New York RAISE Act Is Finalised: 72-Hour Incident Window, $1M Penalties, Effective January 2027
New York Governor Kathy Hochul signed the final chapter amendment to the Responsible AI Safety and Education (RAISE) Act on March 27, 2026, locking in the definitive compliance framework for frontier AI developers operating in the state. The law takes effect January 1, 2027.
The RAISE Act was first signed in December 2025, but lawmakers committed at the time to chapter amendments that would narrow the scope and reduce penalties before any enforcement began. Those amendments passed the legislature on March 11 and were signed sixteen days later.
Who It Covers
The revised law targets “large frontier developers” — defined as anyone who has trained a frontier model with annual revenue exceeding $500 million. The original compute-cost threshold ($100M in training spend) was dropped in favour of the revenue trigger, which aligns the New York definition with California’s SB-53.
A frontier model means a foundation model trained using more than 10^26 floating-point operations. Knowledge distillation models derived from a frontier model are also covered where compute costs exceed $5 million — closing a fine-tuning workaround.
The geographic scope is tight by design: the law applies to frontier models “developed, deployed, or operating in whole or in part in New York State.” Models with any operational footprint in New York are in scope, regardless of where the developer is headquartered.
What It Requires
All covered frontier developers, regardless of revenue, must meet baseline transparency and incident reporting obligations. Large frontier developers face a heavier compliance load:
- Frontier AI framework: Must write, implement, and conspicuously publish a safety framework on its website. Annual review minimum.
- Critical incident reporting: Notify the New York Department of Financial Services within 72 hours of a critical safety incident. This is materially stricter than California’s SB-53, which allows 15 days.
- DFS registration: Large frontier developers cannot develop, deploy, or operate in New York without filing a current registration with the new DFS oversight office.
A new Office of Frontier AI Safety within DFS handles enforcement and will produce anonymised annual reports beginning January 2028.
Penalties
The amendment cut maximum civil penalties from $10 million to $1 million for a first violation, and $3 million for subsequent violations — landing in line with California’s penalty caps. The New York Attorney General retains enforcement authority.
The Compliance Picture
Four state AI laws are now either in effect or taking effect before this one. California’s SB-53 went live January 1, 2026. Texas’s TRAIGA and Colorado’s AI Act both have 2026 enforcement dates. New York joins as the fourth significant state-level frontier model law, but the only one with a sub-24-hour-class incident disclosure requirement.
The White House released its National AI Legislative Framework in March — a nonbinding roadmap explicitly pushing to preempt state laws — but that has no legal force. Until Congress passes a federal preemption statute, the state patchwork stands. Lawmakers in 45 states have introduced 1,561 AI-related bills in the 2026 session, already surpassing the full-year 2024 total of 635.
For the six labs that qualify — Anthropic, OpenAI, Google DeepMind, Meta AI, xAI, and Microsoft — the practical compliance question is now whether to build to New York’s 72-hour reporting standard globally, or maintain state-specific incident response tracks. California’s 15-day window and New York’s 72-hour window are the two active benchmarks in that conversation.
Key Numbers
- Revenue threshold: $500M annual (large frontier developer)
- Compute threshold for covered models: >10^26 FLOPs
- Knowledge distillation threshold: >$5M compute cost
- Incident reporting window: 72 hours (critical incidents)
- First-violation penalty: up to $1M
- Subsequent violations: up to $3M
- Enforcement start: January 1, 2027