New York now has more AI-specific laws in effect or pending than any state except California. Several deadlines in the next 100 days will determine how much stricter that gets.
On September 21, 2026, Governor Hochul announced the next implementation step for the state's RAISE Act. Starting in November 2026, large AI developers must register with a new oversight office before the law's substantive requirements take effect on January 1, 2027. Separately, New York's "synthetic performer" AI-disclosure law has been enforceable with real penalties since June 9, 2026, and the state's new ban on AI-driven "surveillance pricing" has been in effect since mid-September 2026. Beyond those, a package of AI bills the legislature passed back in June, including a companion-chatbot ban for minors and an AI training-data transparency mandate, is still sitting on Hochul's desk.
New York's signing process works differently from what many readers expect from the federal model: once the Legislature has adjourned for the year, as it had by June, the Governor must affirmatively sign a bill for it to take effect. If she lets the clock run out without acting, the bill does not become law, it is automatically vetoed. There is no scenario here where silence quietly enacts a bill. If your business operates in New York, touches New York residents' data, or advertises to New York consumers, at least one of these laws almost certainly applies to you.
New York's AI laws at a glance
| Law | Status | Effective date | Who it covers | Penalty |
|---|---|---|---|---|
| RAISE Act (frontier AI safety) | Signed Dec 19, 2025 | Jan 1, 2027 (registration begins Nov 2026) | Large frontier AI model developers | Enforced via new DIGIT office; specific fine schedule pending regulations |
| Synthetic Performer Disclosure Law | Signed Dec 11, 2025 | Live since June 9, 2026 | Any business advertising with AI-generated "performers" | $1,000 (1st violation) / $5,000 (subsequent), AG-enforced |
| One Fair Price Act (AI/algorithmic surveillance pricing ban) | Signed June 17, 2026 | Live since mid-September 2026 | Businesses using personal data to set individualized prices | Up to $5,000 (1st) / $20,000 (subsequent) or disgorgement, AG-enforced |
| AI Training Data Transparency Act | Passed legislature June 2026 | Awaiting signature | Generative AI model developers | TBD upon signature |
| Companion Chatbot Safety Bill (minors) | Passed legislature June 2026 (137-0 Assembly / 60-0 Senate) | Awaiting signature | AI chatbot providers serving minors | Up to $25,000/violation if signed, AG-enforced |
| FAIR News Act, data center moratorium, AI children's-toy moratorium | Passed legislature June 2026 | Awaiting signature | News/AI publishers, data center operators, chatbot-toy makers | TBD upon signature |
These AI-specific laws sit on top of New York's existing privacy and security infrastructure, including the state's data breach notification and security requirements under the SHIELD Act. Compliance teams tracking the new AI rules should check that baseline too, since the two overlap for any business handling New York residents' data.
The RAISE Act: what's actually happening now
The Responsible AI Safety and Education (RAISE) Act is New York's frontier-AI safety law, the second state law of its kind after California's, and it's the one currently in motion. Hochul's September 21, 2026 announcement laid out the near-term sequence:
- November 2026: large AI developers must begin registering with the state.
- A new Deputy Director role has been appointed within DIGIT, short for the Office of Digital Innovation, Governance, Integrity and Trust, a newly created office housed under the New York Department of Financial Services, to oversee implementation.
- January 1, 2027: the law's substantive requirements take effect, including a mandate that covered developers report safety incidents to DIGIT within 72 hours.
If your organization develops or deploys frontier-scale AI models, the practical to-do right now isn't a January scramble. It's figuring out whether you meet the Act's developer threshold and preparing your incident-reporting process well before the November registration window opens.
The Synthetic Performer Disclosure Law: already enforceable
Unlike the RAISE Act, this one isn't on the horizon. It's live now, and it's easy to trip over precisely because it targets marketing and advertising teams rather than AI developers.
Signed as S.8420-A/A.8887-B and effective since June 9, 2026, the law amends New York General Business Law § 396-b to require any business that creates a commercial advertisement featuring a "synthetic performer" to conspicuously disclose that fact, if the business has actual knowledge of it. A synthetic performer, under the law's definition, is a digital asset that mimics a real human performer and is created using a software algorithm, with or without AI; a traditional, non-AI visual-effects pipeline can trigger the same disclosure duty. Penalties are $1,000 for a first violation and $5,000 for each subsequent one, enforced by the New York Attorney General.
There are real exemptions worth knowing: audio-only ads, AI used solely for translating a human performer's speech, and expressive works like films, TV, and video games where the synthetic performer matches the underlying creative work. But a standard AI-generated marketing video or synthetic voiceover ad almost certainly falls inside the law's scope. Businesses that already disclose AI involvement in other contexts, such as employers who disclose AI use under a workplace AI disclosure law like Connecticut's, will recognize the same conspicuous-disclosure logic here, applied to advertising instead of hiring.
What's awaiting Hochul's signature
On June 5, 2026, New York legislators wrapped their session by passing a package of AI bills that now sit on the Governor's desk. Because the Legislature had already adjourned for the year, the state constitution requires Hochul to affirmatively sign each bill, or it is automatically vetoed when the time allowed runs out, not automatically enacted. In practice, Hochul and legislative leaders have an informal custom of holding end-of-session bills and acting on most of them by year-end (the same custom behind "chapter amendment" negotiations), which is why coverage of this package points to December 31, 2026 as the practical date to watch. But there's no outcome where a missed deadline turns one of these bills into law on its own. Until you see an actual signature, treat the bill as not in effect. The package includes:
- AI Training Data Transparency Act (A.6578/S.6955): would require generative AI developers to publish a high-level summary of the datasets used to build their models, including disclosures about copyrighted material and personal information used in training, going further than California's comparable law.
- Companion Chatbot Safety Bill (S.9051): passed the Assembly 137-0 and the Senate 60-0, and would prohibit AI companies from offering companion chatbots to minors, with age verification requirements, a ban on features that simulate emotional relationships or encourage harmful behavior, and AG fines of up to $25,000 per violation if signed.
- FAIR News Act (S.8451-B/A.8962-B): would require news organizations to disclose when they use generative AI to create news content.
- A one-year moratorium on new large-scale AI data centers, still awaiting Hochul's decision on the legislative version, separate from the executive order she issued in July 2026 that already paused new data-center permits for a year.
- A five-year moratorium on AI-enabled children's chatbot toys (S.9408-A), passed by both chambers, while a task force studies their effects on child development.
One closely related bill isn't on this list because it's already resolved: the One Fair Price Act, which bans AI-driven surveillance pricing, was signed by Hochul on June 17, 2026, took effect in mid-September, and is already AG-enforceable. Because the Governor has to actively decide on each remaining bill rather than simply let time pass, businesses with New York exposure should treat her year-end decisions as a compliance-calendar event, not a wait-and-see later.
On the horizon: algorithmic discrimination and high-risk AI audits
Separately from the signed and pending bills above, New York legislators have also introduced a bill, building on an earlier version (S.1169) that died in the Assembly at the end of the 2025 session, to regulate high-risk AI systems and require independent audits to prevent algorithmic discrimination. It's modeled on the direction Colorado and California have already taken with their own AI Acts. It has not yet passed both chambers as of this writing, so treat it as a bill to watch rather than a compliance obligation today. It does signal where New York is likely headed next if the RAISE Act and disclosure law hold up in practice. If you're already preparing for a bias-audit requirement under another jurisdiction's AI law, the audit obligation in New York's bill will likely look familiar.
How New York compares to other states
New York's approach splits AI regulation into narrower, targeted laws (frontier-model safety, ad disclosure, surveillance pricing, chatbot safety, training-data transparency) rather than one omnibus AI Act. That's a different model from Colorado's AI Act or the EU AI Act's single risk-tiered framework. It means compliance teams need to track New York as several separate obligations, each with its own effective date, rather than one law with one effective date. In that sense, it's closer in spirit to how California has built CCPA/CPRA out through incremental amendments than to a single comprehensive statute. For a side-by-side of how two other major frameworks handle similar ground, see this comparison of California's AI rules against the EU AI Act.
Compliance checklist
▢ Determine whether your organization meets the RAISE Act's "large developer" threshold and prepare a 72-hour incident-reporting process ahead of November 2026 registration
▢ Audit current and planned advertising for AI-generated "synthetic performers" and build a disclosure process now, this law is already enforceable
▢ If your pricing is personalized or algorithmic, confirm compliance with the One Fair Price Act, live since mid-September 2026
▢ Track Hochul's year-end signing decisions on the remaining pending bills and assign an owner to act within 30 days of any signature
▢ If you operate a chatbot that could be accessed by minors, begin assessing age-verification and design changes ahead of the companion chatbot bill's potential enactment
▢ If you train generative AI models, prepare a training-data summary disclosure in case the Training Data Transparency Act is signed
▢ Watch the pending high-risk AI/algorithmic discrimination bill as a leading indicator of New York's next regulatory wave
FAQ
Does New York have AI laws?
Yes, several. New York has a signed frontier-AI safety law (the RAISE Act, effective January 2027), a live AI-generated-advertising disclosure law (effective since June 2026), a live ban on AI-driven surveillance pricing (effective since September 2026), and a package of additional bills awaiting the Governor's decision.
What are the new AI laws in the US?
Beyond New York, Colorado and California have each enacted broader AI Acts addressing algorithmic discrimination and high-risk systems, while multiple other states have passed narrower measures on chatbots, deepfakes, and AI-generated content disclosure. New York's approach of multiple targeted laws rather than one omnibus act is becoming a common pattern among states moving fastest on AI regulation.
When does the RAISE Act take effect?
January 1, 2027, with developer registration beginning in November 2026 under New York's new DIGIT oversight office.
Do I need to disclose AI-generated content in advertising in New York right now?
If your ad includes a "synthetic performer," a digital asset created with a software algorithm (AI or not) meant to look like a real human performer, and you have actual knowledge of it, yes, as of June 9, 2026, unless it falls under one of the law's exemptions (audio-only, translation use, or expressive works like film and games).
What happens if Hochul doesn't act on the pending bills by December 31?
The opposite of what people often assume: under New York's process, a bill passed at the end of a legislative session needs the Governor's affirmative signature to become law. If she takes no action within the time allowed after the Legislature's adjournment, the bill is automatically vetoed, not enacted. So no news by year-end means the bill did not take effect; it doesn't mean the obligations quietly arrived anyway. Wait for an actual signature (or a formal veto) before treating any of these as live compliance requirements.
Secure Privacy helps organizations track consent, disclosure, and data subject rights obligations as new AI and privacy laws take effect, including multi-jurisdiction rollouts like New York's. See how our DSAR automation and consent management platform extend to new regulatory requirements as they land. Book a demo to talk through your New York exposure.



