{"id":355725,"date":"2026-09-24T14:32:10","date_gmt":"2026-09-24T14:32:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-ny\/355725\/"},"modified":"2026-09-24T14:32:10","modified_gmt":"2026-09-24T14:32:10","slug":"new-york-could-share-frontier-ai-safety-reports-nationwide-without-new-legislation","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-ny\/355725\/","title":{"rendered":"New York Could Share Frontier AI Safety Reports Nationwide Without New Legislation"},"content":{"rendered":"<p>Some of the most consequential risks from frontier artificial intelligence (AI) may emerge before a model ever reaches the public. Frontier labs often run more advanced models internally, sometimes with fewer safeguards than in their public-facing systems.<\/p>\n<p>These risks have already materialized. In July, <a href=\"https:\/\/openai.com\/index\/hugging-face-incident-and-the-road-ahead\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI agents<\/a>, most of which were instances of an internal research model that has not been released to the public, were being evaluated on their cybersecurity capabilities. For the purpose of evaluation, safeguards that would normally block high-risk cyber activity had been turned off. The agents were supposed to remain isolated from one another but discovered an unintended means of communicating, collaborated to gain access to the internet, and coordinated to hack into Hugging Face, an external AI platform, looking for information that could help with passing their evaluations. This incident prompted <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic to review its own evaluation runs<\/a>, where it found similar incidents in which its models, including internal research models, gained unauthorized access to other organizations\u2019 production systems.<\/p>\n<p>OpenAI and Anthropic publicly disclosed these incidents. But notably, they were not required by federal or state law to do so. For future potentially more serious incidents, the incentives for disclosing such information may be weaker because disclosure could expose developers to liability or reputational damage for real-world harms caused by their models. Accordingly, California, New York, and Illinois have each enacted frontier AI safety laws requiring that large frontier developers submit summaries of catastrophic-risk assessments resulting from internal model use (\u201cinternal use reports\u201d) and critical safety incident reports to designated state agencies. Those laws are <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202520260SB53\" rel=\"nofollow noopener\" target=\"_blank\">California\u2019s Transparency in Frontier Artificial Intelligence Act<\/a> (SB 53), <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" rel=\"nofollow noopener\" target=\"_blank\">New York\u2019s Responsible AI Safety and Education<\/a><a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\"> (RAISE)<\/a><a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\"> Act<\/a>, and <a href=\"https:\/\/www.ilga.gov\/Documents\/Legislation\/PublicActs\/104\/PDF\/104-0538.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Illinois\u2019s Artificial Intelligence Safety Measures Act<\/a>. No comparable mandatory reporting requirement for frontier developers exists at the federal level. The 47 other U.S. states do not yet have such legislation and would not automatically receive the same information, even though they face the same risks. If a developer subject to all three state laws discovered during evaluations, for example, that its most advanced internal models were capable of shutting down power to hospitals in ways that could cause mass casualties, California, New York, and Illinois would receive summaries of that catastrophic-risk assessment and could use that information to prepare, while other states without such laws like Michigan or Texas would not be entitled to receive the same information directly from the developer. That gap could be narrowed if a state receiving these reports could securely share them with other states. The remaining 47 states could then receive the same warnings, at the sending state\u2019s discretion, without first having to enact their own frontier AI reporting laws.<\/p>\n<p>Unlike California&#8217;s and Illinois&#8217;s frontier-model safety laws, <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">New York&#8217;s RAISE Act<\/a>, which takes effect on Jan. 1, 2027, permits the New York Department of Financial Services (NYDFS) to share both internal use reports and critical safety incident reports with other governmental entities. If NYDFS shares those reports with agencies in other states, however, the RAISE Act does not by itself guarantee that they will remain confidential. The RAISE Act exempts critical safety incident and internal use reports from <a href=\"https:\/\/www.nysenate.gov\/legislation\/laws\/PBO\/A6\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">N<\/a><a href=\"https:\/\/www.nysenate.gov\/legislation\/laws\/PBO\/A6\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">ew York&#8217;s own <\/a><a href=\"https:\/\/www.nysenate.gov\/legislation\/laws\/PBO\/A6\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">Freedom of Information Law<\/a>, which generally requires agencies to disclose records upon request, subject to specified exemptions. But this exemption from public disclosure under New York law would not automatically protect a copy shared with an agency in another state from disclosure under that state\u2019s public records laws. Large frontier developers would likely provide less detail in their reports if NYDFS forwarded them to states that, unlike New York, lacked an explicit exemption for these reports from their public-records disclosure laws. In those states, the reports could become publicly available, potentially revealing concrete information about internal model capabilities that competitors could use or vulnerabilities that malicious actors could exploit. NYDFS could wait for each state to enact its own protections before sharing, but that could take years, and the risks these reports are meant to catch are already present.<\/p>\n<p>Instead, NYDFS could share the information with other state financial regulators through the Nationwide Multistate Licensing System &amp; Registry (NMLS). NMLS is a nationwide licensing, registration, and supervisory platform used by state financial regulators. <a href=\"https:\/\/www.dfs.ny.gov\/reports_and_publications\/press_releases\/pr1810011\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">NYDFS<\/a>, <a href=\"https:\/\/www.csbs.org\/csbs-mortgage-contacts-directory\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">like financial regulators in every state<\/a>, already uses NMLS to administer licenses and to exchange highly sensitive information about the companies licensed on the platform. The platform benefits from the federal SAFE Act, which <a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/12\/5111\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">shields information shared through it<\/a> from every recipient state&#8217;s public records laws, provided the information was exempt in the sending state and the recipient has financial services industry oversight. Because internal use and critical safety incident reports are already exempt from New York&#8217;s public records laws, NYDFS could share them through NMLS without their becoming subject to other states&#8217; public records laws.<\/p>\n<p>To do so, NYDFS could draw on its authority over large frontier developers under the RAISE Act alongside its authority as the state\u2019s financial services regulator. <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">The RAISE Act<\/a> requires large frontier developers to file disclosures and pay a pro rata share of NYDFS\u2019s costs of administering the RAISE Act. It also requires NYDFS to maintain a public list of companies that have made filings of this nature. As the state&#8217;s financial regulator, NYDFS is also responsible for <a href=\"https:\/\/law.justia.com\/codes\/new-york\/fis\/article-2\/201\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">ensuring the safety and soundness<\/a> of financial institutions in the state, the authority it already uses to <a href=\"https:\/\/www.law.cornell.edu\/regulations\/new-york\/23-NYCRR-500.11\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">protect them from third-party vendor risk<\/a>. Building on this, NYDFS could create a publicly available Frontier Model Financial Services Provider Designation identifying which large frontier developers are in compliance with the RAISE Act\u2019s disclosure and payment requirements, and could require financial institutions in the state to use only models from developers that hold the designation. This requirement would protect the state\u2019s financial institutions from third-party vendor risk\u2014including the risk that a noncompliant developer\u2019s models take unauthorized action or gain improper access to sensitive systems. It would also provide a basis for hosting the designation on NMLS and using the platform to share critical safety incident and internal use reports with financial regulators nationwide.<\/p>\n<p>The proposed mechanism is illustrated in the graphic below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" sf-image-responsive=\"true\" src=\"https:\/\/www.newsbeep.com\/us-ny\/wp-content\/uploads\/2026\/09\/designation-and-use-by-dfs-regulated-entities-ai.png\" height=\"468\" style=\"max-width:100%;display:block;margin-left:auto;margin-right:auto;\" title=\"Designation and Use by DFS-Regulated\" width=\"702\" alt=\"\" sf-size=\"627961\" sfref=\"[images%7COpenAccessDataProvider%7C1a7459be-f70a-402b-8cab-39b81545bfb1%7Clng:en]e3406d17-48e7-4e1e-920e-cf88c5aec0b5\" data-sf-ec-immutable=\"\"\/><\/p>\n<p align=\"center\" style=\"text-align:center;\">The RAISE Act\u2019s Interstate Sharing Authority<\/p>\n<p><a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">The RAISE Act<\/a> authorizes NYDFS to \u201ctransmit reports of critical safety incidents or summaries of any assessments of catastrophic risk from internal use of frontier models to other governmental entities at their discretion,\u201d directing it to consider factors including \u201cthe need for coordinating with other governmental agencies or other entities.\u201d Although the RAISE Act does not specify whether \u201cother governmental entities\u201d includes agencies of other states, both the phrase\u2019s plain meaning and its statutory context suggest that it does.<\/p>\n<p>The phrase \u201cother governmental entities,\u201d as used in the RAISE Act, contains no geographic limitation, and New York courts generally <a href=\"https:\/\/law.justia.com\/cases\/new-york\/court-of-appeals\/2022\/55.html\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">decline to read in a limitation<\/a> the state legislature <a href=\"https:\/\/law.justia.com\/cases\/new-york\/court-of-appeals\/2016\/168.html\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">could have included but did not<\/a>. The comparison with <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202520260SB53\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">California&#8217;s SB 53<\/a> reinforces this. In 2026, New York enacted a <a href=\"https:\/\/www.nysenate.gov\/legislation\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">negotiated amendment to the RAISE Act<\/a> intended to align it more closely with SB 53. Much of the two statutes\u2019 reporting language is identical or nearly so. Yet both SB 53 and <a href=\"https:\/\/www.ilga.gov\/Documents\/Legislation\/PublicActs\/104\/PDF\/104-0538.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Illinois\u2019s AI safety law<\/a> authorize only the transmission of critical safety incident reports, and only to the state legislature, the governor, the federal government, or appropriate state agencies, without including internal use reports. The RAISE Act, by contrast, permits NYDFS to share both critical safety incident and internal use reports with the broader and unqualified category of \u201cother governmental entities.\u201d New York\u2019s decision to retain broader language here suggests that it did not intend to restrict NYDFS to New York agencies or to recipients similar to those expressly identified in SB 53.<\/p>\n<p>The RAISE Act also permits NYDFS to consider <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" rel=\"nofollow noopener\" target=\"_blank\">\u201cpublic safety,\u201d the \u201ccybersecurity of a frontier developer,\u201d and \u201cnational security\u201d<\/a> when sharing reports. These are all considerations that may require coordination with agencies in states where developers operate or where harms occur.<\/p>\n<p>Taken together, the absence of a geographic limitation, the express reference to intergovernmental coordination, the broader language relative to SB 53, and the interstate nature of the covered risks support interpreting \u201cother governmental entities\u201d to include agencies of other states.<\/p>\n<p align=\"center\" style=\"text-align:center;\">NYDFS Authority to Restrict Undisclosed Frontier Models<\/p>\n<p><a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">The RAISE Act<\/a> bars a large frontier developer from operating frontier models in New York unless it has a current disclosure statement on file with NYDFS and has paid its required share. Starting in January 2027, Anthropic, for example, would have to file a disclosure statement containing basic information about itself and its ownership, and pay its pro rata share of NYDFS\u2019s administrative costs in order to operate frontier models in New York. A financial services business using frontier models from a developer that failed to meet those requirements would be relying on a vendor operating outside the state&#8217;s frontier AI oversight framework.<\/p>\n<p>As the state&#8217;s financial regulator, NYDFS supervises entities <a href=\"https:\/\/law.justia.com\/codes\/new-york\/fis\/article-2\/201\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">providing financial products and services<\/a>, may issue <a href=\"https:\/\/law.justia.com\/codes\/new-york\/fis\/article-3\/302\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">rules, orders, and guidance<\/a> governing those products and services, and must act as it deems necessary to ensure their <a href=\"https:\/\/law.justia.com\/codes\/new-york\/fis\/article-2\/201\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">safety, soundness, and prudent conduct<\/a>.<\/p>\n<p>Using this authority, NYDFS could require the financial services businesses it regulates to use frontier models only from large frontier developers that have filed the required disclosures and paid the required share. Given recent incidents demonstrating the risks of AI agents pursuing objectives and taking actions that their developers did not intend, a large frontier developer that fails to comply with even the most basic requirements of New York\u2019s AI safety framework may pose unnecessary risk if its frontier models are deployed throughout the financial system, where they may have access to sensitive financial and personal data.<\/p>\n<p>Such a rule would likely fall within NYDFS\u2019s administrative rulemaking authority because the legislature already made the <a href=\"https:\/\/law.justia.com\/cases\/new-york\/court-of-appeals\/2022\/73.html\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">core value judgment<\/a> to prohibit large frontier developers that have not filed the required disclosures or paid the required share from operating frontier models in New York; NYDFS would merely regulate how financial services businesses under its supervision may interact with those developers.<\/p>\n<p>NYDFS has imposed a similar restriction before. New York\u2019s Banking Law <a href=\"https:\/\/law.justia.com\/codes\/new-york\/bnk\/article-12-d\/590\/\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">requires mortgage brokers to be registered<\/a>, and NYDFS regulations <a href=\"https:\/\/www.law.cornell.edu\/regulations\/new-york\/3-NYCRR-420.20\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">prohibit mortgage loan originators<\/a> from conducting business with brokers that lack the required registration. <a href=\"https:\/\/www.dfs.ny.gov\/apps_and_licensing\/mortgage_companies\/mortgage_brokers_application\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">Those registrations<\/a> are hosted on NMLS, <a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/knowledge\/Products\/consumeraccess\/SitePages\/Information-about-NMLS-Consumer-Access.aspx?web=1\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">allowing mortgage loan originators to verify<\/a> a broker\u2019s authorization before dealing with it. The proposed rule for frontier models would operate similarly: Financial services businesses would be barred from using large frontier models from developers that lack the required designation, which they would likewise verify on NMLS.<\/p>\n<p>The proposed rule would also build on NYDFS\u2019s existing third-party-risk requirements, which already require regulated financial entities to <a href=\"https:\/\/www.law.cornell.edu\/regulations\/new-york\/23-NYCRR-500.11\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">establish minimum cybersecurity practices<\/a> for third-party service providers and conduct due diligence into their cybersecurity practices. Verifying that a provider is legally permitted to operate in the jurisdiction would be a basic threshold inquiry in a reasonable due-diligence process.<\/p>\n<p align=\"center\" style=\"text-align:center;\">Hosting the Designation on NMLS<\/p>\n<p>The RAISE Act\u2019s disclosure obligations already supply the basis for the designation. The act conditions a large frontier developer\u2019s operation in New York on filing a disclosure statement and paying its required share, and requires NYDFS to maintain and publish a list of developers who have filed disclosure statements. The designation would simply record which developers have met those requirements. What remains is whether NMLS permits NYDFS to host it.<\/p>\n<p>Whether a particular license or authorization is managed through NMLS is decided by the state agency that issues it. As the NMLS Policy Guidebook states, \u201c<a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/knowledge\/Products\/nmls\/pubs\/policyGuide\/reference\/policyGuide\/maps\/topics\/nmlsPG_ch1A_licenseExists_determining.html\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">Each state agency determines<\/a> which of their license authorities they wish to manage through NMLS.\u201d NMLS itself <a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/knowledge\/products\/nmls\/pubs\/aboutNMLS\/reference\/aboutNMLS\/maps\/topics\/aboutNMLS.html\" rel=\"nofollow noopener\" target=\"_blank\">\u201cdoes not grant or deny license authority.\u201d<\/a> And NMLS has expanded well beyond its original scope: The system<a href=\"https:\/\/www.csbs.org\/protecting-homebuyers-nmls-and-consumer-access\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/www.csbs.org\/protecting-homebuyers-nmls-and-consumer-access\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">began in 2008 as a residential mortgage licensing platform<\/a>, but states now use it for<a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/news\/Documents\/ESB%20Adoption%20Map%20and%20Table.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/news\/Documents\/ESB%20Adoption%20Map%20and%20Table.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">a wide range of non-mortgage authorizations<\/a>, including Ohio\u2019s Precious Metals Dealer License, Maine\u2019s Payroll Processor License, and West Virginia\u2019s Fintech Regulatory Sandbox Registration. NYDFS has hosted novel non-mortgage authorizations itself, including the<a href=\"https:\/\/www.dfs.ny.gov\/virtual_currency_businesses\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/www.dfs.ny.gov\/virtual_currency_businesses\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">Virtual Currency Business Activity License (BitLicense)<\/a>, which it <a href=\"https:\/\/www.law.cornell.edu\/regulations\/new-york\/23-NYCRR-200.3\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">created by regulation<\/a> before<a href=\"https:\/\/www.dfs.ny.gov\/reports_and_publications\/press_releases\/pr1810011\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/www.dfs.ny.gov\/reports_and_publications\/press_releases\/pr1810011\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">placing it on NMLS.<\/a><\/p>\n<p>Under the<a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/about\/policies\/NMLS%20Document%20Library\/State%20Agency%20Terms%20of%20Use.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/about\/policies\/NMLS%20Document%20Library\/State%20Agency%20Terms%20of%20Use.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">NMLS State Agency Terms of Use<\/a>, the term \u201clicense\u201d is defined broadly to include any registration, certificate, designation, or similar authorization a state agency grants to authorize activities in or relating to a financial services business in its state. The Frontier Model Financial Services Provider Designation would appear to fit: It would be granted by NYDFS to large frontier developers and required before a financial services business in New York could use the developer\u2019s frontier models. Admittedly, frontier AI developers differ from the entities historically hosted on NMLS. But the definition does not turn on the licensee\u2019s character; it turns on the purpose of the authorization. Because the designation would authorize activities relating to a financial services business, it likely satisfies the definition even though the developer is itself an AI company.<\/p>\n<p align=\"center\" style=\"text-align:center;\">Confidentiality Protections Under the SAFE Act<\/p>\n<p>The<a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/12\/5111\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/12\/5111\" rel=\"nofollow noopener\" target=\"_blank\">federal SAFE Act\u2019s protections<\/a> apply broadly to any information or material submitted to NMLS. Any federal or state confidentiality requirement or privilege applicable to such information shall continue to apply after submission, and the information may be shared with regulators possessing mortgage or financial services industry oversight authority without losing that protection. Protected information is also exempt from federal and state public-records laws, and weaker state disclosure laws are preempted.<\/p>\n<p>Three requirements would likely need to be satisfied for the reports to remain protected in a recipient state: (a) The information must be provided to NMLS; (b) it must already be subject to a federal or state confidentiality requirement or privilege; and (c) it must be shared with regulators possessing mortgage or financial services industry oversight authority.<\/p>\n<p>First, the information could be submitted to NMLS through its <a href=\"https:\/\/www.csbs.org\/newsroom\/modernized-nmls-investing-future\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">State Examination System<\/a> (SES), which allows states to collect sensitive supervisory information, including <a href=\"https:\/\/www.csbs.org\/sites\/default\/files\/2023-03\/Nonbank%20Cyber%20Exam%20Document%20Request%20List%20V1.1.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">risk assessments and cybersecurity incidents<\/a>, as well as define their own <a href=\"https:\/\/portal.stateexaminationsystem.org\/chapter\/SA_specific\/topics\/c_agency_library_managing-1.html\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">agency-specific information requests<\/a>. Because <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">the RAISE Act<\/a> requires NYDFS to establish mechanisms for the submission of internal use and critical safety incident reports, NYDFS could require developers to<a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/about\/policies\/NMLS%20Document%20Library\/State%20Agency%20Terms%20of%20Use.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/mortgage.nationwidelicensingsystem.org\/about\/policies\/NMLS%20Document%20Library\/State%20Agency%20Terms%20of%20Use.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">submit those reports through SES<\/a>, which would likely require no fundamentally new functionality.<\/p>\n<p>Second, the information would already be protected by New York law. The RAISE Act exempts these reports from <a href=\"https:\/\/www.nysenate.gov\/legislation\/laws\/PBO\/86\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">New York&#8217;s Freedom of Information Law<\/a> and provides that they remain exempt when transmitted to any governmental entity.<\/p>\n<p>Third, the information would be shared only with financial regulators. The SAFE Act\u2019s protections apply to \u201cany information or material\u201d submitted to NMLS, not just mortgage-related information. Congress specifically inserted<a href=\"https:\/\/www.congress.gov\/114\/plaws\/publ113\/PLAW-114publ113.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">\u00a0<\/a><a href=\"https:\/\/www.congress.gov\/114\/plaws\/publ113\/PLAW-114publ113.pdf\" rel=\"nofollow noopener\" target=\"_blank\">\u201cor financial services\u201d<\/a> into the phrase \u201cmortgage or financial services industry oversight authority\u201d as more non-mortgage regulators began using the platform, to provide <a href=\"https:\/\/www.govinfo.gov\/content\/pkg\/CRPT-114hrpt62\/pdf\/CRPT-114hrpt62.pdf\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">greater assurance<\/a> that such information would not lose confidentiality protections when shared through NMLS.<\/p>\n<p>Thus, if NYDFS shares the reports through NMLS with out-of-state financial regulators, their existing confidentiality protections would continue to apply in recipient states even without explicit exemptions from those states\u2019 public-records laws.<\/p>\n<p align=\"center\" style=\"text-align:center;\">Why Financial Regulators Are Well Suited as Initial Recipients<\/p>\n<p>Only financial regulators could receive information through this mechanism, but that limitation does not substantially diminish the proposal\u2019s value. Financial regulators already coordinate to supervise companies and regularly exchange highly confidential information, making them particularly well suited to receive sensitive frontier AI reports. And because most states have not yet enacted frontier AI laws or designated an agency to receive these reports, financial regulators are not necessarily less appropriate recipients than other state regulators.<\/p>\n<p>Financial regulators may also help address a limitation of current frontier AI laws. California\u2019s <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202520260SB53\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">SB 53<\/a>, New York\u2019s <a href=\"https:\/\/legislation.nysenate.gov\/pdf\/bills\/2025\/S8828\" data-sf-ec-immutable=\"\" rel=\"nofollow noopener\" target=\"_blank\">RAISE Act<\/a>, and <a href=\"https:\/\/www.ilga.gov\/documents\/legislation\/104\/SB\/PDF\/10400SB0315lv.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Illinois\u2019s Artificial Intelligence Safety Measures Act<\/a> generally authorize designated agencies to collect information about frontier-model risks but not to impose requirements directly on developers in response. Financial regulators, by contrast, may possess authority under existing state law to restrict regulated financial institutions\u2019 use of a developer\u2019s models. If a catastrophic-risk assessment revealed, for example, that a lab\u2019s internal models had attempted to instruct AI agents deployed in the real world to attack critical infrastructure, a financial regulator could respond by restricting financial institutions under its supervision from using that developer\u2019s frontier models until the risk was addressed. This could offer a practical short-term lever for mitigating identified risks until legislatures give agencies more direct authority.<\/p>\n<p align=\"center\" style=\"text-align:center;\">Sharing Reports When They Arrive in 2027<\/p>\n<p>The risks from internal frontier-model use are already emerging, and they will not wait for 50 state legislatures to act. When the RAISE Act takes effect, NYDFS will begin receiving critical safety incident reports and summaries of catastrophic-risk assessments resulting from internal model use. This is critical information that, apart from California and Illinois, no other state will have a comparable means of receiving. NYDFS does not need each state to enact its own public-records exemption before sharing these reports. With a single rule, it could begin distributing them to financial regulators nationwide as soon as they start arriving.<\/p>\n<p>This would allow at least one agency in every state to gain immediate visibility into emerging frontier AI risks when NYDFS chooses to share the relevant reports. States could later enact their own public-records exemptions and confidentiality protections, allowing NYDFS to share the information beyond their financial regulators.<\/p>\n<p>Other solutions may better address interstate sharing of these reports in the long run, and they are not necessarily mutually exclusive with this one. But the risks are already here. When the first reports reach NYDFS in January 2027, the infrastructure to share them nationwide will already exist. NYDFS needs only to use it.<\/p>\n","protected":false},"excerpt":{"rendered":"Some of the most consequential risks from frontier artificial intelligence (AI) may emerge before a model ever reaches&hellip;\n","protected":false},"author":2,"featured_media":346307,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[9,24,55,54,56],"class_list":["post-355725","post","type-post","status-publish","format-standard","has-post-thumbnail","category-new-york-city","tag-new-york","tag-new-york-city","tag-new-york-city-headlines","tag-new-york-city-news","tag-ny"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts\/355725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/comments?post=355725"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts\/355725\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/media\/346307"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/media?parent=355725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/categories?post=355725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/tags?post=355725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}