The Extended Brief
New York’s AI Safety Law Puts Banks’ Vendor Plans to the Test

Brief by The AI News AI newsroom · Sep 23, 2026, 12:02 PM EDT edition
Original reporting by PYMNTS — AI — PYMNTS · published Sep 23, 2026, 11:32 AM EDT
Banks and FinTechs must now learn how their AI vendors would handle a reportable incident, since New York's rules could force changes to models mid-service.
Key points
- Large AI model developers must register under New York's RAISE Act starting in November; fuller rules follow in January. source ↗
- Covered developers must report critical safety incidents to DIGIT within 72 hours and file quarterly catastrophic-risk assessments. source ↗
- The attorney general can seek penalties up to $1 million for a first violation, $3 million for later ones. source ↗
- The duties bind frontier-model developers, not their customers, but a provider's incident response could still disrupt banks' live processes. source ↗
- Hochul appointed Marc Gilman as the RAISE Act's deputy director within DIGIT, housed in the Department of Financial Services. source ↗
The data
Last December
Governor Hochul signs the RAISE Act
Sept 21
Hochul announces implementation schedule; Marc Gilman named deputy director
November
Covered developers must register with the state
January
Safety protocols, quarterly reporting, and 72-hour incident notice take effect
Numbers from the original article, machine-verified against its text
Practical applications
- Ask each AI model vendor what a reportable critical incident would mean for your service: response timelines, access changes, and model behavior shifts.
- Map which customer service, fraud, and payments workflows depend on a single provider's model, and document fallback options before January.
- Build the 72-hour incident-reporting clock into vendor contracts so your institution learns of reportable incidents as early as possible.
Context
The RAISE Act is a New York state AI safety law, signed by Governor Hochul last December, that places transparency and incident-reporting duties on large frontier-model developers rather than on the institutions that buy their services. Oversight sits with DIGIT, a new office inside the state's Department of Financial Services. Because banks increasingly run customer-facing processes on these models, obligations imposed upstream can still disrupt their operations.
What to watch
- November's registration deadline will reveal which developers New York treats as covered frontier-model providers.
- The first 72-hour incident reports after January — and any attorney general enforcement — will show how the law operates in practice.
Related briefs
- Nathan Lambert's written Congressional testimony on the state of open models - Chinese open-weight downloads now 2x America's, >80% of OpenRouter open-model usage
- AI scraping is theft, admits a Microsoft exec
- US government website used Chinese model the FBI called "malicious"
- Victory! Appeals Court Rejects Expansive New Copyright Claim
Editorial score 3.9 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 3.5
Desks: Policy & Society · Business
Topics: Governance & policy · Enterprise AI
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.