Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

RAISE Act transparency rules: what AI teams need to do now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: New York’s RAISE Act creates the first U.S. state-level framework focused on frontier AI safety, requiring large model developers to disclose risks, incidents, and safeguards and exposing them to civil penalties of up to 30 million dollars, according to ActiveFence. The law shifts AI governance from voluntary reporting to auditable accountability, which will reshape how enterprises evidence observability, red teaming, and incident handling.

NHIMG editorial — based on content published by ActiveFence: RAISE Act Ushers in a New Era of AI Transparency

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do frontier AI systems require more than model cards and policy statements?

A: Because model cards describe intent, but regulators and auditors need evidence of testing, monitoring, and incident handling.

Q: How do teams know if AI observability is actually working?

A: It is working when teams can show which change caused a quality shift, which dataset surfaced the issue, and whether the regression was contained before users were affected.

Practitioner guidance

  • Map AI systems to formal control ownership Assign named owners for model risk, incident escalation, and evidence retention so every frontier AI deployment has a clear accountability chain.
  • Embed red teaming into release gates Require adversarial testing before production release and after major model changes, with test cases that probe unsafe outputs, policy bypass, and misuse paths.
  • Instrument runtime observability for model behaviour Capture prompts, tool calls, policy decisions, and exception events so AI behaviour can be reviewed during investigations and regulatory reporting.

What's in the full article

ActiveFence's full article covers the regulatory detail this post intentionally leaves for the source:

  • The exact scope test for frontier AI models, including the compute threshold used to define coverage.
  • The reporting obligations for incidents, unsafe model behaviour, and model-weight theft under the act.
  • The civil penalty exposure and enforcement authority assigned to New York’s attorney general.
  • The practical compliance framing ActiveFence uses for developers, enterprises, and AI governance teams.

👉 Read ActiveFence's analysis of New York’s RAISE Act and frontier AI transparency →

RAISE Act transparency rules: what AI teams need to do now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18302
 

Transparency is becoming the new security boundary for frontier AI. The RAISE Act makes disclosure, incident reporting, and safety evidence part of the control plane, not a postscript to model release. That is a material shift for AI governance because it forces organisations to prove how they test and monitor models, rather than simply claim responsible behaviour. Practitioners should assume that governance will increasingly be judged by logs, reports, and escalation records.

A question worth separating out:

Q: Who is accountable when an AI agent causes a security incident?

A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.

👉 Read our full editorial: New York’s RAISE Act makes frontier AI transparency mandatory



   
ReplyQuote
Share: