Posted

New York Moves to Implement the RAISE Act: What AI Developers Need to Know

On September 21, 2026, New York Governor Kathy Hochul announced New York’s next steps in implementing the Responsible AI Safety and Education (RAISE) Act, which establishes new safety, transparency and reporting requirements for developers of frontier models. New York is not alone, as California, Connecticut and Illinois have also enacted similar laws. The RAISE Act has significant overlap with California’s Transparency in Frontier Artificial Intelligence Act (SB 53), a law we discuss, along with other recent California AI legislation, in our prior article, New California AI Laws.

Beginning in November, New York will direct covered AI developers to register with the state’s new Office of Digital Innovation, Governance, Integrity and Trust (DIGIT), which will be housed within the New York State Department of Financial Services (DFS). The RAISE Act’s substantive requirements will take effect beginning in January 2027, when covered developers must also begin providing regular reports to the DIGIT Office.

The announcement marks an important step in New York’s effort to establish a regulatory framework for frontier AI. It also suggests that the RAISE Act may be only the beginning, as Gov. Hochul indicated in her announcement that the state will consider additional AI safety measures in the coming months. One potential avenue for additional measures is through DIGIT’s rulemaking authority under the RAISE Act.

Background: New York’s Frontier AI Framework
The RAISE Act regulates developers and large developers of frontier AI models to give regulators greater visibility into the safety frameworks, catastrophic risks and critical safety incidents associated with those models.

The law requires covered developers to establish safety and transparency frameworks and publish them on their websites. It also creates recurring registration, disclosure and reporting obligations designed to allow the state to monitor how developers identify and address potentially significant risks.

Gov. Hochul’s September announcement does not provide detailed guidance on the form or substance of the required submissions. We anticipate that the governor and DFS will provide additional guidance to clarify how developers should make reports to the DIGIT Office, assess catastrophic risks, identify reportable safety incidents and demonstrate compliance with their published safety frameworks.

Key Requirements for Covered Developers
Under the RAISE Act, covered developers will be required to:

  1. Report critical safety incidents to the DIGIT Office within 72 hours and, when required, to other governmental authorities;
  2. Publish a safety and transparency framework on their websites;
  3. Submit quarterly assessments of catastrophic risks to the DIGIT Office;
  4. Register with the DIGIT Office;
  5. File a disclosure statement at least once every two years, beginning January 1, 2027; and
  6. Pay assessments associated with the state’s oversight program.

The 72-hour reporting window is particularly significant. Developers will need internal escalation procedures capable of identifying potentially reportable events, assessing them promptly and coordinating the technical and legal review necessary to meet the deadline.

The DIGIT Office Will Lead Implementation
Primary responsibility for administering the RAISE Act will rest with the DIGIT Office, a new office within DFS. Gov. Hochul appointed Marc Gilman as Deputy Director for the RAISE Act, a role in which he will help oversee implementation of the law. DFS personnel with expertise in technology regulation, cybersecurity and AI are already supporting the effort, with additional dedicated staff expected in the coming weeks and months.

The DIGIT Office will receive registrations, disclosure statements, quarterly risk assessments and critical safety incident reports from covered developers. It will also have authority to request information from AI companies, issue rules and recommend legislative changes as the technology and its associated risks evolve.

Public Reporting and Regulatory Coordination
The RAISE Act’s incident-reporting structure extends beyond submissions from covered developers. Members of the public may also report suspected critical safety incidents to the DIGIT Office, which may refer those reports to other governmental authorities as appropriate.

The DIGIT Office must also publish an annual report summarizing the incident reports it receives, its observations regarding frontier model safety and any recommended changes to the RAISE Act. This process could provide regulators, lawmakers and the public with greater visibility into both individual incidents and broader trends involving advanced AI models.

For developers, this means that a safety incident may involve more than a single submission to the state. Depending on the circumstances, a report could result in inquiries from multiple governmental authorities and may ultimately be discussed, at least in summary form, in the DIGIT Office’s annual public report.

Broader Regulatory Context
The announcement arrives as New York continues to take an active role in AI and technology regulation. Gov. Hochul has indicated that the state will explore additional measures to build on the RAISE Act in the coming months.

New York’s framework is part of a broader movement among states to regulate developers of the most advanced AI models. California’s Transparency in Frontier Artificial Intelligence Act (SB 53), enacted in 2025, requires large frontier developers to publish frontier AI frameworks describing their approaches to catastrophic-risk assessment, mitigation, cybersecurity, incident response and internal governance. The law also requires reporting of certain critical safety incidents to the state, provides whistleblower protections and authorizes civil enforcement by the California Attorney General.

Illinois has adopted a similarly structured regime through its Artificial Intelligence Safety Measures Act, which takes effect January 1, 2027. The Illinois law defines a frontier model by reference to a training-compute threshold of more than 10^26 integer or floating-point operations and generally treats a developer with more than $500 million in annual gross revenue, together with affiliates, as a “large frontier developer.” Among other obligations, the law requires disclosure filings beginning in 2027, critical-safety-incident reporting within 72 hours, and—beginning in 2028—the publication and implementation of a frontier AI framework. Certain violations may result in civil penalties of up to $1 million for a first violation and up to $3 million for each subsequent violation.

Connecticut has taken a more targeted approach. Public Act 26-15 establishes protections for certain employees of frontier developers from retaliation for reporting specified catastrophic risks. By January 1, 2027, large frontier developers must establish a reasonable process for anonymous internal reporting, provide updates to reporting employees and share covered reports and updates with officers and directors at least quarterly, subject to the statute’s requirements.

Together, these laws illustrate an emerging state-level patchwork in which similar concepts—frontier models, catastrophic risk, incident reporting and internal governance—may carry different thresholds, timelines and compliance obligations from one jurisdiction to another.

The creation and continued staffing of the DIGIT Office reinforce that New York is building a dedicated regulatory infrastructure rather than treating the RAISE Act as a one-time legislative measure. As the office begins collecting information from developers, its findings may shape future rulemaking and legislative proposals.

Covered developers should therefore monitor not only the initial registration and reporting guidance, but also any proposals to expand or refine the RAISE Act’s substantive and procedural requirements.

How AI Developers Should Respond
Developers of advanced AI models should begin determining whether they or any of their models fall within the RAISE Act’s scope. Potentially covered organizations should also evaluate whether their existing governance and incident-response programs can support the law’s disclosure and reporting requirements.

In particular, developers should consider:

  • Designating personnel responsible for registration and communications with the DIGIT Office;
  • Reviewing existing safety and transparency frameworks and preparing them for public disclosure;
  • Establishing procedures to identify, escalate and report critical safety incidents within 72 hours;
  • Developing a documented process for preparing quarterly catastrophic-risk assessments;
  • Coordinating legal, technical, cybersecurity and incident-response personnel; and
  • Monitoring DFS and DIGIT guidance concerning filing procedures, reporting standards and other implementation details.

Conclusion
New York’s announcement provides covered developers with a short runway for compliance. Registration activity is expected to begin in November, followed by substantive compliance and reporting obligations in January 2027.

Although important implementation details remain forthcoming, developers should not wait for final guidance to begin preparing. Early coordination will be important because compliance will require organizations to translate complex technical safety assessments into public disclosures and regulatory reports that may be reviewed by multiple governmental authorities.