Law / United States / New York

DFS Guidance: Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks

DFS Industry Letter of

Guidance, not a law: the New York Department of Financial Services's reading of New York Department of Financial Services Cybersecurity Regulation, Cybersecurity Program and Cybersecurity Policy. It binds nobody by itself; the law it reads does.

Guidance on a sector security regimes rule, addressed to private bodies.

Instrument type
guidance published by a regulator
Obligation class
Security, Governance

As of .

What the regulator expects

  • The letter is addressed to the executives and information security personnel of all entities regulated by the New York State Department of Financial Services, and reads 23 NYCRR Part 500, which reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law (reached by declaring that you provide financial services). The Department states that the letter does not impose any new requirements beyond Part 500.
  • The Department says your risk assessment should address AI-related risks in your own use of AI, in the AI technologies your third-party service providers and vendors use, and in any vulnerabilities stemming from AI applications that could affect your information systems or nonpublic information.
  • The Department says your incident response, business continuity and disaster recovery plans should be reasonably designed to address all types of cybersecurity events and other disruptions, including those relating to AI.
  • The Department says your third-party service provider policies should include due diligence guidelines before you use a provider with access to your information systems or nonpublic information, strongly recommends that you consider the threats AI poses to those providers, and says you should require providers to give timely notice of any cybersecurity event that directly impacts your information systems or the nonpublic information they hold, and should consider additional representations and warranties where providers use AI.
  • The Department says you should consider authentication factors that can withstand AI-manipulated deepfakes, avoiding authentication by SMS text, voice or video and using forms such as digital-based certificates and physical security keys; it states that as of November 2025 the regulation requires multi-factor authentication for all authorized users attempting to access your information systems or nonpublic information, and that your access controls must limit each authorized user's privileges to those necessary for the user's job functions.
  • The Department says your training should ensure all personnel are aware of the risks posed by AI, the procedures you have adopted to mitigate them, and how to respond to AI-enhanced social engineering attacks, and that training for cybersecurity personnel should include how threat actors use AI in social engineering attacks, how AI facilitates and enhances existing types of cyberattacks, and how AI can improve cybersecurity.
  • The Department states that the regulation requires you to monitor the activity of authorized users and email and web traffic to block malicious content and protect against the installation of malicious code, and says that if you use AI-enabled products or services or allow personnel to use AI applications you should also consider monitoring for unusual query behaviors that might indicate an attempt to extract nonpublic information and blocking queries that might expose it to a public AI product or system.
  • The Department states that you are required to dispose of nonpublic information that is no longer necessary for business operations or other legitimate business purposes, including nonpublic information used for AI purposes, and says that, although not required until , you should maintain and update data inventories and should identify all information systems that use or rely on AI and maintain an inventory of them.

Who enforces it

Enforcement body

The Superintendent of Financial Services, who enforces 23 NYCRR Part 500, the regulation the letter reads.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Department's industry letter of explains how covered entities should use the framework in Part 500 to assess and address the cybersecurity risks arising from artificial intelligence. The letter states that it does not impose any new requirements beyond the obligations in 23 NYCRR Part 500. It describes four cybersecurity risks, two caused by threat actors' use of AI and two caused by a covered entity's own use of or reliance on AI.

It says a covered entity should address AI-related risks in its risk assessment, in its own use of AI, in the AI technologies used by its third-party service providers and vendors, and in any vulnerabilities stemming from AI applications. It says the incident response, business continuity and disaster recovery plans should be reasonably designed to address all types of cybersecurity events and other disruptions, including those relating to AI.

It calls third-party service provider policies and procedures that include guidelines for due diligence before a covered entity uses a provider with access to its information systems or nonpublic information one of the most important requirements for combatting AI-related risks.

It strongly recommends that covered entities consider the threats AI and AI-enabled products and services pose to their third-party service providers, how those threats could impact the covered entity, and how the providers protect themselves from such exploitation.

It says covered entities should require third-party service providers to provide timely notification of any cybersecurity event that directly impacts the covered entity's information systems or the nonpublic information the provider holds, including threats related to AI. Where providers use AI, it says covered entities should consider incorporating additional representations and warranties related to the secure use of their nonpublic information.

For its third-party service provider, access and multi-factor authentication controls the letter cites sections 500.11(a), 500.7 and 500.12 in turn. It says covered entities should consider authentication factors that can withstand AI-manipulated deepfakes and other AI-enhanced attacks, avoiding authentication by SMS text, voice or video and using forms such as digital-based certificates and physical security keys.

It states that as of November 2025 the regulation will require multi-factor authentication for all authorized users attempting to access a covered entity's information systems or nonpublic information. It states that the access controls in the regulation must limit an authorized user's access privileges to only those necessary for the user's job functions and limit the number of authorized users with elevated permissions and access to nonpublic information.

It says training should ensure all personnel are aware of the risks posed by AI, the procedures the organization has adopted to mitigate those risks, and how to respond to AI-enhanced social engineering attacks. It says training for cybersecurity personnel should include how threat actors are using AI in social engineering attacks, how AI is being used to facilitate and enhance existing types of cyberattacks, and how AI can be used to improve cybersecurity.

For its annual training and monitoring controls the letter cites sections 500.14(a)(3), 500.5(b) and 500.14(a)(2). It states that the regulation requires a covered entity to monitor the activity of authorized users as well as email and web traffic to block malicious content and protect against the installation of malicious code on its information systems.

It says covered entities that use AI-enabled products or services, or allow personnel to use AI applications such as ChatGPT, should also consider monitoring for unusual query behaviors that might indicate an attempt to extract nonpublic information and blocking queries from personnel that might expose it to a public AI product or system.

It states that covered entities are required to dispose of nonpublic information that is no longer necessary for business operations or other legitimate business purposes, which includes nonpublic information used for AI purposes. It says that, although not required until , covered entities should maintain and update data inventories.

It says entities that use AI or rely on a product that uses AI should identify all information systems that use or rely on AI and maintain an inventory of all such systems.

Back to the example  ·  Lint your app