New York is standing up the country's first operational state-level compliance apparatus for frontier AI developers, combining mandatory registration, incident-reporting deadlines, and the specter of an emergency "kill switch" in a framework that goes further than any US state has managed to enact and enforce.
Why it matters
California's attempt at frontier AI safety legislation was vetoed. New York's was not. Governor Kathy Hochul signed the Responsible AI Safety and Education Act in December 20251,5, and on Monday she laid out the operational timeline: registration begins in November, full enforcement starts in January 20273,6. AI developers with annual revenues exceeding $500 million, a threshold that captures OpenAI and Anthropic by name, must register with the New York State Department of Financial Services8. ANALYSIS The revenue threshold and named companies make clear this is aimed squarely at the handful of frontier labs, not the broader software industry.
The big picture
The RAISE Act creates a new oversight body, the Office of Digital Innovation, Governance, Integrity and Trust, known as DIGIT, housed within the Department of Financial Services12. Hochul announced its first full-time hire: Marc Gilman, former head of compliance at Theta Lake, a California-based AI security company, who will serve as deputy director overseeing the law's rollout. Attorney General Letitia James's office will handle enforcement, and companies that fail to comply face civil penalties9.
The substantive obligations are layered. Large frontier AI developers must establish and publish safety frameworks on their websites. They must file quarterly assessments of catastrophic risks with DIGIT. And they must report critical safety incidents to the office within 72 hours. The largest developers must also publicly explain how they assess and guard against potentially catastrophic risks.
Hochul positioned the effort against federal inaction. "Donald Trump and Washington Republicans may be standing still as AI grows more unpredictable, but New York will not," she said. President Trump, for his part, has said the DOJ and "other law enforcement bodies 'will rein things in if we have to'"2, and has floated creating an "AI force" modeled on Space Force, including a yet-to-be-named AI czar4. ANALYSIS The contrast is structural: New York is building a dedicated regulatory office with named staff and statutory deadlines, while the federal posture remains aspirational.
Some Democratic members of Congress are also increasing calls for regulation, as are leaders at Anthropic, OpenAI, and Google. ◆ That alignment between certain labs and state regulators could ease early compliance, though it does not eliminate the legal risk Hochul herself acknowledged.
Between the lines
The most provocative element of Monday's announcement was not the registration mandate but Hochul's willingness to discuss an AI kill switch. "We may even explore safeguards like AI kill switches if they're deemed feasible and in the best interests of our state," she said11. Asked for specifics, she hedged: "All options are on the table," she said, adding that the state would research possible safeguards as it develops proposals for her next State of the State agenda. "No commitments at this time".
ANALYSIS The kill-switch language serves a dual purpose: it signals to safety-minded constituencies that New York will go beyond disclosure requirements if warranted, while the explicit caveat ("if they're deemed feasible") preserves room to retreat if technical or legal analysis counsels against it.
Hochul also acknowledged the industry's likely response head-on. "I also know there's other AI developers already on the phone with their legal teams planning their lawsuits against us," she said. The RAISE Act is part of a broader initiative that includes a one-year statewide moratorium on building large-scale data centers. ◆ Pairing a developer registry with a data-center moratorium raises the compliance burden on two fronts simultaneously, giving potential challengers multiple grounds for litigation.
The push comes, Hochul's team noted, amid "several recent tests in which models acted outside the boundaries their developers intended, including instances involving OpenAI, Anthropic and Meta".
What's next
The November registration window is the first concrete deadline. DIGIT's annual reports on frontier model safety will begin after the January enforcement date, and the office is empowered to recommend changes to the RAISE Act. Another bill in the pipeline would require DIGIT to establish minimum standards for frontier AI safety frameworks. Hochul said the state will continue to explore additional legislation and stronger oversight in the months ahead7. The first legal challenges, if they come, will test whether a single state can impose compliance costs on companies whose models are trained and served globally.