The RAISE Act requires AI companies with $500M+ in revenue to publish safety protocols and disclose safety incidents within 72 hours, with fines up to $3M
Days after President Trump moved to block states from regulating AI, New York's governor signs what the bill's sponsor calls the strongest AI safety law in the U.S.
Context & Ripple Effects
New York’s move completes an arc that began with the state legislature’s passage of frontier-model safety and transparency requirements and continued through a rewrite intended to align the measure more closely with California’s approach. The governor’s signing turned that debated framework into an enforceable state obligation.
The law lands amid a federal push against state-level AI rules, making New York’s decision to proceed a concrete test of how far states can set safety expectations for large AI developers.
First-order effects
- AI companies above the revenue threshold must publish safety protocols and build processes to identify and report qualifying safety incidents within 72 hours.
- Noncompliance now carries a defined financial enforcement risk—fines of up to $3 million—rather than leaving safety commitments solely voluntary.
Second-order effects
- Affected developers will likely standardize incident documentation, escalation, and public-facing safety materials across relevant operations rather than treat disclosure as an ad hoc communications task.
- New York’s California-aligned revision, reflected in the proposed SB 53-style rewrite, increases the incentive for companies to reuse compliance approaches across multiple state regimes.
Third-order effects
- If other states adopt comparable rules, frontier-AI governance could develop through interoperable state disclosure and risk-management baselines before any durable federal settlement emerges.
- The clash between state requirements and federal opposition makes preemption a central uncertainty: a federal override could limit this model, while its absence would reinforce state-led AI oversight.
The trend: Large AI developers are moving from voluntary safety pledges toward legally enforceable, state-level disclosure and risk-management obligations.