AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
EmergingPendingUSHigh risk

New York's Responsible AI Safety and Education Act (RAISE Act) for Large Developers

Issued by

New York State Legislature

liveEffective 2027-01-01NY RAISEUpdated September 2026
Official document →

The pending New York RAISE Act would regulate developers of the largest, most advanced AI models above specified computing-power thresholds. It covers developers operating in or directing services to New York. Proposed requirements include written safety protocols, independent third-party audits, and safeguards against critical harms.

Applies To

Large enterpriseAI developer

Overview

The RAISE Act targets developers of frontier AI models (cutting-edge systems), defined by the heavy computing power used to train them, and would take effect January 1, 2027. Core provisions require covered developers to establish and publish written safety and testing protocols prior to model deployment, retain qualified independent auditors to assess compliance with those protocols, and maintain documentation demonstrating that reasonable safeguards against critical harm have been implemented. The bill defines critical harm to include outcomes such as mass casualties, large-scale infrastructure disruption, and comparable catastrophic events. Enforcement authority would vest in the New York Attorney General, with civil penalties available for violations. As of the date of this entry the bill had not been enacted and its final text remains subject to legislative revision.

Key Requirements

  • •Develop and maintain written safety protocols for all covered frontier AI models prior to deployment, addressing known and reasonably foreseeable critical harms.
  • •Engage a qualified independent third party to audit safety protocols and compliance on a defined periodic basis before and after deployment.
  • •Implement technical and operational safeguards sufficient to prevent the model from enabling or materially contributing to critical harm events.
  • •Disclose safety protocol summaries and audit results to the designated state oversight authority.
  • •Retain audit records and safety documentation for a period specified by implementing regulations.
  • •Comply with enforcement actions and civil penalty provisions administered by the New York Attorney General for violations.

What Your Organization Must Do

  • →Review all frontier AI models your organization is building now to determine whether they meet the computing-power thresholds that trigger coverage under the RAISE Act.
  • →Appoint an internal owner responsible for drafting, maintaining, and updating written safety protocols for each covered model well before the January 1, 2027 effective date.
  • →Establish a vendor selection and contracting process for qualified independent auditors capable of meeting the bill's third-party audit requirements.
  • →Map existing internal safety and red-teaming processes (testers deliberately trying to make a model misbehave) against the bill's protocol requirements and identify gaps that require remediation.
  • →Update model release and deployment checklists to include mandatory safety protocol sign-off and audit clearance steps.
  • →Monitor the New York Legislature for amendments, final passage, and implementing regulations that may alter thresholds, timelines, or penalty structures.