The rollout, detailed by Hochul’s office, creates a compliance calendar that obliges large frontier‑model developers to file a registration form with the newly created Office of Digital Innovation, Governance, Integrity and Trust (DIGIT), housed within the Department of Financial Services.
Marc Gilman was named deputy director for the RAISE Act in DIGIT, tasked with overseeing the quarterly risk assessments, safety‑framework disclosures and 72‑hour critical‑incident notifications that developers must submit to the state.
Under the schedule, developers will have to publish transparency and safety frameworks, submit periodic assessments of catastrophic risks, and report any serious safety incident to DIGIT within 72 hours of occurrence. The first set of public‑safety requirements will become effective in January.
The law targets only the largest AI model developers, not every financial institution that purchases their services, but regulators warn that banks and fintech firms could still feel the impact if a vendor’s model is forced to suspend access or undergo a safety investigation.
Hochul’s administration noted that civil penalties of up to $1 million for a first violation and $3 million for subsequent violations could be imposed for failure to file required reports or for false statements, giving the state enforcement teeth.
Financial institutions are now urged to ask AI vendors how a reportable incident would affect their operations, what notice timelines look like, and whether they can isolate or shut down a model’s authority without halting entire workflows.
The guidance also highlights the need for banks to develop fallback plans, such as manual processes or alternative models, because switching providers can be complex when prompts, data pipelines, and approval steps are tightly integrated with a single vendor.
While Governor Hochul has floated the idea of an AI “kill switch” in future discussions, the current RAISE Act does not require such a mechanism. Nonetheless, the compliance calendar gives banks a concrete deadline to decide how to limit or suspend AI tools within their own systems before a vendor incident forces a reaction.