BILL NUMBER: S10373
SPONSOR: GOUNARDES
 
TITLE OF BILL:
An act to amend the general business law and the public officers law, in
relation to third party verification of compliance with transparency and
safety requirements for developers of artificial intelligence models
 
PURPOSE OR GENERAL IDEA OF BILL:
This bill would require large frontier Al developers to annually retain
an independent third-party verifier to assess their compliance with
their own Al safety frameworks
 
SUMMARY OF PROVISIONS:
Section one of this bill adds a new definition of "third party verifier"
to Section 1420 of the General Business Law (GBL).
Sections two of this bill adds a new section 1425 to Article 44-B of the
GBL, which requires large frontier model developers to draft safety
frameworks regarding mitigations to reduce catastrophic risk posed by
such developer's models. Section 1425 would require large frontier model
developers to annually engage a third party verifier to measure compli-
ance with the developer's safety framework and to publish a general
summary of the third party verifier's report online within sixty days of
the report's completion.
Section two further provides that New York's Office of Digital Inno-
vation, Governance, Integrity & Trust (DIGIT) shall adopt regulations by
July 1st, 2028 to officially accredit third party verifiers to ensure
sufficient technical expertise, address potential conflicts of interest,
and uphold the integrity and independence of third party verifications.
Section three of this bill amends subdivision one of section 1428 of GBL
to make a conforming edit to ensure that this new third party verifica-
tion requirement is subject to the same Attorney General enforcement as
every other provision of Article 44-B.
Section four of this bill adds a new paragraph (w) to subdivision 2 of
Section 87 of the Public Officers Law to exempt the third party verifi-
cation reports from the Freedom of Information Law (FOIL).
Section five is a severability clause.
Section six sets the effective date.
 
JUSTIFICATION:
In 2025, New York enacted the RAISE Act (Chapter 699 of 2025), requiring
large frontier Al developers to maintain and follow safety frameworks
designed to prevent their models from contributing to catastrophic
outcomes, including cyberattacks on critical infrastructure and the
development of weapons of mass destruction.
The law represented a meaningful first step, but it left a significant
gap: while companies are obligated to develop and follow these plans, no
mechanism exists to verify that they are actually doing so. Without
independent verification, compliance disputes play out in the press, the
Attorney General's office may lack the resources to conduct meaningful
investigations into all covered companies, and companies face a compet-
itive incentive to cut corners on safety out of the perception that
their rivals are doing the same.
As some frontier model developers openly acknowledge, voluntary commit-
ments are only as durable as the competitive pressures surrounding them.
This bill improves enforcement by requiring large frontier Al developers
covered under the RAISE Act to annually retain an independent third
party verifier to assess whether they have complied with their own safe-
ty frameworks, whether their public statements about catastrophic risk
are consistent with the verifier's findings, and whether any redactions
from public disclosures were permissible.
The verifier must publish a public summary of its findings within sixty
days of completing the report, and developers must link to that summary
on their own websites.
The Office of Digital Innovation, Governance, Integrity & Trust (DIGIT)
within the Department of Financial Services is directed to establish an
accreditation system for verifiers by July 2028, with conflict-of-inter-
est safeguards and post-employment restrictions as needed, ensuring that
the verification market is both competitive and credible. Large frontier
developers already submit audited financial statements to the public
which must be audited. This bill simply applies the same logic to their
compliance with safety plans designed to prevent Ai from helping to
carry out catastrophic harm.
When companies have disclosed that their latest systems are capable of
autonomously identifying major security vulnerabilities in critical
software, the case for independent verification of safety commitments
makes itself.
 
PRIOR LEGISLATIVE HISTORY:
None
 
FISCAL IMPLICATIONS:
TBD
 
EFFECTIVE DATE:
This act shall take effect on the thirtieth day after it shall have
become a law.

Statutes affected:
S10373: 1420 general business law, 87 public officers law, 87(2) public officers law