NobleCloak
Governance Watch

NYDFS said its 2024 AI guidance adds no new rules

Author

Audrey

NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.

Date Published

What happened

On October 16, 2024, the New York Department of Financial Services issued an industry letter, "Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks." The letter is unusually clear about what it is not. In its own words, it does not impose any new requirements beyond the obligations already in DFS's cybersecurity regulation, 23 NYCRR Part 500. It is guidance — an explanation of how covered entities should use the Part 500 framework they already live under to assess and address the cybersecurity risks that AI introduces.

That "no new requirements" line is the honest headline, and we're going to hold onto it. But read to the vendor section, because that's where the guidance gets specific. NYDFS reminds covered entities that Part 500 already requires them to impose minimum cybersecurity safeguards and incident-notification obligations on third-party service providers — and it goes further, "strongly" recommending that third-party diligence include the AI-related risks a provider poses, and encouraging covered entities to obtain additional representations and warranties concerning the secure use of their nonpublic information. In plain terms: no new rule, and also — put AI-specific reps and warranties in your vendor contracts.

Both statements are the regulator's. Neither cancels the other. (NYDFS has since kept the drumbeat going, issuing further guidance in 2026 on cybersecurity risks associated with frontier AI models — the direction of travel is not subtle.)

Why it matters

This is the exact pattern we keep flagging across Governance Watch, and NYDFS states it more cleanly than anyone: the obligation is inherited, not invented. A regulator can tell you truthfully that it has issued no new requirement and, in the same document, tell you what it now expects you to do — because the "new expectation" is just an existing rule (here, Part 500's third-party service-provider provisions) applied to a new fact pattern (your vendors using AI).

For a compliance owner, that changes how you argue. You cannot say "there's no AI vendor rule, so this is optional." NYDFS pre-empted that: the rule is Part 500's vendor-oversight requirement, which already exists, and the guidance simply tells you it reaches your vendors' AI. "No new requirement" is not "no requirement." It's "the requirement was already yours."

And the specific ask — AI reps and warranties in vendor contracts — is a tell. NYDFS didn't recommend you build AI models or audit your vendors' algorithms. It recommended you get contractual commitments about how vendors handle your nonpublic information when AI is in the loop, and that you diligence the AI risk they carry. That's a third-party-risk-management instruction wearing an AI hat. It's the same muscle you already use for SOC 2 attestations and breach-notification clauses, pointed at a new surface.

What it means for you

If you're a credit union or community bank: NYDFS Part 500 binds NY-chartered and NY-licensed financial-services entities, so unless you're one, this letter is not literally your rule. But its logic is portable, and your own regulators reason the same way. The take-home is the contract move: when a vendor adds AI, your existing vendor-oversight duty already covers it, and the cleanest evidence is contractual. Ask for reps and warranties on how the vendor's AI handles your members' nonpublic information, and diligence the AI-specific risk before you renew. This slots directly into the NCUA-side vendor file described in why NCUA can't examine your AI vendors — where the whole diligence burden lands on you by structural design.

If you're an RIA or broker-dealer: the parallel is almost one-to-one. Reg S-P gives you a written service-provider-oversight obligation that is now live for the whole covered market, and NYDFS just modeled what "good" looks like on the AI dimension: diligence the vendor's AI risk, and get contractual reps and warranties about their handling of your nonpublic information. If you're a NY-licensed entity you may owe Part 500 directly; either way, borrow the vendor-contract language. Concrete Monday move: add two clauses to your standard vendor agreement — an AI-use representation and a warranty on secure handling of nonpublic information when AI processes it — and log both in your oversight file. The Reg S-P oversight playbook shows where they go.

For everyone: the reps-and-warranties recommendation is the rare regulatory suggestion that is cheap to implement and expensive to skip. Contract language costs a redline. Explaining to an examiner why you never asked your AI-enabled vendors for any AI commitments costs a lot more.

How to get ahead of it

The prepared institution does what NYDFS spelled out, ahead of being asked:

  1. Diligence AI risk as part of routine vendor review. When a provider uses or adds AI, ask what it does with your nonpublic information, what models and subprocessors are involved, and how incidents get reported. Fold it into the review you already run — the questions are in the diligence questions that actually matter.
  2. Put AI reps and warranties in the contract. A representation that the vendor's AI use complies with applicable law and its own policies; a warranty on secure handling of your nonpublic information; and confirmation that Part-500-style safeguards and breach-notification duties extend to AI-driven services.
  3. Keep the evidence current. A rep signed in 2024 doesn't describe a vendor that shipped three new AI features in 2026. Vendor AI drifts; your file has to keep up — the case for that is in point-in-time vs. continuous monitoring.

Do those three, and the next time a regulator "clarifies that existing rules cover AI vendors," you're already holding the artifacts.

What to watch out for

The trap here is reading "imposes no new requirements" as "safe to ignore." That's the sentence that gets quoted in the exam finding — right before the examiner points at the Part 500 vendor-oversight rule the guidance was interpreting. "No new rule" describes the guidance, not your obligation. The obligation was already on the books.

The opposite overreaction is real too: treating an AI-vendor-diligence recommendation as a mandate to audit your vendors' models or stand up a governance program built for a global bank. NYDFS asked for proportionate diligence and contractual commitments — not a model-validation lab. And skip any vendor selling "NYDFS AI compliance" as a certificate; there's nothing to be certified against, because the letter added no new requirement. What helps is the boring, real work: diligence, contract language, and a current file.

The bottom line

NYDFS told the truth twice in one letter — no new rules, and get AI reps and warranties from your vendors — and both are true because the obligation was inherited from Part 500 all along. The move is contractual and cheap: diligence your vendors' AI, put the commitments in writing, and keep the file current. Assembling that vendor file — what each provider's AI does with your data, and what they've committed to in writing — is exactly what a Discover scan is built to surface.

Request your Discover scan. We run it with you.