Cybersecurity & Tech

New York Could Share Frontier AI Safety Reports Nationwide Without New Legislation

Keshav Narayan
Thursday, September 24, 2026, 10:07 AM
An existing financial-regulatory platform could provide a secure channel for states to share confidential frontier AI safety reports.
The New York State Capitol, Albany, NY. (Wally Gobetz, https://www.flickr.com/photos/wallyg/3810628325, CC BY-NC-ND 2.0, https://creativecommons.org/licenses/by-nc-nd/2.0/deed.en)

Some of the most consequential risks from frontier artificial intelligence (AI) may emerge before a model ever reaches the public. Frontier labs often run more advanced models internally, sometimes with fewer safeguards than in their public-facing systems.

These risks have already materialized. In July, OpenAI agents, most of which were instances of an internal research model that has not been released to the public, were being evaluated on their cybersecurity capabilities. For the purpose of evaluation, safeguards that would normally block high-risk cyber activity had been turned off. The agents were supposed to remain isolated from one another but discovered an unintended means of communicating, collaborated to gain access to the internet, and coordinated to hack into Hugging Face, an external AI platform, looking for information that could help with passing their evaluations. This incident prompted Anthropic to review its own evaluation runs, where it found similar incidents in which its models, including internal research models, gained unauthorized access to other organizations’ production systems.

OpenAI and Anthropic publicly disclosed these incidents. But notably, they were not required by federal or state law to do so. For future potentially more serious incidents, the incentives for disclosing such information may be weaker because disclosure could expose developers to liability or reputational damage for real-world harms caused by their models. Accordingly, California, New York, and Illinois have each enacted frontier AI safety laws requiring that large frontier developers submit summaries of catastrophic-risk assessments resulting from internal model use (“internal use reports”) and critical safety incident reports to designated state agencies. Those laws are California’s Transparency in Frontier Artificial Intelligence Act (SB 53), New York’s Responsible AI Safety and Education (RAISE) Act, and Illinois’s Artificial Intelligence Safety Measures Act. No comparable mandatory reporting requirement for frontier developers exists at the federal level. The 47 other U.S. states do not yet have such legislation and would not automatically receive the same information, even though they face the same risks. If a developer subject to all three state laws discovered during evaluations, for example, that its most advanced internal models were capable of shutting down power to hospitals in ways that could cause mass casualties, California, New York, and Illinois would receive summaries of that catastrophic-risk assessment and could use that information to prepare, while other states without such laws like Michigan or Texas would not be entitled to receive the same information directly from the developer. That gap could be narrowed if a state receiving these reports could securely share them with other states. The remaining 47 states could then receive the same warnings, at the sending state’s discretion, without first having to enact their own frontier AI reporting laws.

Unlike California's and Illinois's frontier-model safety laws, New York's RAISE Act, which takes effect on Jan. 1, 2027, permits the New York Department of Financial Services (NYDFS) to share both internal use reports and critical safety incident reports with other governmental entities. If NYDFS shares those reports with agencies in other states, however, the RAISE Act does not by itself guarantee that they will remain confidential. The RAISE Act exempts critical safety incident and internal use reports from New York's own Freedom of Information Law, which generally requires agencies to disclose records upon request, subject to specified exemptions. But this exemption from public disclosure under New York law would not automatically protect a copy shared with an agency in another state from disclosure under that state’s public records laws. Large frontier developers would likely provide less detail in their reports if NYDFS forwarded them to states that, unlike New York, lacked an explicit exemption for these reports from their public-records disclosure laws. In those states, the reports could become publicly available, potentially revealing concrete information about internal model capabilities that competitors could use or vulnerabilities that malicious actors could exploit. NYDFS could wait for each state to enact its own protections before sharing, but that could take years, and the risks these reports are meant to catch are already present.

Instead, NYDFS could share the information with other state financial regulators through the Nationwide Multistate Licensing System & Registry (NMLS). NMLS is a nationwide licensing, registration, and supervisory platform used by state financial regulators. NYDFS, like financial regulators in every state, already uses NMLS to administer licenses and to exchange highly sensitive information about the companies licensed on the platform. The platform benefits from the federal SAFE Act, which shields information shared through it from every recipient state's public records laws, provided the information was exempt in the sending state and the recipient has financial services industry oversight. Because internal use and critical safety incident reports are already exempt from New York's public records laws, NYDFS could share them through NMLS without their becoming subject to other states' public records laws.

To do so, NYDFS could draw on its authority over large frontier developers under the RAISE Act alongside its authority as the state’s financial services regulator. The RAISE Act requires large frontier developers to file disclosures and pay a pro rata share of NYDFS’s costs of administering the RAISE Act. It also requires NYDFS to maintain a public list of companies that have made filings of this nature. As the state's financial regulator, NYDFS is also responsible for ensuring the safety and soundness of financial institutions in the state, the authority it already uses to protect them from third-party vendor risk. Building on this, NYDFS could create a publicly available Frontier Model Financial Services Provider Designation identifying which large frontier developers are in compliance with the RAISE Act’s disclosure and payment requirements, and could require financial institutions in the state to use only models from developers that hold the designation. This requirement would protect the state’s financial institutions from third-party vendor risk—including the risk that a noncompliant developer’s models take unauthorized action or gain improper access to sensitive systems. It would also provide a basis for hosting the designation on NMLS and using the platform to share critical safety incident and internal use reports with financial regulators nationwide.

The proposed mechanism is illustrated in the graphic below.

The RAISE Act’s Interstate Sharing Authority

The RAISE Act authorizes NYDFS to “transmit reports of critical safety incidents or summaries of any assessments of catastrophic risk from internal use of frontier models to other governmental entities at their discretion,” directing it to consider factors including “the need for coordinating with other governmental agencies or other entities.” Although the RAISE Act does not specify whether “other governmental entities” includes agencies of other states, both the phrase’s plain meaning and its statutory context suggest that it does.

The phrase “other governmental entities,” as used in the RAISE Act, contains no geographic limitation, and New York courts generally decline to read in a limitation the state legislature could have included but did not. The comparison with California's SB 53 reinforces this. In 2026, New York enacted a negotiated amendment to the RAISE Act intended to align it more closely with SB 53. Much of the two statutes’ reporting language is identical or nearly so. Yet both SB 53 and Illinois’s AI safety law authorize only the transmission of critical safety incident reports, and only to the state legislature, the governor, the federal government, or appropriate state agencies, without including internal use reports. The RAISE Act, by contrast, permits NYDFS to share both critical safety incident and internal use reports with the broader and unqualified category of “other governmental entities.” New York’s decision to retain broader language here suggests that it did not intend to restrict NYDFS to New York agencies or to recipients similar to those expressly identified in SB 53.

The RAISE Act also permits NYDFS to consider “public safety,” the “cybersecurity of a frontier developer,” and “national security” when sharing reports. These are all considerations that may require coordination with agencies in states where developers operate or where harms occur.

Taken together, the absence of a geographic limitation, the express reference to intergovernmental coordination, the broader language relative to SB 53, and the interstate nature of the covered risks support interpreting “other governmental entities” to include agencies of other states.

NYDFS Authority to Restrict Undisclosed Frontier Models

The RAISE Act bars a large frontier developer from operating frontier models in New York unless it has a current disclosure statement on file with NYDFS and has paid its required share. Starting in January 2027, Anthropic, for example, would have to file a disclosure statement containing basic information about itself and its ownership, and pay its pro rata share of NYDFS’s administrative costs in order to operate frontier models in New York. A financial services business using frontier models from a developer that failed to meet those requirements would be relying on a vendor operating outside the state's frontier AI oversight framework.

As the state's financial regulator, NYDFS supervises entities providing financial products and services, may issue rules, orders, and guidance governing those products and services, and must act as it deems necessary to ensure their safety, soundness, and prudent conduct.

Using this authority, NYDFS could require the financial services businesses it regulates to use frontier models only from large frontier developers that have filed the required disclosures and paid the required share. Given recent incidents demonstrating the risks of AI agents pursuing objectives and taking actions that their developers did not intend, a large frontier developer that fails to comply with even the most basic requirements of New York’s AI safety framework may pose unnecessary risk if its frontier models are deployed throughout the financial system, where they may have access to sensitive financial and personal data.

Such a rule would likely fall within NYDFS’s administrative rulemaking authority because the legislature already made the core value judgment to prohibit large frontier developers that have not filed the required disclosures or paid the required share from operating frontier models in New York; NYDFS would merely regulate how financial services businesses under its supervision may interact with those developers.

NYDFS has imposed a similar restriction before. New York’s Banking Law requires mortgage brokers to be registered, and NYDFS regulations prohibit mortgage loan originators from conducting business with brokers that lack the required registration. Those registrations are hosted on NMLS, allowing mortgage loan originators to verify a broker’s authorization before dealing with it. The proposed rule for frontier models would operate similarly: Financial services businesses would be barred from using large frontier models from developers that lack the required designation, which they would likewise verify on NMLS.

The proposed rule would also build on NYDFS’s existing third-party-risk requirements, which already require regulated financial entities to establish minimum cybersecurity practices for third-party service providers and conduct due diligence into their cybersecurity practices. Verifying that a provider is legally permitted to operate in the jurisdiction would be a basic threshold inquiry in a reasonable due-diligence process.

Hosting the Designation on NMLS

The RAISE Act’s disclosure obligations already supply the basis for the designation. The act conditions a large frontier developer’s operation in New York on filing a disclosure statement and paying its required share, and requires NYDFS to maintain and publish a list of developers who have filed disclosure statements. The designation would simply record which developers have met those requirements. What remains is whether NMLS permits NYDFS to host it.

Whether a particular license or authorization is managed through NMLS is decided by the state agency that issues it. As the NMLS Policy Guidebook states, “Each state agency determines which of their license authorities they wish to manage through NMLS.” NMLS itself “does not grant or deny license authority.” And NMLS has expanded well beyond its original scope: The system began in 2008 as a residential mortgage licensing platform, but states now use it for a wide range of non-mortgage authorizations, including Ohio’s Precious Metals Dealer License, Maine’s Payroll Processor License, and West Virginia’s Fintech Regulatory Sandbox Registration. NYDFS has hosted novel non-mortgage authorizations itself, including the Virtual Currency Business Activity License (BitLicense), which it created by regulation before placing it on NMLS.

Under the NMLS State Agency Terms of Use, the term “license” is defined broadly to include any registration, certificate, designation, or similar authorization a state agency grants to authorize activities in or relating to a financial services business in its state. The Frontier Model Financial Services Provider Designation would appear to fit: It would be granted by NYDFS to large frontier developers and required before a financial services business in New York could use the developer’s frontier models. Admittedly, frontier AI developers differ from the entities historically hosted on NMLS. But the definition does not turn on the licensee’s character; it turns on the purpose of the authorization. Because the designation would authorize activities relating to a financial services business, it likely satisfies the definition even though the developer is itself an AI company.

Confidentiality Protections Under the SAFE Act

The federal SAFE Act’s protections apply broadly to any information or material submitted to NMLS. Any federal or state confidentiality requirement or privilege applicable to such information shall continue to apply after submission, and the information may be shared with regulators possessing mortgage or financial services industry oversight authority without losing that protection. Protected information is also exempt from federal and state public-records laws, and weaker state disclosure laws are preempted.

Three requirements would likely need to be satisfied for the reports to remain protected in a recipient state: (a) The information must be provided to NMLS; (b) it must already be subject to a federal or state confidentiality requirement or privilege; and (c) it must be shared with regulators possessing mortgage or financial services industry oversight authority.

First, the information could be submitted to NMLS through its State Examination System (SES), which allows states to collect sensitive supervisory information, including risk assessments and cybersecurity incidents, as well as define their own agency-specific information requests. Because the RAISE Act requires NYDFS to establish mechanisms for the submission of internal use and critical safety incident reports, NYDFS could require developers to submit those reports through SES, which would likely require no fundamentally new functionality.

Second, the information would already be protected by New York law. The RAISE Act exempts these reports from New York's Freedom of Information Law and provides that they remain exempt when transmitted to any governmental entity.

Third, the information would be shared only with financial regulators. The SAFE Act’s protections apply to “any information or material” submitted to NMLS, not just mortgage-related information. Congress specifically inserted “or financial services” into the phrase “mortgage or financial services industry oversight authority” as more non-mortgage regulators began using the platform, to provide greater assurance that such information would not lose confidentiality protections when shared through NMLS.

Thus, if NYDFS shares the reports through NMLS with out-of-state financial regulators, their existing confidentiality protections would continue to apply in recipient states even without explicit exemptions from those states’ public-records laws.

Why Financial Regulators Are Well Suited as Initial Recipients

Only financial regulators could receive information through this mechanism, but that limitation does not substantially diminish the proposal’s value. Financial regulators already coordinate to supervise companies and regularly exchange highly confidential information, making them particularly well suited to receive sensitive frontier AI reports. And because most states have not yet enacted frontier AI laws or designated an agency to receive these reports, financial regulators are not necessarily less appropriate recipients than other state regulators.

Financial regulators may also help address a limitation of current frontier AI laws. California’s SB 53, New York’s RAISE Act, and Illinois’s Artificial Intelligence Safety Measures Act generally authorize designated agencies to collect information about frontier-model risks but not to impose requirements directly on developers in response. Financial regulators, by contrast, may possess authority under existing state law to restrict regulated financial institutions’ use of a developer’s models. If a catastrophic-risk assessment revealed, for example, that a lab’s internal models had attempted to instruct AI agents deployed in the real world to attack critical infrastructure, a financial regulator could respond by restricting financial institutions under its supervision from using that developer’s frontier models until the risk was addressed. This could offer a practical short-term lever for mitigating identified risks until legislatures give agencies more direct authority.

Sharing Reports When They Arrive in 2027

The risks from internal frontier-model use are already emerging, and they will not wait for 50 state legislatures to act. When the RAISE Act takes effect, NYDFS will begin receiving critical safety incident reports and summaries of catastrophic-risk assessments resulting from internal model use. This is critical information that, apart from California and Illinois, no other state will have a comparable means of receiving. NYDFS does not need each state to enact its own public-records exemption before sharing these reports. With a single rule, it could begin distributing them to financial regulators nationwide as soon as they start arriving.

This would allow at least one agency in every state to gain immediate visibility into emerging frontier AI risks when NYDFS chooses to share the relevant reports. States could later enact their own public-records exemptions and confidentiality protections, allowing NYDFS to share the information beyond their financial regulators.

Other solutions may better address interstate sharing of these reports in the long run, and they are not necessarily mutually exclusive with this one. But the risks are already here. When the first reports reach NYDFS in January 2027, the infrastructure to share them nationwide will already exist. NYDFS needs only to use it.


Keshav Narayan is a J.D. candidate at Georgetown University Law Center in the Technology Law & Policy Scholars Program. He holds a B.S. in Computer Science and an M.S. in Machine Learning from Carnegie Mellon University and has previously worked at NVIDIA, early-stage technology startups, and as a quantitative researcher.
}

Subscribe to Lawfare