New York Responsible AI Safety and Education (RAISE) Act
Requires frontier model developers above compute and revenue thresholds to publish safety and security protocols, report critical safety incidents to the state, and refrain from deploying models posing unreasonable risk of critical harm. Chapter amendment signed 27 March 2026.
| Jurisdiction | New York |
|---|---|
| Category | AI Regulations |
| Status | Upcoming |
| Effective date | |
| Latest development |
Analysis
The New York Responsible AI Safety and Education (RAISE) Act is a New York law aimed at large frontier AI developers, with obligations centered on safety and security protocols, critical incident reporting, and restrictions on deploying models that present unreasonable risk of critical harm. The most authoritative materials I found indicate the law was signed in two stages, with the original enactment on December 19, 2025 and a chapter amendment signed March 27, 2026 as the final operative version, with a projected effective date of January 1, 2027.Governor’s office announcementNew York Assembly bill textNew York Senate legislative page
Key Requirements
- Covered developers threshold
- The law targets frontier model developers above specified compute and revenue thresholds, meaning it is not a general-purpose AI law but a frontier-model regime focused on the largest developers.Governor’s office announcementNew York Assembly bill text
- The legislative text creates a dedicated article for the Responsible AI Safety and Education (RAISE) Act, showing that the obligations are codified as a specific regulated framework rather than a guidance-only regime.New York Assembly bill textNew York Senate legislative page
- Publish safety and security protocols
- Covered developers must publish safety and security protocols, with redactions where permitted, to disclose how they manage frontier-model risks.Governor’s office announcementTransparency Coalition overview
- The obligation is designed to increase transparency around pre-deployment and operational risk controls for frontier systems.Governor’s office announcementWiley summary
- Report critical safety incidents
- Covered developers must report critical safety incidents to the state, creating a mandatory escalation channel for serious events.Governor’s office announcementWiley summary
- The law is structured to give state authorities visibility into incidents involving frontier models, rather than relying only on voluntary disclosure.New York Assembly bill textNew York Senate legislative page
- Do not deploy models posing unreasonable risk of critical harm
- The law prohibits or restricts deployment of models that pose an unreasonable risk of critical harm, which is the core substantive safety standard in the act.Governor’s office announcementWiley summary
- That standard is broader than a narrow cybersecurity test because it addresses downstream catastrophic misuse and harmful model behavior, not just technical vulnerabilities.Governor’s office announcementTechCrunch coverage
- State oversight and enforcement
- The law contemplates state-level oversight, including a New York office with rulemaking or implementation authority discussed in reporting on the final version.Wiley summaryNew York Times coverage
- Enforcement is expected to involve civil actions and monetary penalties, according to contemporaneous reporting, but the official penalty framework should be confirmed against the enacted statutory text before relying on it for legal design decisions.New York Times coverageTransparency Coalition overview
Compliance Challenges
- Defining whether the company is a covered “frontier developer”
- Many organizations will struggle with the compute and revenue thresholds, especially when training occurs across affiliates, clouds, or third-party infrastructure.Governor’s office announcementWiley summary
- Real-world issue: frontier-model labs often operate through distributed development and subcontracted compute, which makes threshold calculations and entity-scoping difficult in practice.TechCrunch coverageIAPP coverage
- Producing a publishable safety and security protocol without exposing sensitive details
- Companies must balance disclosure with trade secret protection, cyber-risk confidentiality, and model misuse prevention.Transparency Coalition overviewWiley summary
- This is a common challenge in frontier AI governance because externally useful transparency can also reveal operational weaknesses to adversaries.TechCrunch coverageNorton Rose Fulbright analysis
- Incident classification and reporting
- Organizations will need a defensible process for deciding what counts as a critical safety incident and how quickly it must be escalated.Governor’s office announcementWiley summary
- In practice, incident-reporting obligations are challenging because AI failures can be ambiguous, multi-causal, and discovered after deployment through third-party use.New York Times coverageNorton Rose Fulbright analysis
- Operationalizing the “unreasonable risk of critical harm” standard
- The standard requires a company to create a repeatable risk-assessment process, which is difficult because frontier-model risk is probabilistic rather than binary.Governor’s office announcementTechCrunch coverage
- This is especially hard for organizations with fast model release cycles and limited red-team capacity.Transparency Coalition overviewFisher Phillips analysis
- Cross-functional governance
- Compliance will require coordination among legal, engineering, safety, cybersecurity, product, and executive teams because the obligations touch publication, incident response, and deployment decisions.Wiley summaryNorton Rose Fulbright analysis
- Industry commentary also notes that companies should begin preparing well before effectiveness because the framework demands internal controls, not just policy drafting.Fisher Phillips analysisWiley summary
Implementation Best Practices
- Build a formal model-governance inventory
- Maintain a register of frontier models, training runs, compute usage, revenue attribution, deployment status, and ownership structure so you can test threshold coverage.NIST AI RMFGovernor’s office announcement
- Use this inventory to connect legal obligations to specific models and releases, not just to the company overall.Wiley summaryNIST AI RMF
- Adopt an AI risk management framework
- Map the RAISE Act to the NIST AI Risk Management Framework to structure governance, measurement, and monitoring activities.NIST AI RMF
- Use the NIST framework’s functions—govern, map, measure, manage—to create a repeatable compliance operating model.NIST AI RMF
- Create a publishable safety-and-security protocol template
- Draft a standard protocol document covering evaluation, red-teaming, access controls, cyber protections, incident escalation, and post-deployment monitoring.Wiley summaryTransparency Coalition overview
- Separate a public redacted version from a restricted internal version to preserve security-sensitive details while meeting disclosure duties.Transparency Coalition overviewGovernor’s office announcement
- Implement incident-response playbooks
- Define what constitutes a reportable AI safety incident, who decides, escalation timing, evidence retention, and external notification workflow.NIST AI RMFWiley summary
- Integrate AI incidents into existing security incident-response processes so the organization does not operate two disconnected escalation systems.NIST Cybersecurity FrameworkNIST AI RMF
- Use model evaluation and red-teaming before deployment
- Conduct pre-deployment testing for misuse, autonomy, jailbreaks, and harmful outputs before any model launch decision.NIST AI RMFTechCrunch coverage
- Keep evidence of evaluation results and remediation actions so the deployment decision is auditable.NIST AI RMFWiley summary
- Train legal, engineering, and product teams
- Provide role-based training on threshold analysis, incident triage, and publication rules so teams can act consistently.NIST AI RMFNIST Cybersecurity Framework
- For practical templates and control mappings, the NIST AI RMF Playbook and related NIST materials are useful starting points for implementation design.NIST AI RMF
- Tools and resources
- NIST AI RMF for governance and risk controls.NIST AI RMF
- NIST Cybersecurity Framework for security-control integration.NIST Cybersecurity Framework
- New York legislative text for direct statutory interpretation.New York Assembly bill text
- Governor’s announcement for executive-branch framing and policy intent.Governor’s office announcement
Recent Updates
- December 19, 2025: original signing
- Governor Hochul announced signing legislation requiring AI safety frameworks for frontier models.Governor’s office announcement
- This initial enactment was reflected in legislative materials and later commentary as the first version of the RAISE Act.New York Assembly bill textNorton Rose Fulbright analysis
- March 27, 2026: chapter amendment signed
- A chapter amendment was signed on March 27, 2026, and reporting describes it as the final operative form of the Act.[Wiley summary](https://www.wiley.law/alert-New-York-Finalizes-RAISE-Act-for-Frontier-AI-Models-Law-Takes-Effect
Recent developments
- — Expert commentary explains that the New York Responsible AI Safety and Education (RAISE) Act will take effect on 2027-01-01 and outlines reporting exceptions and enforcement mechanisms focused on frontier AI models, signaling significant compliance obligations for large developers.[8][1] (source)
- — Legal alert reports that Governor Hochul signed chapter amendments on 2026-03-27, finalizing the RAISE Act and establishing detailed transparency, safety, and incident‑reporting obligations for frontier AI developers, with enforcement beginning in 2027.[1][10] (source)
- — Analysis notes that New York amended the RAISE Act to align more closely with California’s SB-53, switching the “large frontier developer” definition to a $500 million annual revenue threshold and reducing civil penalties while delaying enforcement to January 2027, easing but sharpening focus on major AI firms.[10][6] (source)
- — Overview article summarizes the RAISE Act as a New York law imposing transparency, safety, and reporting requirements on developers of large frontier AI models, including mandatory safety protocols and incident reporting for high‑risk systems.[2][7] (source)
- — Policy commentary highlights that the RAISE Act closely mirrors California’s SB-53 “trust but verify” framework, positioning New York as part of an emerging multi‑state front in regulating frontier AI safety and transparency.[6][2] (source)
- — Law firm alert explains that the RAISE Act creates a targeted framework for advanced “frontier” AI models with stringent safety, documentation, audit, and incident‑reporting obligations on large developers, enforced by the Attorney General and fully effective in 2027.[3][4] (source)
- — Privacy and data security alert describes how the RAISE Act “raises the bar” on AI safety by requiring frontier model developers to implement transparency and disclosure measures, making safety and security protocols available to authorities and indicating further chapter amendments before full implementation.[12][1] (source)
- — Guidance piece details what covered companies need to know before the RAISE Act’s effective date in 2026, including safety, transparency, testing, and incident‑reporting obligations and potential civil penalties, prompting early compliance planning among large frontier AI developers.[7][5] (source)
- — Advocacy group guide describes the RAISE Act’s focus on extremely costly, high‑compute frontier models and its aim to prevent “critical harm,” while supporting stringent safety protocols, public disclosure, and state access to unredacted safety documentation, illustrating civil society support for robust AI risk regulation.[15][11] (source)
- — Industry association statement urges Governor Hochul to reject the RAISE Act, arguing that holding AI developers liable for third‑party misuse and restricting standard safeguards would stifle innovation and weaken New York’s tech leadership, reflecting strong industry pushback.[13][14] (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Brazilian Artificial Intelligence Act — Brazil, Proposed
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- Artificial Intelligence and Data Act — Canada, Superseded
- Colorado Artificial Intelligence Act (SB 24-205) — Colorado, Superseded, effective 2026-06-30
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) — Texas, Active, effective 2026-01-01
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
Put it into practice
- Generate the policy: NIST AI RMF policy generator (generatepolicy.com)
- Buy the policy pack: NIST AI RMF Implementation Policy (cyberpolicy.shop)
- Build it yourself: Pillar 06 Companion — The 2026 AI Risk Register (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates