Skip to main content
v2026.11,858 entries · CC-BY 4.0

New York RAISE Act: What It Requires

New York’s RAISE Act requires large frontier AI developers to publish a Frontier AI Framework and report Critical Safety Incidents to DFS within 72 hours — a much tighter window than California SB 53’s 15 days.

Written and maintained by CASRAI Editorial Board

Last updated

New York’s Responsible AI Safety and Education Act (RAISE Act) is a state law that sets disclosure, safety-framework, and incident-reporting obligations for the developers of the largest “frontier” AI models. Governor Hochul signed the original bill on December 19, 2025. Lawmakers and the Governor then agreed to a chapter amendment (introduced January 6, 2026, passed March 11, 2026, and signed March 27, 2026) that narrowed the law’s thresholds and penalties to align more closely with California’s SB 53. The RAISE Act as amended takes effect January 1, 2027.

This guide covers the law as finalized by the chapter amendment. Where earlier coverage describes different numbers (a $100 million compute-cost threshold, or $10 million/$30 million penalties), that reflects the original December 2025 text before the amendment, not the law that will actually take effect.

Who the RAISE Act covers

The law defines two tiers, modeled on the same compute threshold used in the federal AI executive order and in California’s SB 53:

  • Frontier model — a foundation model trained using more than 1026 computational operations (FLOPs).
  • Frontier developer — any entity that trained, or initiated the training of, a frontier model.
  • Large frontier developer — a frontier developer with prior-year revenue of $500 million or more. The heaviest obligations in the law — the published safety framework and the incident-reporting duties — attach to this tier.

Because the definition turns on training activity and revenue rather than headquarters location, an out-of-state developer whose frontier model is deployed or operating in New York can be in scope.

What large frontier developers must publish, and when

Before deploying a frontier model, a large frontier developer must create, implement, comply with, and clearly and conspicuously publish a Frontier AI Framework: a public document describing how the developer identifies and manages “catastrophic risk” — assessment methodology, risk thresholds, mitigation measures, cybersecurity practices, and internal governance for the model’s development and deployment.

  • The Framework must be reviewed and updated at least annually.
  • A material modification to the Framework must be published, with a justification, within 30 days of the change.
  • Large frontier developers must also submit periodic catastrophic-risk-assessment summaries to the state on an ongoing basis rather than only at model release.

“Catastrophic risk” in the statute means a foreseeable, material risk that a frontier model materially contributes to mass casualties or mass-casualty weapons, or to comparably severe harm through the model acting with limited human oversight, intervention, or control.

Critical Safety Incident reporting: the 72-hour clock

This is the provision that most separates New York from California. A large frontier developer that determines — or reasonably believes, based on the facts available — that a Critical Safety Incident has occurred must report it to New York’s Department of Financial Services (DFS) within 72 hours of that determination.

A Critical Safety Incident includes, among other triggers:

  • Unauthorized access to, or theft or misuse of, a frontier model’s weights that causes death or serious injury.
  • Materialized harm consistent with the statute’s catastrophic-risk definition.
  • Loss of control over a frontier model that causes death or serious injury.
  • A frontier model using deceptive techniques to subvert the developer’s monitoring or control, outside of authorized testing or evaluation.

Where an incident poses an imminent risk of death or serious injury, the developer must separately notify law enforcement or public safety authorities within 24 hours, in addition to the 72-hour DFS report.

Oversight and penalties

The RAISE Act creates a dedicated oversight office inside DFS, with rulemaking authority over large frontier developers and a mandate to issue its own annual public reports. That is a structural difference from SB 53, which relies on California’s existing Attorney General and Office of Emergency Services rather than a new dedicated regulator.

Two enforcement tracks apply:

  • The New York Attorney General can bring civil actions for violations of the Framework, testing, or incident-reporting duties: up to $1 million for a first violation and up to $3 million for subsequent violations. There is no private right of action.
  • The DFS office can separately assess $1,000 per day for failures tied to required disclosure statements, plus recovery of any unpaid assessment.

RAISE Act vs. California SB 53

CASRAI has a separate guide to California’s SB 53 (Transparency in Frontier AI Act). After New York’s chapter amendment, the two laws use nearly identical thresholds for who is covered, but they still diverge on mechanism:

Dimension New York RAISE Act California SB 53
Effective date January 1, 2027 January 1, 2026
Large-developer threshold $500M prior-year revenue (post-amendment) $500M annual revenue
Incident-reporting deadline 72 hours from determination 15 days from discovery (24 hours if imminent death/injury risk)
Incident reports go to NY Department of Financial Services CA Office of Emergency Services
Dedicated regulator New DFS office with rulemaking authority None — CA Attorney General enforces; no new agency
Civil penalties (AG track) $1M first violation / $3M subsequent Up to $1,000,000 per violation
Additional agency penalty DFS: $1,000/day for disclosure-statement failures None equivalent

The practical effect for a large frontier developer operating nationally: the safety-framework content required by each law is now close enough to draft once and adapt, but the incident-reporting clock is not — a 72-hour New York deadline runs well inside California’s 15-day window, so an incident-response plan built only around SB 53’s timeline will miss the RAISE Act’s deadline.

Why the definitions matter for NIKOLAI

New York’s “Critical Safety Incident” and California’s “critical safety incident” are named the same but are not defined identically, and both sit alongside the federal executive order’s own thresholds. CASRAI’s NIKOLAI dictionary tracks exactly this kind of cross-jurisdiction terminology drift — mapping how “catastrophic risk,” “critical harm,” and “critical safety incident” are defined across statutes and developer frameworks so the differences are visible rather than assumed away.

Frequently asked questions

Is the RAISE Act in effect now?

No. The law as finalized by the March 2026 chapter amendment takes effect January 1, 2027. The original December 2025 text is superseded by the amendment and is not the version developers need to comply with.

Does the RAISE Act apply to companies outside New York?

It can. Coverage turns on training a frontier model and meeting the revenue threshold, and on the model being developed, deployed, or operating in whole or in part in New York — not on where the developer is headquartered.

Does the RAISE Act apply to companies deploying AI, not just developers?

No. Like SB 53, the obligations run to the entities that train frontier models, not to downstream businesses that merely use them.

What has to happen within 72 hours?

A large frontier developer must report a Critical Safety Incident to the DFS oversight office within 72 hours of determining, or reasonably believing based on available facts, that one has occurred. That is separate from the 24-hour law-enforcement notification required when there is an imminent risk of death or serious injury.

Is New York’s incident-reporting deadline really shorter than California’s?

Yes. New York requires a report within 72 hours of determination. California’s SB 53 allows 15 days from discovery for most incidents, tightening to 24 hours only where there is an imminent risk of death or injury.

Who enforces the RAISE Act?

The New York Attorney General brings civil actions for violations, with penalties up to $1 million for a first violation and up to $3 million for subsequent violations. The DFS oversight office can separately assess $1,000 per day for disclosure-statement failures. There is no private right of action.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about New York RAISE Act: What It Requires

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →