New York is switching its AI safety law from statute to machinery. On Monday, Governor Kathy Hochul announced that starting in November, large frontier AI developers will be directed to register with the state and begin preparing for compliance with the Responsible AI Safety and Education (RAISE) Act — turning the nation’s most aggressive state-level AI oversight law into an operating regime.

What that means in practice: the world’s biggest model developers will soon answer to a state regulator. Published safety frameworks, critical-incident reports within 72 hours, and quarterly assessments of catastrophic risk will all be filed with a brand-new office inside the Department of Financial Services. The full requirements bite on January 1, 2027.

What the law now requires#

The RAISE Act applies to “large frontier AI developers” — press reports peg the cutoff at more than $500 million in annual revenue, which would sweep in the leading labs while leaving smaller shops alone. For covered companies, four obligations take effect in January 2027:

RequirementWhat it demands
Published safety frameworksEach developer must establish safety and transparency frameworks and publish them on its own website.
72-hour incident reportingCritical safety incidents must be reported to the new DIGIT office within 72 hours — and, where required, to other government authorities.
Quarterly risk assessmentsDevelopers file recurring assessments of catastrophic risks; DIGIT may share them with other authorities.
Registration and disclosureCompanies register with DIGIT, file a disclosure statement at least every other year, and pay assessments.

There is also a public channel: anyone can file a report of a suspected critical safety incident with the office, and DIGIT must publish an annual public report summarizing what it received, what it observed about frontier-model safety, and any changes it recommends to the law.

Meet DIGIT, the new regulator#

The law is administered by the Office of Digital Innovation, Governance, Integrity and Trust — DIGIT — a new office housed inside the Department of Financial Services. Hochul announced its first full-time hire: Marc Gilman, who will serve as Deputy Director for the RAISE Act. Gilman previously served as general counsel and vice president of compliance at Theta Lake and has taught financial-services technology at Fordham University’s law school.

The choice of DFS is deliberate, and unusual: the state’s financial regulator brings deep experience in technology supervision, cybersecurity, and enforcement. Attorney General Letitia James, who appeared alongside Hochul at the press conference, pledged that her office “will always enforce the law” — a reminder that this regime arrives with real enforcement capacity. More DIGIT staff are expected in the coming weeks and months.

What is still undecided#

Hochul was explicit that this is a floor, not a ceiling. Her office says she will be “exploring ways to build on the RAISE Act” in the coming months — and the governor would not rule out far sharper tools. “We may even explore safeguards like AI kill switches if they’re deemed feasible and in the best interest of our state,” she said at the press conference, according to press reports. Earlier reporting this month said California’s governor signed an executive order creating a task force to weigh kill-switch requirements — if both tracks proceed, the two largest state economies could end up testing different enforcement philosophies at once.

Still open: what counts as a “critical safety incident” triggering the 72-hour clock, how catastrophic-risk assessments will be judged, and how much of the filings becomes public. The bill’s backers — including State Senator Andrew Gounardes (“AI companies are playing Russian Roulette with humanity’s future”) and Assemblymember Alex Bores, who notes DIGIT can “demand more data from AI companies, issue new rules, and recommend new legislation” — promise more is coming.

Why it matters beyond New York#

Washington has chosen not to act — the Trump administration has dismissed AI safety alarms as a “hoax” and moved to accelerate deployment instead. That vacuum is the point of the story: New York is converting a federal standstill into state power, and Hochul timed the announcement to the UN General Assembly’s convening in New York this week to call on federal and world leaders to follow.

For the labs, this is the shift from voluntary to mandatory. Industry safety pledges — published frameworks, incident disclosures — become legally required filings to a state office with enforcement backing. And a state-level registry means the compliance surface multiplies: if California and others follow with their own versions, frontier developers could face a patchwork of state reporting regimes before any federal standard exists.

It fits a pattern: earlier this year, Hochul issued the nation’s first moratorium on new hyperscale data centers — a signal that New York intends to shape the AI buildout on several fronts at once.

What to watch: which companies register in November and whether anyone challenges the law; how DIGIT defines the 72-hour threshold; what Hochul’s follow-on measures turn out to be; and whether other states copy the registry model — or leapfrog it with kill switches. For the first time, frontier AI development in America has a state regulator. The voluntary era is ending.