but that their capabilities might become available soon, and it urged firms to prepare.

The advisory points to a companion letter issued the same day, Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment, and highlights four areas:

  • Faster vulnerability management. Reassess how known vulnerabilities are rated and whether remediation timelines need to shorten.
  • Third-party dependencies. Build and maintain dependency maps and coordinate with critical providers on significant vulnerabilities.
  • Secure programming. Validate inputs before running scripts or processes, and consider extra testing, validation and human oversight for AI-generated code before it reaches production.
  • Monitoring and resilience. Check whether logging and alerting are adequate, and review and test resilience procedures.

It also suggests firms consider replacing end-of-life or legacy systems as part of updating their risk assessments.

What a firm can take from the three letters

For a firm already covered by Part 500, the letters add expectations rather than sections. A practical reading:

  1. Put AI explicitly into the next risk assessment: the firm’s own tools, staff use of public AI services, vendors’ AI and AI-assisted attacks.
  2. Keep an inventory of systems that use or depend on AI.
  3. Review MFA factors against deepfake and impersonation risk.
  4. Add AI-use and training-data clauses to provider contracts where relevant.
  5. Update training with deepfake and payment-request scenarios.
  6. Decide who reviews AI-generated code before deployment.

Whether a company is a covered entity at all, and which Part 500 sections apply to it, is a separate question covered in our guide to NYDFS Part 500 requirements. For product teams wiring AI into payment flows, the approval and permission questions are in Before an AI Agent Makes a Payment.

The letters are guidance, and a firm should get legal advice on how they apply to its own program.

Sources