On September 21, 2026, New York Governor Kathy Hochul unveiled the implementation timeline for the New York RAISE Act (Responsible AI Safety and Education Act): starting this November, frontier AI developers with more than $500 million in annual revenue must register with the state of New York; once the law takes effect on January 1, 2027, obligations will kick in one by one — publishing safety frameworks, reporting critical safety incidents within 72 hours, and submitting quarterly assessments of catastrophic risks. This is the first U.S. state-level regulatory action to give frontier model developers a concrete compliance calendar, but its authority stops at the New York state line. It is not federal law, and it is certainly not a global rule.
What happened: a two-step compliance calendar
At her September 21 press conference, Hochul drew two lines. Step one, in November 2026: the state will open a registration channel through the Department of Financial Services and require covered frontier AI developers to file. Registration itself creates no new substantive obligations — its purpose is to give regulators a roster of who is training advanced systems. Step two, after the law takes effect on January 1, 2027: covered developers must publish safety and transparency frameworks on their websites, report critical safety incidents to the newly created Office of Digital Innovation, Governance, Integrity and Trust (DIGIT, housed within the Department of Financial Services) within 72 hours, file quarterly assessments of catastrophic risks, and submit a disclosure statement at least every two years. Marc Gilman has been named deputy director of the DIGIT office to lead the rollout.
The price of non-compliance is already on the table: the state Attorney General's office may bring civil actions against companies that fail to comply or make false statements, with penalties disclosed by the governor's office of up to $1 million for a first violation and up to $3 million for subsequent ones. Hochul also told companies planning lawsuits to "bring it on," and said New York is not ruling out a frontier AI "kill switch" — California's frontier AI kill-switch legislation is worth following alongside.
Who is in scope, and who is not
The law's crosshairs are narrow: it covers only large frontier AI developers with more than $500 million in annual revenue, with OpenAI and Anthropic named by multiple outlets as the archetypal examples. Ordinary AI application companies, individual developers, and academic institutions are not subject to the registration or reporting duties.
But "out of scope" does not mean "unaffected." Banks and fintech firms in New York run these frontier models across customer service, fraud detection, and payments — once a vendor reports a critical safety incident under the 72-hour rule and begins investigating, restricting model access, or changing how the model works, downstream business processes may have to adjust in lockstep. The New York City Council is also advancing its own AI bills (NYC Council's AI bills: mandatory third-party verification and kill switches), so AI-related businesses operating in New York face two overlapping rulebooks — state and city.
One more boundary must be drawn clearly: this is a New York state statute. Hochul herself framed the move as a response to federal inaction — Congress has not passed any substantive AI legislation this session. Reading it as a "new U.S. rule" or a "global trend" would be wrong; beyond New York's borders, it has no binding force.
What to do: three things to prepare now
First, frontier model companies doing business in New York, or whose model services reach New York users, should treat November registration as a hard deadline: assemble corporate identity information, descriptions of training activities, and compliance contacts. The state has promised to publish registration details before November, leaving a window to prepare.
Second, write the 72-hour reporting mechanism into internal processes: define what counts as a "critical safety incident," who has authority to approve a filing, and how long evidence and logs are retained. The DIGIT office has said it will review the safety frameworks companies publish — a hollow framework hands regulators ammunition.
Third, enterprise customers of model services — especially in heavily regulated sectors like finance and healthcare — should add incident-notification clauses to vendor contracts: how many hours after a vendor files an incident report must you be told, and what options do you have when services degrade or models change. If you wait until an incident actually happens to negotiate, the leverage is gone.
Where the risks are
The biggest risk is not any single obligation being too heavy — it is regulatory fragmentation. California signed an executive order on September 18 advancing independent audits and a kill switch, New York's RAISE Act starts registration in November and takes effect in January, and New York City has its own bills on the way. Frontier model companies will soon have to satisfy several state-level regimes at once, and the compliance costs stack rather than substitute.
Second is enforcement uncertainty. Registration and reporting details have not been published, and the DIGIT office is still being staffed. Every document companies prepare now may need rework once the details land. The governor has already signaled a courtroom fight, and corporate legal teams are likely preparing constitutional challenges — until the courts weigh in, this timeline could be delayed or amended.
Finally, there is the "roster effect" itself: November's registration will give regulators, for the first time, a complete roster of who the regulated frontier AI companies are. That means covered companies will henceforth operate in the spotlight — companies with strong compliance can turn registration into a trust asset; those with weak practices will be scrutinized under a magnifier.