Law / United States /
New York
DFS Advisory: Heightened Cybersecurity Risks Associated with Frontier AI Models
DFS Industry Letter of on Frontier AI Models
Guidance, not a law: the New York Department of Financial Services's reading of New York Department of Financial Services Cybersecurity Regulation, Cybersecurity Program and Cybersecurity Policy. It binds nobody by itself; the law it reads does.
Guidance on a sector security regimes rule, addressed to private bodies.
- Instrument type
- guidance published by a regulator
- Obligation class
- Security, Governance
As of .
What the regulator expects
- The advisory is addressed to the chief information security officers of the individuals and entities the Department regulates, and it reads 23 NYCRR Part 500, which reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The Department states that the advisory does not impose any new requirements.
- The Department says you should review and update your risk assessments to reflect the evolving risks posed by frontier AI models, review your cybersecurity program to ensure full compliance with Part 500, and consider whether additional cybersecurity measures are warranted to address the heightened risks.
- The Department says you should reassess your procedures for evaluating the criticality and threat of known vulnerabilities and review your vulnerability management timelines to determine whether accelerated detection and remediation processes are necessary, based on your updated risk assessments.
- The Department says you should develop and maintain dependency maps, coordinate with your critical third-party service providers and material downstream providers to address significant vulnerabilities and operational risks, and monitor and validate third-party code and engage with critical providers, including to communicate the specific responsibilities of each side.
- The Department says you should restrict and validate inputs before running scripts or processes, confirm that secure programming practices are used, apply additional testing and validation, including human oversight, to AI-generated code before it is deployed in production, and, if you use AI to identify and remediate vulnerabilities, employ secure programming practices to prevent unknown changes in code or configurations.
- The Department says you should consider whether your logging and security event alerting capabilities are sufficient to address heightened threats, and review and test your threat-relevant operational resilience procedures, which may require more frequent use as AI-enabled cyber capabilities evolve.
- The Department says you should consider whether to strengthen operational resilience by replacing end-of-life or legacy information systems.
Who enforces it
Enforcement body
The Superintendent of Financial Services, who enforces 23 NYCRR Part 500, the regulation the letter reads.
What this law does
The Department's industry letter of is addressed to the chief information security officers of the entities the Department regulates. It is an advisory about certain frontier artificial intelligence models that amplify the potency, scale, and speed of identifying vulnerabilities and exploits in information systems. The advisory states that it does not impose any new requirements for regulated entities and is intended to inform their risk management and compliance efforts.
It urges regulated entities to improve their security posture in preparation for the release of these models. It says the best preparation is a robust cybersecurity program that includes timely and comprehensive vulnerability identification and remediation. It says regulated entities should review and update risk assessments to reflect the evolving risks posed by this new technology.
It says entities should consider whether to strengthen operational resilience by replacing end-of-life or legacy information systems. It says entities should review their cybersecurity programs to ensure full compliance with 23 NYCRR Part 500 and consider whether additional cybersecurity measures are warranted. The Department issued, in conjunction with the advisory, guidance on measures regulated entities should consider in a heightened cybersecurity threat environment.
For frontier AI models it says regulated entities should consider the measures in sections 1, 2 and 3.2 of that guidance. On vulnerability management it says regulated entities should reassess their procedures for evaluating the criticality and threat of known vulnerabilities and review their vulnerability management timelines to determine whether accelerated detection and remediation processes are necessary.
On third-party dependencies it says regulated entities should develop and maintain dependency maps and coordinate with critical third-party service providers and material downstream providers to address significant vulnerabilities and operational risks.
It says the guidance recommends that regulated entities monitor and validate third-party code and engage with critical third-party service providers, including to communicate the specific responsibilities of the regulated entity and the third party. On programming practices it says that additional testing and validation procedures, including human oversight, may be applied to AI-generated code before it is deployed in production environments.
It says the guidance recommends that organizations restrict and validate inputs before running scripts or processes and confirm that secure programming practices are used. It says regulated entities using AI to identify and remediate vulnerabilities should employ secure programming practices to prevent unknown changes in code or configurations, or the inadvertent destruction or material degradation of necessary code.
On monitoring it says regulated entities should consider evaluating whether existing logging and security event alerting capabilities are sufficient to address heightened threats. It says the guidance recommends that regulated entities review and test threat-relevant operational resilience procedures, which may require more frequent use as AI-enabled cyber capabilities evolve.
The advisory points to the Department's October 2024 guidance on cybersecurity risks arising from artificial intelligence for additional information.