I encourage all readers to attend the NYC-DSA Tech Action Working Group’s demonstration on October 5th to center workers in any discussion of the city’s AI policy.
On Monday, October 5th, a Committee of the Whole hearing on AI will be held in NYC City Council. This rare procedure will see all 51 Council members sit as one committee chaired by Speaker Julie Menin.
The stated purpose is to examine the risks highly capable AI systems pose to New Yorkers and what the city can do about it, with a 10-bill package on the table.
There are four companies under oath, Anthropic, OpenAI, Google, and Meta, and the CEOs will not be attending. The MechaHitler division of SpaceX is under subpoena because Musk never responded to Council.
The Committee of the Whole was called by Menin in response to the hack of Hugging Face by internally deployed OpenAI models and the resignation of Jacob Coxon from Anthropic, and is framed as responding to federal inaction.
But why is this actually happening?
What is unclear is why the hell this is a widely publicized 51-member Committee of the Whole instead of just prioritizing legislation within the normal committee system. I can come up with four theories.
i) The first is that we take Menin at her word, that she actually is super concerned about catastrophic risks and federal inaction. Perhaps she is!
ii) However, this is a rather odd mechanism for doing so, and has the additional benefit of giving her a bunch of public attention, political capital, and ability to set the agenda. This thing is going to draw heavy coverage and Menin has put herself at the center with a 51-member hearing with her as chair. Even if i) is true, this is certainly a significant ancillary benefit.
iii) Menin has been the target of lobbying by the frontier AI companies and is doing this, at some level, on their behalf, or at least the structure and narrative of the hearing is impacted by their input. Though independent experts will testify in addition to corporate representatives, they have not been named, and I will admit suspecting that they will be more industry-friendly voices. Why not extend the hearing motivation outside of catastrophic risks, especially to labor displacement? Menin has stated she wants the input of AI companies on the legislation. More importantly, OpenAI held introductions with Menin in March-April 2026, and Anthropic hired lobbyists over the Summer to interface with all 51 members. However, on August 1st, they retained a CMW Strategies lobbyist whose only target was Julie Menin! No civil society, safety advocacy group such as Encode, Irreplaceable, Americans for Responsible Innovation, or AI Policy Network, or labor group has recorded recent contact on this issue with Menin in the NYC filings. On June 1st, Menin headlined a NY Tech Week fireside chat with an a16z general partner; that is, with a partner at the firm at the forefront of the AI lobby’s attempt to buy our elections and prevent substantive regulation.
iv) Menin is attempting to distract from existing legislation pushed by progressives on Council on technology policy, such as Int 213 Ban the Scan, the Delivery Protection Act, or self-checkout regulation. While we at One Thousand Means strongly disagree with the notion that recognizing catastrophic risk distracts from other harms of the technology industry, establishing a flashy 51-member committee on catastrophic risk that does actually center the firms’ testimony may actually fall into this category. If she had called a committee that explicitly focused on a wide set of issues to build a broad coalition, or even just endorsed Ban the Scan and the Delivery Protection Act alongside this effort, I’d be less skeptical. It is crucial to not fall into a trap where socialists oppose the idea of catastrophic risk because of this though, and instead we ought to use this opportunity to go, “yes, and”, marking the AI companies as an enemy to be defeated that puts us all at risk while also assisting in exploitation and price gouging.
I expect that her motivations lie across all four of these theories, and certainly that, like the vast majority of Americans, she is genuinely concerned about catastrophic risk. I hope public pressure can push her towards more substantive legislating than the bills proposed.
The Bills
Throughout these summaries, I will be using a variety of acronyms and so on. At some point I may write an introduction to New York State and New York City AI policymaking that is more accessible and provides definitions and the status quo, and I recognize this isn’t very accessible.
Int 2602
Sponsors: Menin, Maloney
This legislation makes it illegal to “market, offer for sale, sell or deploy” any AI model unless it has been validated by a third-party validator and includes a “shut-down capability”. Third-party validators are mandated to assess task performance, determinism, latency and throughput, data provenance, disparate impact on protected classes, lawful and secure data handling and informed consent, safety, and anything the director of Cyber Command adds.
The third-party validator then certifies to the developer and to Cyber Command whether the model is “appropriately positioned for deployment” and discloses any conflicts of interest. Cyber Command is responsible for writing the rules on validator qualifications and filing formatting.
The penalty for violations is quite small, $25,000 per instance of marketing, sale, or deployment, per instance of falsifying a validation, or for other violations. Especially for instances of deployment and validation falsification, this easily-absorbed fine is less than a slap on the wrist and should be on the order of millions of dollars. Enforcement lies in OATH summonses from Cyber Command or whatever agency it designates (given other legislation, presumably the Department of Consumer and Worker Protection in some matters) or a Corporation Counsel lawsuit.
I think kill-switch legislation is best done at a state level, and Governor Hochul has floated state kill switch legislationif deemed feasible. The kill-switch language is similar to the Lieu-Moran AI Kill Switch Act in the House, which has been endorsed by some AI safety organizations.
This legislation has some serious limitations, the most important of which is that the developer retains and pays the validator, with conflicts of interests disclosed but not prohibited. This lays out a red carpet for the labs to engage in severe validator shopping. Google has backed a regulator that sets standards and audits frontier models. I would expect the frontier AI companies to quickly embrace in-principle audits while selecting or even standing up industry-affiliated safe-harbor validators.
Council could strengthen this legislation to require the publication of every certification, full assessment and disclosure of interest on a public registry within some period, with narrow redactions approved by Cyber Command, make the validators liable for negligent or reckless certification, and introduce a tier of penalties for frontier model developers either in the tens of millions or at some fraction of prior-year global revenue per violation. Council could also require annual re-validation, onsite validation access, or adversarial red-teaming for dangerous chemical and biological capabilities. Council ought to fund enforcement here with the developer assessment.
The kill-switch mechanism is poor, and could be redefined as the capability to promptly cease all inference, API access, and agentic operation of the model, and all copies of the model. In my view, you probably also need to run drills for this to do anything. Council could grant Cyber Command the power to order a developer to suspend service to NYC users under Int 2606’s “AI model emergency”, with an incredibly expensive penalty for non-compliance every hour.
Most importantly, Council could establish a public evaluator insulated from industry capture. However, I am currently doubtful that the City currently has the capacity to stand up such an agency given the Office of Algorithmic Accountability is also not yet fully staffed. I am partially convinced of the idea that this legislation is simply a way for Menin to demonstrate that she is doing something about AI, both ignoring more powerful pieces of legislation on frontier risk and the slate of anti-surveillance, pro-labor legislation advanced by Socialists-in-Office. I could be swayed otherwise, especially with amendments, but given some skepticism that a kill-switch bill is even the right path forward, I am currently marginally opposed to this legislation and urge more substantive action at the state level.
Int 2605
Sponsors: Menin, Maloney
This legislation covers the subchapters created by Int 2599, 2602, and 2603 and states that any natural person except city enforcement staff may file a complaint with evidence to DCWP, which must investigate and share with Corporation Counsel. The city will inform the complainant that it will enforce the complaint, deputize the complainant as a special assistant to corporation counsel to sue, authorize the complainant to file a notice of violation at OATH, or decline. The complainant receives 25% of recovered proceeds when the city enforces and 50% if the complainant enforces. If anything, this is more aggressive than some existing law it seems to be based off of, such as the False Claims Act which has some guardrails against abuse by complainants.
One note on this bill: the deadline listed is inverted, “No less than 180 days after receiving a complaint … shall notify.”, allowing DCWP to sit on complaints indefinitely. It’s unclear if this is an error, and if something about this is above board, I’m open to clarification.
I will admit a pretty limited understanding of how this bill interacts with the rest of the package, given that it doesn’t cover some of the other bills like 2600, 2601, or even existing AI legislation like LL 114.
Council could fix the deadline, route complaints to the enforcing agency and let deputized complainants seek injunctions. One could also add whistleblower protections for the complainant, but I’m pretty unsure if that would make any sense.
The bounty structure here is stronger than existing legislation in other jurisdictions, and that 50% share is pretty fat compared to equivalent federal programs, but the value is capped by the underlying penalties, which are tiny. If combined with a much stronger version of Int 2602, I could be convinced this would have some impact, but without substantial amendments to the underlying penalty structure and validation mechanisms, I don’t think this would do much besides increase Menin’s political capital.
Int 2600
Sponsor: Maloney
This bill creates a private right of action for jailbreaks. It states that a person may sue an “artificial intelligence provider” for any harm occurring in the city if the following conditions hold:
1) the harm was caused by a third party’s malicious use or misuse, such as circumventing guardrails, filters, or safety restrictions.
2) the provider “failed to implement reasonable safeguard.”
3) the harm was “foreseeable.”
This is the opposite of the industry’s legislation like the White House’s March framework and TRAIGA in Texas, which both shield developers from jailbreaks. It’s stronger than equivalent laws in Colorado and Illinois because of the private right of action.
One limitation here is that in combination with 2602, the AI companies could argue that if they have passed validation, they have implemented reasonable safeguards. Given that condition (3) will nearly always be met, I think this is where the problems lie.
The obvious way to make this thing stronger is strict liability, which is the standard in 2599. There are probably intermediate solutions here, but I don’t have a strong enough grasp of how the law here works. Possibly, Council could add fat statutory damages and fee-shifting, and explicitly eliminate a defense predicated on certification from 2602 or any other statutory body. I will admit I have a relatively poor understanding of the mechanisms here, but this seems stronger than 2602/2600, and especially if amended I think may be worthwhile. However, given city capacity constraints and better interactions with existing law, I think the state is the best actor here and would love to see something like this in Albany. As with any bill that will likely have a sister at the state level with similar text, proposing this now is a political play by Menin that I’m unsure should be rewarded.
Int 2601
Sponsors: Hanks, Maloney
This bill creates a system for AI safety incident reporting in city contracts. Cyber Command sets the standards with the city’s chief procurement officer and OTI and mandates that new contracts that foreseeably involve AI must require the contractor to report such incidents within 24 hours. Cyber Command then posts each incident publicly with redactions.
“AI safety incident” is language ported from California’s SB 53, and includes weight theft causing harm, harm from materialized substantial risk, loss of control causing harm, and deceptive subversion of developer controls outside an evaluation. “Substantial risk” is SB53’s definition, which includes any death or serious injury, property loss or breach, arising from chemical and biological capabilities help, unsupervised cyberattacks or crimes, or evasion of control. Notably, SB53 was supported by Anthropic, but the rest of the industry and affiliated trade groups opposed it. As with SB53, I would argue that the redaction of trade secrets from public disclosure and the exclusion provided to behavior “outside of the context of an evaluation designed to elicit this behavior” are sops to the AI companies. At minimum, that exception should be struck, given that it provides protections from actual harm created during testing.
However, this bill is probably less favorable to the industry than SB53, which has a host of other protections like severity thresholds.
The glaring problem here is that there is no penalty for failing to report beyond ordinary remedies for contracts. IL and CA’s legislation imposes million dollar penalties. This bill needs to be amended to include penalties and possible debarment from city contracts if enough failures emerge. You could also strengthen this a bunch by expanding its scope upstream on subcontractors and model providers, and narrow the redaction clause.
Without a penalty beyond normal contract remedies, I don’t think any frontier model provider will change their behavior from this legislation.
Int 2606
Sponsors: Ossé (Socialist-in-Office), Santosuosso, Maloney
This bill requires Cyber Command and the New York City Emergency Management Department to develop or update an “AI model emergency response plan” to detect, assess, prepare for, mitigate, respond to and recover from AI events that compromise city systems or critical infrastructure, or significantly disrupt government operations or public health and welfare.
It largely duplicates existing authority under Cyber Command and NYCEM’s existing authorities, but adds a written AI-specific plan and reporting.
This is a fantastic beginning to securing New York City against catastrophic risk, and I applaud the sponsors for sticking their neck out here on a nationally unprecedented piece of legislation outside of state equivalents in CA’s EO N-9-26 and IL’s SB 315. This is the first piece of legislation proposed on a municipal level for disaster preparedness in response to accelerated risks from highly capable AI agents.
Arguably, one could strengthen it further by permitting Cyber Command to order any developer or deployer serving NYC users to shut-down, suspend specific features, or preserve logs with hourly penalties. In order for this to be actualized, frontier model developers possibly should be required to participate in war-gaming exercises, share threat intelligence relevant to city infrastructure, designate someone responsible as an emergency liaison, and - if legal - pay for the whole emergency planning process given that it is their models imposing these risks on the public.
I have a lot of ideas about what emergency preparedness actually looks like here, and other departments (Sanitation) that may need to be integrated into planning, but do not think I’m qualified to give anything specific here that isn’t spit-balling based on public critical infrastructure threat assessments. This is a great bill and the State ought to pass something similar with substantial resourcing paid for by the frontier model developers should a legal mechanism be found (rest in peace New York State Climate Superfund…).
Int 2604
Sponsors: Riley, Maloney
This bill adds protected reporting for city employees and covered contractor employees who report conduct related to AI use or development that they think may cause harm to public health or public safety, with the reports going to DOI and other listed officials. The existing remedies here apply, which are 2x back pay for contractor employees, reinstatement, and fees, and the agency head has discretion to decide the remedies for city employees. It strikes the $100,000 threshold for posting notices and for contract clauses and adds AI counts to the DOI annual whistleblower report.
My reading of this legislation, and I’m happy to be corrected, is that the definitions of contract and covered contractor still require a value of above $100,000, and aren’t amended, so the protections in ¶7 only reach contracts over $100,000 even though posting and contract clauses are expanded.
Limiting our whistleblower protections here to city contractors makes this weaker than both SB53 and IL’s SB 315 in scope, which protect employees of frontier AI developers. However, I think stronger whistleblower protections at the state level are likely the better idea there if Governor Hochul gets her act together on the subject. Council could extend this bill to cover AI company employees in NYC, which would be pretty aggressive. In general, frontier AI developer whistleblower protections should likely include stronger language voiding NDAs, non-disparagement, and equity-clawback provisions that deter AI safety reports. Rewriting this bill into some sweeping private sector whistleblower protections extension would be pretty cool, but without significant public pressure I kind of doubt that would get through council.
Regardless, this bill is fine given its intended scope.
Int 2603
Sponsors: Wilson, Maloney
This is an advertising disclosure and deceptive safety claims bill. Every AI advertisement in the city must disclose where the promoted model was validated under Int 2602. Ads may not include any materially false or misleading statements about any substantial risk of the model, measures taken to manage it, or validation status. The penalty is up to $25,000 per violation and stacks with existing consumer protection penalties. The enforcement lies in Corporation Counsel lawsuits.
This inherits SB53’s narrow substantial risk definition. False claims about bias, child safety, mental health safety, projected job loss, or privacy are not covered. Most of this is just porting similar language from SB53, but removing the protections for industry in SB53 for good faith.
The penalty is still pretty weak. As with this entire crop of legislation, a $25,000 penalty is basically free to OpenAI, and though my preference would be the penalty being 100% of the valuation of the company paid in stock, I think we can do something in between. The RAISE Act’s original penalty schedule, in the tens of millions, seems appropriate.
This is a good starting point, but I’m not sure it actually does much given the lack of such claims in most advertising. Council could expand the legislation by covering all public statements by AI companies about safety, including model cards, blog posts, executive statements, investor communications directed at NYC, and interfaces, and broaden protected subject matter to any material claim about safety, security, bias, child safety, mental health effects, data use, or regulatory compliance. Legislation of that form could be extremely strong given the importance of the NYC commercial client market for the frontier model developers.
Int 2599
Sponsors: Morano and Maloney
This is a Chatbot data privacy, security, transparency, and strict liability bill. It requires any chatbot provider to meet the following requirements:
1. A public data-security program
2. User access to chat logs
3. “Not a human” notice before any output, every hour, and whenever asked
4. Affirmative consent before processing personal data beyond user input, training on adult chat logs, and selling chat logs
5. No training on minors’ data ever
6. No ad targeting based on chat logs, profiling, or discrimination against users who refuse
7. Retention capped at 10 years
8. No implying outputs come from licensed professionals
9. Monthly self-assessment of risks, published
It imposes a strict liability standard, which is probably appropriate, and is enforced by DCWP rules and Corporation Counsel lawsuits, with a $25,000 penalty per violation and private right of action for relief.
Much of this bill is language from the People-First Chatbot Bill from 2025, from EPIC, CFA, and Fairplay. However, the bill is weaker, with chat-log sales permitted with consent and company-chosen risk metrics. In my read, the public data exclusion may also be weaker. I think most of these changes are probably fine given the structure, but am open to correction, especially by child safety advocates.
I would like to see CA’s SB 1119’s minor engagement limits here. The private remedy is weaker than SB 243 in CAwhich has statutory damages and fees, but it is broader than similar legislation regulating health use cases and therapy use cases in other states.
Though this legislation could certainly be stronger, I think that State action on this subject is the better fit, so would be fine with this thing mostly as is.
Int 161
Sponsors: De La Rosa, Gutiérrez, Lois, Schulman, Maloney
Int 161 adds to each agency’s annual algorithmic tool report the number of city employees whose employment was affected by each tool.
This seems weaker than state law? The LOADinG Act and existing civil service law prohibits local governments from using AI to discharge or displace employees, cut hours or wages, transfer existing duties, or impair collective bargaining. A9581-B, pending Governor Hochul’s signature, requires employment impact reports from private employers.
You could rewrite the bill to make it less about counting and more about protecting by requiring advance notice to affected unions and Council before deploying any tool with such effects or require collective bargaining over introduction. Council could also cover contractors and impose private sector reporting even stronger than A9581-B. My read is that this bill is perfectly fine but possibly under LOADinG is not particularly impactful. I am curious to see how this text evolves in interaction with the hearing or the Mayor’s Office’s intentions of making city administration more efficient.
Int 504
Sponsors: Williams and 13 Others
This is an election deepfake bill. Within 120 days an elected official or candidate may notify an owner, licensee or operator of a generative system that they refuse authorization, and the covered entity must then implement a method of preventing users from generating materially deceptive depictions of that person within 60 days of the election. Compliance is satisfied by a method “consistent with industry standards” and violation is a misdemeanor with a $2,500 per depiction fine. There’s no liability if the entity is unable to prevent the depiction after implementing a method.
This is probably the most industry-favorable bill in the whole package, and isn’t particularly burdensome. Public Citizen has stronger language regulating distributors and using a disclosure safe harbor, closer conceptually to something like DMCA. I’d rather see that get passed at a state level, but I guess this is fine. It is crucial to protect our elections from deepfakes, including facsimile chatbots representing a candidate of the type deployed in the CA-11 race.
Interactions Between Legislation
There are a lot of duplicative or inefficiently distributed duties in the package, a product of the 51-member committee. For example, for Int 2605’s bounties to work, Cyber Command has to designate DCWP as an agency capable of issuing summonses if Int 2602 is in force, and the number of evaluators here is large, with 2602 having third-parties, 2599 DCWP, 2601 incidents to Cyber Command, 2604 reports to DOI, etc. There needs to be mutual reporting requirements so that whistleblower reports get flagged by Cyber Command, etc.
Int 2600 does conflict with 2599, and the industry could argue that the liability standard in 2600 displaces that in 2599. Int 2605 defines AI model emergency separately from 2601.
I expect all of this messiness to be fixed in Council, as is normal in the legislative process. As a top-level concern across the bills, I worry about burdening Cyber Command, the Office of Algorithmic Accountability, and DCWP without a bigger budget line, though I am hoping that the political will will be generated to assist them fiscally to address the threats posed by highly capable AI agents.



