Market
AI law in New York City
10 binding provisions TwinEthos encodes that reach New York City (US-NY-NYC): 7 in force, 3 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Includes US federal law, which applies in every state, and city law inside the state. See also United States (federal).
Get the build plan for New York City
The guards that cover the most here
50 guards address 68 items across 3 jurisdictions with binding law: 7 binding law in force, 3 enacted but not yet applying, 34 standards and frameworks, 24 TwinEthos recommended guardrails.
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 4 items: 1 binding law in force · 2 standards · 1 recommended guardrail
Law in force in New York (US-NY).
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 2 items: 1 binding law in force · 1 recommended guardrail
Law in force in New York (US-NY).
AEDT used without 10-day candidate notice
Send each candidate an AEDT notice with alternative-selection instructions at least 10 business days before the tool scores them, and hold scoring until then.
Addresses 1 item: 1 binding law in force
Law in force in New York City (US-NY-NYC).
Automated employment tool without a current bias audit
Keep a dated bias-audit record for the AEDT with a link to its published summary, and disable AEDT scoring once the audit is more than one year old.
Addresses 1 item: 1 binding law in force
Law in force in New York City (US-NY-NYC).
AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent
Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
More health information than the task needs is sent to an AI model
Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Frontier developer without a critical safety incident reporting process
Keep a critical safety incident runbook that classifies the defined incident classes and runs the 72-hour report and 24-hour imminent-risk escalation clocks.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in New York (US-NY); next date 2027-01-01.
Frontier model deployed without a public transparency report
Publish a transparency report or system card on the developer's website before or at each new or substantially modified frontier-model deployment, and gate release on it.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in New York (US-NY); next date 2027-01-01.
Frontier AI developer without a published catastrophic-risk framework
Publish a frontier AI framework covering capability thresholds, mitigations, incident response, and internal-use risk, and gate model releases on it.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in New York (US-NY); next date 2027-01-01.
The top 10 of 50; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in New York City:
- Chat or assistant
- Agents that use tools or take actions
- Decisions about people (hiring, credit, insurance, health)
- Generated text, images, audio or video
- Classification, scoring or biometrics
Laws
- FTC Impersonation Rule (16 CFR Part 461) United States (federal) (US)
- HIPAA Privacy Rule (45 CFR 160, 164 Subpart E) United States (federal) (US)
- NYC Local Law 144 New York City (US-NY-NYC)
- New York Gen. Bus. Law Art. 47 (AI companion models) New York (US-NY)
- New York RAISE Act (Gen. Bus. Law Art. 44-B) New York (US-NY)
Coming into force
- : Frontier developers must report critical safety incidents within 72 hours, or 24 hours if lives are at imminent risk (New York RAISE Act) (New York (US-NY))
- : Large frontier developers must publish and follow a frontier AI framework (New York RAISE Act) (New York (US-NY))
- : Frontier developers must publish a transparency report when deploying a new or substantially modified frontier model (New York RAISE Act) (New York (US-NY))
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.