New York opens RAISE Act registration for AI vendors in November
New York begins RAISE Act registration for large frontier AI developers in November, with 72-hour incident reporting live January 1. What it hands you as a buyer.
RAISE Act registration starts in November, and the useful part for a business your size is not the rule — it's the paperwork it forces your model vendor to publish. On September 21, Governor Hochul's office announced that New York will direct large frontier AI developers to register with the state in November, roughly two months before the law's core requirements take effect. You are almost certainly not a covered developer. You almost certainly buy from one.
What actually happened
New York stood up the Office of Digital Innovation, Governance, Integrity and Trust — DIGIT — inside the Department of Financial Services, and named Marc Gilman as Deputy Director for RAISE Act implementation. He came from Theta Lake, where he was General Counsel and VP of Compliance. He is the office's first full-time hire.
The mechanics, per the state and Wiley's read of the final text:
- Registration opens November 2026. Compliance obligations land January 1, 2027.
- Who's covered: developers of models trained on more than 10^26 operations, and only those with annual revenue above $500 million. That amendment, signed in March, is what keeps this off your desk as a builder.
- Critical safety incidents get reported to DIGIT within 72 hours — 24 hours if there is imminent risk of death or serious injury.
- Quarterly catastrophic-risk assessments go to DIGIT.
- DIGIT publishes annual public summaries of incidents and safety observations.
- Enforcement is the Attorney General's: up to $1 million for a first violation, $3 million after, plus $1,000/day for disclosure failures after notice and hearing.
Why AI vendor regulation matters for your business
You get three things out of this that you could not previously buy at any price.
A safety framework you can actually read. Covered developers must publish one. Today, when you ask a model vendor what happens when their classifier misfires, you get a marketing page. Starting January, the largest ones have a document with their name on it and an Attorney General attached to its accuracy. Put the link in your vendor file next to the SOC 2 and the DPA. It costs you nothing.
A 72-hour clock that is not yours. The thing that actually burns a small shop is finding out six weeks later that the model behind a client's intake agent had a known failure window. A 72-hour report to a state regulator plus an annual public summary means that information has a path to daylight it did not have in 2025. Build the habit now: subscribe to your vendors' status and incident feeds, and log the date you learned about anything that touched production.
A revenue threshold that tells you where the line is. The $500 million cut is the useful signal here. The open-weight model you self-host, the fine-tune you shipped for a client, the agent you wrote on top of somebody's API — none of it is in scope. If a consultant tells you your automation project now needs a New York compliance workstream, read them the threshold.
The honest caveat: this is one state, the federal preemption fight is unresolved, and a framework document is a disclosure, not a guarantee. It gives you something to compare across vendors. It does not tell you the model is safe.
Key takeaways
- RAISE Act registration for large frontier developers opens November 2026; requirements take effect January 1, 2027
- Coverage requires 10^26+ training operations and $500M+ annual revenue — you are the buyer here, not the target
- Critical safety incidents must reach New York's DIGIT office within 72 hours; 24 hours if there's imminent risk of serious harm
- Quarterly catastrophic-risk assessments go to DIGIT; the office publishes annual public incident summaries
- Penalties run to $1M first violation, $3M subsequent, enforced by the NY Attorney General
- Action for you: save each vendor's published safety framework in the same folder as their SOC 2, and subscribe to their incident feeds
- Nothing here puts your own fine-tune, self-hosted model, or API-layer agent in scope
We keep the vendor file so the audit question takes ten minutes, not ten days. Rush Commerce scopes AI systems with the model provider documented, swappable, and paired with the disclosures that back it. See how we scope it or send us your current stack and we'll tell you what's missing.
Sources: Office of Governor Kathy Hochul, NY Department of Financial Services, Wiley.
- #raise-act
- #ai-regulation
- #vendor-risk
- #compliance
- #new-york
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
AI CEOs brief the UN Security Council: what changes for you
France convened the Security Council's first session on AI safety risks on Sept 23, with Altman, Amodei, Bengio and Delangue briefing. Here's the operator read.
Read itSnorkel AI raises $350M at $3.5B: data work is the moat
Snorkel's revenue grew 18x to a $375M run rate by selling finished datasets, not labeling software. The lesson for small studios is about what you sell.
Read it