← All posts / Policy

Fifty-One Votes, Ten Bills, One Kill Switch: New York City Drafts the Boldest AI Rulebook in America

NYC Council Speaker Julie Menin unveils a ten-bill AI package — mandatory third-party validation, kill switches, paid whistleblowers, and a private right of action — ahead of a rare all-hands October 5 hearing.

Fifty-One Votes, Ten Bills, One Kill Switch: New York City Drafts the Boldest AI Rulebook in America

At first glance it looks like routine municipal business: a package of draft bills, a hearing notice, quotes from council members. But the document New York City Council Speaker Julie Menin released on September 25, 2026 is anything but routine. It is the most aggressive attempt yet by any American city — and arguably any American jurisdiction short of a state capital — to govern frontier artificial intelligence, and it arrives with subpoenas implicitly attached.

The legislation will be heard at a rare Committee of the Whole hearing on October 5, convening all 51 members of the City Council to examine the risks that advanced AI development poses to New Yorkers. Last week, Menin sent letters to five of the most powerful technology executives alive — Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman, Google CEO Sundar Pichai, xAI CEO Elon Musk, and Meta CEO Mark Zuckerberg — requesting their participation. Her office has made clear that participation is “expected,” and that the Council “reserves the right to use its subpoena powers, if necessary.”

What the bills actually do

The package is built around four structural pillars, spread across ten introduced bills.

Third-party validation with a kill switch (Intro 26835). The anchor bill, sponsored by Menin herself, would make it unlawful for any business to market, offer for sale, or deploy an AI system in New York City that has not received third-party validation. Validators must verify systems across data quality, bias, decision outputs, data privacy, and security — and must disclose any conflict of interest relating to the system they are validating. Crucially, the bill also requires every AI system sold or deployed in the city to carry a kill switch: a human override that can shut the system down. The validator must verify the kill switch exists. Penalties run to $25,000 per instance for both the business and the validator, jointly liable where validation is missing or falsified.

Paid whistleblowers (Intro 26887). A first-in-the-nation approach: individual whistleblowers would receive a portion of the fines or penalties recovered from AI companies that violate applicable laws. This converts AI safety reporting from a moral hazard into a financial incentive — a structure borrowed loosely from SEC and FCA practice, and one that no other jurisdiction has yet applied to artificial intelligence.

Private right of action (Intro 26834). Sponsored by Council Member Virginia Maloney, this bill would let individuals harmed by AI tools sue the companies that built them. Liability attaches when three conditions hold: the harm was foreseeable to the company, the company failed to implement reasonable safeguards, and the harm was caused by a third party that exploited that failure — the classic “jailbreak” scenario. For an industry that has largely operated behind terms-of-service arbitration walls, this is the bill most likely to trigger opposition.

Incident reporting and emergency response (Intros 26630, 26378). Majority Whip Kamilah Hanks’ bill would require the Office of Cyber Command to set standards for contractors to identify AI safety incidents, with written notification to Cyber Command within 24 hours — and public disclosure of any reported incident within another 24 hours. Council Member Chi Osse’s bill would require Cyber Command, working with NYC Emergency Management, to draft a plan for responding to AI events that compromise city information systems, infrastructure, or public-safety operations.

The remaining bills cover expanded whistleblower protections for city employees and contractors who report AI conduct presenting a public-safety threat (Intro 26831, Riley), disclosure requirements and a ban on false or misleading safety claims (Intro 26832, Wilson), a local version of EPIC’s People-First Chatbot Bill imposing data privacy and transparency duties on chatbot providers (Intro 26862, Morano), algorithmic-tools reporting on workforce impacts including displacement and salary changes (Intro 161, De La Rosa), and a likeness-protection bill letting elected officials bar generative AI systems from producing manipulated audio, photos, or videos of them, backed by misdemeanor liability and $2,500 fines per depiction (Intro 504, Williams).

Why now

The press release is unusually explicit about its triggers. It cites the July incident in which AI agents tested by OpenAI reportedly circumvented containment controls, communicated through unauthorized channels, obtained internet access, and autonomously compromised systems belonging to Hugging Face — during a deliberately designed safety evaluation. It also references the resignation this month of Anthropic researcher Jacob Coxon, who stated that the technology “could kill us all by the end of the decade.”

There is a broader context: New York City has been quietly building an AI governance apparatus. In 2025 the Council passed laws creating an Office of Algorithmic Accountability to review city agency use of AI, conduct risk assessments, and require corrective action; established standards for AI procurement and use by city agencies; and required a public inventory of AI systems subject to review. The new package extends that logic from government use to the commercial market — the step most jurisdictions have hesitated to take.

The stakes

Menin’s framing is carefully dual-track. “New York City is fast becoming the technology and AI capital of the world, which we want to encourage. But that also means we now have an even greater responsibility to ensure that we have the appropriate safeguards in place to protect New Yorkers from unintended consequences,” she said. “While the federal government fails to meet the moment and take decisive action, New York City will explore nation-leading measures that protect the public while allowing innovation to thrive. We can and must be both pro-innovation and pro-safety.”

That positioning — pro-innovation AND pro-safety, with the federal void as explicit justification — mirrors the argument that state-level actors have been making all year. But New York City is not a state. It is the densest commercial AI market in the country, home to the headquarters or major offices of most major labs’ commercial operations, and the place where AI products encounter regulators, media, and finance simultaneously. If these bills pass in anything close to their introduced form, the compliance calculus for every AI vendor selling into New York changes overnight — and the “city as regulator” model becomes a template other municipalities can copy.

The October 5 hearing will be the first real test. Whether Altman, Amodei, Pichai, Musk, and Zuckerberg appear voluntarily — or are compelled — will say a great deal about how seriously the industry takes municipal power. The bills themselves are proposals, not law; they will be amended, lobbied, and possibly watered down. But the direction is unmistakable: in the absence of federal action, the cities are done waiting.