New York AI Registration Begins in November Ahead of 2027 RAISE Act Deadline
New York will begin directing large developers of frontier AI models to register with the state in November, Gov. Kathy Hochul announced, opening the first operational phase of New York AI registration under the Responsible AI Safety and Education Act. The statute, known as the RAISE Act, takes effect on January 1, 2027, and the November window gives Albany a standing inventory of who is training advanced systems inside the state. Hochul also announced the first hire for the new office that will oversee the law.
Registration runs through a state portal and is aimed at large frontier developers rather than the whole industry. Companies generating more than $500 million in annual revenue fall within scope and must file with the New York State Department of Financial Services. Those filings are the front end of a broader set of obligations covering transparency, safety practices and incident reporting.
The filing requirement is administratively modest on its own. Its weight comes from what it enables. New York is assembling the roster it needs to enforce a safety regime that has no federal counterpart, and it is doing so while national AI legislation remains unresolved. For developers, the question has shifted from whether state oversight arrives to how many versions of it they must satisfy at the same time.
What the RAISE Act Requires
The law's core obligation is disclosure. Developers must report certain safety incidents within 72 hours, prepare for transparency duties toward regulators and the public, and accept state oversight of how they manage model risk. The November registration period exists so the state has identified its regulated population before the effective date rather than after it.
The 72-hour incident window is the most operationally demanding piece. Engineering teams that uncover a serious model failure must decide quickly whether it qualifies, notify the state and preserve documentation. That timeline compresses the internal review that most AI labs currently run on their own schedules and at their own discretion.
Enforcement sits with an office that is still being built. The state named its first hire for that office alongside the November timeline, which leaves a narrow runway before January 1, 2027. Between now and then, the office must define reportable incidents, stand up intake processes and decide how it will handle filings from companies headquartered far from Albany.
California Moved First, on a Different Mechanism
New York is not the first state to act. California has already passed audit and procurement laws governing how its agencies buy and evaluate AI, and on September 18 it issued an executive order pushing agencies toward frontier-model oversight, including a proposed emergency shut-off. The two states regulate through different levers.
California's procurement route binds vendors that want state contracts. New York's registration route binds firms by revenue and model capability whether or not they ever sell to the state. A developer that never bids on a California contract can still owe New York a filing, and a developer that does both carries two separate compliance calendars.
| Dimension | New York (RAISE Act) | California |
|---|---|---|
| Primary lever | Registration and incident reporting | Audit and procurement requirements |
| Who is bound | Developers above $500M annual revenue | Vendors and agencies in scope of state contracting |
| Key dates | Registration from November; law effective January 1, 2027 | Executive order issued September 18; audit and procurement rules in force |
| Reporting clock | Safety incidents within 72 hours | Disclosure tied to audit and procurement review |
| Enforcement venue | New state AI oversight office, filings to DFS | State agencies and their procurement processes |
The table understates the practical overlap. Both states are acting while federal rules stay unresolved, so developers face New York AI registration, California's audit and procurement rules, and disclosure duties stacked across jurisdictions instead of one national standard.
The severities differ too. California's proposed emergency shut-off would let the state halt a model in operation, a power New York's statute does not grant in the same form. New York's leverage runs through disclosure and the reputational cost of being a named filer, which is a slower instrument but one that reaches developers regardless of whether they contract with the state.
The Trade-Offs for Developers
For frontier labs, the cost calculus splits. Registration is cheap next to auditing. A filing plus an incident-reporting channel costs far less than a third-party safety audit or a procurement review, and it does not require opening a model to outside examiners. What labs give up is control over timing: under a 72-hour rule, the moment a failure becomes visible to a regulator is set partly by statute rather than by the company's own review cycle.
New York gains visibility and takes on enforcement risk. A registry is only as useful as the office behind it, and that office is not yet fully staffed. If definitions of reportable incidents are vague, filings become inconsistent and comparisons across developers become meaningless. If they are too broad, small events flood the system and the registry stops functioning as an early-warning tool.
The $500 million revenue threshold creates its own distortion. Startups stay out of the filing regime, which preserves room for smaller labs. Crossing the line, however, adds a state reporting duty overnight on top of any federal and other state obligations already in place. Companies approaching the threshold have a reason to model that step change before it arrives, since compliance staffing follows revenue with a lag.
Placing the registry with the Department of Financial Services is a detail with consequences. The agency already supervises banks and insurers, so it brings an examination culture and existing reporting machinery to AI oversight. That could shorten the build-out. It could also push AI developers toward the documentation and record-keeping habits of regulated financial firms, which are heavier than what most model labs maintain today.
A Patchwork, Not a Standard
The structural outcome is fragmentation. Developers now face registration in New York, audit and procurement duties in California, and disclosure expectations that shift by jurisdiction, all with no federal statute to consolidate them. Multistate compliance teams will maintain parallel calendars, incident definitions, reporting templates and disclosure formats.
That overhead is easy to underestimate. Incident definitions rarely match across regimes, so one event can start different clocks in different states. Legal and policy staff become the bottleneck, and product timelines absorb the delay. For companies with a single large model release per year, a poorly timed incident can push a launch into a quarter where reporting obligations are already queued.
The counterargument is that this is transitional and that federal preemption or a national framework will eventually fold the state rules into one. Nothing in the current record supports that. New York's registration window opens in November, California's executive order is already in force, and no federal statute sets a competing deadline.
What to Watch
Treat New York AI registration as a standing compliance function rather than a project. Companies above the revenue threshold should map which entities in their corporate structure owe a filing, confirm who signs it, and build a 72-hour incident escalation path that does not run through a single legal team. Companies below the threshold should track the trigger and price the cost of crossing it.
The near-term milestone is the state's first published list of registered developers and its guidance on what counts as a reportable incident. Those two artifacts will decide whether New York AI registration becomes a working enforcement regime or a filing exercise that consumes staff time without changing how models are built and released.
Why this matters
New York's November window matters less for what it demands this year than for the infrastructure it creates by 2027: a state-level registry and incident-reporting system operating without federal cover. For AI developers, compliance burden is now a function of geography as much as capability, and firms that build state-by-state reporting into their operations early will absorb the January deadline far more cheaply than those that treat it as a one-off filing.
Sources
Related Articles
- New Deadlines for EU AI Act Compliance: High-Risk System Requirements Delayed to 2027
- EU AI Act Deadlines Shifted for High-Risk Systems and New Prohibitions
- Illinois Mandates Independent AI Safety Audits in Landmark Accountability Law
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.