NYDFS SEP 14, 2026 · InsureAI Wire

NYDFS Risk Assessment Guidance Names AI Adoption as an Emerging Risk and Asks for Risk-to-Control Records

On September 10, 2026, the New York State Department of Financial Services (NYDFS) issued an Industry Letter to every entity it regulates on how to conduct and use the risk assessments its cybersecurity regulation, Part 500, requires. The letter says it “does not create new obligations” and describes itself as clarifying regulatory requirements and highlighting best practices; it sets no compliance date and names no examination cycle. Its addressees, Covered Entities, are those licensed or otherwise authorized under the Banking, Insurance or Financial Services Law (footnote 1), so Insurance Law licensees, including insurers, are included.

In the May advisory, the Department said frontier AI risk belongs in the Part 500 risk assessment. The September letter’s subject is cybersecurity risk assessment generally, and AI is named in it as an example, twice. A passage headed Emerging Risks in the scope section lists examples an assessment should consider, and the first is “the adoption or use of artificial intelligence.” In the section on updates, “significant developments in cybersecurity technologies (e.g., frontier AI models)” appears among the things that “may all constitute material changes” to cyber risk, and footnote 21 there cites the May advisory.

The letter keeps requirements and recommendations in different verbs; the recommendations say “should.” Under § 500.9(a), a risk assessment must be reviewed and updated at least annually and whenever a change in business or technology causes a material change to the entity’s cyber risk. Under § 500.9(b), it must follow written policies and procedures that set criteria for categorizing risks, criteria for assessing systems and existing controls, and requirements for how the program addresses identified risks. Under § 500.2, the cybersecurity program must be based on the risk assessment. The Department “does not require Covered Entities to use a specific methodology”; a footnote names NIST’s Cybersecurity Framework 2.0, the Cyber Risk Institute’s Profile and ISO 27005 as frameworks many entities align with, not as requirements.

The documentation section opens with a requirement: Covered Entities “must maintain documentation sufficient to demonstrate how cybersecurity risks were identified, assessed, and addressed through the Risk Assessment process.” It goes on to describe records that “link each identified cybersecurity risk to the specific controls or compensating measures implemented to mitigate the risks identified.” Where management elects to accept a risk, the documentation should capture that decision, “including the justification for risk acceptance and any residual risk considerations.” Entities should also keep “a mechanism, such as a risk register or comparable tracking process,” to record results. The letter’s standard is stated earlier: the Department “expects each Covered Entity to be able to demonstrate how its Risk Assessment informed cybersecurity controls, compensating controls, and risk acceptance decisions.”

The scope section also asks that assessments evaluate Third-Party Service Providers, naming, among others, cloud service providers, managed security service providers, software vendors, payment processors and Affiliates. A passage on concentration risk adds that “Technologies, platforms, or vendors that present limited risk when evaluated independently may collectively create significant cyber risk” when several critical systems rely on the same shared dependencies. Neither passage mentions AI; the same-day press release, not the letter, says AI adoption can change an entity’s “third-party dependencies,” and AI vendor risk assessment takes up the questions the letter leaves there.

On size, the letter says “A Risk Assessment conducted by an individual or small business will often look very different from one performed by a Class A Company.” The regulation defines that term at § 500.1(d). The goal, informed decisions about the program, is the same regardless of size, it adds.

The Department says its observations come from “examinations and investigations” and “interviews with Covered Entity personnel,” and that the gaps found “have contributed to deficient cybersecurity programs.” It names five, “among others.” One is failure to account for evolving and interconnected risks, including emerging technologies, concentration risk and single points of failure. The other four are incomplete asset scope and visibility, weak or inconsistent methodologies, insufficient governance and risk treatment, and failure to account for or inform the cybersecurity program, which leaves controls and resource decisions “not demonstrably based on the Covered Entity’s identified cyber risks.” That is the list a Covered Entity can hold its own assessment against.

Share

InsureAI Wire seal IAW Source

Official document

dfs.ny.gov →

The instrument itself, issued by a government, court, legislature, or standard-setting body.

Information aggregation and analysis, not legal advice. See our disclaimer.