The office that will supervise frontier artificial intelligence in New York has one full-time employee and a filing calendar. Governor Kathy Hochul named the employee on Monday: Marc Gilman, a technology lawyer who was general counsel and vice president of compliance at the software company Theta Lake, and now deputy director for the state's AI law.

The calendar is the part with teeth. Large developers must register with the office starting in November. From January they must publish written safety protocols, file catastrophic-risk assessments every quarter, pay a share of the office's operating costs, and report critical safety incidents within 72 hours, or within 24 hours if the harm looks imminent.

The office is called the Office of Digital Innovation, Governance, Integrity and Trust, and it sits inside the Department of Financial Services. The acting superintendent, Kaitlin Asrow, framed the placement plainly in the state's announcement of the next steps: "DFS is proud to lead the implementation of the RAISE Act for New York."

That sentence is doing more work than it looks like. New York did not simply pick a building with spare desks. It handed the compliance machinery for the most powerful commercial technology of the decade to an agency whose examiners already spend their days deciding whether banks and insurers can demonstrate control over their own systems.

A supervisor's toolkit, assembled from the banking side

The RAISE Act, the Responsible AI Safety and Education Act, was signed in December 2025 and takes effect January 1, 2027. Its requirements read like a list borrowed from bank supervision and relabeled. A registration is the entry point. A biennial disclosure statement is the filing obligation, renewed sooner if ownership changes or the facts shift. Assessments paid by the regulated cover the regulator's operating expenses, which is how the Office of the Comptroller of the Currency and the Federal Reserve fund much of their work. Incident reporting on a short clock is the notification duty banks owe after a breach.

New York's legislature could have put the office anywhere. California, which passed the frontier AI transparency law that New York's was explicitly aligned with, assigned oversight to its Office of Emergency Services. New York chose the financial regulator instead, and the choice imports a culture along with a budget line. DFS earned a reputation for aggressive enforcement of its Part 500 cybersecurity rules, which require financial institutions to document their controls and answer for gaps. Lawyers who advise on that regulation expect the same posture here. A Jones Walker analysis of the act told developers to expect "detailed document requests, comprehensive reviews, and enforcement proceedings," and cautioned that the results could include consent orders requiring operational changes.

Consent orders are the interesting word. They are how banking supervision produces change without going to court, and they exist because the supervisor has the power to examine.

The threshold follows the money

Who counts as covered is set by revenue, not by capability. A frontier model is one trained using more than 10 to the 26th power of computational operations, with compute costs above $100 million, and the definition reaches models produced by distilling a larger model's capabilities into a smaller one. From that population, the law covers developers with more than $500 million in annual revenue.

That combination is deliberate, and it is a business test wearing a technical costume. Two labs can train comparable models and land on opposite sides of the line because one sold more software last year. The revenue trigger replaced compute-cost thresholds in an amendment negotiated at signing, and it was chosen to match California's framework so that the two largest technology states would share one benchmark rather than two. Accredited universities are exempt unless they hand their intellectual property to a commercial entity, which means the academic work that generates much of the field's safety research sits outside the regime entirely.

The other number the statute fixes is the harm it is built to catch. Critical harm means death or serious injury to 100 or more people, or at least $1 billion in damage to property or money, caused or materially enabled by a frontier model, either through chemical, biological, radiological or nuclear weapons or through model conduct with limited human oversight that would be a crime if a person had done it. Everything the office collects, from quarterly risk assessments to the annual public report, is oriented toward that threshold.

A threshold of that shape converts a question about probability into a question about scale. A model that causes a regional outage or a run of smaller frauds falls below it, and a regulator whose mandate is defined by catastrophe has limited purchase on the slower harms that arrive first.

What the office will know, and when

Here the regime's design becomes visible, and so does its constraint. The material the office receives is material the developers write. Published protocols, quarterly assessments, incident reports, biennial disclosures: all of it originates with the regulated party, arrives on a schedule the regulated party can plan for, and describes a model the office is not equipped to interrogate.

Self-reporting regimes fail in a familiar way. The report is only as good as the reporter's incentive to write it, and the incentive runs against disclosure whenever a report creates liability. The statute addresses that directly in places. It forbids knowing false or materially misleading statements in filed documents, and it protects employees who report concerns to the developer or to the attorney general from retaliation. It also requires each developer to designate senior personnel responsible for compliance, which gives the state a named individual to hold.

None of that eliminates the gap between a filing and a fact. Florida's insurers file solvency reports that are accurate because examiners verify them. The verification step is what makes the filing meaningful, and it is the step a registration regime does not supply on its own. DFS has rulemaking authority and could build a verification process, but the statute's text gives the office its leverage through the documents it collects and the penalties attached to them.

The missing rung between a report and a remedy

Think of banking supervision as a ladder. Examiners see a problem in a quarterly filing. They issue findings and then a consent order. If the bank deteriorates, prompt corrective action restricts its business by statute. If it fails, a receiver takes it over. Every rung is specified in advance, and each one is available before the final harm lands.

New York built the bottom of that ladder for AI and left the middle open. The office can require filings, publish an annual report, and refer matters to the attorney general, who can seek civil penalties of up to $1 million for a first violation and up to $3 million after that, along with injunctions. There is no private right of action, so enforcement depends on the attorney general's priorities and budget rather than on the volume of complaints.

What is missing is the order that makes a developer change a model before it causes the harm the statute defines. The governor gestured at it. She said the state might explore "safeguards like AI kill switches if they're deemed feasible and in the best interests of our state," according to Reuters reporting published by Insurance Journal, and her office put the idea on the agenda for the next State of the State rather than in the current law. California's governor signed an executive order the previous Friday directing developers to build emergency shutoff capability, which is a lighter obligation than a state power to use one.

A kill switch is what you reach for when you cannot inspect. If an examiner can see the model's behavior and the developer's controls, the intervention that matters is an order to fix a specific thing. If the state's knowledge arrives as a 72-hour incident report about something that has already happened, the remaining choices are retrospective penalties and a shutdown. The idea is being discussed because the earlier rungs are thin.

January arrives before any court does

The federal government is pursuing the opposite direction. President Trump signed an executive order targeting state AI regulation days before Hochul signed the RAISE Act, and it set out a framework the administration described as minimally burdensome, with preemption of state AI laws as an explicit theme. The Department of Commerce is reviewing state AI statutes, and a federal litigation task force has been assembled to challenge them.

The case for that approach has a real foundation. Fifty state AI regimes would impose a patchwork on companies that deploy models nationally, and compliance costs fall hardest on smaller developers that cannot staff fifty jurisdictions. A single federal standard would be cheaper to meet and easier to compare. The case against it rests on the police power states have always used over local harms, and on the observation that a federal framework described as minimally burdensome is not a substitute for rules that address catastrophic risk.

For developers, the practical problem is timing. Registration opens in November and enforcement begins in January. Constitutional litigation over preemption will run on a much longer clock than either. Companies must decide this quarter whether to build a compliance function for a rule that may not survive its first court test, and the penalties for guessing wrong in one direction are real filings that a future regulator could read.

There is an asymmetry that favors the state. An office with staff, a budget funded by assessments, and two years of accumulated filings is a fact on the ground. A statute is a legal proposition that a court can reject. If preemption wins, the law can fall while the office remains, with its records and its institutional knowledge intact. The alignment with California makes the federal case harder, because preempting one state is easier than preempting two that have adopted the same benchmark on purpose.

What compliance will cost, and where the exposure sits

The published protocol is the provision with the longest reach. A developer's safety framework stops being a marketing document once the statute requires it, and the attorney general can penalize a developer for failing to follow the framework it wrote. Vendor contracts inherit the same pressure: a company buying a frontier model should expect incident-notification windows that track the 72-hour clock and should plan for the service disruption an enforcement action could cause.

Against companies with more than $500 million in revenue, a $1 million penalty is a rounding error and a $3 million one is not much larger. The cost is the apparatus, and the exposure is disclosure. Publishing a safety framework tells competitors and plaintiffs what a company promised, and then holds it to that. The compliance staff, the quarterly assessments and the incident procedures are the price of staying inside the line.

What New York has built, then, is a supervisor's paperwork without the supervisor's access. The power it does have is real, and it is the power of comparison: the state will be able to read what a developer promised and what a developer reported, and ask why the two differ. That is the kind of question a supervisory culture is good at asking, and it works slowly, on a quarterly calendar, against systems that change weekly. The state set a threshold of 100 deaths for the harm it exists to prevent and gave itself a reporting duty to detect it, which makes the office's first annual report the document worth watching.

Primary sources

  1. New York State Department of Financial Services for the September 21 announcement of the RAISE Act's next steps, the DIGIT office, the registration and reporting calendar, the quarterly catastrophic-risk assessments, and the statements from Kathy Hochul, Letitia James, Andrew Gounardes, Alex Bores, Kaitlin Asrow and Marc Gilman.
  2. Jones Walker for the frontier model definition, the $500 million revenue threshold, the chapter amendments agreed at signing, the critical harm definition, the incident categories, the attorney general's penalty range, and the expected examination posture.
  3. Reuters, published by Insurance Journal, for Hochul's kill switch remarks, the comparison with California's executive order, and the descriptions of the registration and incident reporting requirements.
  4. Morrison Foerster and Davis Wright Tremaine for the RAISE Act's alignment with California's Transparency in Frontier Artificial Intelligence Act.