New York City wants auditors, a kill switch and a paid whistleblower

Share
New York City wants auditors, a kill switch and a paid whistleblower

Washington has spent a decade holding AI hearings and passing almost nothing. New York City Council now wants to see whether a city can do what Congress won't — starting with the systems its own residents are already using, sold by the five companies with the biggest offices in town.

New York City Council Speaker Julie Menin unveiled a package of AI bills on Friday that would make it unlawful to market, sell or deploy an AI system in the city without third-party validation — and require that every system carry a kill switch the validator confirms exists. Under Introduction 26835, an outside validator would check data quality, bias, decision outputs, privacy and security against standards set by the city's Office of Cyber Command, and would have to disclose conflicts of interest. The penalty is $25,000 per instance, and it lands on the business and the validator both. Menin's reading of the per-instance rule is expansive: "if there's a swarm of agents, the penalty would apply per agent."

The bill that has no precedent is Introduction 26887, which would pay individual whistleblowers a share of the fines and penalties recovered from AI companies that break the law — the council calls it a first in the nation. A companion measure, Introduction 26831, extends the city's whistleblower protections to city employees and contractors who report AI they reasonably believe threatens public safety, and Introduction 26834 creates a private right of action against AI companies for foreseeable harm caused by a third party who jailbreaks their product, provided the company failed to implement reasonable safeguards.

The rest of the slate is broad. Contractors would have to report AI safety incidents to Cyber Command within 24 hours, with public disclosure inside the same window (Intro 26630). AI companies could not make false or misleading safety claims (Intro 26832). Chatbot providers would inherit a local version of the Electronic Privacy Information Center's People-First Chatbot Bill (Intro 26862), city agencies would have to report how algorithmic tools changed employees' jobs (Intro 161), and elected officials could opt out of AI-generated likenesses, with violations a misdemeanor and $2,500 per depiction (Intro 504). More bills are coming on deceptive deepfakes.

All of it gets heard on October 5 at a Committee of the Whole — all 51 members, the first such session since 2022. Menin sent letters last week to Dario Amodei, Sam Altman, Sundar Pichai, Elon Musk and Mark Zuckerberg asking them to appear, and the council reserves the right to subpoena them. None of the five is expected to testify. Their companies' New York footprint is the jurisdictional argument: Google has more than 14,000 employees in the city, Meta leases 1.2 million square feet at 50 Hudson Yards, Anthropic took a 16-story building at 330 Hudson Street this summer and expects over 1,000 city employees by year end, and OpenAI holds 90,000 square feet at the Puck Building.

The kill switch is the headline and the least interesting part of this. The mechanism that actually changes behavior is the bounty: a regulator with no budget can rent enforcement from insiders, which is how the federal False Claims Act works, and it is the first time an AI regulator has tried it. The validator requirement is where the risk sits, because it makes the audit market the choke point — the same companies that certify also compete for the work, which is precisely why the conflict-of-interest clause is in the text. And the timing is the trap: a bipartisan Senate bill would likely override most state AI laws including New York's RAISE Act, so the city is building a regime that the federal government is simultaneously moving to erase. We covered the state-level version of this in New York starts registering frontier AI developers in November, and the resignation the council cites in its own press release — OpenAI and Anthropic both got worse today — one shipped, one lost a researcher — is now written into the legislative record.

What to watch: whether any of the five CEOs shows up on October 5, or whether the council's subpoena threat turns into the first real test of a city's power to compel a frontier lab — and whether Menin's office publishes a validator standard before the hearing or after.

Would an outside auditor you don't get to choose make you trust an AI product more — or is a city-sized regulator the wrong layer for a global industry? Tell us in the comments.

Sources: New York City Council — AI legislative proposals · Fortune · New York Post · amNY