New York’s RAISE Act: frontier AI safety, with a 72-hour clock.
New York has joined California in regulating the companies that build the largest AI models — and it added a stopwatch. Under the Responsible AI Safety and Education (RAISE) Act, a covered developer that learns of a safety incident has 72 hours to tell the state. Governor Hochul signed the Act in December 2025, a chapter amendment finalized it on March 27, 2026, and it takes effect January 1, 2027.
As with every frontier-developer law, the headline is louder than the reach. Here is what it actually requires, and — just as important — who it does not touch.
What the RAISE Act requires
Covered developers must stand up a written set of safety and security protocols, keep an unredacted copy, publish a redacted version, and transmit that redacted copy to the New York Attorney General and the Division of Homeland Security and Emergency Services. They must grant access to the protocols on request. And they must report safety incidents — events that create a demonstrable increased risk of “critical harm” — to those same two agencies within 72 hours of learning of them. Rulemaking authority sits with the New York Department of Financial Services.
Who it binds — and who it doesn’t
Precision matters here more than anywhere, because “New York is regulating AI” will be read far too broadly.
- It binds large frontier developers. The obligations fall on developers with more than $500 million in annual revenue that train or operate frontier models — broadly, models trained above roughly 1026 FLOP with compute costs north of $100 million — in New York.
- It does not bind ordinary deployers. If you use AI, buy AI, or embed a vendor’s AI in your product, RAISE places no obligation on you. It is aimed squarely at the handful of companies training frontier-scale models.
The pattern is now unmistakable
Three states, one direction. California’s SB 53 requires frontier developers to publish safety frameworks and report incidents. Illinois’s SB 315 goes further and mandates independent third-party audits. New York’s RAISE Act adds published, agency-filed safety protocols and a hard 72-hour incident-reporting clock. The specifics differ; the through-line does not: transparency and fast incident reporting for the largest model builders, written into state law.
A 72-hour reporting duty will feel familiar to anyone who has lived through data-breach notification or product-safety regimes. That familiarity is the point — it signals that AI safety incidents are being absorbed into the same “tell the regulator quickly” machinery that already governs other high-stakes failures.
Why it matters even if it never touches you
If you build on top of frontier models — and most AI products do — your vendors are now the ones with published safety protocols and reporting obligations. That changes your diligence. The questions you should already ask (“what is your safety framework, and what happens when the model fails?”) now have a documented, state-filed answer you can request. Use it.
An honest disclosure about us
RAISE, like SB 53 and SB 315, concerns frontier-model safety. That is a different discipline from the AI management-system assurance chain — ISO/IEC 42001, ISO/IEC 42006, and ANAB accreditation — that Sentinel Assurance Group operates inside. We are not frontier-safety auditors and will not present ourselves as RAISE or SB 315 auditors. What we do is help the organizations these laws don’t directly bind build the governance they will increasingly be asked to evidence anyway.
What to do now
1. Confirm scope. Unless you train frontier-scale models in New York, RAISE is not your obligation — do not build a compliance program for a law that doesn’t reach you. 2. Fold it into vendor diligence. If a core AI vendor is a large frontier developer, their RAISE safety protocols and incident history are now part of your due-diligence trail. 3. Adopt incident-reporting hygiene early. Even without a 72-hour legal duty, knowing within hours that one of your AI systems has failed — and having a path to act — is simply good governance. 4. Build the portable foundation. Inventory, risk management, documented impact, disclosure: the same base every AI law rewards.
An honest limitation
The signing (December 2025), the finalizing chapter amendment (March 27, 2026), and the effective date (January 1, 2027) are well documented across counsel analyses; the FLOP and compute thresholds and the precise definition of “critical harm” come from that analysis and from the enacting text, and the DFS rulemaking that will put flesh on them is still to come. Treat the thresholds as directional until the rules land, and verify against the statute before relying on any specific number. What will not change is the shape: New York now expects the largest developers to publish their safety posture and report failures fast — and it tells everyone downstream where the expectation is heading.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 14, 2026.
See how a Gap Assessment maps your exposure →Not sure whether any frontier-AI law reaches you?
Find out in 30 minutes.
The free AI Risk Exposure call maps your AI footprint — and your vendors’ — to the obligations that actually apply.
Book the call →