Skip to content

NYDFS on AI Cybersecurity Risk: What the 2024 Letter Requires

9 min read · updated August 11, 2026

On 16 October 2024 the New York Department of Financial Services issued an industry letter on cybersecurity risks arising from artificial intelligence. It imposes no new obligation, and that is the point: every risk it names is routed back to a numbered section of Part 500 that already applied to you.

What the letter is, and what it is not

The instrument is a guidance letter, not a regulation. DFS says so explicitly in the letter itself: it does not impose new requirements beyond those in 23 NYCRR Part 500, the Department’s cybersecurity regulation for covered entities. What it does is set out how the Department expects existing obligations to be applied to AI-related risk, which in supervisory practice means it is the checklist an examiner has read. Covered entities are the banks, insurers, mortgage servicers, money transmitters and virtual currency businesses licensed under the New York Banking, Insurance or Financial Services Law — a wide population that includes many firms that do not think of themselves as New York regulated. The letter is published on the DFS industry letters page.

Guidance letters describe how a regulator reads its own rule; they are not the rule and they do not create a cause of action. This page is not legal advice. If you are a covered entity, have counsel confirm which Part 500 tier you fall into, because the exemptions in section 500.19 materially change what applies.

The four risks it names

The letter organises AI-related cybersecurity risk into four categories, and the split is more useful than most because two of them are about attackers using AI and two are about you using it.

  • AI-enabled social engineering. The Department singles out deepfake audio and video used to impersonate executives or customers, and treats it as the most significant near-term threat — specifically because it defeats voice-based identity verification and callback controls that were designed against human impersonation.
  • AI-enhanced cyberattacks. Faster reconnaissance, more capable malware, and a lower skill floor for attackers, which compresses the time between a vulnerability being disclosed and being exploited.
  • Exposure or theft of nonpublic information. Systems that use AI often accumulate large, centralised stores of NPI — including biometric data used for authentication — which makes them a more valuable target than the systems they replaced.
  • Increased vulnerabilities from supply chain dependencies. AI introduces new third and fourth parties: model providers, data vendors, and the vendors’ own vendors, each a path into your environment.

Where each one lands in Part 500

The compliance work is the mapping, so here it is in the terms the regulation uses.

  • Section 500.9 — risk assessment. The amended regulation requires the risk assessment to be reviewed and updated at least annually and whenever a material change occurs. Deploying an AI system, or a materially new use of one, is such a change; the letter expects AI-specific threats to appear in the assessment by name.
  • Section 500.11 — third-party service provider policy. Due diligence, minimum security practices, periodic assessment, and contractual protections. A model provider is a third party for this purpose, and the letter asks entities to consider the provider’s own AI-related exposure, which pushes the enquiry to the fourth party.
  • Section 500.12 — multi-factor authentication. The Second Amendment extends MFA to all individuals accessing any information system of a covered entity, with the final transitional period ending 1 November 2025. The letter notes that deepfakes weaken authentication factors based on voice or video, which is an argument for factor selection rather than for MFA in general.
  • Section 500.14 — monitoring and training. Annual cybersecurity awareness training must include social engineering; the letter expects that training to cover deepfakes specifically, and to reach the people who authorise payments.
  • Sections 500.7 and 500.13 — access privileges and asset inventory. Least privilege, periodic review of entitlements, and a documented inventory of information systems. An AI system that holds NPI is an asset that belongs on the inventory with an owner and an end-of-life.
  • Sections 500.3, 500.4 and 500.17 — policy, CISO and notice. The written policy must be approved annually by the board or a senior officer, the CISO reports on material risks, and cybersecurity events are notified within 72 hours.

The dates that matter

Part 500 was substantially amended by the Second Amendment adopted on 1 November 2023, and the new obligations phased in over two years, with transitional periods ending on 1 April 2024, 1 November 2024, 1 May 2025 and 1 November 2025. The AI industry letter of 16 October 2024 sits on top of that timeline and does not shift it. If you are reading this and your governance documents still describe the pre-2023 regulation, the AI letter is not your most urgent problem.

What an examiner will ask to see

Because the letter is a mapping exercise, the evidence is documentary rather than technical. Expect to be asked for: the risk assessment showing AI-related threats considered and rated; the vendor file for each model provider, including the due diligence performed and the contractual security terms; the inventory entry for each AI system with its data classification; the training materials showing deepfake content and the completion records; and the incident response plan revised to include a scenario in which an instruction to move money arrives by convincing synthetic voice.

If the entity also handles card payments, most of that file does double duty: the inventory, the vendor diligence and the retention decisions are the same artefacts PCI DSS asks for when a model can see a payment flow, scoped differently. Build them once and map them twice rather than maintaining two registers that drift apart.

The insurance side of the Department has moved separately and further: see its circular letter on AI in underwriting and pricing, which unlike this letter does ask insurers to demonstrate positive testing results rather than merely to consider a risk.