New York City's Council wants to be the first local government in the country to require a human override switch on every AI system sold or deployed within its own borders. Speaker Julie Menin unveiled a ten-bill package on Sept. 25 that would bar any business from marketing, offering for sale, or deploying an AI system in New York City without independent third-party validation covering data quality, bias, decision outputs, data privacy, and security -- and would require every validated system to carry "a human override that can shut down the system." A business or a validator that skips the process, or falsifies a validation, faces a $25,000 penalty per instance.
That's Introduction 2602, and it's the anchor of a package that runs to nine more bills. Introduction 2605 would create what Menin's office calls a first-in-the-nation whistleblower bounty -- a share of any fine the city recovers from a violating AI company paid to the person who reported it -- though the press release doesn't specify the percentage, leaving the incentive's real size an open question until bill text is published. A private-right-of-action bill from Council Member Virginia Maloney (Introduction 2600) would let New Yorkers sue an AI developer directly when a foreseeable harm occurs, the company failed to build reasonable safeguards, and a third party exploited that failure -- a three-part test modeled on ordinary product-liability reasoning rather than anything AI-specific. A fourth bill from Majority Whip Kamilah Hanks would require city contractors to report AI safety incidents to the Office of Cyber Command within 24 hours, with Cyber Command required to disclose them publicly within another 24.
What each number in the package actually triggers
- $25,000 · per instance
- Penalty for deploying, selling, or marketing an unvalidated AI system, or falsifying a validation
Includes: Both the business and the third-party validator, charged separately
Excludes: Any cap on total exposure across multiple instances -- the release states a per-instance figure, not a maximum - $2,500 · per depiction
- Fine for an unauthorized AI-generated likeness of an elected official
Includes: A misdemeanor charge under Introduction 504, triggered per generated depiction
Excludes: AI-generated depictions of private individuals, which this specific bill does not cover - Undisclosed · share of recovered fines
- The whistleblower bounty's actual payout
Includes: A share of fines or penalties the city recovers from a violating company
Excludes: Any stated percentage -- the Sept. 25 release calls the program 'first-in-the-nation' without saying how large the incentive is
The remaining six bills round out the package: mandatory public disclosure requirements and a ban on false safety claims (Introduction 2603), data-privacy and transparency rules specific to chatbot providers (Introduction 2599), an emergency-response mandate for Cyber Command if AI infrastructure is compromised (Introduction 2606), extended whistleblower protections for city employees and contractors (Introduction 2604), and a requirement that companies disclose algorithmic impacts on jobs -- displacement, salary changes, position eliminations, training requirements (Introduction 161). Deepfake restrictions round out the list: Introduction 504 would let elected officials bar generative AI from creating their own likeness, backed by a $2,500-per-depiction fine. "We can and must be both pro-innovation and pro-safety," Menin said in the release; Council Member Carmen De La Rosa, the job-displacement bill's sponsor, put the sharper version of the same argument: "efficiency does not become a substitute for accountability."
The hearing set to consider all ten bills is unusual on its own terms: a Committee-of-the-Whole session on Oct. 5 puts every one of the Council's 51 members in the room at once, a format City & State New York and amNewYork both describe as rare for a single policy area. Menin's office says it is "inviting and expecting" OpenAI and Anthropic to send representatives, and has said the Council reserves subpoena power if they decline. The invitation isn't abstract: Anthropic leased an entire 16-story building at 330 Hudson Street this summer and expects more than 1,000 New York employees by year's end, while OpenAI has held 90,000 square feet at the Puck Building since 2024 -- both labs are already the kind of local employer a city council can plausibly summon, which is part of why this hearing reads differently than a written comment period would.
Three governments, three different levers on the same problem
| NYC Council package Introductions 2599-2606, 161, 504 | New York State's RAISE Act signed Dec. 19, 2025 | Illinois / Oregon executive orders issued Sept. 2026 | |
|---|---|---|---|
| What triggers the rule | Marketing, selling, or deploying an AI system inside city limits | Being a frontier AI developer, regardless of where the company is based | Executive-branch directive to state agencies, not a law binding private companies |
| Enforcement hook | Local commerce -- can't legally sell or deploy without validation | Safety-framework disclosure requirements enforced by the state | Agency practice and procurement rules; no penalty structure for private AI labs |
| Stated penalty | $25,000 per violation instance | Not primarily penalty-based -- disclosure and framework compliance | None disclosed -- executive orders of this kind typically lack one |
| Status as of this writing | Introduced; Oct. 5 hearing scheduled | In effect | In effect, disputed reach |
That comparison is the real story underneath the kill-switch headline. Illinois' and Oregon's AI executive orders, issued days apart in September, ran into the same wall every executive order aimed at private AI labs eventually hits: neither governor's office can actually tell a company headquartered elsewhere what to build. New York's own RAISE Act sidesteps that by regulating frontier developers directly, wherever they're based, through disclosure requirements rather than product bans. The NYC Council's bet is different from both: it isn't trying to reach into a lab's training run at all. It's regulating the point of sale and deployment inside its own five boroughs -- the same authority a city already uses to require permits, licenses, and safety inspections for anything else sold there. That framing is narrower than the RAISE Act's reach and more concrete than an executive order's -- whether it's actually more enforceable is a question that gets answered the first time a company decides it's worth challenging in court rather than showing up Oct. 5.
“Efficiency does not become a substitute for accountability.” -- Council Member Carmen De La Rosa, sponsor of the algorithmic-impact disclosure bill, Sept. 25, 2026
None of the ten bills has been voted on. Oct. 5 is a hearing, not a markup, and a Committee-of-the-Whole session is designed to generate public record and pressure as much as to move legislation quickly -- New York City bills routinely sit in committee for months after a first hearing. The immediate test isn't whether any of this becomes enforceable law by year's end. It's whether OpenAI and Anthropic, both now sizable New York employers with a direct stake in how the city treats them, choose to show up and negotiate the specifics, or force the Council to find out how far its subpoena power actually reaches.
- NYC Council Speaker Julie Menin unveiled 10 AI bills on Sept. 25, including a kill-switch and third-party-validation mandate.
- Violations of the validation/kill-switch rule carry a $25,000 penalty per instance, for both the business and the validator.
- A first-in-the-nation whistleblower bounty is proposed, though the bill text doesn't yet state the payout percentage.
- A rare Committee-of-the-Whole hearing is set for Oct. 5; the Council says it may subpoena OpenAI and Anthropic if they skip it.
- Caveat: the package regulates AI 'marketed, offered for sale, or deployed' in the city -- narrower, and likely more enforceable, than a state or federal rule, but untested against a legal challenge.