Law / United States / New York / New York City

New York City

All 7 named instruments researched to a stage, across two of the eight areas of law we track: 2 in force and 5 proposed. As of .

  1. AI law 6
  2. Privacy law 1
  3. Scraping law not researched
  4. Cybersecurity law not researched
  5. Communications law not researched
  6. Content moderation law not researched
  7. Age gating law not researched
  8. Reuse law not researched

in forcenot yet in forceblocked by a courtproposedno longer in force

AI law6 instruments, 1 in force, 5 proposed

Research summary (132 words)

New York City conditions an employer's or employment agency's use of an automated employment decision tool (AEDT) on an independent bias audit and a set of disclosures, rather than banning the technology outright.

A covered tool may not be used to screen a candidate or employee unless it has been the subject of a bias audit within the past year, a summary of that audit is published, and both the fact of automated screening and the tool's job-relevant data are disclosed to the candidate or employee at least ten business days before use.

The Council is also considering several pending bills on artificial intelligence models, chatbots, advertising for AI models and AI-generated depictions of public officials, heard in committee on . None of them binds anyone until it is enacted.

AI governance

Establishing a Private Cause of Action for Certain Harms Arising from Third-Party Misuse of Artificial Intelligence ModelsNew, proposed

N.Y.C. Council Int. No. 1116 of 2026 (proposed Admin. Code tit. 10, new ch. 12, §§ 10-1201 and 10-1202)New York City Council, legislation record and bill text for Int. No. 1116 of 2026 (pre-considered as T2026-2600)

Proposed. proposed Not law. It binds no one unless it is enacted.

In committee, dated , as of . Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

Sponsored by Council Member Virginia Maloney, it would let a person sue an artificial intelligence provider, meaning any person that makes an artificial intelligence model available for commercial or public use, for harm occurring in the city that a third-party user caused by misusing or maliciously using the model, including by circumventing its ethical guardrails, content filters or safety restrictions, where the provider failed to implement reasonable safeguards against that misuse and the harm was foreseeable.

A court could award damages, including punitive damages, injunctive relief and other appropriate remedies, and the bill would take effect immediately.

What it requires

Third-Party Validation and Shut-Down Capability of Artificial Intelligence ModelsNew, proposed

N.Y.C. Council Int. No. 1100 of 2026 (proposed Admin. Code tit. 20, ch. 5, subch. 27, §§ 20-883 to 20-888)New York City Council, legislation record and bill text for Int. No. 1100 of 2026 (pre-considered as T2026-2602)

Proposed. proposed Not law. It binds no one unless it is enacted.

In committee, dated , as of . Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

Sponsored by Council Member Julie Menin, the Speaker, it would make it unlawful to market, offer for sale, sell or deploy an artificial intelligence model unless a third-party validator (a person other than an affiliate of the model's developer, engaged by the developer) has validated it on topics including task performance, data provenance, disparate impact and safety, and the model includes a shut-down capability, meaning the technical capability for a human operator to make it stop functioning temporarily or permanently.

The validator would have to certify to the developer and to the Office of Cyber Command whether the model has been validated and disclose any financial or other interest it has in the model or its developer, and the director of the Office of Cyber Command would write rules on those submissions and on validator qualifications.

The civil penalty would be $25,000 per instance of marketing, offering for sale, selling or deploying a non-compliant model and $25,000 per instance of falsifying a validation, and up to $25,000 for a violation of any other provision of the subchapter, recoverable before the Office of Administrative Trials and Hearings or in a civil action by the corporation counsel, and the bill would take effect 180 days after it becomes law.

What it requires

AI risk obligations

Automated Employment Decision Tools Bias Audit and Notice Law

N.Y.C. Admin. Code tit. 20, ch. 5, subch. 25, secs. 20-870 to 20-874 (Local Law 144 of 2021)New York City Administrative Code, official codified text of Subchapter 25 of Title 20

In force since . Binds private bodies.

What this law does

In New York City it is unlawful for an employer or employment agency to use an automated employment decision tool to screen a candidate or employee for an employment decision unless the tool has been the subject of a bias audit conducted within the prior year and a summary of that audit is published on the employer's or agency's website before use.

Any employer or agency using such a tool must also notify each covered candidate or employee, at least ten business days before use, that the tool will be used and what job qualifications and characteristics it assesses.

What it requires

AI sector rules

Prohibiting the Unauthorized Depiction of Public Officials by Artificial Intelligence

N.Y.C. Council Int. No. 504 of 2026 (proposed Admin. Code tit. 3, new ch. 12, § 1057-h)New York City Council, legislation record and bill text for Int. No. 504

Proposed. proposed Not law. It binds no one unless it is enacted.

In committee, dated , as of . Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

Sponsored by Council Member Nantasha M. Williams, it would let an elected official or a candidate for nomination for election notify any owner, licensee or operator of a system that generates materially deceptive audio or visual media (a video, image or sound recording intentionally manipulated to depict speech or conduct by a candidate, some or all of which did not occur, and so realistic that a reasonable person would believe it did) of their refusal to authorize it to produce such media of them within 120 days of a covered election.

For a candidate who gives that notice, the entity would have to implement a method preventing users from generating such media of that person within 60 days of a covered election, and the method would meet the duty if it is consistent with industry standards, not overly burdensome on the system, cost-effective to implement and maintain and up to date.

An entity that fails to comply and permits the unauthorized creation or dissemination of such media would be guilty of a misdemeanor punishable by a fine of not more than $2,500 per depiction, and the official or candidate could seek injunctive relief.

The bill would not apply where the system's outputs are processed by a third party with no ownership or control over the underlying generative model, would not make an entity liable where it implemented a method and still could not prevent a depiction, for incidental or unforeseeable depictions, or where no notice was sent, and would take effect 120 days after it becomes law.

What it requires

AI transparency

Chatbot Data Privacy, Security, and TransparencyNew, proposed

N.Y.C. Council Int. No. 1118 of 2026 (proposed Admin. Code tit. 20, ch. 4, subch. 17, §§ 20-699.31 to 20-699.40)New York City Council, legislation record and bill text for Int. No. 1118 of 2026 (pre-considered as T2026-2599)

Proposed. proposed Not law. It binds no one unless it is enacted.

In committee, dated , as of . Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

Sponsored by Council Member Frank Morano, it would put duties on a chatbot provider, meaning any person creating, distributing or otherwise making available an artificial intelligence model that generates text, audio, image or video simulating conversation: notify each user that they are talking to a chatbot rather than a human, publish a data security program, give users access to their own retained chat logs, assess the chatbot for risks of harm to users every month, and not imply that its outputs come from or equal those of a licensed or certified professional.

It would also restrict the processing of personal data and chat logs: that of a user the provider knows or has reason to know is under 18 could never be used for training and could be processed otherwise only with a parent's or guardian's affirmative consent, and an adult's could be used for training only with that user's consent.

It would limit advertising use, profiling, sale and retention of chat logs, bar retaliation against users who refuse consent to training or access their own chat logs, and make a provider liable for any injury its chatbot causes a user, with chatbots treated as products for product liability actions.

A civil penalty of not more than $25,000 per violation would apply, the corporation counsel could bring an action to correct violations, a person alleging a violation could sue for compensatory, injunctive and declaratory relief, and the bill would take effect 180 days after it becomes law.

What it requires

Requiring Certain Disclosures and Prohibiting Deceptive Representations in the Promotion of Artificial Intelligence ModelsNew, proposed

N.Y.C. Council Int. No. 1130 of 2026 (proposed Admin. Code tit. 20, ch. 5, subch. 28, §§ 20-890 to 20-894)New York City Council, legislation record and bill text for Int. No. 1130 of 2026 (pre-considered as T2026-2603)

Proposed. proposed Not law. It binds no one unless it is enacted.

In committee, dated , as of . Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

Sponsored by Council Member Carl Wilson, it would bar any person from disseminating, or causing to be disseminated, in the city a commercial message promoting an artificial intelligence model, directly or indirectly, that does not disclose whether a third-party validator validated the model under the proposed subchapter 27 of chapter 5, or that includes a materially false or misleading statement about a substantial risk the model poses, any measure taken or to be taken to manage that risk, or whether the model was validated.

That subchapter is the one Council bill Int 1100-2026 would add. Each violation would carry a civil penalty of up to $25,000, with a separate penalty under section 20-703 where a deceptive advertisement also violates section 20-700, and the corporation counsel could sue to recover penalties and obtain injunctive relief. The commissioner would write rules on the form of the disclosure, and the bill would take effect 180 days after it becomes law.

What it requires

Privacy law1 instrument, 1 in force

Research summary (65 words)

New York City conditions a commercial establishment's collection of biometric identifier information on entrance signage disclosing the practice, and separately bars any commercial establishment from selling, leasing, trading, or otherwise profiting from the transaction of biometric identifier information regardless of whether it posts a sign. The law exempts government agencies entirely and arms an aggrieved customer with a private right of action carrying statutory damages.

Biometric privacy

Biometric Identifier Information Law

N.Y.C. Admin. Code tit. 22, ch. 12, secs. 22-1201 to 22-1205 (Local Law 3 of 2021)New York City Administrative Code, official codified text of Chapter 12 of Title 22

In force since . Binds private bodies.

What this law does

A commercial establishment, a place of entertainment, retail store, or food and drink establishment, that collects, retains, converts, stores, or shares customers' biometric identifier information must post a clear and conspicuous sign at every customer entrance disclosing that practice.

Separately, it is unlawful for any commercial establishment to sell, lease, trade, share in exchange for anything of value, or otherwise profit from the transaction of biometric identifier information, and the law does not apply to a government agency, employee, or agent.

What it requires

Case law

  • No current case law for New York City AI law
  • No current case law for New York City privacy law
  • No current case law for New York City scraping law
  • No current case law for New York City cybersecurity law
  • No current case law for New York City communications law
  • No current case law for New York City content moderation law
  • No current case law for New York City age gating law
  • No current case law for New York City reuse law

Reporting clocks that run here9 instruments

The instruments whose obligation lines set a deadline for reporting an incident, a vulnerability or a personal-data breach, each deadline read from the sentence that carries it and listed shortest first. The law of New York City comes first, then the law of the bodies above it that applies here.

Each flag is one law, and a link to it. Read down the scale: the clocks document's time axis, with the empty stretches shortened so the deadlines sit close. Flags on one line set the same duty at the same deadline, and the laws behind them are named to the right, with what each clock counts from.

24 hours
Safety-incident reportfrontier-model AI law
36 hours
72 hours
Safety-incident reportfrontier-model AI law
4 business days
60 days
Breach notificationprivacy law
The deadlines above on one time axis, shortest at the top. The axis keeps its order and, between neighbors, its proportion, but a stretch with no deadline on it is shortened, so the hour marks on the left are what say how far apart two stations really are. Beside each action, the laws that set it, what each counts from, and a status where the law is not yet in force. The List tab has the same data in full, with the sentences.

The law of New York, which applies in New York City

24 hours72 hours30 days

New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent

23 NYCRR 500.17security law, in force

The sentences the clocks are read from

Notify the Superintendent electronically, in the form set forth on the Department's website, as promptly as possible but no later than 72 hours after you determine that a Cybersecurity Incident has occurred at your organization, an affiliate, or a third-party service provider: an event that requires notice to a government or supervisory body, that has a reasonable likelihood of materially harming a material part of your normal operations, or that results in the deployment of ransomware within a material part of your information systems.

Promptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty.

Where you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules.

24 hours72 hours

Responsible AI Safety and Education Act (RAISE Act)

N.Y. Gen. Bus. Law art. 44-B (§§ 1420-1429), ch. 699 of 2025, as amended by ch. 96 of 2026frontier-model AI law, not yet in force, from

The sentence the clocks are read from

Report any critical safety incident involving your frontier models to the Department of Financial Services office within 72 hours of determining that it occurred or of learning facts sufficient for a reasonable belief that it did, and disclose an incident posing an imminent risk of death or serious physical injury within 24 hours to an appropriate law enforcement or public safety authority.

The law of the United States, which applies in New York City

24 hours72 hours

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

6 U.S.C. 681-681g (CIRCIA)security law, enacted, not yet in force

The sentences the clocks are read from

Once the final rule takes effect, report a covered cyber incident to the Agency not later than 72 hours after your organization reasonably believes that the covered cyber incident has occurred.

Once the final rule takes effect, report a ransom payment to the Agency not later than 24 hours after your organization makes the payment, even where the underlying ransomware attack is not itself a covered cyber incident.

Once the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes.

36 hours

Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers

12 CFR Part 53 (OCC); 12 CFR Part 225, Subpart N (Federal Reserve Board); 12 CFR Part 304, Subpart C (FDIC)security law, in force since

The sentences the clocks are read from

If your organization is a banking organization, notify your primary federal banking regulator, the OCC, the Federal Reserve Board, or the FDIC, whichever supervises it, about a notification incident, as soon as possible and no later than 36 hours after your organization determines that a notification incident has occurred.

A notification incident is the subset of computer-security incidents that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, your ability to serve customers, a business line, or an operation whose failure would threaten the financial stability of the United States, so a computer-security incident that falls short of that threshold does not by itself start this clock.

If your organization is a bank service provider, notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible after your organization determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for a period of four hours or more.

This duty carries a standard, as soon as possible, rather than a fixed number of hours to notify by, and that disruption threshold is what engages the duty rather than a period to notify within.

4 business days

SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)

17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05)security law, in force since

The sentence the clocks are read from

If your organization is an Securities and Exchange Commission (SEC) reporting company, determine, without unreasonable delay after you discover a cybersecurity incident, whether the incident is material, and if it is, file a Form 8-K under Item 1.05 within four business days after you make that determination.

Which of these one incident starts turns on the facts: the incident method works that through. The clocks document draws every clock in the LexLint law library on one axis, with the sentence beside every rung.

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

This page covers the instruments LexLint has researched to a stage. Instruments named in the law library but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.