LBD01361-01-5
A. 768 2
(B) SHALL NOT INCLUDE:
(I) THE OFFER, LICENSE, OR USE OF A HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM BY A DEVELOPER OR DEPLOYER FOR THE SOLE PURPOSE OF:
(A) SUCH DEVELOPER'S OR DEPLOYER'S SELF-TESTING TO IDENTIFY, MITIGATE,
OR PREVENT DISCRIMINATION OR OTHERWISE ENSURE COMPLIANCE WITH STATE AND
FEDERAL LAW; OR
(B) EXPANDING AN APPLICANT, CUSTOMER, OR PARTICIPANT POOL TO INCREASE
DIVERSITY OR REDRESS HISTORIC DISCRIMINATION; OR
(II) AN ACT OR OMISSION BY OR ON BEHALF OF A PRIVATE CLUB OR OTHER
ESTABLISHMENT NOT OPEN TO THE GENERAL PUBLIC, AS SET FORTH IN TITLE II
OF THE CIVIL RIGHTS ACT OF 1964, 42 U.S.C. § 2000A(E), AS AMENDED.
2. "ARTIFICIAL INTELLIGENCE DECISION SYSTEM" SHALL MEAN ANY COMPUTA-
TIONAL PROCESS, DERIVED FROM MACHINE LEARNING, STATISTICAL MODELING,
DATA ANALYTICS, OR ARTIFICIAL INTELLIGENCE, THAT ISSUES SIMPLIFIED
OUTPUT, INCLUDING ANY CONTENT, DECISION, PREDICTION, OR RECOMMENDATION,
THAT IS USED TO SUBSTANTIALLY ASSIST OR REPLACE DISCRETIONARY DECISION
MAKING FOR MAKING CONSEQUENTIAL DECISIONS THAT IMPACT CONSUMERS.
3. "BIAS AND GOVERNANCE AUDIT" MEANS AN IMPARTIAL EVALUATION BY AN
INDEPENDENT AUDITOR, WHICH SHALL INCLUDE, AT A MINIMUM, THE TESTING OF
AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM TO ASSESS SUCH SYSTEM'S
DISPARATE IMPACT ON EMPLOYEES BECAUSE OF SUCH EMPLOYEE'S AGE, RACE,
CREED, COLOR, ETHNICITY, NATIONAL ORIGIN, DISABILITY, CITIZENSHIP OR
IMMIGRATION STATUS, MARITAL OR FAMILIAL STATUS, MILITARY STATUS, RELI-
GION, OR SEX, INCLUDING SEXUAL ORIENTATION, GENDER IDENTITY, GENDER
EXPRESSION, PREGNANCY, PREGNANCY OUTCOMES, AND REPRODUCTIVE HEALTHCARE
CHOICES.
4. "CONSEQUENTIAL DECISION" SHALL MEAN ANY DECISION THAT HAS A MATERI-
AL LEGAL OR SIMILARLY SIGNIFICANT EFFECT ON THE PROVISION OR DENIAL TO
ANY CONSUMER OF, OR THE COST OR TERMS OF, ANY:
(A) EDUCATION ENROLLMENT OR EDUCATION OPPORTUNITY;
(B) EMPLOYMENT OR EMPLOYMENT OPPORTUNITY;
(C) FINANCIAL OR LENDING SERVICE;
(D) ESSENTIAL GOVERNMENT SERVICE;
(E) HEALTH CARE SERVICE, AS DEFINED IN SECTION 42 U.S.C. § 324(D)(2),
AS AMENDED;
(F) HOUSING OR HOUSING OPPORTUNITY;
(G) INSURANCE; OR
(H) LEGAL SERVICE.
5. "CONSUMER" SHALL MEAN ANY NEW YORK STATE RESIDENT.
6. "DEPLOY" SHALL MEAN TO USE A HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM.
7. "DEPLOYER" SHALL MEAN ANY PERSON DOING BUSINESS IN THIS STATE THAT
DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
8. "DEVELOPER" SHALL MEAN ANY PERSON DOING BUSINESS IN THIS STATE THAT
DEVELOPS, OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES, AN ARTIFICIAL
INTELLIGENCE DECISION SYSTEM.
9. "GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL":
(A) SHALL MEAN ANY FORM OF ARTIFICIAL INTELLIGENCE DECISION SYSTEM
THAT:
(I) DISPLAYS SIGNIFICANT GENERALITY;
(II) IS CAPABLE OF COMPETENTLY PERFORMING A WIDE RANGE OF DISTINCT
TASKS; AND
(III) CAN BE INTEGRATED INTO A VARIETY OF DOWNSTREAM APPLICATIONS OR
SYSTEMS; AND
A. 768 3
(B) SHALL NOT INCLUDE ANY ARTIFICIAL INTELLIGENCE MODEL THAT IS USED
FOR DEVELOPMENT, PROTOTYPING, AND RESEARCH ACTIVITIES BEFORE SUCH ARTI-
FICIAL INTELLIGENCE MODEL IS RELEASED ON THE MARKET.
10. "HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM":
(A) SHALL MEAN ANY ARTIFICIAL INTELLIGENCE DECISION SYSTEM THAT, WHEN
DEPLOYED, MAKES, OR IS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL
DECISION; AND
(B) SHALL NOT INCLUDE:
(I) ANY ARTIFICIAL INTELLIGENCE DECISION SYSTEM THAT IS INTENDED TO:
(A) PERFORM ANY NARROW PROCEDURAL TASK; OR
(B) DETECT DECISION-MAKING PATTERNS, OR DEVIATIONS FROM DECISION-MAK-
ING PATTERNS, UNLESS SUCH ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS
INTENDED TO REPLACE OR INFLUENCE ANY ASSESSMENT PREVIOUSLY COMPLETED BY
AN INDIVIDUAL WITHOUT SUFFICIENT HUMAN REVIEW; OR
(II) UNLESS THE TECHNOLOGY, WHEN DEPLOYED, MAKES, OR IS A SUBSTANTIAL
FACTOR IN MAKING, A CONSEQUENTIAL DECISION:
(A) ANY ANTI-FRAUD TECHNOLOGY THAT DOES NOT MAKE USE OF FACIAL RECOG-
NITION TECHNOLOGY;
(B) ANY ARTIFICIAL INTELLIGENCE-ENABLED VIDEO GAME TECHNOLOGY;
(C) ANY ANTI-MALWARE, ANTI-VIRUS, CALCULATOR, CYBERSECURITY, DATABASE,
DATA STORAGE, FIREWALL, INTERNET DOMAIN REGISTRATION, INTERNET-WEB-SITE
LOADING, NETWORKING, ROBOCALL-FILTERING, SPAM-FILTERING, SPELLCHECKING,
SPREADSHEET, WEB-CACHING, WEB-HOSTING, OR SIMILAR TECHNOLOGY;
(D) ANY TECHNOLOGY THAT PERFORMS TASKS EXCLUSIVELY RELATED TO AN ENTI-
TY'S INTERNAL MANAGEMENT AFFAIRS, INCLUDING, BUT NOT LIMITED TO, ORDER-
ING OFFICE SUPPLIES OR PROCESSING PAYMENTS; OR
(E) ANY TECHNOLOGY THAT COMMUNICATES WITH CONSUMERS IN NATURAL
LANGUAGE FOR THE PURPOSE OF PROVIDING CONSUMERS WITH INFORMATION, MAKING
REFERRALS OR RECOMMENDATIONS, AND ANSWERING QUESTIONS, AND IS SUBJECT TO
AN ACCEPTED USE POLICY THAT PROHIBITS GENERATING CONTENT THAT IS DISCRI-
MINATORY OR HARMFUL.
11. "INTENTIONAL AND SUBSTANTIAL MODIFICATION":
(A) SHALL MEAN ANY DELIBERATE CHANGE MADE TO:
(I) AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM THAT RESULTS IN ANY NEW
REASONABLY FORESEEABLE RISK OF ALGORITHMIC DISCRIMINATION; OR
(II) A GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL THAT:
(A) AFFECTS COMPLIANCE OF THE GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE
MODEL;
(B) MATERIALLY CHANGES THE PURPOSE OF THE GENERAL-PURPOSE ARTIFICIAL
INTELLIGENCE MODEL; OR
(C) RESULTS IN ANY NEW REASONABLY FORESEEABLE RISK OF ALGORITHMIC
DISCRIMINATION; AND
(B) SHALL NOT INCLUDE ANY CHANGE MADE TO A HIGH-RISK ARTIFICIAL INTEL-
LIGENCE DECISION SYSTEM, OR THE PERFORMANCE OF A HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM, IF:
(I) THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM CONTINUES TO
LEARN AFTER SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS:
(A) OFFERED, SOLD, LEASED, LICENSED, GIVEN OR OTHERWISE MADE AVAILABLE
TO A DEPLOYER; OR
(B) DEPLOYED; AND
(II) SUCH CHANGE:
(A) IS MADE TO SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM
AS A RESULT OF ANY LEARNING DESCRIBED IN SUBPARAGRAPH (I) OF THIS PARA-
GRAPH;
(B) WAS PREDETERMINED BY THE DEPLOYER, OR THE THIRD PARTY CONTRACTED
BY THE DEPLOYER, WHEN SUCH DEPLOYER OR THIRD PARTY COMPLETED THE INITIAL
A. 768 4
IMPACT ASSESSMENT OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM PURSUANT TO SUBDIVISION THREE OF SECTION ONE THOUSAND FIVE
HUNDRED FIFTY-TWO OF THIS ARTICLE; AND
(C) IS INCLUDED IN THE TECHNICAL DOCUMENTATION FOR SUCH HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
12. "PERSON" SHALL MEAN ANY INDIVIDUAL, ASSOCIATION, CORPORATION,
LIMITED LIABILITY COMPANY, PARTNERSHIP, TRUST OR OTHER LEGAL ENTITY
AUTHORIZED TO DO BUSINESS IN THIS STATE.
13. "RED-TEAMING" SHALL MEAN AN EXERCISE THAT IS CONDUCTED TO IDENTIFY
THE POTENTIAL ADVERSE BEHAVIORS OR OUTCOMES OF AN ARTIFICIAL INTELLI-
GENCE DECISION SYSTEM AND HOW SUCH BEHAVIORS OR OUTCOMES OCCUR, AND
STRESS TEST THE SAFEGUARDS AGAINST SUCH ADVERSE BEHAVIORS OR OUTCOMES.
14. "SUBSTANTIAL FACTOR":
(A) SHALL MEAN A FACTOR THAT:
(I) ASSISTS IN MAKING A CONSEQUENTIAL DECISION;
(II) IS CAPABLE OF ALTERING THE OUTCOME OF A CONSEQUENTIAL DECISION;
AND
(III) IS GENERATED BY AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM; AND
(B) INCLUDES, BUT IS NOT LIMITED TO, ANY USE OF AN ARTIFICIAL INTELLI-
GENCE DECISION SYSTEM TO GENERATE ANY CONTENT, DECISION, PREDICTION, OR
RECOMMENDATION CONCERNING A CONSUMER THAT IS USED AS A BASIS TO MAKE A
CONSEQUENTIAL DECISION CONCERNING SUCH CONSUMER.
15. "SYNTHETIC DIGITAL CONTENT" SHALL MEAN ANY DIGITAL CONTENT,
INCLUDING, BUT NOT LIMITED TO, ANY AUDIO, IMAGE, TEXT, OR VIDEO, THAT IS
PRODUCED OR MANIPULATED BY AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM,
INCLUDING, BUT NOT LIMITED TO, A GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE
MODEL.
16. "TRADE SECRET" SHALL MEAN ANY FORM AND TYPE OF FINANCIAL, BUSI-
NESS, SCIENTIFIC, TECHNICAL, ECONOMIC, OR ENGINEERING INFORMATION,
INCLUDING, BUT NOT LIMITED TO, A PATTERN, PLAN, COMPILATION, PROGRAM
DEVICE, FORMULA, DESIGN, PROTOTYPE, METHOD, TECHNIQUE, PROCESS, PROCE-
DURE, PROGRAM, OR CODE, WHETHER TANGIBLE OR INTANGIBLE, AND WHETHER
STORED, COMPILED, OR MEMORIALIZED PHYSICALLY, ELECTRONICALLY, GRAPH-
ICALLY, PHOTOGRAPHICALLY, OR IN WRITING, THAT:
(A) DERIVES INDEPENDENT ECONOMIC VALUE, WHETHER ACTUAL OR POTENTIAL,
FROM NOT BEING GENERALLY KNOWN TO, OR READILY ASCERTAINABLE BY PROPER
MEANS BY, OTHER PERSONS WHO CAN OBTAIN ECONOMIC VALUE FROM ITS DISCLO-
SURE OR USE; AND
(B) IS THE SUBJECT OF EFFORTS THAT ARE REASONABLE UNDER THE CIRCUM-
STANCES TO MAINTAIN ITS SECRECY.
§ 1551. REQUIRED DOCUMENTATION. 1. (A) BEGINNING ON JANUARY FIRST, TWO
THOUSAND TWENTY-SEVEN, EACH DEVELOPER OF A HIGH-RISK ARTIFICIAL INTELLI-
GENCE DECISION SYSTEM SHALL USE REASONABLE CARE TO PROTECT CONSUMERS
FROM ANY KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMI-
NATION ARISING FROM THE INTENDED AND CONTRACTED USES OF A HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM. IN ANY ENFORCEMENT ACTION
BROUGHT ON OR AFTER SUCH DATE BY THE ATTORNEY GENERAL PURSUANT TO THIS
ARTICLE, THERE SHALL BE A REBUTTABLE PRESUMPTION THAT A DEVELOPER USED
REASONABLE CARE AS REQUIRED PURSUANT TO THIS SUBDIVISION IF:
(I) THE DEVELOPER COMPLIED WITH THE PROVISIONS OF THIS SECTION; AND
(II) AN INDEPENDENT THIRD PARTY IDENTIFIED BY THE ATTORNEY GENERAL
PURSUANT TO PARAGRAPH (B) OF THIS SUBDIVISION AND RETAINED BY THE DEVEL-
OPER COMPLETED BIAS AND GOVERNANCE AUDITS FOR THE HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM.
(B) NO LATER THAN JANUARY FIRST, TWO THOUSAND TWENTY-SIX, AND AT LEAST
ANNUALLY THEREAFTER, THE ATTORNEY GENERAL SHALL:
A. 768 5
(I) IDENTIFY INDEPENDENT THIRD PARTIES WHO, IN THE ATTORNEY GENERAL'S
OPINION, ARE QUALIFIED TO COMPLETE BIAS AND GOVERNANCE AUDITS FOR THE
PURPOSES OF SUBPARAGRAPH (II) OF PARAGRAPH (A) OF THIS SUBDIVISION; AND
(II) PUBLISH A LIST OF SUCH INDEPENDENT THIRD PARTIES AVAILABLE ON THE
ATTORNEY GENERAL'S WEBSITE.
2. BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND EXCEPT
AS PROVIDED IN SUBDIVISION FIVE OF THIS SECTION, A DEVELOPER OF A HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM SHALL MAKE AVAILABLE TO
EACH DEPLOYER OR OTHER DEVELOPER THE FOLLOWING INFORMATION:
(A) A GENERAL STATEMENT DESCRIBING THE REASONABLY FORESEEABLE USES,
AND THE KNOWN HARMFUL OR INAPPROPRIATE USES, OF SUCH HIGH-RISK ARTIFI-
CIAL INTELLIGENCE DECISION SYSTEM;
(B) DOCUMENTATION DISCLOSING:
(I) HIGH-LEVEL SUMMARIES OF THE TYPE OF DATA USED TO TRAIN SUCH HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM;
(II) THE KNOWN OR REASONABLY FORESEEABLE LIMITATIONS OF SUCH HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM, INCLUDING, BUT NOT LIMITED TO,
THE KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION
ARISING FROM THE INTENDED USES OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM;
(III) THE PURPOSE OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM;
(IV) THE INTENDED BENEFITS AND USES OF SUCH HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM; AND
(V) ANY OTHER INFORMATION NECESSARY TO ENABLE SUCH DEPLOYER OR OTHER
DEVELOPER TO COMPLY WITH THE PROVISIONS OF THIS ARTICLE;
(C) DOCUMENTATION DESCRIBING:
(I) HOW SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM WAS
EVALUATED FOR PERFORMANCE, AND MITIGATION OF ALGORITHMIC DISCRIMINATION,
BEFORE SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM WAS
OFFERED, SOLD, LEASED, LICENSED, GIVEN, OR OTHERWISE MADE AVAILABLE TO
SUCH DEPLOYER OR OTHER DEVELOPER;
(II) THE DATA GOVERNANCE MEASURES USED TO COVER THE TRAINING DATASETS
AND EXAMINE THE SUITABILITY OF DATA SOURCES, POSSIBLE BIASES, AND APPRO-
PRIATE MITIGATION;
(III) THE INTENDED OUTPUTS OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM;
(IV) THE MEASURES SUCH DEPLOYER OR OTHER DEVELOPER HAS TAKEN TO MITI-
GATE ANY KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMI-
NATION THAT MAY ARISE FROM DEPLOYMENT OF SUCH HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM; AND
(V) HOW SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM SHOULD
BE USED, NOT BE USED, AND BE MONITORED BY AN INDIVIDUAL WHEN SUCH HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS USED TO MAKE, OR AS A
SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION; AND
(D) ANY ADDITIONAL DOCUMENTATION THAT IS REASONABLY NECESSARY TO
ASSIST A DEPLOYER OR OTHER DEVELOPER TO:
(I) UNDERSTAND THE OUTPUTS OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM; AND
(II) MONITOR THE PERFORMANCE OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM FOR RISKS OF ALGORITHMIC DISCRIMINATION.
3. (A) EXCEPT AS PROVIDED IN SUBDIVISION FIVE OF THIS SECTION, ANY
DEVELOPER THAT, ON OR AFTER JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN,
OFFERS, SELLS, LEASES, LICENSES, GIVES, OR OTHERWISE MAKES AVAILABLE TO
A DEPLOYER OR OTHER DEVELOPER A HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM SHALL, TO THE EXTENT FEASIBLE, MAKE AVAILABLE TO SUCH
A. 768 6
DEPLOYERS AND OTHER DEVELOPERS THE DOCUMENTATION AND INFORMATION RELAT-
ING TO SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM NECESSARY
FOR A DEPLOYER, OR THE THIRD PARTY CONTRACTED BY A DEPLOYER, TO COMPLETE
AN IMPACT ASSESSMENT PURSUANT TO THIS ARTICLE. THE DEVELOPER SHALL MAKE
SUCH DOCUMENTATION AND INFORMATION AVAILABLE THROUGH ARTIFACTS SUCH AS
MODEL CARDS, DATASET CARDS, OR OTHER IMPACT ASSESSMENTS.
(B) A DEVELOPER THAT ALSO SERVES AS A DEPLOYER FOR ANY HIGH-RISK ARTI-
FICIAL INTELLIGENCE DECISION SYSTEM SHALL NOT BE REQUIRED TO GENERATE
THE DOCUMENTATION AND INFORMATION REQUIRED PURSUANT TO THIS SECTION
UNLESS SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS
PROVIDED TO AN UNAFFILIATED ENTITY ACTING AS A DEPLOYER.
4. (A) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, EACH
DEVELOPER SHALL PUBLISH, IN A MANNER THAT IS CLEAR AND READILY AVAIL-
ABLE, ON SUCH DEVELOPER'S WEBSITE, OR A PUBLIC USE CASE INVENTORY, A
STATEMENT SUMMARIZING:
(I) THE TYPES OF HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEMS
THAT SUCH DEVELOPER:
(A) HAS DEVELOPED OR INTENTIONALLY AND SUBSTANTIALLY MODIFIED; AND
(B) CURRENTLY MAKES AVAILABLE TO A DEPLOYER OR OTHER DEVELOPER; AND
(II) HOW SUCH DEVELOPER MANAGES ANY KNOWN OR REASONABLY FORESEEABLE
RISKS OF ALGORITHMIC DISCRIMINATION THAT MAY ARISE FROM THE DEVELOPMENT
OR INTENTIONAL AND SUBSTANTIAL MODIFICATION OF THE TYPES OF HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEMS DESCRIBED IN SUBPARAGRAPH (I)
OF THIS SUBDIVISION.
(B) EACH DEVELOPER SHALL UPDATE THE STATEMENT DESCRIBED IN PARAGRAPH
(A) OF THIS SUBDIVISION:
(I) AS NECESSARY TO ENSURE THAT SUCH STATEMENT REMAINS ACCURATE; AND
(II) NO LATER THAN NINETY DAYS AFTER THE DEVELOPER INTENTIONALLY AND
SUBSTANTIALLY MODIFIES ANY HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM DESCRIBED IN SUBPARAGRAPH (I) OF PARAGRAPH (A) OF THIS SUBDIVI-
SION.
5. NOTHING IN SUBDIVISIONS TWO OR FOUR OF THIS SECTION SHALL BE
CONSTRUED TO REQUIRE A DEVELOPER TO DISCLOSE ANY INFORMATION:
(A) THAT IS A TRADE SECRET OR OTHERWISE PROTECTED FROM DISCLOSURE
PURSUANT TO STATE OR FEDERAL LAW; OR
(B) THE DISCLOSURE OF WHICH WOULD PRESENT A SECURITY RISK TO SUCH
DEVELOPER.
6. BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, THE ATTORNEY
GENERAL MAY REQUIRE THAT A DEVELOPER DISCLOSE TO THE ATTORNEY GENERAL,
AS PART OF AN INVESTIGATION CONDUCTED BY THE ATTORNEY GENERAL AND IN A
FORM AND MANNER PRESCRIBED BY THE ATTORNEY GENERAL, THE GENERAL STATE-
MENT OR DOCUMENTATION DESCRIBED IN SUBDIVISION TWO OF THIS SECTION. THE
ATTORNEY GENERAL MAY EVALUATE SUCH GENERAL STATEMENT OR DOCUMENTATION TO
ENSURE COMPLIANCE WITH THE PROVISIONS OF THIS SECTION. IN DISCLOSING
SUCH GENERAL STATEMENT OR DOCUMENTATION TO THE ATTORNEY GENERAL PURSUANT
TO THIS SUBDIVISION, THE DEVELOPER MAY DESIGNATE SUCH GENERAL STATEMENT
OR DOCUMENTATION AS INCLUDING ANY INFORMATION THAT IS EXEMPT FROM
DISCLOSURE PURSUANT TO SUBDIVISION FIVE OF THIS SECTION OR ARTICLE SIX
OF THE PUBLIC OFFICERS LAW. TO THE EXTENT SUCH GENERAL STATEMENT OR
DOCUMENTATION INCLUDES SUCH INFORMATION, SUCH GENERAL STATEMENT OR
DOCUMENTATION SHALL BE EXEMPT FROM DISCLOSURE. TO THE EXTENT ANY INFOR-
MATION CONTAINED IN SUCH GENERAL STATEMENT OR DOCUMENTATION IS SUBJECT
TO THE ATTORNEY-CLIENT PRIVILEGE OR WORK PRODUCT PROTECTION, SUCH
DISCLOSURE SHALL NOT CONSTITUTE A WAIVER OF SUCH PRIVILEGE OR
PROTECTION.
A. 768 7
§ 1552. RISK MANAGEMENT. 1. (A) BEGINNING ON JANUARY FIRST, TWO THOU-
SAND TWENTY-SEVEN, EACH DEPLOYER OF A HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM SHALL USE REASONABLE CARE TO PROTECT CONSUMERS FROM ANY
KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION. IN
ANY ENFORCEMENT ACTION BROUGHT ON OR AFTER SAID DATE BY THE ATTORNEY
GENERAL PURSUANT TO THIS ARTICLE, THERE SHALL BE A REBUTTABLE PRESUMP-
TION THAT A DEPLOYER OF A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM USED REASONABLE CARE AS REQUIRED PURSUANT TO THIS SUBDIVISION IF:
(I) THE DEPLOYER COMPLIED WITH THE PROVISIONS OF THIS SECTION; AND
(II) AN INDEPENDENT THIRD PARTY IDENTIFIED BY THE ATTORNEY GENERAL
PURSUANT TO PARAGRAPH (B) OF THIS SUBDIVISION AND RETAINED BY THE
DEPLOYER COMPLETED BIAS AND GOVERNANCE AUDITS FOR THE HIGH-RISK ARTIFI-
CIAL INTELLIGENCE DECISION SYSTEM.
(B) NO LATER THAN JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND AT
LEAST ANNUALLY THEREAFTER, THE ATTORNEY GENERAL SHALL:
(I) IDENTIFY THE INDEPENDENT THIRD PARTIES WHO, IN THE ATTORNEY GENER-
AL'S OPINION, ARE QUALIFIED TO COMPLETE BIAS AND GOVERNANCE AUDITS FOR
THE PURPOSES OF SUBPARAGRAPH (II) OF PARAGRAPH (A) OF THIS SUBDIVISION;
AND
(II) MAKE A LIST OF SUCH INDEPENDENT THIRD PARTIES AVAILABLE ON THE
ATTORNEY GENERAL'S WEB SITE.
2. (A) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND
EXCEPT AS PROVIDED IN SUBDIVISION SEVEN OF THIS SECTION, EACH DEPLOYER
OF A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM SHALL IMPLEMENT
AND MAINTAIN A RISK MANAGEMENT POLICY AND PROGRAM TO GOVERN SUCH
DEPLOYER'S DEPLOYMENT OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM. THE RISK MANAGEMENT POLICY AND PROGRAM SHALL SPECIFY AND INCOR-
PORATE THE PRINCIPLES, PROCESSES, AND PERSONNEL THAT THE DEPLOYER SHALL
USE TO IDENTIFY, DOCUMENT, AND MITIGATE ANY KNOWN OR REASONABLY FORESEE-
ABLE RISKS OF ALGORITHMIC DISCRIMINATION. THE RISK MANAGEMENT POLICY
SHALL BE THE PRODUCT OF AN ITERATIVE PROCESS, THE RISK MANAGEMENT
PROGRAM SHALL BE AN ITERATIVE PROCESS AND BOTH THE RISK MANAGEMENT POLI-
CY AND PROGRAM SHALL BE PLANNED, IMPLEMENTED, AND REGULARLY AND SYSTEM-
ATICALLY REVIEWED AND UPDATED OVER THE LIFECYCLE OF THE HIGH-RISK ARTI-
FICIAL INTELLIGENCE DECISION SYSTEM. EACH RISK MANAGEMENT POLICY AND
PROGRAM IMPLEMENTED AND MAINTAINED PURSUANT TO THIS SUBDIVISION SHALL BE
REASONABLE, CONSIDERING:
(I) THE GUIDANCE AND STANDARDS SET FORTH IN THE LATEST VERSION OF:
(A) THE "ARTIFICIAL INTELLIGENCE RISK MANAGEMENT FRAMEWORK" PUBLISHED
BY THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY;
(B) ISO OR IEC 42001 OF THE INTERNATIONAL ORGANIZATION FOR STANDARDI-
ZATION; OR
(C) A NATIONALLY OR INTERNATIONALLY RECOGNIZED RISK MANAGEMENT FRAME-
WORK FOR ARTIFICIAL INTELLIGENCE DECISION SYSTEMS, OTHER THAN THE GUID-
ANCE AND STANDARDS SPECIFIED IN CLAUSES (A) AND (B) OF THIS SUBPARA-
GRAPH, THAT IMPOSES REQUIREMENTS THAT ARE SUBSTANTIALLY EQUIVALENT TO,
AND AT LEAST AS STRINGENT AS, THE REQUIREMENTS ESTABLISHED PURSUANT TO
THIS SECTION FOR RISK MANAGEMENT POLICIES AND PROGRAMS;
(II) THE SIZE AND COMPLEXITY OF THE DEPLOYER;
(III) THE NATURE AND SCOPE OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEMS DEPLOYED BY THE DEPLOYER, INCLUDING, BUT NOT LIMITED
TO, THE INTENDED USES OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEMS; AND
(IV) THE SENSITIVITY AND VOLUME OF DATA PROCESSED IN CONNECTION WITH
THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEMS DEPLOYED BY THE
DEPLOYER.
A. 768 8
(B) A RISK MANAGEMENT POLICY AND PROGRAM IMPLEMENTED AND MAINTAINED
PURSUANT TO PARAGRAPH (A) OF THIS SUBDIVISION MAY COVER MULTIPLE HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEMS DEPLOYED BY THE DEPLOYER.
3. (A) EXCEPT AS PROVIDED IN PARAGRAPHS (C) AND (D) OF THIS SUBDIVI-
SION AND SUBDIVISION SEVEN OF THIS SECTION:
(I) A DEPLOYER THAT DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM ON OR AFTER JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, OR A
THIRD PARTY CONTRACTED BY THE DEPLOYER, SHALL COMPLETE AN IMPACT ASSESS-
MENT OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM; AND
(II) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, A DEPLOY-
ER, OR A THIRD PARTY CONTRACTED BY THE DEPLOYER, SHALL COMPLETE AN
IMPACT ASSESSMENT OF A DEPLOYED HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM:
(A) AT LEAST ANNUALLY; AND
(B) NO LATER THAN NINETY DAYS AFTER AN INTENTIONAL AND SUBSTANTIAL
MODIFICATION TO SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM
IS MADE AVAILABLE.
(B) (I) EACH IMPACT ASSESSMENT COMPLETED PURSUANT TO THIS SUBDIVISION
SHALL INCLUDE, AT A MINIMUM AND TO THE EXTENT REASONABLY KNOWN BY, OR
AVAILABLE TO, THE DEPLOYER:
(A) A STATEMENT BY THE DEPLOYER DISCLOSING THE PURPOSE, INTENDED USE
CASES AND DEPLOYMENT CONTEXT OF, AND BENEFITS AFFORDED BY, THE HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM;
(B) AN ANALYSIS OF WHETHER THE DEPLOYMENT OF THE HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM POSES ANY KNOWN OR REASONABLY FORESEEABLE
RISKS OF ALGORITHMIC DISCRIMINATION AND, IF SO, THE NATURE OF SUCH ALGO-
RITHMIC DISCRIMINATION AND THE STEPS THAT HAVE BEEN TAKEN TO MITIGATE
SUCH RISKS;
(C) A DESCRIPTION OF:
(I) THE CATEGORIES OF DATA THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM PROCESSES AS INPUTS; AND
(II) THE OUTPUTS SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM PRODUCES;
(D) IF THE DEPLOYER USED DATA TO CUSTOMIZE THE HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM, AN OVERVIEW OF THE CATEGORIES OF DATA THE
DEPLOYER USED TO CUSTOMIZE SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM;
(E) ANY METRICS USED TO EVALUATE THE PERFORMANCE AND KNOWN LIMITATIONS
OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM;
(F) A DESCRIPTION OF ANY TRANSPARENCY MEASURES TAKEN CONCERNING THE
HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM, INCLUDING, BUT NOT
LIMITED TO, ANY MEASURES TAKEN TO DISCLOSE TO A CONSUMER THAT SUCH HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS IN USE WHEN SUCH HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS IN USE; AND
(G) A DESCRIPTION OF THE POST-DEPLOYMENT MONITORING AND USER SAFE-
GUARDS PROVIDED CONCERNING SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEM, INCLUDING, BUT NOT LIMITED TO, THE OVERSIGHT, USE, AND
LEARNING PROCESS ESTABLISHED BY THE DEPLOYER TO ADDRESS ISSUES ARISING
FROM DEPLOYMENT OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM.
(II) IN ADDITION TO THE STATEMENT, ANALYSIS, DESCRIPTIONS, OVERVIEW,
AND METRICS REQUIRED PURSUANT TO SUBPARAGRAPH (I) OF THIS PARAGRAPH, AN
IMPACT ASSESSMENT COMPLETED PURSUANT TO THIS SUBDIVISION FOLLOWING AN
INTENTIONAL AND SUBSTANTIAL MODIFICATION MADE TO A HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM ON OR AFTER JANUARY FIRST, TWO THOUSAND
TWENTY-SEVEN, SHALL INCLUDE A STATEMENT DISCLOSING THE EXTENT TO WHICH
A. 768 9
THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM WAS USED IN A
MANNER THAT WAS CONSISTENT WITH, OR VARIED FROM, THE DEVELOPER'S
INTENDED USES OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
(C) A SINGLE IMPACT ASSESSMENT MAY ADDRESS A COMPARABLE SET OF HIGH-
RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEMS DEPLOYED BY A DEPLOYER.
(D) IF A DEPLOYER, OR A THIRD PARTY CONTRACTED BY THE DEPLOYER,
COMPLETES AN IMPACT ASSESSMENT FOR THE PURPOSE OF COMPLYING WITH ANOTHER
APPLICABLE LAW OR REGULATION, SUCH IMPACT ASSESSMENT SHALL BE DEEMED TO
SATISFY THE REQUIREMENTS ESTABLISHED IN THIS SUBDIVISION IF SUCH IMPACT
ASSESSMENT IS REASONABLY SIMILAR IN SCOPE AND EFFECT TO THE IMPACT
ASSESSMENT THAT WOULD OTHERWISE BE COMPLETED PURSUANT TO THIS SUBDIVI-
SION.
(E) A DEPLOYER SHALL MAINTAIN THE MOST RECENTLY COMPLETED IMPACT
ASSESSMENT OF A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM AS
REQUIRED PURSUANT TO THIS SUBDIVISION, ALL RECORDS CONCERNING EACH SUCH
IMPACT ASSESSMENT AND ALL PRIOR IMPACT ASSESSMENTS, IF ANY, FOR A PERIOD
OF AT LEAST THREE YEARS FOLLOWING THE FINAL DEPLOYMENT OF THE HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
4. EXCEPT AS PROVIDED IN SUBDIVISION SEVEN OF THIS SECTION, A DEPLOY-
ER, OR A THIRD PARTY CONTRACTED BY THE DEPLOYER, SHALL REVIEW, NO LATER
THAN JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND AT LEAST ANNUALLY
THEREAFTER, THE DEPLOYMENT OF EACH HIGH-RISK ARTIFICIAL INTELLIGENCE
DECISION SYSTEM DEPLOYED BY THE DEPLOYER TO ENSURE THAT SUCH HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS NOT CAUSING ALGORITHMIC
DISCRIMINATION.
5. (A) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND
BEFORE A DEPLOYER DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM TO MAKE, OR BE A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL
DECISION CONCERNING A CONSUMER, THE DEPLOYER SHALL:
(I) NOTIFY THE CONSUMER THAT THE DEPLOYER HAS DEPLOYED A HIGH-RISK
ARTIFICIAL INTELLIGENCE DECISION SYSTEM TO MAKE, OR BE A SUBSTANTIAL
FACTOR IN MAKING, SUCH CONSEQUENTIAL DECISION; AND
(II) PROVIDE TO THE CONSUMER:
(A) A STATEMENT DISCLOSING:
(I) THE PURPOSE OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM; AND
(II) THE NATURE OF SUCH CONSEQUENTIAL DECISION;
(B) CONTACT INFORMATION FOR SUCH DEPLOYER;
(C) A DESCRIPTION, IN PLAIN LANGUAGE, OF SUCH HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM; AND
(D) INSTRUCTIONS ON HOW TO ACCESS THE STATEMENT MADE AVAILABLE PURSU-
ANT TO PARAGRAPH (A) OF SUBDIVISION SIX OF THIS SECTION.
(B) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, A DEPLOYER
THAT HAS DEPLOYED A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM TO
MAKE, OR AS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION
CONCERNING A CONSUMER SHALL, IF SUCH CONSEQUENTIAL DECISION IS ADVERSE
TO THE CONSUMER, PROVIDE TO SUCH CONSUMER:
(I) A STATEMENT DISCLOSING THE PRINCIPAL REASON OR REASONS FOR SUCH
ADVERSE CONSEQUENTIAL DECISION, INCLUDING, BUT NOT LIMITED TO:
(A) THE DEGREE TO WHICH, AND MANNER IN WHICH, THE HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM CONTRIBUTED TO SUCH ADVERSE CONSEQUENTIAL
DECISION;
(B) THE TYPE OF DATA THAT WAS PROCESSED BY SUCH HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM IN MAKING SUCH ADVERSE CONSEQUENTIAL DECI-
SION; AND
(C) THE SOURCE OF SUCH DATA; AND
A. 768 10
(II) AN OPPORTUNITY TO:
(A) CORRECT ANY INCORRECT PERSONAL DATA THAT THE HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM PROCESSED IN MAKING, OR AS A SUBSTANTIAL
FACTOR IN MAKING, SUCH ADVERSE CONSEQUENTIAL DECISION; AND
(B) APPEAL SUCH ADVERSE CONSEQUENTIAL DECISION, WHICH SHALL, IF TECH-
NICALLY FEASIBLE, ALLOW FOR HUMAN REVIEW UNLESS PROVIDING SUCH OPPORTU-
NITY IS NOT IN THE BEST INTEREST OF SUCH CONSUMER, INCLUDING, BUT NOT
LIMITED TO, IN INSTANCES IN WHICH ANY DELAY MIGHT POSE A RISK TO THE
LIFE OR SAFETY OF SUCH CONSUMER.
(C) THE DEPLOYER SHALL PROVIDE THE NOTICE, STATEMENTS, INFORMATION,
DESCRIPTION, AND INSTRUCTIONS REQUIRED PURSUANT TO PARAGRAPHS (A) AND
(B) OF THIS SUBDIVISION:
(I) DIRECTLY TO THE CONSUMER;
(II) IN PLAIN LANGUAGE;
(III) IN ALL LANGUAGES IN WHICH SUCH DEPLOYER, IN THE ORDINARY COURSE
OF SUCH DEPLOYER'S BUSINESS, PROVIDES CONTRACTS, DISCLAIMERS, SALE
ANNOUNCEMENTS, AND OTHER INFORMATION TO CONSUMERS; AND
(IV) IN A FORMAT THAT IS ACCESSIBLE TO CONSUMERS WITH DISABILITIES.
6. (A) BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND
EXCEPT AS PROVIDED IN SUBDIVISION SEVEN OF THIS SECTION, EACH DEPLOYER
SHALL MAKE AVAILABLE, IN A MANNER THAT IS CLEAR AND READILY AVAILABLE ON
SUCH DEPLOYER'S WEBSITE, A STATEMENT SUMMARIZING:
(I) THE TYPES OF HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEMS
THAT ARE CURRENTLY DEPLOYED BY SUCH DEPLOYER;
(II) HOW SUCH DEPLOYER MANAGES ANY KNOWN OR REASONABLY FORESEEABLE
RISKS OF ALGORITHMIC DISCRIMINATION THAT MAY ARISE FROM DEPLOYMENT OF
EACH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM DESCRIBED IN
SUBPARAGRAPH (I) OF THIS PARAGRAPH; AND
(III) IN DETAIL, THE NATURE, SOURCE AND EXTENT OF THE INFORMATION
COLLECTED AND USED BY SUCH DEPLOYER.
(B) EACH DEPLOYER SHALL PERIODICALLY UPDATE THE STATEMENT REQUIRED
PURSUANT TO PARAGRAPH (A) OF THIS SUBDIVISION.
7. THE PROVISIONS OF SUBDIVISIONS TWO, THREE, FOUR, AND SIX OF THIS
SECTION SHALL NOT APPLY TO A DEPLOYER IF, AT THE TIME THE DEPLOYER
DEPLOYS A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM, AND AT ALL
TIMES WHILE THE HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS
DEPLOYED:
(A) THE DEPLOYER:
(I) HAS ENTERED INTO A CONTRACT WITH THE DEVELOPER IN WHICH THE DEVEL-
OPER HAS AGREED TO ASSUME THE DEPLOYER'S DUTIES PURSUANT TO SUBDIVISIONS
TWO, THREE, FOUR, OR SIX OF THIS SECTION; AND
(II) DOES NOT EXCLUSIVELY USE SUCH DEPLOYER'S OWN DATA TO TRAIN SUCH
HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM;
(B) SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM:
(I) IS USED FOR THE INTENDED USES THAT ARE DISCLOSED TO SUCH DEPLOYER
PURSUANT TO SUBPARAGRAPH (IV) OF PARAGRAPH (B) OF SUBDIVISION TWO OF
SECTION ONE THOUSAND FIVE HUNDRED FIFTY-ONE OF THIS ARTICLE; AND
(II) CONTINUES LEARNING BASED ON A BROAD RANGE OF DATA SOURCES AND NOT
SOLELY BASED ON THE DEPLOYER'S OWN DATA; AND
(C) SUCH DEPLOYER MAKES AVAILABLE TO CONSUMERS ANY IMPACT ASSESSMENT
THAT:
(I) THE DEVELOPER OF SUCH HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEM HAS COMPLETED AND PROVIDED TO SUCH DEPLOYER; AND
(II) INCLUDES INFORMATION THAT IS SUBSTANTIALLY SIMILAR TO THE INFOR-
MATION INCLUDED IN THE STATEMENT, ANALYSIS, DESCRIPTIONS, OVERVIEW, AND
A. 768 11
METRICS REQUIRED PURSUANT TO SUBPARAGRAPH (I) OF PARAGRAPH (B) OF SUBDI-
VISION THREE OF THIS SECTION.
8. NOTHING IN THIS SUBDIVISION OR SUBDIVISIONS TWO, THREE, FOUR, FIVE,
OR SIX OF THIS SECTION SHALL BE CONSTRUED TO REQUIRE A DEPLOYER TO
DISCLOSE ANY INFORMATION THAT IS A TRADE SECRET OR OTHERWISE PROTECTED
FROM DISCLOSURE PURSUANT TO STATE OR FEDERAL LAW. IF A DEPLOYER WITH-
HOLDS ANY INFORMATION FROM A CONSUMER PURSUANT THIS SUBDIVISION, THE
DEPLOYER SHALL SEND NOTICE TO SUCH CONSUMER DISCLOSING:
(A) THAT THE DEPLOYER IS WITHHOLDING SUCH INFORMATION FROM SUCH
CONSUMER; AND
(B) THE BASIS FOR THE DEPLOYER'S DECISION TO WITHHOLD SUCH INFORMATION
FROM SUCH CONSUMER.
9. BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, THE ATTORNEY
GENERAL MAY REQUIRE THAT A DEPLOYER, OR A THIRD PARTY CONTRACTED BY THE
DEPLOYER PURSUANT TO SUBDIVISION THREE OF THIS SECTION, AS APPLICABLE,
DISCLOSE TO THE ATTORNEY GENERAL, AS PART OF AN INVESTIGATION CONDUCTED
BY THE ATTORNEY GENERAL, NO LATER THAN NINETY DAYS AFTER A REQUEST BY
THE ATTORNEY GENERAL, AND IN A FORM AND MANNER PRESCRIBED BY THE ATTOR-
NEY GENERAL, THE RISK MANAGEMENT POLICY IMPLEMENTED PURSUANT TO SUBDIVI-
SION TWO OF THIS SECTION, THE IMPACT ASSESSMENT COMPLETED PURSUANT TO
SUBDIVISION THREE OF THIS SECTION; OR RECORDS MAINTAINED PURSUANT TO
PARAGRAPH (E) OF SUBDIVISION THREE OF THIS SECTION. THE ATTORNEY GENERAL
MAY EVALUATE SUCH RISK MANAGEMENT POLICY, IMPACT ASSESSMENT OR RECORDS
TO ENSURE COMPLIANCE WITH THE PROVISIONS OF THIS SECTION. IN DISCLOSING
SUCH RISK MANAGEMENT POLICY, IMPACT ASSESSMENT OR RECORDS TO THE ATTOR-
NEY GENERAL PURSUANT TO THIS SUBDIVISION, THE DEPLOYER OR THIRD-PARTY
CONTRACTOR, AS APPLICABLE, MAY DESIGNATE SUCH RISK MANAGEMENT POLICY,
IMPACT ASSESSMENT OR RECORDS AS INCLUDING ANY INFORMATION THAT IS EXEMPT
FROM DISCLOSURE PURSUANT TO SUBDIVISION EIGHT OF THIS SECTION OR ARTICLE
SIX OF THE PUBLIC OFFICERS LAW. TO THE EXTENT SUCH RISK MANAGEMENT POLI-
CY, IMPACT ASSESSMENT, OR RECORDS INCLUDE SUCH INFORMATION, SUCH RISK
MANAGEMENT POLICY, IMPACT ASSESSMENT, OR RECORDS SHALL BE EXEMPT FROM
DISCLOSURE. TO THE EXTENT ANY INFORMATION CONTAINED IN SUCH RISK MANAGE-
MENT POLICY, IMPACT ASSESSMENT, OR RECORD IS SUBJECT TO THE ATTORNEY-
CLIENT PRIVILEGE OR WORK PRODUCT PROTECTION, SUCH DISCLOSURE SHALL NOT
CONSTITUTE A WAIVER OF SUCH PRIVILEGE OR PROTECTION.
§ 1553. TECHNICAL DOCUMENTATION. 1. BEGINNING ON JANUARY FIRST, TWO
THOUSAND TWENTY-SEVEN, EACH DEVELOPER OF A GENERAL-PURPOSE ARTIFICIAL
INTELLIGENCE MODEL SHALL, EXCEPT AS PROVIDED IN SUBDIVISION TWO OF THIS
SECTION:
(A) CREATE AND MAINTAIN TECHNICAL DOCUMENTATION FOR THE GENERAL-PUR-
POSE ARTIFICIAL INTELLIGENCE MODEL, WHICH SHALL:
(I) INCLUDE:
(A) THE TRAINING AND TESTING PROCESSES FOR SUCH GENERAL-PURPOSE ARTI-
FICIAL INTELLIGENCE MODEL; AND
(B) THE RESULTS OF AN EVALUATION OF SUCH GENERAL-PURPOSE ARTIFICIAL
INTELLIGENCE MODEL PERFORMED TO DETERMINE WHETHER SUCH GENERAL-PURPOSE
ARTIFICIAL INTELLIGENCE MODEL IS IN COMPLIANCE WITH THE PROVISIONS OF
THIS ARTICLE;
(II) INCLUDE, AS APPROPRIATE, CONSIDERING THE SIZE AND RISK PROFILE OF
SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL, AT LEAST:
(A) THE TASKS SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL IS
INTENDED TO PERFORM;
(B) THE TYPE AND NATURE OF ARTIFICIAL INTELLIGENCE DECISION SYSTEMS IN
WHICH SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL IS INTENDED TO
BE INTEGRATED;
A. 768 12
(C) ACCEPTABLE USE POLICIES FOR SUCH GENERAL-PURPOSE ARTIFICIAL INTEL-
LIGENCE MODEL;
(D) THE DATE SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL IS
RELEASED;
(E) THE METHODS BY WHICH SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE
MODEL IS DISTRIBUTED; AND
(F) THE MODALITY AND FORMAT OF INPUTS AND OUTPUTS FOR SUCH GENERAL-
PURPOSE ARTIFICIAL INTELLIGENCE MODEL; AND
(III) BE REVIEWED AND REVISED AT LEAST ANNUALLY, OR MORE FREQUENTLY,
AS NECESSARY TO MAINTAIN THE ACCURACY OF SUCH TECHNICAL DOCUMENTATION;
AND
(B) CREATE, IMPLEMENT, MAINTAIN AND MAKE AVAILABLE TO PERSONS THAT
INTEND TO INTEGRATE SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL
INTO SUCH PERSONS' ARTIFICIAL INTELLIGENCE DECISION SYSTEMS DOCUMENTA-
TION AND INFORMATION THAT:
(I) ENABLES SUCH PERSONS TO:
(A) UNDERSTAND THE CAPABILITIES AND LIMITATIONS OF SUCH GENERAL-PUR-
POSE ARTIFICIAL INTELLIGENCE MODEL; AND
(B) COMPLY WITH SUCH PERSONS' OBLIGATIONS PURSUANT TO THIS ARTICLE;
(II) DISCLOSES, AT A MINIMUM:
(A) THE TECHNICAL MEANS REQUIRED FOR SUCH GENERAL-PURPOSE ARTIFICIAL
INTELLIGENCE MODEL TO BE INTEGRATED INTO SUCH PERSONS' ARTIFICIAL INTEL-
LIGENCE DECISION SYSTEMS;
(B) THE INFORMATION LISTED IN SUBPARAGRAPH (II) OF PARAGRAPH (A) OF
THIS SUBDIVISION; AND
(III) EXCEPT AS PROVIDED IN SUBDIVISION TWO OF THIS SECTION, IS
REVIEWED AND REVISED AT LEAST ANNUALLY, OR MORE FREQUENTLY, AS NECESSARY
TO MAINTAIN THE ACCURACY OF SUCH DOCUMENTATION AND INFORMATION.
2. (A) THE PROVISIONS OF PARAGRAPH (A) AND SUBPARAGRAPH (III) OF PARA-
GRAPH (B) OF SUBDIVISION ONE OF THIS SECTION SHALL NOT APPLY TO A DEVEL-
OPER THAT DEVELOPS, OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES, A
GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL ON OR AFTER JANUARY FIRST,
TWO THOUSAND TWENTY-SEVEN, IF:
(I) (A) THE DEVELOPER RELEASES SUCH GENERAL-PURPOSE ARTIFICIAL INTEL-
LIGENCE MODEL UNDER A FREE AND OPEN-SOURCE LICENSE THAT ALLOWS FOR:
(I) ACCESS TO, AND MODIFICATION, DISTRIBUTION, AND USAGE OF, SUCH
GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL; AND
(II) THE PARAMETERS OF SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE
MODEL TO BE MADE PUBLICLY AVAILABLE PURSUANT TO CLAUSE (B) OF THIS
SUBPARAGRAPH; AND
(B) UNLESS SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL IS
DEPLOYED AS A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM, THE
PARAMETERS OF SUCH GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL,
INCLUDING, BUT NOT LIMITED TO, THE WEIGHTS AND INFORMATION CONCERNING
THE MODEL ARCHITECTURE AND MODEL USAGE FOR SUCH GENERAL-PURPOSE ARTIFI-
CIAL INTELLIGENCE MODEL, ARE MADE PUBLICLY AVAILABLE; OR
(II) THE GENERAL-PURPOSE ARTIFICIAL INTELLIGENCE MODEL IS:
(A) NOT OFFERED FOR SALE IN THE MARKET;
(B) NOT INTENDED TO INTERACT WITH CONSUMERS; AND
(C) SOLELY UTILIZED:
(I) FOR AN ENTITY'S INTERNAL PURPOSES; OR
(II) PURSUANT TO AN AGREEMENT BETWEEN MULTIPLE ENTITIES FOR SUCH ENTI-
TIES' INTERNAL PURPOSES.
(B) THE PROVISIONS OF THIS SECTION SHALL NOT APPLY TO A DEVELOPER THAT
DEVELOPS, OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES, A GENERAL-PURPOSE
ARTIFICIAL INTELLIGENCE MODEL ON OR AFTER JANUARY FIRST, TWO THOUSAND
A. 768 13
TWENTY-SEVEN, IF SUCH GENERAL PURPOSE ARTIFICIAL INTELLIGENCE MODEL
PERFORMS TASKS EXCLUSIVELY RELATED TO AN ENTITY'S INTERNAL MANAGEMENT
AFFAIRS, INCLUDING, BUT NOT LIMITED TO, ORDERING OFFICE SUPPLIES OR
PROCESSING PAYMENTS.
(C) A DEVELOPER THAT TAKES ANY ACTION UNDER AN EXEMPTION PURSUANT TO
PARAGRAPH (A) OR (B) OF THIS SUBDIVISION SHALL BEAR THE BURDEN OF DEMON-
STRATING THAT SUCH ACTION QUALIFIES FOR SUCH EXEMPTION.
(D) A DEVELOPER THAT IS EXEMPT PURSUANT TO SUBPARAGRAPH (II) OF PARA-
GRAPH (A) OF THIS SUBDIVISION SHALL ESTABLISH AND MAINTAIN AN ARTIFICIAL
INTELLIGENCE RISK MANAGEMENT FRAMEWORK, WHICH SHALL:
(I) BE THE PRODUCT OF AN ITERATIVE PROCESS AND ONGOING EFFORTS; AND
(II) INCLUDE, AT A MINIMUM:
(A) AN INTERNAL GOVERNANCE FUNCTION;
(B) A MAP FUNCTION THAT SHALL ESTABLISH THE CONTEXT TO FRAME RISKS;
(C) A RISK MANAGEMENT FUNCTION; AND
(D) A FUNCTION TO MEASURE IDENTIFIED RISKS BY ASSESSING, ANALYZING AND
TRACKING SUCH RISKS.
3. NOTHING IN SUBDIVISION ONE OF THIS SECTION SHALL BE CONSTRUED TO
REQUIRE A DEVELOPER TO DISCLOSE ANY INFORMATION THAT IS A TRADE SECRET
OR OTHERWISE PROTECTED FROM DISCLOSURE PURSUANT TO STATE OR FEDERAL LAW.
4. BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, THE ATTORNEY
GENERAL MAY REQUIRE THAT A DEVELOPER DISCLOSE TO THE ATTORNEY GENERAL,
AS PART OF AN INVESTIGATION CONDUCTED BY THE ATTORNEY GENERAL, NO LATER
THAN NINETY DAYS AFTER A REQUEST BY THE ATTORNEY GENERAL AND IN A FORM
AND MANNER PRESCRIBED BY THE ATTORNEY GENERAL, ANY DOCUMENTATION MAIN-
TAINED PURSUANT TO THIS SECTION. THE ATTORNEY GENERAL MAY EVALUATE SUCH
DOCUMENTATION TO ENSURE COMPLIANCE WITH THE PROVISIONS OF THIS SECTION.
IN DISCLOSING ANY DOCUMENTATION TO THE ATTORNEY GENERAL PURSUANT TO THIS
SUBDIVISION, THE DEVELOPER MAY DESIGNATE SUCH DOCUMENTATION AS INCLUDING
ANY INFORMATION THAT IS EXEMPT FROM DISCLOSURE PURSUANT TO SUBDIVISION
THREE OF THIS SECTION OR ARTICLE SIX OF THE PUBLIC OFFICERS LAW. TO THE
EXTENT SUCH DOCUMENTATION INCLUDES SUCH INFORMATION, SUCH DOCUMENTATION
SHALL BE EXEMPT FROM DISCLOSURE. TO THE EXTENT ANY INFORMATION CONTAINED
IN SUCH DOCUMENTATION IS SUBJECT TO THE ATTORNEY-CLIENT PRIVILEGE OR
WORK PRODUCT PROTECTION, SUCH DISCLOSURE SHALL NOT CONSTITUTE A WAIVER
OF SUCH PRIVILEGE OR PROTECTION.
§ 1554. REQUIRED DISCLOSURE. 1. BEGINNING ON JANUARY FIRST, TWO THOU-
SAND TWENTY-SEVEN, AND EXCEPT AS PROVIDED IN SUBDIVISION TWO OF THIS
SECTION, EACH PERSON DOING BUSINESS IN THIS STATE, INCLUDING, BUT NOT
LIMITED TO, EACH DEPLOYER THAT DEPLOYS, OFFERS, SELLS, LEASES, LICENSES,
GIVES, OR OTHERWISE MAKES AVAILABLE, AS APPLICABLE, ANY ARTIFICIAL
INTELLIGENCE DECISION SYSTEM THAT IS INTENDED TO INTERACT WITH CONSUMERS
SHALL ENSURE THAT IT IS DISCLOSED TO EACH CONSUMER WHO INTERACTS WITH
SUCH ARTIFICIAL INTELLIGENCE DECISION SYSTEM THAT SUCH CONSUMER IS
INTERACTING WITH AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
2. NO DISCLOSURE SHALL BE REQUIRED PURSUANT TO SUBDIVISION ONE OF THIS
SECTION UNDER CIRCUMSTANCES IN WHICH A REASONABLE PERSON WOULD DEEM IT
OBVIOUS THAT SUCH PERSON IS INTERACTING WITH AN ARTIFICIAL INTELLIGENCE
DECISION SYSTEM.
§ 1555. PREEMPTION. 1. NOTHING IN THIS ARTICLE SHALL BE CONSTRUED TO
RESTRICT A DEVELOPER'S, DEPLOYER'S, OR OTHER PERSON'S ABILITY TO:
(A) COMPLY WITH FEDERAL, STATE OR MUNICIPAL LAW;
(B) COMPLY WITH A CIVIL, CRIMINAL OR REGULATORY INQUIRY, INVESTI-
GATION, SUBPOENA, OR SUMMONS BY A FEDERAL, STATE, MUNICIPAL, OR OTHER
GOVERNMENTAL AUTHORITY;
A. 768 14
(C) COOPERATE WITH A LAW ENFORCEMENT AGENCY CONCERNING CONDUCT OR
ACTIVITY THAT THE DEVELOPER, DEPLOYER, OR OTHER PERSON REASONABLY AND IN
GOOD FAITH BELIEVES MAY VIOLATE FEDERAL, STATE, OR MUNICIPAL LAW;
(D) INVESTIGATE, ESTABLISH, EXERCISE, PREPARE FOR, OR DEFEND A LEGAL
CLAIM;
(E) TAKE IMMEDIATE STEPS TO PROTECT AN INTEREST THAT IS ESSENTIAL FOR
THE LIFE OR PHYSICAL SAFETY OF A CONSUMER OR ANOTHER INDIVIDUAL;
(F) (I) BY ANY MEANS OTHER THAN FACIAL RECOGNITION TECHNOLOGY,
PREVENT, DETECT, PROTECT AGAINST, OR RESPOND TO:
(A) A SECURITY INCIDENT;
(B) A MALICIOUS OR DECEPTIVE ACTIVITY; OR
(C) IDENTITY THEFT, FRAUD, HARASSMENT OR ANY OTHER ILLEGAL ACTIVITY;
(II) INVESTIGATE, REPORT, OR PROSECUTE THE PERSONS RESPONSIBLE FOR ANY
ACTION DESCRIBED IN SUBPARAGRAPH (I) OF THIS PARAGRAPH; OR
(III) PRESERVE THE INTEGRITY OR SECURITY OF SYSTEMS;
(G) ENGAGE IN PUBLIC OR PEER-REVIEWED SCIENTIFIC OR STATISTICAL
RESEARCH IN THE PUBLIC INTEREST THAT:
(I) ADHERES TO ALL OTHER APPLICABLE ETHICS AND PRIVACY LAWS; AND
(II) IS CONDUCTED IN ACCORDANCE WITH:
(A) PART FORTY-SIX OF TITLE FORTY-FIVE OF THE CODE OF FEDERAL REGU-
LATIONS, AS AMENDED; OR
(B) RELEVANT REQUIREMENTS ESTABLISHED BY THE FEDERAL FOOD AND DRUG
ADMINISTRATION;
(H) CONDUCT RESEARCH, TESTING, AND DEVELOPMENT ACTIVITIES REGARDING AN
ARTIFICIAL INTELLIGENCE DECISION SYSTEM OR MODEL, OTHER THAN TESTING
CONDUCTED PURSUANT TO REAL WORLD CONDITIONS, BEFORE SUCH ARTIFICIAL
INTELLIGENCE DECISION SYSTEM OR MODEL IS PLACED ON THE MARKET, DEPLOYED,
OR PUT INTO SERVICE, AS APPLICABLE;
(I) EFFECTUATE A PRODUCT RECALL;
(J) IDENTIFY AND REPAIR TECHNICAL ERRORS THAT IMPAIR EXISTING OR
INTENDED FUNCTIONALITY; OR
(K) ASSIST ANOTHER DEVELOPER, DEPLOYER, OR PERSON WITH ANY OF THE
OBLIGATIONS IMPOSED PURSUANT TO THIS ARTICLE.
2. THE OBLIGATIONS IMPOSED ON DEVELOPERS, DEPLOYERS, OR OTHER PERSONS
PURSUANT TO THIS ARTICLE SHALL NOT APPLY WHERE COMPLIANCE BY THE DEVEL-
OPER, DEPLOYER, OR OTHER PERSON WITH THE PROVISIONS OF THIS ARTICLE
WOULD VIOLATE AN EVIDENTIARY PRIVILEGE PURSUANT TO STATE LAW.
3. NOTHING IN THIS ARTICLE SHALL BE CONSTRUED TO IMPOSE ANY OBLIGATION
ON A DEVELOPER, DEPLOYER, OR OTHER PERSON THAT ADVERSELY AFFECTS THE
RIGHTS OR FREEDOMS OF ANY PERSON, INCLUDING, BUT NOT LIMITED TO, THE
RIGHTS OF ANY PERSON:
(A) TO FREEDOM OF SPEECH OR FREEDOM OF THE PRESS GUARANTEED IN:
(I) THE FIRST AMENDMENT TO THE UNITED STATES CONSTITUTION; AND
(II) SECTION EIGHT OF THE NEW YORK STATE CONSTITUTION; OR
(B) PURSUANT TO SECTION SEVENTY-NINE-H OF THE CIVIL RIGHTS LAW.
4. NOTHING IN THIS ARTICLE SHALL BE CONSTRUED TO APPLY TO ANY DEVELOP-
ER, DEPLOYER, OR OTHER PERSON:
(A) INSOFAR AS SUCH DEVELOPER, DEPLOYER OR OTHER PERSON DEVELOPS,
DEPLOYS, PUTS INTO SERVICE, OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES,
AS APPLICABLE, A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM:
(I) THAT HAS BEEN APPROVED, AUTHORIZED, CERTIFIED, CLEARED, DEVELOPED,
OR GRANTED BY:
(A) A FEDERAL AGENCY, INCLUDING, BUT NOT LIMITED TO, THE FEDERAL FOOD
AND DRUG ADMINISTRATION OR THE FEDERAL AVIATION ADMINISTRATION, ACTING
WITHIN THE SCOPE OF SUCH FEDERAL AGENCY'S AUTHORITY; OR
A. 768 15
(B) A REGULATED ENTITY SUBJECT TO SUPERVISION AND REGULATION BY THE
FEDERAL HOUSING FINANCE AGENCY; OR
(II) IN COMPLIANCE WITH STANDARDS THAT ARE:
(A) ESTABLISHED BY:
(I) ANY FEDERAL AGENCY, INCLUDING, BUT NOT LIMITED TO, THE FEDERAL
OFFICE OF THE NATIONAL COORDINATOR FOR HEALTH INFORMATION TECHNOLOGY; OR
(II) A REGULATED ENTITY SUBJECT TO SUPERVISION AND REGULATION BY THE
FEDERAL HOUSING FINANCE AGENCY; AND
(B) SUBSTANTIALLY EQUIVALENT TO, AND AT LEAST AS STRINGENT AS, THE
STANDARDS ESTABLISHED PURSUANT TO THIS ARTICLE;
(B) CONDUCTING RESEARCH TO SUPPORT AN APPLICATION:
(I) FOR APPROVAL OR CERTIFICATION FROM ANY FEDERAL AGENCY, INCLUDING,
BUT NOT LIMITED TO, THE FEDERAL FOOD AND DRUG ADMINISTRATION, THE FEDER-
AL AVIATION ADMINISTRATION, OR THE FEDERAL COMMUNICATIONS COMMISSION; OR
(II) THAT IS OTHERWISE SUBJECT TO REVIEW BY ANY FEDERAL AGENCY;
(C) PERFORMING WORK PURSUANT TO, OR IN CONNECTION WITH, A CONTRACT
WITH THE FEDERAL DEPARTMENT OF COMMERCE, THE FEDERAL DEPARTMENT OF
DEFENSE, OR THE NATIONAL AERONAUTICS AND SPACE ADMINISTRATION, UNLESS
SUCH DEVELOPER, DEPLOYER, OR OTHER PERSON IS PERFORMING SUCH WORK ON A
HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM THAT IS USED TO MAKE,
OR AS A SUBSTANTIAL FACTOR IN MAKING, A DECISION CONCERNING EMPLOYMENT
OR HOUSING; OR
(D) THAT IS A COVERED ENTITY, AS DEFINED BY THE HEALTH INSURANCE
PORTABILITY AND ACCOUNTABILITY ACT OF 1996 AND THE REGULATIONS PROMUL-
GATED THEREUNDER, AS AMENDED, AND PROVIDING HEALTH CARE RECOMMENDATIONS
THAT:
(I) ARE GENERATED BY AN ARTIFICIAL INTELLIGENCE DECISION SYSTEM;
(II) REQUIRE A HEALTH CARE PROVIDER TO TAKE ACTION TO IMPLEMENT SUCH
RECOMMENDATIONS; AND
(III) ARE NOT CONSIDERED TO BE HIGH RISK.
5. NOTHING IN THIS ARTICLE SHALL BE CONSTRUED TO APPLY TO ANY ARTIFI-
CIAL INTELLIGENCE DECISION SYSTEM THAT IS ACQUIRED BY OR FOR THE FEDERAL
GOVERNMENT OR ANY FEDERAL AGENCY OR DEPARTMENT, INCLUDING, BUT NOT
LIMITED TO, THE FEDERAL DEPARTMENT OF COMMERCE, THE FEDERAL DEPARTMENT
OF DEFENSE, OR THE NATIONAL AERONAUTICS AND SPACE ADMINISTRATION, UNLESS
SUCH ARTIFICIAL INTELLIGENCE DECISION SYSTEM IS A HIGH-RISK ARTIFICIAL
INTELLIGENCE DECISION SYSTEM THAT IS USED TO MAKE, OR AS A SUBSTANTIAL
FACTOR IN MAKING, A DECISION CONCERNING EMPLOYMENT OR HOUSING.
6. ANY INSURER, AS DEFINED BY SECTION FIVE HUNDRED ONE OF THE INSUR-
ANCE LAW, OR FRATERNAL BENEFIT SOCIETY, AS DEFINED BY SECTION FOUR THOU-
SAND FIVE HUNDRED ONE OF THE INSURANCE LAW, SHALL BE DEEMED TO BE IN
FULL COMPLIANCE WITH THE PROVISIONS OF THIS ARTICLE IF SUCH INSURER OR
FRATERNAL BENEFIT SOCIETY HAS IMPLEMENTED AND MAINTAINS A WRITTEN ARTI-
FICIAL INTELLIGENCE DECISION SYSTEMS PROGRAM IN ACCORDANCE WITH ALL
REQUIREMENTS ESTABLISHED BY THE SUPERINTENDENT OF FINANCIAL SERVICES.
7. (A) ANY BANK, OUT-OF-STATE BANK, NEW YORK CREDIT UNION, FEDERAL
CREDIT UNION, OR OUT-OF-STATE CREDIT UNION, OR ANY AFFILIATE OR SUBSID-
IARY THEREOF, SHALL BE DEEMED TO BE IN FULL COMPLIANCE WITH THE
PROVISIONS OF THIS ARTICLE IF SUCH BANK, OUT-OF-STATE BANK, NEW YORK
CREDIT UNION, FEDERAL CREDIT UNION, OUT-OF-STATE CREDIT UNION, AFFIL-
IATE, OR SUBSIDIARY IS SUBJECT TO EXAMINATION BY ANY STATE OR FEDERAL
PRUDENTIAL REGULATOR PURSUANT TO ANY PUBLISHED GUIDANCE OR REGULATIONS
THAT APPLY TO THE USE OF HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION
SYSTEMS, AND SUCH GUIDANCE OR REGULATIONS:
(I) IMPOSE REQUIREMENTS THAT ARE SUBSTANTIALLY EQUIVALENT TO, AND AT
LEAST AS STRINGENT AS, THE REQUIREMENTS OF THIS ARTICLE; AND
A. 768 16
(II) AT A MINIMUM, REQUIRE SUCH BANK, OUT-OF-STATE BANK, NEW YORK
CREDIT UNION, FEDERAL CREDIT UNION, OUT-OF-STATE CREDIT UNION, AFFIL-
IATE, OR SUBSIDIARY TO:
(A) REGULARLY AUDIT SUCH BANK'S, OUT-OF-STATE BANK'S, NEW YORK CREDIT
UNION'S, FEDERAL CREDIT UNION'S, OUT-OF-STATE CREDIT UNION'S, AFFIL-
IATE'S, OR SUBSIDIARY'S USE OF HIGH-RISK ARTIFICIAL INTELLIGENCE DECI-
SION SYSTEMS FOR COMPLIANCE WITH STATE AND FEDERAL ANTI-DISCRIMINATION
LAWS AND REGULATIONS APPLICABLE TO SUCH BANK, OUT-OF-STATE BANK, NEW
YORK CREDIT UNION, FEDERAL CREDIT UNION, OUT-OF-STATE CREDIT UNION,
AFFILIATE, OR SUBSIDIARY; AND
(B) MITIGATE ANY ALGORITHMIC DISCRIMINATION CAUSED BY THE USE OF A
HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM, OR ANY RISK OF ALGO-
RITHMIC DISCRIMINATION THAT IS REASONABLY FORESEEABLE AS A RESULT OF THE
USE OF A HIGH-RISK ARTIFICIAL INTELLIGENCE DECISION SYSTEM.
(B) FOR THE PURPOSES OF THIS SUBDIVISION, THE FOLLOWING TERMS SHALL
HAVE THE FOLLOWING MEANINGS:
(I) "AFFILIATE" SHALL HAVE THE SAME MEANING AS SET FORTH IN SECTION
NINE HUNDRED TWELVE OF THE BUSINESS CORPORATION LAW.
(II) "BANK" SHALL HAVE THE SAME MEANING AS SET FORTH IN SECTION TWO OF
THE BANKING LAW.
(III) "CREDIT UNION" SHALL HAVE THE SAME MEANING AS SET FORTH IN
SECTION TWO OF THE BANKING LAW.
(IV) "OUT-OF-STATE BANK" SHALL HAVE THE SAME MEANING AS SET FORTH IN
SECTION TWO HUNDRED TWENTY-TWO OF THE BANKING LAW.
(V) "SUBSIDIARY" SHALL HAVE THE SAME MEANING AS SET FORTH IN SECTION
ONE HUNDRED FORTY-ONE OF THE BANKING LAW.
8. IF A DEVELOPER, DEPLOYER, OR OTHER PERSON ENGAGES IN ANY ACTION
UNDER AN EXEMPTION PURSUANT TO SUBDIVISIONS ONE, TWO, THREE, FOUR, FIVE,
SIX, OR SEVEN OF THIS SECTION, THE DEVELOPER, DEPLOYER, OR OTHER PERSON
BEARS THE BURDEN OF DEMONSTRATING THAT SUCH ACTION QUALIFIES FOR SUCH
EXEMPTION.
§ 1556. ENFORCEMENT. 1. THE ATTORNEY GENERAL SHALL HAVE EXCLUSIVE
AUTHORITY TO ENFORCE THE PROVISIONS OF THIS ARTICLE.
2. EXCEPT AS PROVIDED IN SUBDIVISION SIX OF THIS SECTION, DURING THE
PERIOD BEGINNING ON JANUARY FIRST, TWO THOUSAND TWENTY-SEVEN, AND ENDING
ON JANUARY FIRST, TWO THOUSAND TWENTY-EIGHT, THE ATTORNEY GENERAL SHALL,
PRIOR TO INITIATING ANY ACTION FOR A VIOLATION OF THIS SECTION, ISSUE A
NOTICE OF VIOLATION TO THE DEVELOPER, DEPLOYER, OR OTHER PERSON IF THE
ATTORNEY GENERAL DETERMINES THAT IT IS POSSIBLE TO CURE SUCH VIOLATION.
IF THE DEVELOPER, DEPLOYER, OR OTHER PERSON FAILS TO CURE SUCH VIOLATION
WITHIN SIXTY DAYS AFTER RECEIPT OF SUCH NOTICE OF VIOLATION, THE ATTOR-
NEY GENERAL MAY BRING AN ACTION PURSUANT TO THIS SECTION.
3. EXCEPT AS PROVIDED IN SUBDIVISION SIX OF THIS SECTION, BEGINNING ON
JANUARY FIRST, TWO THOUSAND TWENTY-EIGHT, THE ATTORNEY GENERAL MAY, IN
DETERMINING WHETHER TO GRANT A DEVELOPER, DEPLOYER, OR OTHER PERSON THE
OPPORTUNITY TO CURE A VIOLATION DESCRIBED IN SUBDIVISION TWO OF THIS
SECTION, CONSIDER:
(A) THE NUMBER OF VIOLATIONS;
(B) THE SIZE AND COMPLEXITY OF THE DEVELOPER, DEPLOYER, OR OTHER
PERSON;
(C) THE NATURE AND EXTENT OF THE DEVELOPER'S, DEPLOYER'S, OR OTHER
PERSON'S BUSINESS;
(D) THE SUBSTANTIAL LIKELIHOOD OF INJURY TO THE PUBLIC;
(E) THE SAFETY OF PERSONS OR PROPERTY; AND
(F) WHETHER SUCH VIOLATION WAS LIKELY CAUSED BY HUMAN OR TECHNICAL
ERROR.
A. 768 17
4. NOTHING IN THIS ARTICLE SHALL BE CONSTRUED AS PROVIDING THE BASIS
FOR A PRIVATE RIGHT OF ACTION FOR VIOLATIONS OF THE PROVISIONS OF THIS
ARTICLE.
5. EXCEPT AS PROVIDED IN SUBDIVISIONS ONE, TWO, THREE, FOUR, AND SIX
OF THIS SECTION, A VIOLATION OF THE REQUIREMENTS ESTABLISHED IN THIS
ARTICLE SHALL CONSTITUTE AN UNFAIR TRADE PRACTICE FOR PURPOSES OF
SECTION THREE HUNDRED FORTY-NINE OF THIS CHAPTER AND SHALL BE ENFORCED
SOLELY BY THE ATTORNEY GENERAL; PROVIDED, HOWEVER, THAT SUBDIVISION (H)
OF SECTION THREE HUNDRED FORTY-NINE OF THIS CHAPTER SHALL NOT APPLY TO
ANY SUCH VIOLATION.
6. (A) IN ANY ACTION COMMENCED BY THE ATTORNEY GENERAL FOR ANY
VIOLATION OF THIS ARTICLE, IT SHALL BE AN AFFIRMATIVE DEFENSE THAT THE
DEVELOPER, DEPLOYER, OR OTHER PERSON:
(I) DISCOVERS A VIOLATION OF ANY PROVISION OF THIS ARTICLE THROUGH
RED-TEAMING;
(II) NO LATER THAN SIXTY DAYS AFTER DISCOVERING SUCH VIOLATION THROUGH
RED-TEAMING:
(A) CURES SUCH VIOLATION; AND
(B) PROVIDES TO THE ATTORNEY GENERAL, IN A FORM AND MANNER PRESCRIBED
BY THE ATTORNEY GENERAL, NOTICE THAT SUCH VIOLATION HAS BEEN CURED AND
EVIDENCE THAT ANY HARM CAUSED BY SUCH VIOLATION HAS BEEN MITIGATED; AND
(III) IS OTHERWISE IN COMPLIANCE WITH THE LATEST VERSION OF:
(A) THE ARTIFICIAL INTELLIGENCE RISK MANAGEMENT FRAMEWORK PUBLISHED BY
THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY;
(B) ISO/IEC 42001 OF THE INTERNATIONAL ORGANIZATION FOR STANDARDI-
ZATION AND THE INTERNATIONAL ELECTROTECHNICAL COMMISSION;
(C) A NATIONALLY OR INTERNATIONALLY RECOGNIZED RISK MANAGEMENT FRAME-
WORK FOR ARTIFICIAL INTELLIGENCE DECISION SYSTEMS, OTHER THAN THE RISK
MANAGEMENT FRAMEWORKS DESCRIBED IN CLAUSES (A) AND (B) OF THIS SUBPARA-
GRAPH, THAT IMPOSES REQUIREMENTS THAT ARE SUBSTANTIALLY EQUIVALENT TO,
AND AT LEAST AS STRINGENT AS, THE REQUIREMENTS ESTABLISHED PURSUANT TO
THIS ARTICLE; OR
(D) ANY RISK MANAGEMENT FRAMEWORK FOR ARTIFICIAL INTELLIGENCE DECISION
SYSTEMS THAT IS SUBSTANTIALLY EQUIVALENT TO, AND AT LEAST AS STRINGENT
AS, THE RISK MANAGEMENT FRAMEWORKS DESCRIBED IN CLAUSES (A), (B), AND
(C) OF THIS SUBPARAGRAPH.
(B) THE DEVELOPER, DEPLOYER, OR OTHER PERSON BEARS THE BURDEN OF
DEMONSTRATING TO THE ATTORNEY GENERAL THAT THE REQUIREMENTS ESTABLISHED
PURSUANT TO PARAGRAPH (A) OF THIS SUBDIVISION HAVE BEEN SATISFIED.
(C) NOTHING IN THIS ARTICLE, INCLUDING, BUT NOT LIMITED TO, THE
ENFORCEMENT AUTHORITY GRANTED TO THE ATTORNEY GENERAL PURSUANT TO THIS
SECTION, SHALL BE CONSTRUED TO PREEMPT OR OTHERWISE AFFECT ANY RIGHT,
CLAIM, REMEDY, PRESUMPTION, OR DEFENSE AVAILABLE AT LAW OR IN EQUITY.
ANY REBUTTABLE PRESUMPTION OR AFFIRMATIVE DEFENSE ESTABLISHED PURSUANT
TO THIS ARTICLE SHALL APPLY ONLY TO AN ENFORCEMENT ACTION BROUGHT BY THE
ATTORNEY GENERAL PURSUANT TO THIS SECTION AND SHALL NOT APPLY TO ANY
RIGHT, CLAIM, REMEDY, PRESUMPTION, OR DEFENSE AVAILABLE AT LAW OR IN
EQUITY.
§ 3. This act shall take effect on the two hundred seventieth day
after it shall have become a law.