New York Attorney General Letitia James is asking employees inside artificial intelligence companies to report potentially illegal or unsafe practices directly to state investigators, giving regulators another path into conduct that may otherwise remain hidden inside AI labs.
In an industry alert issued September 17, James encouraged workers with information about AI companies to use the New York Attorney General’s confidential whistleblower portal to report activity that could put New Yorkers at risk.
The announcement specifically points to cybersecurity, economic and other safety risks associated with rapidly developing AI systems. The Attorney General’s office said it is monitoring recent developments in the industry and wants individuals with knowledge of possible legal violations to come forward.
The timing is notable.
New York’s Responsible AI Safety and Education Act, better known as the RAISE Act, takes effect January 1, 2027. The law will impose new transparency, safety and incident-reporting obligations on developers of the most computationally powerful AI models and will give the Attorney General authority to pursue significant civil penalties for violations.
But the September whistleblower notice makes another point clear: New York is not waiting until January to start looking inside AI companies.
The Whistleblower Portal Is Open Now
The Attorney General did not announce a new whistleblower law specifically for artificial intelligence.
Instead, the office is directing AI employees and others with inside knowledge to its existing secure whistleblower system.
According to the alert, complaints can be submitted anonymously and confidentially. The request is broad, applying to people who possess information about potentially unlawful conduct associated with companies developing AI technology.
James framed the request around conduct that crosses the line from risky development into potential violations of law.
That distinction matters.
AI companies routinely conduct experiments that involve powerful or potentially dangerous model capabilities. The fact that a model behaves unexpectedly during an internal evaluation does not automatically establish that a law has been violated.
What regulators appear particularly interested in is evidence that companies are concealing serious risks, ignoring required security practices, misleading the public about their safety controls or engaging in conduct covered by existing cybersecurity, privacy, fraud or computer-crime laws.
New York Already Has Enforcement Tools for AI Companies
The Attorney General’s announcement repeatedly emphasizes that New York does not need a dedicated AI statute for every possible problem involving an AI company.
The office already enforces the state’s SHIELD Act, which requires covered organizations to maintain reasonable safeguards for private information. The Attorney General also cited broader authority involving privacy, fraud and federal laws including the Computer Fraud and Abuse Act.
That means an AI company’s conduct could create legal exposure even when the behavior itself is not expressly labeled an “AI violation.”
Consider a company that inadequately protects sensitive training data or customer information.
That can become a data-security issue.
An employee who gains unauthorized access to computer systems could create a computer-crime issue.
A company that makes materially misleading representations about the security or capabilities of its product could face a different category of legal scrutiny.
The technology may be new. Many of the legal theories available to regulators are not.
The RAISE Act Changes the Landscape in January
The bigger shift arrives on January 1, 2027, when New York’s RAISE Act becomes effective.
The law does not regulate every chatbot, machine-learning system or company using AI.
Its core provisions focus on frontier models and the developers responsible for training them.
Under the statute, a “frontier model” is generally a foundation model trained using more than 1026 integer or floating-point operations. A “large frontier developer” is a qualifying frontier developer that, together with its affiliates, had more than $500 million in gross revenue during the previous calendar year.
This makes the law particularly relevant to the companies building the largest general-purpose AI systems rather than businesses simply using an outside AI service.
The RAISE Act requires large frontier developers to create, implement and publicly disclose a written frontier AI framework explaining how they assess and manage catastrophic risks associated with their models.
The framework must address areas including cybersecurity, model evaluations, risk thresholds, mitigations, third-party assessments, internal governance and procedures for identifying and responding to critical safety incidents.
Importantly, the law does not allow companies to treat that framework purely as marketing material.
Large frontier developers are required to comply with their own framework.
AI Companies Will Have to Explain How They Manage Catastrophic Risk
New York’s definition of catastrophic risk is narrower than the general public discussion around whether AI could be dangerous.
The law focuses on foreseeable and material risks involving more than 50 deaths or serious injuries, or more than $1 billion in property damage or loss from a single incident.
The covered scenarios include a frontier model materially assisting in creating or releasing chemical, biological, radiological or nuclear weapons; autonomously carrying out certain serious criminal activity or cyberattacks without meaningful human oversight; or evading the control of its developer or user.
Large developers will have to explain how they determine when those types of risks become serious enough to require additional safeguards.
Their published frameworks must address how models are evaluated, what thresholds are used, which mitigations are applied and how those findings factor into decisions about deploying a model.
The law also specifically requires developers to address cybersecurity protections for unreleased model weights and risks associated with a model circumventing internal oversight mechanisms.
Those requirements make internal employees potentially important sources of information for regulators.
A public safety framework describes what a company says it does.
An engineer, researcher or security employee may know whether those procedures actually operate that way internally.
That Creates a New Problem for AI Safety Claims
One provision of the RAISE Act could become particularly relevant if whistleblowers provide internal documents that conflict with a company’s public statements.
The statute prohibits frontier developers from making materially false or misleading statements about catastrophic risk or how they manage those risks. Large frontier developers also cannot make materially false or misleading statements about whether they are implementing and following their published frontier AI frameworks.
There is a good-faith exception for statements that were reasonable under the circumstances.
Still, the provision creates a potential enforcement gap between public representations and internal reality.
Imagine a developer publicly states that a certain category of dangerous model capability is rigorously tested before deployment.
Internal employees, however, possess emails showing management repeatedly bypassed that evaluation process.
Or a published framework states that certain security controls protect unreleased model weights, while security engineers internally documented that those controls had not actually been implemented.
Those are the kinds of discrepancies that an insider could potentially bring to regulators.
The Attorney General’s whistleblower invitation creates a direct channel for that information.
Serious AI Safety Incidents Will Have a 72-Hour Reporting Clock
The RAISE Act also creates mandatory incident reporting.
A frontier developer must generally report a qualifying critical safety incident within 72 hours after determining that the incident occurred, or after learning enough facts to reasonably believe one occurred.
For incidents presenting an imminent risk of death or serious physical injury, the law requires disclosure within 24 hours to an appropriate law enforcement or public-safety authority.
The statutory definition of a “critical safety incident” is specific.
It includes certain unauthorized access to or exfiltration of frontier model weights resulting in death or injury; harm caused by a catastrophic risk; loss of control over a frontier model that causes death or injury; and certain cases where a model deceptively circumvents its developer’s controls outside an evaluation designed to test that behavior.
This is not a requirement to report every hallucination, jailbreak or unusual model response.
But when an event reaches the statutory threshold, a company cannot simply address it internally and move on.
Whistleblowers Could Matter Most When a Company Decides an Incident Is Not Reportable
The difficult cases may involve incidents near the edge of those definitions.
Companies will inevitably have to make judgment calls about whether a particular event satisfies the statutory reporting threshold.
An internal safety team might argue that an incident should be reported. Management might conclude that it does not qualify.
That type of disagreement is where whistleblower information can become particularly consequential.
New York’s new safety office, housed within the Department of Financial Services, must establish a mechanism allowing both frontier developers and members of the public to report critical safety incidents. The office can review those reports and share appropriate information with other government entities, including the Attorney General.
The Attorney General’s separate September alert effectively tells employees that they do not necessarily have to rely entirely on their employer’s reporting process if they believe unlawful conduct is occurring.
Penalties Can Reach $3 Million for Subsequent Violations
The RAISE Act gives the New York Attorney General direct enforcement authority.
Once the law takes effect, the Attorney General can seek civil penalties of up to $1 million for a first violation and up to $3 million for each subsequent violation, depending on severity.
Potential violations include failing to publish or transmit required documentation, failing to report a qualifying incident, making prohibited misleading statements, or failing to comply with the company’s own frontier AI framework.
The statute does not create a private right of action. Enforcement of those provisions rests with the state rather than private plaintiffs.
This Is Also About Internal AI Governance
One of the more practical lessons from New York’s announcement has little to do with futuristic AI scenarios.
It is about corporate governance.
AI companies increasingly have internal model-safety teams, cybersecurity groups, red teams, responsible-AI committees and researchers tasked with identifying dangerous behavior.
Those functions only work if uncomfortable findings can reach people with authority to act on them.
A company can have sophisticated safety documentation and still have a weak safety program if employees believe raising a problem will damage their careers or if internal warnings repeatedly disappear before reaching senior decision-makers.
With regulators actively asking those workers to report concerns externally, internal escalation processes take on additional importance.
AI governance is no longer simply about writing policies explaining how a company intends to manage model risk.
Companies also need records showing what happened when their own researchers identified a problem.
The Alert Reaches Beyond the Companies Covered by the RAISE Act
There is another important distinction in the Attorney General’s announcement.
The whistleblower invitation is broader than the RAISE Act itself.
The RAISE Act’s most demanding obligations target frontier developers meeting specific technical thresholds, with additional requirements for large frontier developers above the revenue threshold.
The Attorney General’s September alert, by contrast, invites information from workers with knowledge about companies developing AI technology generally and refers to potential violations of existing law.
A company therefore does not necessarily need to qualify as a large frontier developer before an employee can submit information to the Attorney General.
The legal theory behind any resulting investigation would depend on the conduct involved.
New York Is Building an AI Enforcement Pipeline Before the New Law Starts
The September 17 announcement arrives a little more than three months before the RAISE Act takes effect.
That timing does not by itself establish that any particular AI company is under investigation, and the Attorney General did not name a company accused of wrongdoing in the alert.
What it does establish is that New York wants information from inside the industry.
That information could involve current cybersecurity or privacy violations enforceable under existing law. Beginning January 1, it could also become relevant to a new statutory system requiring frontier developers to document their safety programs, report serious incidents and accurately describe how they manage catastrophic risks.
For AI companies, the result is a different kind of regulatory environment.
It is no longer enough for the public-facing AI safety report to look good.
The internal testing results, security findings, escalation records and decisions made after researchers identify dangerous behavior increasingly matter too.
And New York just made clear that if employees believe those internal records tell a different story from what their company is saying publicly, the Attorney General wants to hear from them.