REGULATOR · US-NY · COVERED ENTITIES
REVISED 2026-05-08 · 23 NYCRR § 500 · POST SECOND AMENDMENT

NYDFS Part 500.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant. 23 NYCRR § 500, post Second Amendment · jurisdiction: NY-licensed financial services Covered Entities · AI cybersecurity guidance issued 16 October 2024 (Industry Letter, applies existing Part 500 to AI deployments) · penalty: enforcement under NY Banking Law and Insurance Law. Covered Entities bring AI components inside the cybersecurity program, and § 500.17(a)(1) requires notice to the superintendent within 72 hours of determining that a cybersecurity incident as defined at § 500.1(g) has occurred — not every Cybersecurity Event, and not from the moment of occurrence.

CLAUSE
§ 500.6 · § 500.17(a)(1)
Audit trail, and 72-hour notice on determining a cybersecurity incident.
DEFINITIONS
§ 500.1(e)/(f)/(g)/(k)
Covered Entity (e), Cybersecurity Event (f), cybersecurity incident (g) — the notice trigger — and NPI (k).
AI GUIDANCE
2024-10-16
Industry Letter applying existing Part 500 to AI deployments.
01 · § 500.6 · AUDIT TRAILS

Audit trails for Cybersecurity Events.

Each Covered Entity shall securely maintain systems that, to the extent applicable and based on its Risk Assessment, include audit trails designed to detect and respond to Cybersecurity Events that have a reasonable likelihood of materially harming any material part of the normal operations of the Covered Entity. 23 NYCRR § 500.6, opening words of (a) read with paragraph (a)(2) · Second Amendment text; the Second Amendment sets defined terms in lower case · as at the text retrieved 6 Aug 2026

Note the section number: § 500.6, not § 500.06. The Second Amendment, in force since 1 November 2023, restructured the numbering. § 500.6(a)(2) is the audit-trail clause. The 16 October 2024 Industry Letter does not cite it, so reading it against an AI deployment is Warrant's inference from the regulation's own text. For why static API logs fall short, see standard logs do not satisfy § 500.6. How § 500.6(a)(2) reads next to Federal Reserve model-risk guidance — SR 26-2's footnote 3 leaves the agent's own conduct to rules like this one — is worked through in the AI agent audit trail: NYDFS 500.6 + SR 26-2.

§ 500.6(a)(2) requires audit trails designed to detect and respond. On our reading the verbs carry the obligation: a static log is a record, not a detection capability.Warrant's reading of 23 NYCRR § 500.6(a)(2) · not a quotation from NYDFS
02 · § 500.17 · 72-HOUR NOTICE

Notice in 72 hours. Two signatures.

Each covered entity shall notify the superintendent electronically in the form set forth on the department's website as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred at the covered entity, its affiliates, or a third-party service provider. 23 NYCRR § 500.17(a)(1), Second Amendment text, quoted verbatim · as at the text retrieved 6 Aug 2026

Two things in that sentence are routinely misquoted, and both change the obligation. The trigger is a cybersecurity incident under § 500.1(g), not a Cybersecurity Event under § 500.1(f) — every incident is an event, but only an event meeting one of the three limbs of § 500.1(g) starts the clock. And the notice goes "electronically in the form set forth on the department's website", not through a named portal. The 72-hour clock then starts at determination, not at occurrence.

§ 500.17(b)(2) is the signature clause: the annual certification or acknowledgment "shall be signed by the covered entity's highest-ranking executive and its CISO" — both signatures, not one — and where there is no CISO, by the highest-ranking executive and the senior officer responsible for the cybersecurity program. "Highest-ranking executive" is verbatim regulator language; the rule does not say "CEO". The submission itself sits at § 500.17(b)(1): annually, by April 15, either a written certification of material compliance or a written acknowledgment of non-compliance identifying the sections not complied with and giving a remediation timeline. Warrant does not evidence either signature. The warrant-v1 package carries no field that names a person or a role — no signer, no officer, no approver — so the certification and the authorship of it sit in the Covered Entity's own governance record, not on anything Warrant emits.

§ 500.17(a)(1)
72-hour notice to the superintendent on determination of a cybersecurity incident under § 500.1(g) — the narrower term, not a Cybersecurity Event under § 500.1(f). WARRANT · Incident-mode trace ingestion ships v0.5; today: incident traces produce independently verifiable packages by Warrant. 72-hour clock is customer process.
§ 500.17(b)(2)
Annual program certification signed by the highest-ranking executive and the CISO — § 500.17(b)(2) requires both signatures, or, where there is no CISO, the highest-ranking executive and the senior officer responsible for the cybersecurity program. WARRANT · no field. warrant-v1 names no person and no role, so neither signature § 500.17(b)(2) requires is evidenced by the package. Cross-trace inventory roll-up ships v0.5.
03 · § 500.1 · DEFINED TERMS

The four load-bearing definitions.

Four defined terms in § 500.1 carry the regulation. AI deployments fall in scope where they touch any of them. The fourth — cybersecurity incident at § 500.1(g) — is the one most often dropped, and it is the term the 72-hour clock actually runs on.

§ 500.1(e)
Covered Entity. Any Person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation, or similar authorization under the Banking Law, Insurance Law, or Financial Services Law.
§ 500.1(f)
Cybersecurity Event. Any act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System.
§ 500.1(g)
Cybersecurity incident — the trigger for 72-hour notice. A cybersecurity event that has occurred at the covered entity, its affiliates, or a third-party service provider that: (1) impacts the covered entity and requires it to notify any government body, self-regulatory agency or other supervisory body; (2) has a reasonable likelihood of materially harming any material part of the normal operation(s) of the covered entity; or (3) results in the deployment of ransomware within a material part of the covered entity's information systems. Every incident is an event; not every event is an incident.
§ 500.1(k)
Nonpublic Information (NPI). All electronic information that is not publicly available information and is one of three things: (1) business-related information whose tampering, unauthorized disclosure, access or use would cause a material adverse impact to the business, operations or security of the covered entity; (2) information that can identify an individual in combination with a listed data element (social security number, driver's licence or non-driver ID number, account or card number, security or access code or password permitting account access, or biometric records); or (3) health information, except age or gender, derived from a health care provider or the individual. A conjunctive three-limb test, not an open-ended list.
72hr
NOTICE WINDOW
From determination of a cybersecurity incident under § 500.1(g) to notice under § 500.17(a)(1).
2024-10-16
AI INDUSTRY LETTER
"Cybersecurity Risks Arising from Artificial Intelligence" · applies the existing Part 500 to AI deployments without amending the regulation.
04 · WHY THIS REGULATOR NOW

Does NYDFS Part 500 apply to AI agents?

The NYDFS AI Industry Letter of 16 October 2024, "Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks," did not amend Part 500. It says so itself: "This Guidance does not impose any new requirements beyond obligations that are in DFS's cybersecurity regulation codified at 23 NYCRR Part 500 … rather, the Guidance is meant to explain how Covered Entities should use the framework set forth in Part 500 to assess and address" these risks. It identifies four AI-related risk categories — AI-enabled social engineering, AI-enhanced cybersecurity attacks, exposure or theft of nonpublic information, and increased vulnerabilities from third-party, vendor and supply-chain dependencies — and works them mainly through § 500.11, third-party service provider and vendor management. Note what it does not do: the Letter does not cite § 500.6 or § 500.17. Reading § 500.6 against an AI deployment is an inference from the regulation's own text, not something the Letter instructs, and this page marks it as such. Letter retrieved 6 August 2026.

The enforcement record is worth reading precisely, because what NYDFS actually cites is narrower than the audit-trail framing suggests. The PayPal consent order (23 January 2025, USD 2 million civil monetary penalty over a December 2022 exposure of Form 1099-K data) concluded that PayPal violated § 500.3(d), (i) and (k) — cybersecurity policies — § 500.10(a), qualified cybersecurity personnel and training, and § 500.12(a), multi-factor authentication. The GEICO consent order (25 November 2024, USD 5 million DFS civil monetary penalty, announced with a parallel New York Attorney General settlement) turned on §§ 500.2, 500.3 and 500.9(a) — a risk assessment that did not inform the architecture of the information systems it was meant to inform. The First American Title consent order (27 November 2023, announced 28 November 2023, USD 1 million) concluded violations of § 500.3 and § 500.7 only; on notice, the order records the opposite of a failure — at paragraph 17, that First American "notified the Department of the existence of the Vulnerability as required by Section 500.17(a)". Warrant has not found a NYDFS consent order citing § 500.6 at all, and says so rather than implying one exists. Orders retrieved 6 August 2026. A Covered Entity running a lending or credit agent also answers to the federal consumer-protection layer — the reading is at CFPB AI guidance for lending and credit agents.

Where this leaves counsel, stated as a reading rather than as the regulator's position. § 500.6 splits into two duties with different objects: (a)(1) systems "designed to reconstruct material financial transactions", retained five years under (b); (a)(2) "audit trails designed to detect and respond to cybersecurity events" meeting the materiality threshold, retained three years. Reconstruction attaches to financial transactions, detection to events — a page that says the audit trail must reconstruct the event end-to-end has merged the two, and NYDFS has not said that. One more limit worth stating plainly: § 500.6 is one of the sections a limited-exemption entity is exempt from under § 500.19(a) — fewer than 20 employees and independent contractors, or under USD 7.5 million gross annual revenue in each of the last three fiscal years, or under USD 15 million in year-end total assets — and §§ 500.19(c) and (d) also exempt from it. If a Covered Entity qualifies, the audit-trail obligation this page maps does not attach to it at all.

05 · DECISION TREE · NPI

Does the AI deployment touch NPI.

Five clauses to walk in order. The ordering is Warrant's construction from the text of Part 500, offered as how we would expect a Covered Entity's AI exposure to be read on examination — the Department has not published a sequence.

Q1
Is the firm a Covered Entity under § 500.1(e) (any Person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation, or similar authorization under the Banking Law, Insurance Law, or Financial Services Law). NO → Part 500 does not attach. YES → continue.
Q2
Does the AI deployment touch Nonpublic Information under § 500.1(k) (electronic information that is not Publicly Available, including business information, personally identifiable information, and protected health information). YES → § 500.6(a)(2) audit-trail rule attaches, unless the entity is exempt from § 500.6 under § 500.19(a), (c) or (d); § 500.17 reporting and certification carries forward; § 500.12 multi-factor authentication, § 500.14(a)(1) monitoring of authorized users, and § 500.7 access privileges read against AI tooling. Before the Second Amendment, § 500.12(a) let a Covered Entity use "Multi-Factor Authentication or Risk-Based Authentication"; that option is gone and § 500.12(a) now mandates MFA.
Q3
Could a successful or unsuccessful act against the AI system constitute a Cybersecurity Event under § 500.1(f) (any act or attempt to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System) — and if so, does it also meet one of the three limbs of a cybersecurity incident under § 500.1(g)? EVENT → § 500.6(a)(2) audit trails must be designed to detect and respond to such Events. INCIDENT as well → § 500.17(a)(1) 72-hour notice clock starts at determination. An event that is not an incident does not start the clock.
Q4
Is the audit trail designed to detect and respond to Cybersecurity Events that have a reasonable likelihood of materially harming any material part of normal operations. ON WARRANT'S READING → the package's per-action actions[] row (action_id, actor, action, subject), its authorizations[*].justification and its obligations.<action_id>[].evidence and .complianceobligations being an object keyed by action id, not a flat array — carry that operation-level detail in a record independently verifiable without contacting Warrant. Rotating application logs do not. Stated as what the question asks for, not as a citation: the obligation corpus carries no § 500.6 sub-clause, so no package cites the clause and Part 500 is reported as classified and in scope, not evaluated.
Q5
Is the annual certification under § 500.17(b)(2) signed by both the Covered Entity's highest-ranking executive and its CISO — or, where there is no CISO, the highest-ranking executive and the senior officer responsible for the cybersecurity program. "Highest-ranking executive" is verbatim regulator language; the rule does not say "CEO", and it does not accept one signature. YES → and Warrant does not evidence that signature. warrant-v1 has no field naming a signer or an officer, so the package evidences the underlying decisions, not the certification. Cross-trace inventory roll-up ships v0.5.
06 · MAPPING · § 500 OBLIGATIONS

Per-section field map.

Each covered entity shall implement and maintain a written policy or policies, approved at least annually by a senior officer or the covered entity's senior governing body for the protection of its information systems and nonpublic information stored on those information systems. 23 NYCRR § 500.3, Second Amendment text, quoted verbatim · note "approved at least annually" — the approval is a recurring obligation, not a one-off · as at the text retrieved 6 Aug 2026

The mapping below carries each Part 500 obligation Warrant attaches to. Each row names the section cite, the operative duty, and the warrant-v1 field that carries evidence for it — or states that no field does. Read the field names literally: they are properties of the signed package as defined in api/spec/warrant-v1-evidence.schema.json and api/spec/warrant-v1-receipt.schema.json. Both set additionalProperties: false at the root, so a name absent from the schema is not merely unimplemented — it is prohibited, and no package can ever carry it. Five of the twelve rows below say plainly that no field carries the obligation: Part 500 asks in places for signatures, policy approvals, event determinations and data classifications that live in the Covered Entity's own governance record, not in a per-decision evidence package. Warrant publishes this as the table it would put in front of an NYDFS examiner on a Covered Entity examination — our framing, not a procedure the Department has described.

§ 500.3
Cybersecurity policy approved by Senior Officer or Senior Governing Body. WARRANT · no field. warrant-v1 carries no policy identifier and no approver, so the annual senior-officer approval § 500.3 requires is evidenced in the entity's own governance record. What the package does bind to a determination is trace_metadata.regulations_corpus_sha256 — the regulation text the decision was assessed against, which is not the entity's policy.
§ 500.4
Chief Information Security Officer (CISO) responsibility. WARRANT · no field. Nothing on the package identifies a CISO or attributes authorship to one — warrant-v1 has no person field and no role field. § 500.4 responsibility sits with the entity and is not readable off the evidence package.
§ 500.6(a)(2)
Audit trails designed to detect and respond to Cybersecurity Events. WARRANT · actions[*] (action_id, actor, action, subject) + authorizations[*].justification + obligations.<action_id>[].evidence and .complianceobligations is an object keyed by action id whose values are arrays of rows, so there is no flat obligations[] path — bound into a record independently verifiable without contacting Warrant. No retrieval field: warrant-v1 records no retrieved passages and no chunk identifiers, so where an agent's answer came from is reconstructable only as far as the ingested trace's own step inputs and outputs carried it.
§ 500.7
Access privileges based on Risk Assessment. WARRANT · actions[].actor — the actor string as the ingested trace supplied it, not a validated identity — plus authorizations[].preconditions_met. No privilege field: warrant-v1 does not distinguish a privileged actor from an ordinary one, so § 500.7 access-privilege review rests on the entity's own entitlement records.
§ 500.14(a)(1)
Monitoring and training — risk-based policies, procedures and controls designed to monitor the activity of authorized users and detect unauthorized access or use of, or tampering with, nonpublic information by such authorized users. (Authentication is § 500.12, multi-factor authentication. "Risk-Based Authentication" was an option under the pre-amendment § 500.12(a) and appears nowhere in the Second Amendment text — it was never in § 500.14.) WARRANT · actions[].actor + the per-action authorizations[] row (within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification, refusal). No authentication field: warrant-v1 records nothing about how the actor was authenticated, so monitoring of authorized users under § 500.14(a)(1) rests on the entity's own access logs. The package evidences what the actor then did.
§ 500.16
Incident response plan and business continuity. WARRANT · Incident-mode trace ingestion ships v0.5; today, incident traces produce independently verifiable packages by Warrant. Incident-response chain auditable.
§ 500.17(a)(1)
72-hour notice to the superintendent on determining a cybersecurity incident (§ 500.1(g)) at the covered entity, an affiliate, or a third-party service provider. WARRANT · the ingested trace's per-step timestamp (decision time) and trace_metadata.timestamp (attestation time), plus the Warrant Cloud receipt store. Neither is a determination time — warrant-v1 has no determination field, and the 72-hour clock starts at determination, not at occurrence. The clock is customer process.
§ 500.17(b)(1)
Annual notice of compliance — by April 15, either a written certification of material compliance for the prior calendar year, based on data and documentation sufficient to demonstrate it, or a written acknowledgment of non-compliance identifying the sections not complied with plus a remediation timeline. WARRANT · cross-trace inventory roll-up ships v0.5; per-trace evidence today is part of the data and documentation the certification must rest on. § 500.17(b)(3) requires those supporting records to be kept five years.
§ 500.17(b)(2)
Annual certification signed by the highest-ranking executive (verbatim) and the CISO — both signatures. WARRANT · no field. warrant-v1 carries no signer name and no officer role, so neither of the two signatures § 500.17(b)(2) requires — the highest-ranking executive's and the CISO's — is evidenced by the package. "Highest-ranking executive" is the rule's own term; it does not say CEO.
§ 500.1(e)
Covered Entity definition. WARRANT · no field in the signed package. regulated_entity is a real key at the root of the trace a customer submits — a sibling of the root trace array, so there is no trace.regulated_entity path — and it is read by the pipeline rather than re-emitted, so nothing in warrant-v1 asserts Covered Entity status. Whether § 500.1(e) attaches is the entity's own determination.
§ 500.1(f)
Cybersecurity Event definition · act or attempt against Information System. WARRANT · no dedicated field. warrant-v1 defines no event-classification property and no property named for deviation, so whether an act against an information system is a Cybersecurity Event under § 500.1(f) is the entity's determination and does not appear as a value on the package. State the nearest signed signal rather than claiming nothing exists: authorizations[*].within_purpose records, per action, whether the action fell inside the purpose the submitted trace declared for that run. That is a related signal and it is not sufficient here — the purpose is the run's own declared purpose rather than the entity's policy, and an out-of-purpose action is not the same finding as a § 500.1(f) event.
§ 500.1(k)
Nonpublic Information definition. WARRANT · no field. warrant-v1 has no data-classification field, so nothing on the package marks an input as Nonpublic Information. classification.domain records the business domain of the decision, and whatever the ingested trace put in a step's inputs stays as the trace supplied it — unlabelled.
07 · READ THE SOURCE

Primary citations.

Every clause quoted on this page is quoted from the Department's own published text of the Second Amendment to 23 NYCRR 500, at dfs.ny.gov · 23 NYCRR § 500 Second Amendment PDF, read in full and retrieved 6 August 2026. One caveat stated rather than hidden: that document carries the Department's own note that it "is not an official version of the Second Amendment to Part 500", the codified text being the one in Title 23 of the Official Compilation. Where the two differ, the codified text governs and the quotations on this page should be read against it. § 500.21 fixes the dates quoted here: Part 500 effective 1 March 2017, Second Amendment effective 1 November 2023, with the § 500.12 and § 500.13(a) tranche running two years from that date under § 500.22(d)(4). The AI Industry Letter is at il20241016-cyber-risks-ai. The consent orders cited above are the Department's own: PayPal (23 Jan 2025), GEICO (25 Nov 2024) and First American Title (27 Nov 2023). The full Cybersecurity Resource Center is at dfs.ny.gov/industry_guidance/cybersecurity.

W
Sample US evidence package · NYDFS Covered Entity small-business underwritingINDEPENDENTLY VERIFIABLE · ID 041f2335488dd56f
→ us-fintech.pdf
Verify a package → Open the demo All regulators