The New York State Department of Financial Services (NYDFS, or DFS) is the New York State agency that regulates banks, insurers, and other financial-services entities operating in the state. Because of the concentration of the financial industry in New York, its rules and guidance carry influence beyond the state. In AI policy its relevance derives chiefly from its cybersecurity regulation, 23 NYCRR Part 500, and from supervisory guidance applying that regulation to risks introduced by AI.
| Field | Value |
|---|---|
| Jurisdiction | New York State (banking, insurance, financial services) |
| Core AI-relevant rule | 23 NYCRR Part 500 (cybersecurity regulation) |
| AI guidance | October 2024 letter on AI cybersecurity risks; May 21, 2026 advisory on frontier-AI cybersecurity risks |
Frontier-AI cybersecurity advisory (May 2026)
On May 21, 2026, NYDFS issued an industry letter to the chief information security officers of regulated entities titled "Heightened Cybersecurity Risks Associated with Frontier AI Models." The advisory addresses "certain frontier artificial intelligence models that amplify the potency, scale, and speed of identifying vulnerabilities and exploits in information systems," and urges regulated entities to improve their security posture ahead of the wider availability of such models. It states explicitly that it imposes no new requirements and is intended to inform existing risk-management and compliance efforts rather than to create obligations (Source: https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-heightened-cybersecurity-risks-assoc-with-frontier-ai-models).
The letter directs entities to a companion guidance document issued the same day, "Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment," and highlights several measures: expedited vulnerability identification and remediation; coordination with third-party and downstream service providers and maintenance of dependency maps; strengthened secure-programming practices, including human oversight and testing of AI-generated code before production deployment; and heightened monitoring, logging, and prompt reporting of suspicious activity. The advisory builds on the Department's October 2024 guidance on cybersecurity risks arising from AI but is narrower, focused specifically on the offensive-cyber capabilities of frontier models (Source: https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-heightened-cybersecurity-risks-assoc-with-frontier-ai-models; https://datamatters.sidley.com/2026/05/28/new-york-department-of-financial-services-issues-coordinated-guidance-on-frontier-ai-cybersecurity-risks/).
The advisory has been described as among the first guidance from a U.S. state financial regulator aimed explicitly at frontier-model capabilities, and it positions NYDFS alongside federal cybersecurity bodies as a state-level counterpart on the AI-cyber question (Source: https://www.gtlaw.com/en/insights/2026/6/nydfs-issues-dual-guidance-on-heightened-cybersecurity-threats-frontier-ai-risks).
Relationships
- related: CISA — Cybersecurity and Infrastructure Security Agency (AI Deployer) — federal counterpart referenced alongside NYDFS on frontier-AI cyber risk.
- related: National Institute of Standards and Technology (NIST), NIST CAISI (Center for AI Standards and Innovation) — federal standards-side counterparts on AI cybersecurity.
Provenance note
Page created 2026-06-15 (gap-scan) from the primary NYDFS industry letter plus law-firm analyses. It resolves a dangling [[entities/ny-dfs]] reference relied on by CISA — Cybersecurity and Infrastructure Security Agency (AI Deployer). The primary letter is dated May 21, 2026; CISA — Cybersecurity and Infrastructure Security Agency (AI Deployer) currently cites the advisory as "May 26, 2026," a date discrepancy flagged for lint/curator review.