Rules that shape the buildNew York rules to design around
For a business putting AI or automation to work in New York, six sets of rules come up most: a New York City law on hiring tools, the statewide SHIELD Act on data security and breach notice, the state’s cybersecurity regulation for financial companies, a disclosure law for prices set by algorithm, DFS guidance on AI in insurance underwriting, and — for model developers only — the RAISE Act. A separate bill to protect health data held outside HIPAA passed both houses in January 2025 but was vetoed on December 19, 2025, so it is not law.
Automated Employment Decision Tools law (Local Law 144)
New York City Local Law 144 of 2021; rules of the Department of Consumer and Worker Protection · Effective: Enforcement began July 5, 2023
Employers and employment agencies may not use an automated employment decision tool on job candidates or employees in New York City unless the tool has had a bias audit within one year of its use, information about that audit is publicly available, and the required notices have gone to the people assessed. The Department of Consumer and Worker Protection enforces it under its published rules.
SHIELD Act — data security protections
N.Y. Gen. Bus. Law § 899-bb (added by S5575B, ch. 117 of 2019) · Effective: March 21, 2020 (the 240th day after signing on July 25, 2019)
Any person or business that owns or licenses computerized private information of a New York resident must keep reasonable administrative, technical and physical safeguards, such as a named security coordinator, risk assessments, staff training and vetted service providers. Small businesses under the statute’s employee, revenue or asset tests may scale those safeguards to their size.
SHIELD Act — breach notification
N.Y. Gen. Bus. Law § 899-aa (as amended, including by S5575B, ch. 117 of 2019) · Effective: First in force in October 2019 and amended later; the summary describes the current text on nysenate.gov
“Private information” includes biometric data, medical and health-insurance information, and a username or email address combined with a password or security answer, so intake records and stored credentials are both in scope. The current text requires notice to affected residents within thirty days after a breach is discovered, with copies to the Attorney General, the Department of State, the State Police and, for DFS-covered entities, the Department of Financial Services.
NYDFS Cybersecurity Regulation
23 NYCRR Part 500, as amended by the Second Amendment · Effective: Second Amendment effective November 1, 2023; the expanded multi-factor rule applied from November 1, 2025
Banks, insurers and other companies licensed under the Banking, Insurance or Financial Services Law must run a cybersecurity program, report qualifying incidents to DFS within 72 hours, use multi-factor authentication and maintain an asset inventory. Firms under 20 staff, $7.5 million in revenue or $15 million in assets get a limited exemption from parts of it, but must still use multi-factor authentication for remote access to their systems, for remote access to third-party applications holding nonpublic information, and for privileged accounts. Since November 1, 2025, every other covered entity has had to require it for anyone accessing its information systems.
Algorithmic Pricing Disclosure Act
N.Y. Gen. Bus. Law § 349-a (added by S3008C, Part X, ch. 58 of 2025) · Effective: The 60th day after signing on May 9, 2025
A business that sets a price with an algorithm using a consumer’s personal data must show the words “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA” next to it. Insurers, financial institutions covered by Gramm-Leach-Bliley and certain existing-subscriber discounts are excepted, and a court may impose up to $1,000 per violation.
DFS Insurance Circular Letter No. 7 (2024)
Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing · Effective: Issued July 11, 2024
Addressed to every insurer authorized in New York, it says AI systems and external consumer data should not be used for underwriting or pricing where that would permit unfair discrimination. Insurers are expected to govern that use at board and management level, test for discrimination before an AI system goes into production and regularly afterwards, and tell applicants the reasons behind an adverse decision.
Responsible AI Safety and Education (RAISE) Act
N.Y. Gen. Bus. Law art. 44-B (enacted by S6953B, ch. 699 of 2025) · Effective: January 1, 2027, per the current statute text (signed December 19, 2025)
Binds only developers of frontier models, meaning foundation models trained with more than 10^26 operations; a company using a commercial model inside its own tools is not one.
General information, not legal advice. Laws, regulations and their effective dates change; confirm how they apply to your business with your own counsel. Last reviewed 2026-09-26.