On 21 September 2026, New York Governor Kathy Hochul announced the next steps for enforcing the RAISE Act on frontier AI developers: registration from November, application from 1 January 2027, and reports of serious safety incidents within 72 hours; on AI kill switches, she said only that the state may explore them if they are deemed feasible. While no state yet holds the power to stop a frontier AI model, what actually binds its safety today? The answer is published safety protocols and reporting deadlines, and users of AI need to write their own procedure for stopping it.
01New York's RAISE Act first imposes a reporting deadline on AI developers
To test that answer, the announcement of 21 September has to be split into two parts: what now has dates and procedures attached, and what exists only as words. The procedures are settled. Frontier AI developers register with the state from November, carry the Act's duties from 1 January 2027, and must report any serious safety incident within 72 hours.
Settled
Registration from November, application from 1 January 2027, and serious incidents reported within 72 hours.
Unsettled
A kill switch will be explored only if deemed feasible; nothing has been promised.
The kill switch belongs to the unsettled part. The governor said the state may explore safeguards such as AI kill switches if they are deemed feasible and in the state's interest. That is not a commitment, and the press coverage said as much. When the law starts to apply in 2027, there is no present basis for saying New York will have any mechanism for stopping a frontier model from outside.
One conclusion follows. The state law binds what developers disclose and how quickly they report incidents. It does not bind whether a model keeps running. And, as Section 03 shows, those duties do not reach users at all. So organisations that have put AI into their work should not wait for a state kill switch. They need to decide, on their own, the conditions under which they stop AI in their own processes and what they record when they do.
The rest of this column checks that conclusion in turn: the content of the law, who it reaches, how two states got here, the numbers on deadlines and penalties, and what may come next.
02The Act's duties are publishing safety protocols and reporting incidents within 72 hours
The previous section treated registration and reporting as settled. Here is what the law actually requires, of whom, and at what cost for breaking it. The RAISE Act applies to companies that develop AI models trained with the largest amounts of compute. Governor Hochul signed it in December 2025, and it was built on the framework California had already enacted.
Two duties sit at the centre. The first is publishing a safety protocol: a written account of how the developer assesses catastrophic risk and how it prepares for it. The second is incident reporting: a serious safety incident must be reported to the state within 72 hours. Reports go to the DIGIT Office, housed within the Department of Financial Services.
Breaches are met with civil penalties. According to press reports, the cap is $1 million for a first violation and $3 million for repeat violations, and the state attorney general enforces them. Reports also say that companies with revenue above $500 million face additional duties, though I have not been able to confirm the exact threshold in the text of the law.
The boundary matters. The Act's sequence closes with registration, disclosure, reporting and enforcement. No step in it compels a model to stop. The state now has a way to learn about incidents, but the law gives it no power to halt a model after it learns. That is why the kill switch was discussed separately, as something to be studied, rather than as part of the enforcement plan.
Put plainly, the RAISE Act asks developers for two things: to publish their preparations in advance and to tell the state what happened within a deadline. The actual means of keeping a model safe are left to each company's own protocol.
03The duty falls on developers; organisations that use AI for review and decisions are outside it
Once we ask how far those duties reach, the answer is: not very far. Both the RAISE Act and California's earlier SB 53 are aimed at developers of frontier models. SB 53 uses a threshold of annual revenue above $500 million.
| What to look at | Frontier model developers | Organisations using AI at work |
|---|---|---|
| Publishing safety protocols | Required (New York, California) | Not required |
| Incident reporting | 72 hours (New York) / 15 days (California) | Not required |
| Penalties | Up to $1 million for a first violation | Not covered |
| A procedure to stop | No legal duty yet | For high-risk uses in the EU, stopping at the point of use is required |
The right-hand column describes most readers. A company that uses AI to review documents or support business decisions carries none of the reporting duties in either state law. A company that uses generative AI to draft or review promotional materials is on the same side of that line.
As a result, errors that happen where AI is used do not enter the state's reporting stream. If a model produces a wrong summary and someone makes a wrong decision based on it, the record stays inside that organisation unless the event counts as a serious safety incident under the developer's duties. Whether a record is kept at all is left to the user.
The last row of the table notes one exception. In the European Union, uses classed as high-risk require a procedure that lets a person stop the system safely at the point of use. Section 06 returns to it.
04Kill switches appear to come later because when to use one has not yet been defined
The arrangement just described, with reporting duties for developers and nothing for users, did not arise by chance. Following the history in two states shows that reporting has consistently been put ahead of stopping.
In California, SB 1047, debated in 2024, would have required developers of frontier models to have the capability to shut them down. Governor Gavin Newsom vetoed it on 29 September 2024. SB 53, enacted in September 2025, changed direction and centred on publishing safety protocols and reporting incidents.
New York followed. The RAISE Act was signed in December 2025, and its enforcement steps were set out on 21 September 2026. In that announcement the kill switch appeared as something to be studied.
On 18 September California issued an executive order to advance work on a kill switch. The order says the switch's effectiveness should be verified on an ongoing basis by an independent verification organisation. Read the other way round, that means a stop cannot be written into law as a duty until someone has settled who checks that it works, and how.
A stop cannot be drafted as a legal rule without first deciding when to stop, what happens when you do, and who judges whether stopping was right. Reporting needs none of that. It only requires telling the state what happened within a set time. My reading is that both states started with reporting because it was the part they could define. That is my inference from the order of events, not a reason stated in the sources.
05Deadlines split between 72 hours and 15 days, while penalty caps are about the same
Having seen why reporting came first, we can ask how fast and how heavily it actually operates. Here are the numbers for the two states side by side.
| What to look at | New York RAISE Act | California SB 53 |
|---|---|---|
| Reporting deadline | Within 72 hours | Within 15 days of discovery (24 hours if imminent) |
| Penalty cap | $1 million first / $3 million repeat | $1 million per violation |
| Takes effect | 1 January 2027 | 1 January 2026 |
| Kill switch | Under study | Studied under the 18 September 2026 executive order |
The gap in deadlines is large. New York wants serious incidents reported within 72 hours. California allows 15 days from discovery, shortened to 24 hours only when there is imminent danger of death or serious injury. The same kind of incident reaches the state at very different speeds depending on which law applies.
The penalty caps are close. New York sets $1 million for a first violation and $3 million for repeats; California sets $1 million per violation. California's law started a year earlier, so its practice may become a reference for the state that starts later.
As the last row shows, neither state has yet put a kill switch into the numbers of its law. The only duties that can be counted today are deadlines and dollar amounts.
06Reporting gathers facts, but the decision to stop stays with the user's own procedure
Taken together, the numbers describe a system in which reporting is fast and there is no way to stop. Three things follow for an organisation that uses AI.
Incidents become records
The 72-hour deadline means serious incidents will be collected by the state.
Penalties are small
Caps of $1–3 million are small for firms above $500 million in revenue; the governor mentioned raising them.
Stopping sits with users
The EU AI Act requires that people be able to halt high-risk AI safely at the point of use.
First, incidents become public records. Serious incidents that used to stay inside developers will now be collected by the state under a deadline. Because the deadline is fixed, there is little room to decide afterwards whether to report. For users, this means more information will eventually exist about what happened to the models they rely on. How much of it the state will publish cannot be read from this announcement.
Second, the penalty caps are small relative to the firms involved. The companies reported to face extra duties earn more than $500 million a year, and for them the cap on a first violation is $1 million. The governor also mentioned raising penalties. At current levels, what pushes a company to report is less the size of the fine than the prospect that a failure to report will later come to light in the record.
Third, there is the question of where the power to stop should sit. Article 14(4)(e) of the EU AI Act requires that people overseeing a high-risk AI system be able to interrupt it through a stop button or a similar procedure that brings it to a halt in a safe state. That rule puts the means of stopping at the point of use. Users do not need to wait for a state kill switch; they can build a stopping procedure into their own work.
Such a procedure can be written in four steps. Decide in advance which errors or deviations trigger a stop. Record the signs, with time and output. Have a named person decide whether to stop. When stopping, hand the work back to people. None of these steps can be skipped on the grounds that state law does not require it. The user is simply doing, within its own scope, the disclosure and record-keeping the law asks of developers.
07Whether a kill switch becomes law appears to turn on whether a way to verify it is set out
If the power to stop can sit with users, the remaining question is under what conditions a state kill switch might become law. It helps to separate what is known from what is not.
Two things are known. California's executive order calls for expert guidance within two months and for ongoing verification of the switch's effectiveness by an independent body. New York has said it will study kill switches ahead of the governor's next State of the State agenda.
Three things are not known: the conditions under which a stop would apply, who bears the losses a stop causes, and how anyone would measure whether a stop worked. Neither state has published any of these.
From here on I am inferring. If California's guidance sets out concrete ways to verify effectiveness, New York may build on it, as it built the RAISE Act on California's framework. If no method of verification appears, the kill switch is likely to stay under study. Which of these happens cannot be confirmed today.
Either way, users' preparation stays the same. Even if a state kill switch arrives, it will be aimed at developers. Stopping an error in a company's own work will still depend on that company's own procedure.
- From 1 January 2027, New York requires serious incidents to be reported within 72 hours, so AI incidents will start to accumulate as state records.
- Kill switches remain under study in both New York and California, and neither has published when a stop would apply or how its effect would be measured.
- The reporting duty falls on developers, not users, so an organisation using AI has to set its own conditions and records for stopping it.
While no state yet holds the power to stop frontier AI, what binds its safety is disclosure and reporting deadlines. Rather than wait for a kill switch in law, organisations using AI should first hold their own conditions and records for stopping it.
The disclosure and reporting the law asks of developers also serve as a model for users. Write down now what would make you stop, and where you would record that you did.
- Governor Kathy Hochul, New York State. AI Safety: Governor Hochul Announces Next Steps to Regulate Major AI Developers and Protect New Yorkers. 21 September 2026. (registration, application from 1 January 2027, 72-hour reports to the DIGIT Office)
- amNewYork. Hochul floats 'AI kill switches' as New York prepares to enforce frontier AI law. 21 September 2026. (kill switch under consideration, penalty caps, enforcement by the attorney general)
- TechCrunch. New York Governor Kathy Hochul signs RAISE Act to regulate AI safety. 20 December 2025. (signing of the Act and its duties, relation to California's framework)
- Governor of California. Governor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch. 18 September 2026. (kill switch order, expert guidance, independent verification)
- Future of Privacy Forum. California's SB 53: The First Frontier AI Law, Explained. 2025. (SB 53 deadlines, the $500 million threshold, penalty cap)
- Inside Global Tech (Covington & Burling). California Governor Vetoes AI Safety Bill. 30 September 2024. (veto of SB 1047)
- Regulation (EU) 2024/1689. Artificial Intelligence Act, Article 14: Human Oversight. 2024. (procedure for people to halt high-risk AI in a safe state)
