NY Financial Regulator Issues New Cyber Threat Guidance on AI Risks

June 29, 2026

NY Financial Regulator Issues New Cyber Threat Guidance on AI Risks
Futuristic digital background. Hexagon shell with binary code and glowing opened warning sign with exclamation mark. Hacker attack and data breach. Safe your data. Internet security and privacy concept. 3d illustration

The New York State Department of Financial Services (NYDFS) issued two industry letters in May 2026 urging regulated entities to strengthen their cybersecurity programs in response to an increasingly dangerous cyber threat landscape. Mayer Brown writes about the developments in a recent article on its website.

The guidance specifically highlights risks from advanced artificial intelligence models capable of identifying and exploiting system vulnerabilities at unprecedented speed and scale.

NYDFS has a well-established record of issuing cybersecurity guidance to the financial services sector. These latest letters continue that pattern, responding to two broad categories of elevated risk: geopolitical developments, such as ongoing international conflicts, and rapid technological advancement.

The department defines a heightened threat environment as one where cybersecurity risks are substantially elevated and likely to affect information systems, nonpublic information, or operations.

The first letter addresses general best practices across three areas. The first is reducing attack surfaces through network controls, input validation, and phishing-resistant multi-factor authentication. The second is improving threat detection through updated intrusion controls and vendor monitoring. The third is strengthening resilience through tested backup systems, incident response plans, and communication strategies.

The second letter focuses on frontier AI models that are expected to emerge to the broader market soon. It recommends enhanced vulnerability management timelines, third-party dependency mapping, secure programming practices with human oversight of AI-generated code, and heightened monitoring and prompt incident reporting.

Although the letters disclaim creation of new legal requirements, regulated entities should treat these recommendations as reflecting supervisory and enforcement expectations, raising meaningful enterprise risk management considerations.

Lawyers advising financial services clients on transactional due diligence should assess whether target companies have cybersecurity programs addressing frontier AI risks.

Regulatory approvals for transactions involving NYDFS-regulated entities may now implicate cybersecurity program adequacy as a reviewable factor. Enforcement trends suggest regulators will scrutinize alignment between a firm’s stated policies and actual cyber readiness.

Board governance obligations may require directors to receive specific briefings on frontier AI-related cyber exposures.

Critical intelligence for general counsel

Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.

Daily Updates

Sign up for our free daily newsletter for the latest news and business legal developments.

Scroll to Top