FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
    Filters
      Symbols
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      New York’s AI Safety Law Puts Banks’ Vendor Plans to the Test 

      New York is giving the largest artificial intelligence (AI) model developers a compliance calendar. Starting in November, the state will direct them to register under its RAISE Act. In January, requirements for public safety protocols, regular reporting and notice of critical incidents take effect.

      For banks and FinTechs using those models, the immediate issue is practical: What happens to a customer service, fraud or payments process when its AI provider reports a serious incident?

      Gov. Kathy Hochul announced the implementation schedule on Monday (Sept. 21) and appointed Marc Gilman as deputy director for the RAISE Act in the state’s new Office of Digital Innovation, Governance, Integrity and Trust, known as DIGIT. The office sits within the Department of Financial Services. Covered developers must publish safety and transparency frameworks, submit quarterly assessments of catastrophic risks and report critical safety incidents to DIGIT within 72 hours. They must also register and file periodic disclosures.

      Those duties apply to large frontier-model developers, not automatically to every institution that buys their services. But the distinction offers little comfort if a bank has built a business process around one provider’s model. An incident could require the developer to investigate, change access or alter how the model works while its customers still need to serve account holders and process transactions.

      The law gives New York a way to see and track serious model risks. When Hochul signed the RAISE Act last December, her office said the attorney general could seek civil penalties for failures to submit required reports or for false statements, with penalties of up to $1 million for a first violation and $3 million for subsequent violations. That enforcement mechanism adds weight to a developer’s reporting obligations.

      For financial institutions, the useful next step is to ask vendors what a reportable incident would mean for customers. How quickly would the institution learn about it? Which services might be affected? Could staff suspend the model’s access to sensitive data or its authority to take an action while keeping the rest of the workflow running?

      Those answers matter most where AI does more than produce text. A tool that helps draft a customer response poses a different operational problem from one that can initiate a refund, change an account setting or approve a payment. Institutions need to know where a model’s authority ends and who can turn off that authority if its behavior becomes unreliable.

      They may also need a workable route to another model or to a manual process. Switching providers sounds simple until a firm discovers that prompts, data connections and approval steps all depend on one vendor. Testing a fallback before an incident would show which parts of the process can actually continue.

      Hochul has discussed possible future AI “kill switches,” according to a  Tuesday (Sept. 22) report by Insurance Journal. That remains an exploratory idea, not a current RAISE Act requirement. Banks, however, can decide now how to limit or suspend an AI tool inside their own operations. New York’s calendar gives them a reason to make that decision before a provider’s incident forces it.


      Source: PYMNTS.com
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud