Skip to content

New York's RAISE Act: Frontier AI Safety Reporting

9 min read · updated August 11, 2026

The RAISE Act is the second American attempt to regulate frontier model developers by compute threshold. Its substance is close to California’s; its status has moved more than its substance, and that is the first thing to establish.

Status: check this before anything else

The Responsible AI Safety and Education Act was introduced in the New York legislature as S6953B and its Assembly companion A6453B, and passed both houses in June 2025. Under New York’s procedure a passed bill is not law until it is delivered to and signed by the Governor, and New York routinely enacts bills subject to chapter amendments — an agreement under which the Governor signs on condition that the legislature immediately amends the text in the following session. The RAISE Act was negotiated on that basis, and the amended text differs from the version that passed in June 2025.

This is not legal advice, and this page deliberately does not assert a current effective date. Before relying on any obligation described here, check the bill’s status and the chaptered text directly at the New York Senate’s bill page. Writing about a proposal as though it were in force is the single most common error in coverage of this statute, and the reported thresholds and penalty figures were among the items in negotiation.

What follows describes the mechanism the Act establishes and the shape of its duties, which is stable across the versions, and flags the specific figures that were subject to amendment.

Who is a large developer

Coverage works the way California’s does: two gates, one about compute and one about money. A frontier model is defined by a training-compute threshold, expressed in the passed version as more than 1026 operations combined with a compute cost above $100,000,000, with a parallel branch capturing models distilled from such a model above a much lower compute-cost figure. A large developer is a person who has trained at least one frontier model and has spent more than $100,000,000 in aggregate compute costs doing so.

The effect of the money gate is the same as California’s revenue gate and is worth stating plainly: this is not a law about AI products. It reaches a handful of laboratories, it does not reach the companies that build on their APIs, and a startup fine-tuning an open-weight model is nowhere near it. If you are deploying models rather than training them from scratch at that scale, your New York obligations come from elsewhere — from Local Law 144 if you screen candidates, from the SHIELD Act if you hold private information about New Yorkers, and from general consumer protection law.

The safety and security protocol

The central duty is documentary. A large developer must implement a written safety and security protocol describing how it manages the risk of critical harm from its frontier models, publish a copy with trade secrets and security-sensitive detail redacted, retain an unredacted copy for a defined period, and review the protocol periodically. It must also not deploy a frontier model where doing so would create an unreasonable risk of critical harm.

Critical harm is defined by scale rather than by kind, and the passed version set it at the death or serious injury of 100 or more people, or at least $1,000,000,000 in damages to rights in money or property, caused or materially enabled by a frontier model through chemical, biological, radiological or nuclear weapon assistance or through conduct that would be a crime if committed by a human with intent. Those figures are higher than California’s equivalents, and both sets of numbers were the subject of amendment discussion.

One provision was in the passed bill and was reported as removed during the chapter-amendment negotiation: a requirement for annual third-party audits of compliance. Whether the enacted text contains an audit duty is exactly the kind of question that has to be answered from the chaptered text rather than from coverage of the June 2025 version.

Incident reporting to the Attorney General

The Act requires a large developer to disclose a safety incident to the New York Attorney General and to the Division of Homeland Security and Emergency Services within 72 hours of discovering it, or of receiving information from which a reasonable belief of an incident arises. The defined incidents include unauthorised access to or theft of model weights, a model autonomously engaging in behaviour other than at a user’s request in a way that increases the risk of critical harm, a critical failure of technical or administrative controls, and conduct that materially increases the risk of critical harm.

The 72-hour clock is shorter than California’s 15 days and matches the rhythm of breach-notification law rather than of safety engineering. It runs from the point at which a reasonable belief arises, which in practice means from an on-call escalation and not from the completion of a post-incident review. Enforcement is by the Attorney General through civil penalties; the penalty figures in the passed version were reported at up to $10,000,000 for a first violation and up to $30,000,000 for subsequent ones, and were among the terms discussed in the amendment process. There is no private right of action.

Read alongside California SB 53

A laboratory in scope of both will find the duties broadly parallel and the details irreconcilable in exactly the ways that create work: different compute and cost thresholds, different critical-harm definitions, different incident categories, different clocks — 72 hours in New York against 15 days, or 24 hours in the imminent-risk case, in California — and different recipients, the Attorney General and DHSES in one, the Office of Emergency Services in the other.

The rational response to two nearly-identical regimes is one internal process built to the strictest element of each: the shortest clock, the broadest incident definition, the most detailed published protocol. That is a familiar pattern from privacy law, where organisations built to GDPR and then treated the American regimes as subsets. For the California instrument in detail, see the SB 53 page; for the wider American picture, see the state law overview.

One final point of caution. Because this page is about an instrument whose status has moved, the honest position is that it tells you what to look for and where the differences from California lie — not what binds you today. That question has one correct source, and it is the chaptered text on the legislature’s own site.