Skip to content
followmy.ai
Blog

Why New York’s New AI Law Is a Big Deal for Everyone

New York's new AI safety law requires major developers to register and report incidents, setting a potential new standard for AI accountability across the US.

By Craig Mason 7 min read

The short version

New York is rolling out a major AI safety law, and it has actual teeth. The biggest AI companies will have to register with the state and report serious safety problems within 72 hours. This move could set the standard for how the rest of the country handles powerful AI.


I spend my days sorting through the relentless flood of AI news, and honestly, most of it is just noise. A new model that’s a fraction of a percent better. Another startup with a vague promise to revolutionize some industry. But every so often, something lands in my inbox that feels different. Something that feels solid.

That’s what happened when I saw the latest update on New York’s plan for AI regulation. While the federal government seems stuck in a perpetual debate loop, New York is just… doing it. On September 21, Governor Hochul announced the next steps for the state’s Responsible AI Safety and Education (RAISE) Act, and it’s one of the most practical, no-nonsense approaches to AI safety I’ve seen anywhere in the US. It’s not a vague ethics statement. It’s a set of rules with deadlines and consequences. And frankly, I’m here for it.

What exactly is New York proposing?

This isn’t some broad, sweeping law trying to regulate every line of code. It’s targeted, and that’s why it’s so smart. The RAISE Act focuses specifically on what it calls “frontier AI developers.” Think of the big guns: OpenAI, Google, Anthropic, Meta. The companies building the massive, general-purpose models that are advancing at a dizzying pace.

The law lays out a few key requirements. First, registration. Starting this November, any company developing or significantly modifying a frontier AI model will have to register with New York State. This is a simple but powerful first step. It creates an official list. It says, “we see you, and we’re paying attention.”

The real core of the law, however, kicks in by January 2027. By then, these developers must adhere to a strict set of safety and transparency standards. The headline item is the mandatory reporting of “critical safety incidents.” If something goes seriously wrong with one of these powerful models, the developer has 72 hours to report it to a new state office, the Division of Information and Generative Intelligence Technology (DIGIT). Seventy-two hours. That’s a tight deadline, mirroring what’s required for major data breaches. It forces immediate transparency.

This new office, DIGIT, is also critical. A law is just a piece of paper without an enforcement mechanism. Creating a dedicated division means there will be people whose job is to understand this tech, review the incident reports, and hold these companies accountable. It gives the regulation real weight.

Why does this matter more than other AI talk?

We’ve seen a lot of AI principles and voluntary commitments. They’re nice. They make for good press releases. But they lack the force of law. New York’s approach matters because it’s binding.

This reminds me of what happened with data privacy. For years, the US had no federal privacy law. Then California passed the California Consumer Privacy Act (CCPA). Suddenly, companies had a choice: build a completely separate, compliant version of their product just for the massive California market, or just apply California’s rules to everyone. Most chose the latter. The CCPA became the de facto national standard. New York’s RAISE Act has the potential to do the same for AI safety. New York is too big a market to ignore, and building a separate, less-safe AI for the other 49 states is a technical and logistical nightmare. So, companies will likely just build to New York’s standard.

The law’s focus on frontier models is also incredibly important. It avoids stifling innovation at the lower end of the market. Your friend’s weekend project building a simple chatbot won’t get tangled in this. The regulation is aimed squarely at the technology with the highest potential for unpredictable, large-scale impact. It recognizes the difference between a tool that summarizes emails and one that could potentially discover novel bioweapons or destabilize financial markets.

And that 72-hour reporting rule—it changes everything. Right now, if a company discovers a dangerous emergent capability in their model, they could quietly work on it for months, never telling the public. With this rule, that secrecy is no longer an option. A “critical incident” could be many things: the model being used to successfully generate a sophisticated cyberattack, evidence of the AI being used to manipulate a large group of people, or the discovery of a dangerous capability the developers themselves can’t control. Now, there’s a clock ticking.

How will this actually impact AI companies?

The first impact is cost. Compliance will require significant investment. AI labs will need to staff up their legal and safety teams. They’ll need to build robust internal testing frameworks—red-teaming—not just as a best practice, but as a legal necessity. This will likely favor the incumbent giants who have the resources to absorb these costs, potentially making it harder for new frontier model startups to compete.

But the bigger impact is cultural. The immense reputational damage of having to file a critical incident report with New York State will be a powerful motivator. No CEO wants to be on the front page for that. This creates a strong incentive to build a culture of safety from the ground up, making it a core part of the engineering process rather than an afterthought. It pushes safety from the ethics department to the product team.

Of course, there are potential downsides. A patchwork of state laws would be a disaster. Imagine if Texas, Florida, and Washington all passed their own slightly different versions of this law. It would create a compliance labyrinth for developers. For now, however, New York is leading the way, giving it a chance to set a clear, high bar that other states might simply copy, avoiding that messy outcome.

For the big labs like OpenAI and Google, this is the new cost of doing business. They operate globally, but they are American companies. They have huge offices and thousands of employees in New York. They cannot afford to be on the wrong side of this law. This will force them to be more transparent, not just in their marketing, but in their actual operations.

What should you, a regular person, do about this?

For now, you don’t have to do anything. Your experience using ChatGPT or Claude won’t change overnight. You won’t see a pop-up asking you to consent to the RAISE Act. This is an industry-facing regulation, working in the background.

But you should absolutely pay attention. This is the start of real accountability for a technology that has been advancing in a regulatory vacuum. Think of it like the creation of the FDA or the NTSB. Before them, food safety and transportation safety were inconsistent at best. These agencies created standards and, most importantly, a process for when things go wrong. That’s what DIGIT could become for AI. When a major incident happens, we, the public, will have a better chance of finding out about it quickly and from an official source.

When you talk to friends or family who are nervous about AI—and they should be, to some extent—this is the kind of development you can point to. It shows that people in power are thinking seriously about guardrails. This isn’t about banning AI. It’s about making it safer for everyone. It’s the equivalent of demanding seatbelts, airbags, and crash testing for cars. We don’t let car companies just sell us whatever they can build; we require them to prove their products are reasonably safe. New York is saying we should do the same for the most powerful AI systems.

This move makes the entire enterprise of AI feel a little less like a precarious high-wire act and a little more like a technology we can actually integrate into our society responsibly. It’s a good thing. It’s a necessary thing.

FAQ

Q: Does this law affect all AI apps I use? A: No, it specifically targets developers of very large, powerful “frontier” AI models, not the smaller apps or specialized tools you might use daily.

Q: When does this law take effect? A: Major AI developers must register with New York State by November 2026. Full compliance, including the mandatory incident reporting, is required by January 2027.

Q: Is New York the only state doing this? A: While other states are discussing AI rules, New York’s RAISE Act is one of the nation’s most comprehensive and binding laws specifically targeting high-risk AI systems.

Q: What is a “frontier” AI model? A: The term refers to the most advanced, general-purpose AI models with capabilities that could present significant risks to public safety. These are the foundational models built by companies like OpenAI, Google, and Anthropic.

Found this useful? Read more from the blog →