New York Just Put a Clock on Frontier AI — and a New Regulator Behind It
A law without a regulator and a date is a press release with a signature. For most of 2026, that was a fair description of New York’s RAISE Act — passed in June, signed in December 2025, and then quiet while everyone waited to learn who would enforce it and when the clock would start. On September 21, Governor Kathy Hochul’s office answered both questions, and the answers are worth reading closely, because they are where a transparency statute either grows teeth or doesn’t.
The machinery first. New York is standing up a new regulator: the Office of Digital Innovation, Governance, Integrity and Trust — DIGIT — housed inside the Department of Financial Services, the same agency that already supervises banks and insurers. That placement is a tell. New York chose to route frontier-AI oversight through a muscular financial regulator with a long history of examinations and consent orders, rather than a new standalone agency starting from zero. Marc Gilman was named DIGIT’s deputy director for the RAISE Act, per the state’s announcement.
Then the clock. Large frontier AI developers must register with the state in November 2026. Compliance obligations begin January 1, 2027. From that date, covered companies must publish a safety and transparency framework on their own websites, report critical safety incidents to DIGIT within 72 hours of determining one has occurred, file quarterly catastrophic-risk assessments, and submit biennial disclosure statements along with state assessment fees. The public gets a channel too: anyone can file a suspected-incident report with DIGIT, and the office is to publish annual reports on what it learns.
What’s genuinely new here is the 72-hour incident clock and the quarterly risk filing. California’s SB 53, the comparable frontier-AI transparency law, leans on published frameworks and disclosure. New York is layering on a continuous reporting cadence — the regulatory rhythm of a supervised industry, not a one-time filing. A lab that ships a model and discovers a serious safety failure three weeks later now has a legal duty to tell Albany within three days. Whether DIGIT has the technical staff to do anything useful with a flood of 72-hour notices is the open question, and it is the same question every AI-safety reporting regime faces: disclosure is only as good as the reader on the other end.
The enforcement backstop is the Attorney General. Letitia James, whose office brings the civil actions, framed the rollout as New York “leading the nation in passing safe and responsible laws and regulations to protect our state.” The penalties are real but modest by frontier-lab standards: up to $1 million for a first violation and up to $3 million for subsequent ones, reduced during negotiations from an earlier $10 million / $30 million proposal. For a company spending tens of billions on compute, a seven-figure fine is a line item. The leverage, if there is any, comes from the disclosure duty and reputational exposure, not the check.
Who’s actually covered is where the reporting gets murky, and where readers should be careful. The RAISE Act targets “large frontier developers,” but secondary legal analyses do not fully agree on the trigger. Several — including National Law Review and DLA Piper — describe a compute-spending threshold keyed to models trained with over $100 million in aggregate compute. At least one firm, Fisher Phillips, reports the final law swapped that for a $500-million-annual-revenue test. The distinction matters: a compute threshold catches the handful of labs training the largest models; a revenue threshold sweeps in a broader set of large tech companies. We flag this rather than paper over it — see the desk note.
Either way, the practical target is small: OpenAI, Anthropic, Google, Meta, and the short list of outfits training the biggest models. And that is the quiet strategic point of the September 21 announcement. New York is betting that it can regulate frontier AI without waiting for Washington — that a determined state financial regulator, with examination powers and a 72-hour clock, can impose transparency on companies that are overwhelmingly headquartered elsewhere. Lawmakers behind the bill, including Assemblymember Alex Bores, have cast it explicitly as a rebuke to federal efforts to preempt state AI rules.
The skeptical read is that none of this bites until 2027, that the penalties are small, and that a new office inside DFS has to hire the expertise to make any of it meaningful before the first filings arrive. The fair read is that New York did the unglamorous thing that most AI “landmark laws” skip: it named the regulator, set the date, and started the clock. We’ll know by spring whether DIGIT is a watchdog or a mailbox.
Sources
- NY Governor's Office: Next steps to regulate major AI developers (Sept. 21, 2026)
- NY Department of Financial Services press release (Sept. 21, 2026)
- National Law Review: What frontier model developers need to know
- Fisher Phillips: New York governor signs sweeping AI safety law
- GovTech: New York's AI law creates oversight office
Felix Strauss covers tech policy and regulation for prompt/power, from Brussels and Ottawa to Washington and Sacramento. He reads the 400-page regulation so you don't have to, and highlights the one sentence that actually matters.
Latest from prompt/power
- Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
Leave a Reply