Implementing New York’s RAISE Act: What General Counsel Need to Know

The RAISE Act regulates frontier-model developers but creates disclosures that may shape vendor diligence and governance across industries.


Timothy J. Plunkett

September 23, 2026 02:30 PM

New York is implementing the Responsible AI Safety and Education Act (“RAISE Act”), a targeted law governing developers of frontier artificial intelligence models. Beginning in November 2026, New York will direct covered developers to register in advance of the Act’s January 1, 2027, effective date. The Office of Digital Innovation, Governance, Integrity and Trust (“DIGIT”), within the Department of Financial Services, will oversee implementation.

For most companies, the Act will matter less as a direct compliance mandate than as a new source of information about major AI vendors and their risk controls.

Who Is Covered?

A “frontier model” is generally a foundation model trained using more than 10^26 integer or floating-point operations. The most extensive duties apply to “large frontier developers,” meaning frontier developers whose annual gross revenues, together with affiliates, exceeded $500 million in the preceding calendar year.
The Act does not generally regulate a business merely because it buys or uses a third-party AI tool.

What Does the RAISE Act Require?

Covered developers face several core requirements:

  • Large frontier developers must publish and follow Frontier AI Frameworks addressing catastrophic-risk controls, cybersecurity, incident response and governance.
  • Frontier developers must publish specified information when deploying new or substantially modified models; large frontier developers must also summarize catastrophic-risk assessments and related safeguards.
  • Large frontier developers must confidentially report assessments of catastrophic risks arising from use of internal modelsevery three months, unless DIGIT approves another schedule.
  • Frontier developers must report critical safety incidents within 72 hours. Incidents presenting an imminent risk of death or serious physical injury also require disclosure within 24 hours to an appropriate authority, as required by law.
  • Large frontier developers must maintain disclosure statements with DIGIT, renew them at least every two years and pay pro rata regulatory assessments.
  • The Attorney General may seek penalties of up to $1 million for a first violation and up to $3 million for each subsequent violation. The Act expressly creates no private right of action.

Why This Matters to General Counsel

Although few companies will be directly regulated, the required disclosures may improve vendor diligence and contract negotiations by revealing how covered developers govern safety, cybersecurity and catastrophic risk. Examples:

  1. AI Vendor Diligence
    The new disclosures should give legal and procurement teams a more concrete basis to compare providers, test contractual representations and evaluate whether vendors have credible safety, cybersecurity and escalation controls.
  2. Board and Management Oversight
    Even where the Act does not apply directly, its framework offers a useful benchmark for documenting responsibility, risk assessment and escalation. Companies should be prepared to explain how material AI risks are identified, assigned and monitored.
  3. Incident Management
    The 72-hour reporting period underscores the need for rapid internal escalation. Businesses should confirm that AI-related events are incorporated into existing cybersecurity, privacy and incident-response procedures, including vendor-notification requirements.

    General Counsel should use the implementation period to inventory AI use, review vendor disclosures and contracts, and confirm that governance and incident-response processes address AI-related risks.
  4. Regulatory Change
    DIGIT has express rulemaking authority, and state officials have indicated that additional AI initiatives may follow.

Practical Takeaway

The RAISE Act is not a general AI-use law. It regulates frontier-model developers while creating disclosures that may shape vendor diligence and AI governance across industries.

Our Artificial Intelligence Industry Team is closely tracking this and related matters. If you have questions or concerns, please contact attorney Timothy J. Plunkett at (914) 298-3004 and tplunkett@harrisbeachmurtha.com; attorney Brendan M. Palfreyman at (315) 214-2161 and bpalfreyman@harrisbeachmurtha.com; or the Harris Beach Murtha attorney with whom you most frequently work.

This alert is not a substitute for advice of counsel on specific legal issues.

Harris Beach Murtha’s lawyers and consultants practice from offices throughout Connecticut in Bantam, Hartford, New Haven and Stamford; New York State in Albany, Binghamton, Buffalo, Ithaca, New York City, Niagara Falls, Rochester, Saratoga Springs, Syracuse, Long Island and White Plains; as well as in Boston, Massachusetts; Providence, Rhode Island; and Newark, New Jersey.