← All posts / Policy

'Bring It On': New York Orders Frontier AI Labs to Register — and Won't Rule Out a Kill Switch

Governor Hochul sets November registration and a January 2027 compliance deadline under the RAISE Act, stands up the DIGIT enforcement office, and floats 'AI kill switches' as Washington stalls.

'Bring It On': New York Orders Frontier AI Labs to Register — and Won't Rule Out a Kill Switch

With world leaders descending on Manhattan for the United Nations General Assembly, New York picked the week’s biggest stage to formally launch the implementation of the most aggressive frontier-AI safety law in the United States. On Monday, September 21, Governor Kathy Hochul announced that starting in November 2026, large frontier AI developers must register with the state — and that from January 2027, they will be legally required to publish safety frameworks and report critical safety incidents within 72 hours, on pain of civil penalties.

The announcement marks the moment the Responsible AI Safety and Education (RAISE) Act — signed in December 2025 and amended in March 2026 — moves from statute books to enforcement machinery. And Hochul, flanked by Attorney General Letitia James and the law’s legislative sponsors, Senator Andrew Gounardes and Assemblymember Alex Bores, left no ambiguity about who she expects to fight: “I know there’s other AI developers already on the phone with their legal teams planning their lawsuits against us,” she said. “Here’s my message to them: Bring it on. We will fight you in court, and we will hold you accountable.”

What actually takes effect, and when

The rollout comes in two phases, and the calendar matters more than the rhetoric.

Phase one — November 2026. Frontier AI developers must begin registering with the state through the Department of Financial Services. The threshold is steep: the amended law applies to developers with $500 million or more in annual revenue who build frontier models. That is a list short enough to name in a paragraph — OpenAI, Anthropic, Google, Meta, xAI, and a handful of others — which is precisely the point. New York is not regulating the app economy; it is regulating the labs that train the largest models.

Phase two — January 2027. Registration becomes compliance. Covered companies must publish Frontier AI Frameworks documenting their safety protocols, and they must report any critical safety incident to the state within 72 hours of identifying it. Companies that fail to play by the rules face civil penalties, with Attorney General James — introduced by Hochul as “our enforcer” — holding the enforcement pen.

To run the regime, New York is standing up the Office of Digital Innovation, Governance, Integrity and Trust (DIGIT), housed within the Department of Financial Services and proposed in Hochul’s State of the State address. On Monday she named Marc Gilman, a technology risk and compliance attorney and Fordham professor who previously served as general counsel to financial firms, as Deputy Director. Hochul’s pitch for him was pointed: he “understands what the big lawyers at the firms will be saying” and “knows how to make sure they’re staying in line.”

The kill switch question

The line that traveled furthest from the press conference was the governor’s refusal to take emergency shutdown mechanisms off the table. “We may even explore safeguards like AI kill switches if they’re deemed feasible and in the best interest of our state,” Hochul said — the first time she has publicly embraced the idea.

The reversal is notable because Hochul herself weakened the RAISE Act during its passage. As Hell Gate reported, the original bill banned companies from releasing demonstrably unsafe models outright; the version she signed, amended in March to align with California’s framework, requires only that developers disclose such risks in their safety plans. Monday’s kill-switch comments signal that the governor now wants to rebuild some of that lost muscle — incrementally, through DIGIT’s power to propose new regulations, rather than through another bruising legislative fight.

The technical feasibility question is genuinely open. Critics of kill-switch proposals — including the UK government, which formally rejected a mandatory regime earlier in September — argue that “turning off” a widely deployed frontier model is not like halting a reactor: weights are replicated across continents, open-weight variants can’t be recalled, and agentic systems distributed across third-party infrastructure resist central control. New York explicitly hedged its language (“if they’re deemed feasible”) in apparent recognition of exactly that critique.

States filling a federal void

Hochul framed the announcement as a deliberate counterweight to Washington. “In the absence of national engagement and uniform standards for AI companies, that’s where, once again, states like New York are stepping in to fill the void,” she said, noting pointedly that President Trump — who addresses the UN General Assembly on Tuesday — has dismissed AI guardrails while claiming “one high IQ President can manage the biggest technological revolution since the advent of the internet.”

The timing was less than subtle: the president posted on Truth Social an hour after Hochul’s event that he would not “stifle growth,” adding that law enforcement would “rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” The juxtaposition — a governor demanding pre-deployment transparency the same day the president promises only post-hoc enforcement — crystallizes the regulatory split now defining American AI policy.

New York is also not starting from zero. The state already imposed a one-year moratorium on hyperscale data centers drawing more than 50 megawatts, the first of its kind nationally. The RAISE implementation now makes New York the testbed for a second, sharper question: whether a single state can impose disclosure duties on global labs whose training runs happen, by design, everywhere at once.

What it means for the labs

For the frontier companies, the practical burden lands first as paperwork — a registration portal, a published safety framework, an incident hotline — and then as legal exposure. The 72-hour reporting clock mirrors the incident-reporting norms that serious labs already practice internally, but converting a voluntary norm into a statutory deadline with civil penalties changes the calculus: every safety team now needs a lawyer-validated escalation path, and every incident review generates discoverable records.

The harder question is jurisdictional. Labs headquartered in San Francisco will now track a California-style transparency regime under the amended RAISE Act, DFS oversight, and — if Hochul’s expansion instincts hold — a future rulebook that could diverge again. Compliance teams that spent 2026 building for California’s template get a variant to manage in New York; a national patchwork is no longer a hypothetical but a staffing line item.

Hochul, for her part, is inviting replication rather than litigation. “Take a close look at what we’re doing here in New York,” she said, addressing fellow governors and world leaders. “Use it as a model… something we can scale, expand, and evolve nationwide and, indeed, worldwide.”

Whether the labs sue, comply quietly, or lobby Congress to preempt the whole patchwork — as many have openly urged — the clock is now running. Registration opens in November. The law bites in January.