Audit trails for Cybersecurity Events.
Note the section number: § 500.6, not § 500.06. The Second Amendment, in force since 1 November 2023, restructured the numbering. § 500.6(a)(2) is the audit-trail clause. The 16 October 2024 Industry Letter does not cite it, so reading it against an AI deployment is Warrant's inference from the regulation's own text. For why static API logs fall short, see standard logs do not satisfy § 500.6. How § 500.6(a)(2) reads next to Federal Reserve model-risk guidance — SR 26-2's footnote 3 leaves the agent's own conduct to rules like this one — is worked through in the AI agent audit trail: NYDFS 500.6 + SR 26-2.
Notice in 72 hours. Two signatures.
Two things in that sentence are routinely misquoted, and both change the obligation. The trigger is a cybersecurity incident under § 500.1(g), not a Cybersecurity Event under § 500.1(f) — every incident is an event, but only an event meeting one of the three limbs of § 500.1(g) starts the clock. And the notice goes "electronically in the form set forth on the department's website", not through a named portal. The 72-hour clock then starts at determination, not at occurrence.
§ 500.17(b)(2) is the signature clause: the annual certification or acknowledgment "shall be signed by the covered entity's highest-ranking executive and its CISO" — both signatures, not one — and where there is no CISO, by the highest-ranking executive and the senior officer responsible for the cybersecurity program. "Highest-ranking executive" is verbatim regulator language; the rule does not say "CEO". The submission itself sits at § 500.17(b)(1): annually, by April 15, either a written certification of material compliance or a written acknowledgment of non-compliance identifying the sections not complied with and giving a remediation timeline. Warrant does not evidence either signature. The warrant-v1 package carries no field that names a person or a role — no signer, no officer, no approver — so the certification and the authorship of it sit in the Covered Entity's own governance record, not on anything Warrant emits.
warrant-v1 names no person and no role, so neither signature § 500.17(b)(2) requires is evidenced by the package. Cross-trace inventory roll-up ships v0.5.
The four load-bearing definitions.
Four defined terms in § 500.1 carry the regulation. AI deployments fall in scope where they touch any of them. The fourth — cybersecurity incident at § 500.1(g) — is the one most often dropped, and it is the term the 72-hour clock actually runs on.
Does NYDFS Part 500 apply to AI agents?
The NYDFS AI Industry Letter of 16 October 2024, "Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks," did not amend Part 500. It says so itself: "This Guidance does not impose any new requirements beyond obligations that are in DFS's cybersecurity regulation codified at 23 NYCRR Part 500 … rather, the Guidance is meant to explain how Covered Entities should use the framework set forth in Part 500 to assess and address" these risks. It identifies four AI-related risk categories — AI-enabled social engineering, AI-enhanced cybersecurity attacks, exposure or theft of nonpublic information, and increased vulnerabilities from third-party, vendor and supply-chain dependencies — and works them mainly through § 500.11, third-party service provider and vendor management. Note what it does not do: the Letter does not cite § 500.6 or § 500.17. Reading § 500.6 against an AI deployment is an inference from the regulation's own text, not something the Letter instructs, and this page marks it as such. Letter retrieved 6 August 2026.
The enforcement record is worth reading precisely, because what NYDFS actually cites is narrower than the audit-trail framing suggests. The PayPal consent order (23 January 2025, USD 2 million civil monetary penalty over a December 2022 exposure of Form 1099-K data) concluded that PayPal violated § 500.3(d), (i) and (k) — cybersecurity policies — § 500.10(a), qualified cybersecurity personnel and training, and § 500.12(a), multi-factor authentication. The GEICO consent order (25 November 2024, USD 5 million DFS civil monetary penalty, announced with a parallel New York Attorney General settlement) turned on §§ 500.2, 500.3 and 500.9(a) — a risk assessment that did not inform the architecture of the information systems it was meant to inform. The First American Title consent order (27 November 2023, announced 28 November 2023, USD 1 million) concluded violations of § 500.3 and § 500.7 only; on notice, the order records the opposite of a failure — at paragraph 17, that First American "notified the Department of the existence of the Vulnerability as required by Section 500.17(a)". Warrant has not found a NYDFS consent order citing § 500.6 at all, and says so rather than implying one exists. Orders retrieved 6 August 2026. A Covered Entity running a lending or credit agent also answers to the federal consumer-protection layer — the reading is at CFPB AI guidance for lending and credit agents.
Where this leaves counsel, stated as a reading rather than as the regulator's position. § 500.6 splits into two duties with different objects: (a)(1) systems "designed to reconstruct material financial transactions", retained five years under (b); (a)(2) "audit trails designed to detect and respond to cybersecurity events" meeting the materiality threshold, retained three years. Reconstruction attaches to financial transactions, detection to events — a page that says the audit trail must reconstruct the event end-to-end has merged the two, and NYDFS has not said that. One more limit worth stating plainly: § 500.6 is one of the sections a limited-exemption entity is exempt from under § 500.19(a) — fewer than 20 employees and independent contractors, or under USD 7.5 million gross annual revenue in each of the last three fiscal years, or under USD 15 million in year-end total assets — and §§ 500.19(c) and (d) also exempt from it. If a Covered Entity qualifies, the audit-trail obligation this page maps does not attach to it at all.
Does the AI deployment touch NPI.
Five clauses to walk in order. The ordering is Warrant's construction from the text of Part 500, offered as how we would expect a Covered Entity's AI exposure to be read on examination — the Department has not published a sequence.
actions[] row (action_id, actor, action, subject), its authorizations[*].justification and its obligations.<action_id>[].evidence and .compliance — obligations being an object keyed by action id, not a flat array — carry that operation-level detail in a record independently verifiable without contacting Warrant. Rotating application logs do not. Stated as what the question asks for, not as a citation: the obligation corpus carries no § 500.6 sub-clause, so no package cites the clause and Part 500 is reported as classified and in scope, not evaluated.
warrant-v1 has no field naming a signer or an officer, so the package evidences the underlying decisions, not the certification. Cross-trace inventory roll-up ships v0.5.
Per-section field map.
The mapping below carries each Part 500 obligation Warrant attaches to. Each row names the section cite, the operative duty, and the warrant-v1 field that carries evidence for it — or states that no field does. Read the field names literally: they are properties of the signed package as defined in api/spec/warrant-v1-evidence.schema.json and api/spec/warrant-v1-receipt.schema.json. Both set additionalProperties: false at the root, so a name absent from the schema is not merely unimplemented — it is prohibited, and no package can ever carry it. Five of the twelve rows below say plainly that no field carries the obligation: Part 500 asks in places for signatures, policy approvals, event determinations and data classifications that live in the Covered Entity's own governance record, not in a per-decision evidence package. Warrant publishes this as the table it would put in front of an NYDFS examiner on a Covered Entity examination — our framing, not a procedure the Department has described.
warrant-v1 carries no policy identifier and no approver, so the annual senior-officer approval § 500.3 requires is evidenced in the entity's own governance record. What the package does bind to a determination is trace_metadata.regulations_corpus_sha256 — the regulation text the decision was assessed against, which is not the entity's policy.
warrant-v1 has no person field and no role field. § 500.4 responsibility sits with the entity and is not readable off the evidence package.
actions[*] (action_id, actor, action, subject) + authorizations[*].justification + obligations.<action_id>[].evidence and .compliance — obligations is an object keyed by action id whose values are arrays of rows, so there is no flat obligations[] path — bound into a record independently verifiable without contacting Warrant. No retrieval field: warrant-v1 records no retrieved passages and no chunk identifiers, so where an agent's answer came from is reconstructable only as far as the ingested trace's own step inputs and outputs carried it.
actions[].actor — the actor string as the ingested trace supplied it, not a validated identity — plus authorizations[].preconditions_met. No privilege field: warrant-v1 does not distinguish a privileged actor from an ordinary one, so § 500.7 access-privilege review rests on the entity's own entitlement records.
actions[].actor + the per-action authorizations[] row (within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification, refusal). No authentication field: warrant-v1 records nothing about how the actor was authenticated, so monitoring of authorized users under § 500.14(a)(1) rests on the entity's own access logs. The package evidences what the actor then did.
timestamp (decision time) and trace_metadata.timestamp (attestation time), plus the Warrant Cloud receipt store. Neither is a determination time — warrant-v1 has no determination field, and the 72-hour clock starts at determination, not at occurrence. The clock is customer process.
warrant-v1 carries no signer name and no officer role, so neither of the two signatures § 500.17(b)(2) requires — the highest-ranking executive's and the CISO's — is evidenced by the package. "Highest-ranking executive" is the rule's own term; it does not say CEO.
regulated_entity is a real key at the root of the trace a customer submits — a sibling of the root trace array, so there is no trace.regulated_entity path — and it is read by the pipeline rather than re-emitted, so nothing in warrant-v1 asserts Covered Entity status. Whether § 500.1(e) attaches is the entity's own determination.
warrant-v1 defines no event-classification property and no property named for deviation, so whether an act against an information system is a Cybersecurity Event under § 500.1(f) is the entity's determination and does not appear as a value on the package. State the nearest signed signal rather than claiming nothing exists: authorizations[*].within_purpose records, per action, whether the action fell inside the purpose the submitted trace declared for that run. That is a related signal and it is not sufficient here — the purpose is the run's own declared purpose rather than the entity's policy, and an out-of-purpose action is not the same finding as a § 500.1(f) event.
warrant-v1 has no data-classification field, so nothing on the package marks an input as Nonpublic Information. classification.domain records the business domain of the decision, and whatever the ingested trace put in a step's inputs stays as the trace supplied it — unlabelled.
Primary citations.
Every clause quoted on this page is quoted from the Department's own published text of the Second Amendment to 23 NYCRR 500, at dfs.ny.gov · 23 NYCRR § 500 Second Amendment PDF, read in full and retrieved 6 August 2026. One caveat stated rather than hidden: that document carries the Department's own note that it "is not an official version of the Second Amendment to Part 500", the codified text being the one in Title 23 of the Official Compilation. Where the two differ, the codified text governs and the quotations on this page should be read against it. § 500.21 fixes the dates quoted here: Part 500 effective 1 March 2017, Second Amendment effective 1 November 2023, with the § 500.12 and § 500.13(a) tranche running two years from that date under § 500.22(d)(4). The AI Industry Letter is at il20241016-cyber-risks-ai. The consent orders cited above are the Department's own: PayPal (23 Jan 2025), GEICO (25 Nov 2024) and First American Title (27 Nov 2023). The full Cybersecurity Resource Center is at dfs.ny.gov/industry_guidance/cybersecurity.