What the RAISE Act Requires From Company Boards
The RAISE Act requires large AI developers to publish safety frameworks and report incidents. All boards should establish AI governance structures to manage risks.

New York's Responsible AI Safety and Education (RAISE) Act will require large artificial intelligence developers to publish detailed safety frameworks, report critical incidents to the state within 72 hours, and conduct annual reviews starting January 1, 2027. For any board overseeing a company that develops advanced AI systems or deploys them at scale, the law creates immediate compliance obligations. For boards at all New York companies, it establishes a regulatory baseline for thinking about AI governance as an operational risk.
The RAISE Act applies to "large developers"—companies that have spent more than $100 million in aggregate compute costs training frontier models. A frontier model is defined by specific technical thresholds: either a model trained using more than 10 to the 26th power computational operations with a training cost exceeding $100 million, or a model created by applying knowledge distillation with a training cost exceeding $5 million.
What Developers Must Publish and When
Large developers must create and publicly post a frontier AI framework describing how they identify and mitigate catastrophic risk, implement cybersecurity protections for unreleased model weights, use third-party evaluators, maintain internal governance practices, and respond to critical incidents. The framework must be reviewed and updated at least annually, with material modifications published within 30 days of implementation.
Before deploying a new frontier model or substantially modified version, developers must publish a transparency report that includes the model's release date, supported languages and output modalities, intended uses, and use restrictions. The report must also summarize assessments of critical harm and disclose the extent of third-party involvement in those assessments.
Critical harm is defined as a risk that a frontier model will contribute to the death of or serious injury of 100 or more people, or more than $1 billion in property damage.
Large developers must report critical safety incidents to the New York Department of Financial Services within 72 hours of determining that an incident occurred. These reports trigger oversight by a new office within the department, which will assess large developers on an ongoing basis, issue rules interpreting the statute, and publish annual reports on AI safety.
How Boards at Other Companies Should Think About AI Governance
For boards at companies that do not trigger RAISE Act obligations but deploy AI systems, the law establishes a regulatory floor for AI governance. The Securities and Exchange Commission's Investor Advisory Committee recommended in December 2025 that public companies disclose how their boards oversee AI deployment, including any dedicated AI risk committees, the frequency and scope of AI risk assessments, and the effects of AI deployment on business operations and cybersecurity.
The Harvard Law School Forum on Corporate Governance identifies five core board responsibilities: building AI literacy among directors through experts and independent learning, promoting C-suite fluency with AI risks, recruiting board members with operational AI experience, establishing dedicated governance structures such as AI subcommittees, and guiding responsible deployment using risk assessment frameworks.
Building AI literacy does not require technical expertise in machine learning. It requires directors to understand what frontier AI systems can do, what risks they pose, and what governance frameworks can mitigate those risks. The risks include the capacity to accelerate cybersecurity attacks by compressing the time required to discover and exploit vulnerabilities, the challenge that the same reasoning capability benefits both defenders and attackers, and unpredictable behavior—frontier models can exhibit capabilities outside the scope of their training.
What Boards Need to Oversee in Practice
Boards should ensure that AI governance addresses three domains. The first is operational risk: how the company protects unreleased model weights, assesses risk before and after model deployment, isolates AI workloads from critical infrastructure, and responds to incidents. The second is regulatory risk: whether the company understands which New York rules apply to its business. The third is reputational and strategic risk: whether the company's AI programs align with its stated values and whether third-party involvement in risk assessments gives them credibility.
The RAISE Act requires developers to use third-party evaluators to assess frontier AI risks. Boards should ask whether the company's third-party assessors are independent, whether they have access to the full training process not just the final model, and what they are actually testing. A third-party assessment that examines only a model's outputs is less rigorous than one that includes access to weights, training data, and internal safety practices.
Boards should establish the frequency and scope of AI risk reviews. While the RAISE Act requires annual reviews of frameworks, boards at companies building frontier AI should consider whether annual reviews are sufficient if the company is updating models or training new ones more frequently. Boards at companies deploying AI at scale should establish a regular cadence for assessing how those deployments are performing and whether new risks have emerged.
“A third-party assessment that examines only a model's outputs is less rigorous than one that includes access to weights, training data, and internal safety practices.”
Aligning Compliance with Governance
The RAISE Act creates a state oversight office that will assess large developers annually and can impose civil penalties up to $1 million for a first violation and $3 million for subsequent ones. The Attorney General can bring enforcement actions against developers that fail to file required reports or make false statements.
For boards, the combination of state oversight and investor expectations means that AI governance is no longer optional. The most effective approach integrates RAISE Act compliance obligations with broader board governance. This means assigning responsibility for compliance to a specific executive or team, establishing a board committee with oversight authority, creating processes for regular reporting to the board on AI safety and risk management, and documenting board-level decisions about AI strategy. The same practices that satisfy the RAISE Act's requirements—frameworks that describe risk mitigation, transparency about how models work, third-party assessment, incident response protocols, and annual review—also satisfy investor and regulatory expectations about board governance of AI.



