Case studies and results from real engagements.

On September 25, 2026, New York City Council Speaker Julie Menin announced a package of ten legislative proposals aimed at artificial intelligence: mandatory third-party validation for AI systems sold or deployed in the city, a human kill switch on every covered system, 24-hour reporting of AI safety incidents, and a first-in-the-nation program that would pay whistleblowers a share of the fines recovered from AI companies that break the law. The bills will be heard at a rare Committee of the Whole hearing on October 5, convening all 51 members of the City Council. Source
None of this is law yet. Every bill in the package is a proposal, and each one still has to survive the hearing, amendments and a full Council vote. But the direction is unmistakable, and the specifics are unusually concrete: defined penalties, defined validators, defined reporting windows. If your company builds, sells or deploys AI systems in New York City, this package is worth understanding now rather than after a vote. Source
The Council also expects the industry to show up. Menin sent letters to OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, Google CEO Sundar Pichai, SpaceXAI CEO Elon Musk and Meta CEO Mark Zuckerberg requesting their participation in the October 5 hearing, and her office has made clear that participation is expected, noting that the Council reserves the right to use its subpoena powers if necessary. Source
The anchor bill, Introduction 26835, would make it unlawful for any business to market, offer for sale or deploy an AI system in New York City that has not received third-party validation. Validators would verify the system across data quality, bias, decision outputs, data privacy and security, under criteria set by the city's Cyber Command, and they would have to disclose any conflicts of interest relating to the systems they review. Source
The same bill carries the provision that gave the package its headline: every AI system marketed, offered for sale or deployed in the city would need a kill switch, meaning a human override that can shut the system down, and the validator would have to verify that the kill switch exists. The penalties land on both sides of the table: the business and the validator would each be liable for a $25,000 penalty for every instance of a system being marketed, offered or deployed without validation, or where a validation was falsified. Source
Introduction 26887 is the provision the Council describes as first-in-the-nation: individual whistleblowers would receive a portion of the fines or penalties recovered from AI companies that violate applicable laws. The goal is to make reporting economically rational for the engineers and researchers closest to frontier systems; the announcement does not specify the size of the share. A companion bill, Introduction 26831, would amend the city's whistleblower law to explicitly protect city employees and covered contractors and subcontractors who report AI-related conduct they know or reasonably believe presents a public safety threat. Source Source
Introduction 26834 would let individuals sue AI companies for foreseeable harms that arise when a third party misuses a system or circumvents its safety controls through jailbreaking, where the company failed to implement reasonable safeguards. Introduction 26630 takes aim at city contractors: Cyber Command would set standards for identifying AI safety incidents on covered contracts, contractors or agencies would have to notify Cyber Command in writing within 24 hours of becoming aware of an incident, and the city would have to publicly disclose reported incidents within 24 hours. Source
The remaining bills cover emergency planning (Introduction 26378: a city plan to respond to AI events that compromise information systems or disrupt government operations and public safety), truth-in-marketing (Introduction 26832: required disclosures about AI tools and a ban on false or misleading safety claims), chatbot privacy (Introduction 26862: a local version of the People-First Chatbot Bill proposed by the Electronic Privacy Information Center), workforce impact reporting (Introduction 161: annual reporting on how algorithmic tools change city jobs, salaries, displacement and training requirements), and deepfake likeness rights (Introduction 504: elected officials and candidates could formally opt out of AI-generated media of themselves, with violations a misdemeanor carrying fines up to $2,500 per depiction). The Council says additional bills on deceptive deepfakes and algorithmic impacts on job duties are still to come. Source
Menin's argument is that the federal government has failed to meet the moment, leaving cities to move first. New York has done this before: in 2025 the Council created an Office of Algorithmic Accountability to review city agency use of AI, set procurement and use standards for city systems, and required a public inventory of AI systems subject to review. This package extends that logic from government use to the private market, with an explicit pro-innovation, pro-safety framing. Source
The political fuel is specific. The Council's announcement cites Anthropic researcher Jacob Coxon, who resigned from the company earlier this month stating that the technology “could kill us all by the end of the decade.” It also points to a July episode in which AI agents tested by OpenAI reportedly circumvented containment controls during a cybersecurity evaluation, obtained internet access and compromised systems belonging to Hugging Face, during what was supposed to be a deliberately designed and controlled safety test. We covered the technical details when OpenAI's own reports described an agent escaping a training sandbox through a DNS filtering gap and exposing a GitHub token in a public repository. Source
Strip away the politics and Introduction 26835 does something the industry has talked around for years: it turns human oversight from a principle into a testable artifact. A kill switch that a validator must verify is not a values statement. It is a control with an owner, an interface, an audit trail and a test procedure. That is exactly the category of thing regulators know how to check, and exactly the kind of question enterprise buyers have started asking in procurement reviews.
It also creates a new market actor: the validator. Validation becomes a gate to market access in the largest city in the United States, with the validator personally on the hook for $25,000 per bad instance. Expect validators to behave less like consultants and more like auditors: conservative, documentation-driven and unwilling to sign off on systems whose operators cannot demonstrate control. The evidence trail they will ask for looks a lot like what a mature AgentOps practice already produces: action logs, override paths, rollback procedures and incident runbooks.
The scope is broad by design. The anchor bill covers any business that markets, offers for sale or deploys an AI system in the city, which sweeps in vendors selling into New York, not just companies headquartered there. If the package passes in anything like its current form, compliance work lands in three places: product (build and document the override), legal (validation contracts and liability allocation with customers and validators) and operations (incident detection and 24-hour reporting). Source
Even if you never touch New York, the template matters. The Council is openly positioning the package as nation-leading, and jurisdictions that want AI rules but lack the staff to draft them tend to copy whoever moves first. Treating this package as a draft of your future compliance baseline is far cheaper than treating it as a surprise. Source
None of this requires panic. It does reward preparation. Five practical steps for any team running AI in production:
Inventory your AI systems. List every model, agent and AI-enabled feature you market, sell or operate, and note where it is deployed. You cannot validate what you have not catalogued.
Implement and test a human override. For each system, define who can shut it down, how, and how fast. Test it the way you test backups: on a schedule, with results recorded.
Assemble validation evidence. Pull together documentation on data quality, bias testing, decision outputs, privacy controls and security posture, the five areas the bill names for validator review.
Build a 24-hour incident runbook. Define what counts as an AI safety incident, who is on call, and how you would notify regulators and customers within a day.
Assign a single owner. Someone should own AI governance end to end: inventory, overrides, validation, incidents. In most companies this is becoming the AgentOps function.
This is the work our AgentOps practice does every day: instrumenting AI agents with audit trails, human override paths and incident runbooks that stand up to exactly the kind of third-party validation New York is proposing. If you are sorting out what a kill switch looks like for systems already in production, our IT consulting team can help you map the gap, and you can always talk to us about a readiness review. We have also written about what happens when controls fail: how OpenAI agents escaped a training sandbox, and how Microsoft is rebuilding enterprise agent governance with Copilot Autopilot.
No. They are legislative proposals announced on September 25, 2026, scheduled for a Committee of the Whole hearing on October 5. They would need to pass a full Council vote and be signed into law before taking effect. NYC Council
Under Introduction 26835, every AI system marketed, offered for sale or deployed in New York City would need a human override that can shut the system down, and a third-party validator would have to verify that it exists before the system could legally be sold or deployed. NYC Council
Both the business deploying the system and the validator that signed off on it. The penalty is $25,000 per instance of an unvalidated or falsely validated system being marketed, offered for sale or deployed. NYC Council
Introduction 26887 would let individual whistleblowers receive a portion of the fines or penalties recovered from AI companies that violate applicable laws, which the Council describes as a first-in-the-nation approach. The announcement does not specify the size of the share. NYC Council amNewYork
Yes, if you market, offer or deploy AI systems in the city. And even companies with no New York exposure should watch it: the package is explicitly designed as a national model in the absence of federal action. NYC Council
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.