New York will begin registering large frontier artificial-intelligence developers in November, opening a two-month compliance runway before the state’s RAISE Act takes effect Jan. 1, 2027. The rollout moves the law from legislation to administration: covered companies must identify themselves to the state, publish safety frameworks and prepare to report critical incidents within 72 hours.

Gov. Kathy Hochul’s announcement assigns implementation to the new Office of Digital Innovation, Governance, Integrity and Trust, or DIGIT, within the Department of Financial Services. The state appointed Marc Gilman as deputy director for the RAISE Act, the office’s first full-time hire, while additional DFS staff work on cybersecurity, technology regulation and artificial intelligence.

The law is deliberately narrower than a general rule for every business using AI. A current legal analysis says the most extensive duties apply to developers of frontier models trained with more than 1026 operations when the developer and affiliates exceeded $500 million in prior-year gross revenue. Ordinary companies that purchase third-party AI tools generally are not directly regulated merely because they use them.

Covered developers must publish and follow frontier-AI frameworks addressing catastrophic-risk controls, cybersecurity, incident response and internal governance. They also must publish transparency reports when deploying new or substantially modified models, confidentially submit internal catastrophic-risk assessments on a quarterly schedule unless DIGIT approves another timetable, and maintain a disclosure statement renewed at least every two years.

The enacted bill text requires a critical safety incident report within 72 hours after a developer determines, or reasonably believes, an incident occurred. If an incident presents an imminent risk of death or serious physical injury, the developer must notify an appropriate authority within 24 hours as required by law. Members of the public may also submit suspected incidents to DIGIT.

Enforcement rests principally with Attorney General Letitia James and DIGIT. The attorney general may seek civil penalties of up to $1 million for a first violation and up to $3 million for later violations. A developer that operates without a current disclosure may face an additional $1,000-per-day penalty after notice and a hearing. The law creates no private right of action.

Some information will remain confidential. Incident reports and internal risk assessments are exempt from public-record disclosure, although DIGIT may share them with other government entities. Beginning in 2028, the office must publish an annual report with anonymized incident information, observations about frontier-model safety and recommended statutory changes.

The November registration drive therefore matters beyond paperwork. It will establish which developers New York considers covered, give regulators contact points before the law starts, and test whether a financial-services agency can build a workable oversight system for advanced models. For New York businesses outside the law’s direct scope, the disclosures may still become a practical benchmark for evaluating AI vendors’ safety and cybersecurity claims.