NEW YORK — New York is setting deadlines for major artificial intelligence developers to register with the state, publish safety plans and report serious incidents, raising a practical question for credit unions and banks that use their models: What happens to member and customer services when an AI provider reports a problem?
Registration under the state’s RAISE Act begins in November. Requirements for public safety protocols, regular reporting and critical incident notices take effect in January, according to a PYMNTS analysis of the implementation schedule announced Sept. 21 by Gov. Kathy Hochul.
The requirements apply to large developers of advanced AI models, not automatically to every financial institution that uses them. But PYMNTS said a developer’s response to an incident could affect a credit union or bank that relies on its model for customer service, fraud prevention or payments. The provider might investigate the model, restrict access or change how it works while the institution still needs to serve account holders.

Covered developers must publish safety and transparency frameworks, submit quarterly assessments of catastrophic risks and notify the state of critical safety incidents within 72 hours. They also must register and file periodic disclosures. Hochul appointed Marc Gilman to oversee the RAISE Act as a deputy director in the state’s new Office of Digital Innovation, Governance, Integrity and Trust, within the Department of Financial Services.
When Hochul signed the law last December, her office said New York’s attorney general could seek civil penalties for missing required reports or making false statements. Penalties can reach $1 million for a first violation and $3 million for subsequent violations, the report noted.
Questions for Credit Unions
Although PYMNTS discusses banks and credit unions, its operational questions apply directly to credit unions using outside AI models. The analysis recommends asking vendors how quickly they would notify an institution of a reportable incident, which services could be affected and whether the institution could suspend the model’s access to sensitive data or its authority to act without shutting down an entire process.
The answer depends in part on what the AI tool is allowed to do. A model that drafts a response for an employee to review presents a different risk from one that can issue a refund, change an account setting or approve a payment, PYMNTS said. Institutions should identify who can revoke those permissions if the model becomes unreliable.
PYMNTS also urged financial institutions to test a backup model or manual process before an incident. Prompts, data connections and approval steps may be tied to one vendor, making a switch harder than it appears.
Hochul has discussed the possibility of future AI “kill switches,” according to a Sept. 22 Insurance Journal report cited by PYMNTS. That is an exploratory idea, not a current RAISE Act requirement. Institutions can establish their own procedures now for limiting or suspending an AI tool when its behavior or availability creates a problem, the analysis said.




