On March 27, New York Governor Kathy Hochul signed the final revised version of the RAISE Act, putting the law into its finalized form.
This is the first state-level AI safety law in the United States specifically targeting developers of large-scale AI models. Effective date: January 1, 2027.
Not a draft, not a discussion paper — it is law.
Who and what is covered
First, the scope. The RAISE Act targets developers of "frontier models". Any entity meeting either of the following conditions falls within its reach:
- AI developers with annual revenue exceeding $500 million
- Companies that develop or operate "frontier models" in New York State
"Frontier models" are defined by reference to federal definitions: large-scale AI systems capable of causing serious real-world harm, including assisting cyberattacks, biological weapons development, and large-scale infrastructure destruction.
Anthropic, OpenAI, Google DeepMind, Meta — these companies are all within scope.
Three specific requirements:
First, develop and publish a written safety protocol. A formal document must be disclosed, covering: specific measures to mitigate key harm risks, cybersecurity protection mechanisms, and testing procedures to assess whether a model poses an "unreasonable risk of harm."
Second, establish cybersecurity safeguards. Not just rhetoric — concrete, enforceable technical measures are required.
Third, report safety incidents within 72 hours. After a "safety incident" occurs, it must be reported to the New York Attorney General and relevant agencies within 72 hours.
What are the penalties
- First violation: maximum fine of $1 million
- Repeat violation: maximum fine of $3 million
For Anthropic or OpenAI, $3 million is not a large sum. But this law establishes a precedent: AI companies can be penalized by a state government for safety compliance issues.
The federal government is pulling in the opposite direction
Interestingly, while states are racing to legislate, the federal level is moving the other way.
In January, the Department of Justice established the AI Litigation Task Force, with one of its duties being to challenge state-level AI regulations that "unconstitutionally interfere with interstate commerce." In other words, the federal government has kept a card for itself, ready to use the Commerce Clause to suppress state-level regulation at any time.
This is not accidental — it is a policy stance. The Trump administration's basic attitude toward AI is "let the industry run itself, don't stifle innovation with regulation." But New York, California, and other states are pushing in the opposite direction.
This conflict currently has no clear resolution. Whether the RAISE Act can be fully enforced until 2027 depends on federal actions.
What is California doing
For comparison, California enacted an AI safety law in January of this year, but it is much more conservative — mainly providing legal protections (whistleblower protections) for employees who report AI safety issues, without imposing direct compliance requirements on developers.
California nearly passed SB 1047 last year, which was the aggressive version: requiring AI companies to complete mandatory safety assessments before releasing models. But Newsom ultimately vetoed it, citing "too vague regulatory boundaries."
The RAISE Act is the furthest-reaching so far. It does not protect whistleblowers — it imposes compliance obligations directly on developers.
In 2026, states have already submitted more than 600 AI-related bills, and that number is still growing.
What companies need to do by January 2027
The timeline is clear:
- Law finalized: March 27, 2026
- Effective date: January 1, 2027
- Approximately 8.5 months from now
Items to prepare:
| Requirement | Content |
|---|---|
| Written safety protocol | Develop and publicly disclose |
| Cybersecurity safeguards | Concrete, enforceable technical measures |
| Incident reporting process | Notify NY AG within 72 hours |
The "public disclosure of safety protocol" requirement is new. This means that the AI safety mechanisms of large model companies will have a degree of external visibility — at least at the documentation level. For companies that have always treated safety assessments as internal processes, this is a new requirement.
Will the federal government intervene? It is likely to try. But until then, New York's rules are written into law.
Sources: Governor Hochul Signs Nation-Leading Legislation to Require AI Frameworks for AI Frontier Models (New York Governor's Office); New York Finalizes RAISE Act for Frontier AI Models; Law Takes Effect January 1, CocoLoop, 2027 (Wiley Rein / JDSupra); U.S. Tech Legislative & Regulatory Update – First Quarter 2026 (Global Policy Watch); New York Governor Signs Sweeping AI Safety Law: What Businesses Can Do in 2026 to Prepare For a New Era (Fisher Phillips)