Close this menu

NetChoice Testimony in Opposition to NYC’s AI Legislative Package

NetChoice opposes New York City’s 10-bill AI legislative package (Ints. 2602, 2599, 2603, 2600, 2605, 2601, 504, 2604, 2606, and 161), as it introduces fragmented, overlapping municipal mandates on AI. The Council should defer to existing, specialized state and federal functional regulators.

NetChoice Testimony in Opposition to NYC 2602, 2599, 2603, 2600, 2605, 2601, 504, 2604, 2606 and 161

October 8, 2026

New York City Council
City Council Park
New York, NY 10007

Dear Members of the New York City Council, 

On behalf of NetChoice, a trade association working to make the Internet safe for free enterprise and free expression, we write in opposition to the legislative package comprising ten distinct bills aimed at regulating artificial intelligence (AI) systems marketed, deployed, or developed in New York City. This package includes Introductions 2602, 2599, 2603, 2600, 2605, 2601, 504, 2604, 2606 and 161. 

NetChoice shares the Council’s goal of protecting New Yorkers and appreciates your stated goal of making New York City “the technology and AI capital of the world.” However,  these bills work directly against that goal. This package introduces fragmented, overlapping, and unworkable municipal mandates that risk undermining the city’s premier commercial ecosystems, while simultaneously doing nothing to protect New Yorkers. 

Active Regulation Under Existing NY State and Federal Frameworks

This package rests on the false premise that AI is unregulated. In reality, existing state and federal law aggressively police harmful practices, civil rights violations, and abuse.

New York State already possesses robust statutory protections that directly govern AI tools. Executive Law § 63(12) and General Business Law § 349 grant the Attorney General broad authority to penalize deceptive AI practices or illegal algorithmic outcomes; the SHIELD Act mandates strict data security and technical safeguards; and the NY Human Rights Law (Executive Law Art. 15) prohibits algorithmic discrimination in employment, credit, housing, and public accommodations.

Federal regulators enforce these same principles nationwide: the FTC polices deceptive AI claims and unfair algorithmic harms under Section 5 of the FTC Act; the EEOC targets hiring bias under Title VII; the Fair Housing Act (FHA) and Fair Credit Reporting Act (FCRA) prohibit discriminatory screening, underwriting, and credit decisions; and HIPAA, enforced by HHS OCR, protects health data and clinical AI applications.

State Attorneys General Possess The Power To Enforce Existing Frameworks 

State AGs across the nation are actively relying on existing consumer protection and statutory frameworks to police AI deployment. For example, Connecticut Attorney General William Tong issued formal guidance establishing that existing statutes—including state civil rights laws, unfair trade practices acts (CUTPA), and data privacy laws—apply directly to companies deploying AI systems. Similar actions under Unfair and Deceptive Acts or Practices (UDAP) authority are being enforced across states like California and Massachusetts to target algorithmic bias, misleading AI marketing, and privacy abuses without creating a fragmented web of local municipal laws. 

Because existing New York State laws and federal enforcement regimes already target bad actors and protect consumers, the city should defer to existing functional regulators rather than introducing duplicative municipal liability. While a rush to add additional regulations at every level of government may feel the most protective, in actuality, duplicative or conflicting rules diminish safety, as companies struggle to come into compliance and consumers are left confused about the protections to which they are legally entitled. Clarity and simplicity then are important safety tools unto themselves. 

The Package Conflicts With New York’s RAISE Act

New York has already acted on AI safety. The RAISE Act, finalized in March of 2026 and effective January 1, 2027, requires frontier developers to publish safety protocols and report critical incidents to a dedicated office within the Department of Financial Services. It already applies to models operating in New York City. Introduction 2601 would add a second, inconsistent regime. The State requires reporting within 72 hours and reserves a 24-hour deadline for incidents posing imminent risk of death or serious injury. Introduction 2601 would apply a 24-hour deadline to a broader, less defined set of incidents. Two regulators, two deadlines, and two definitions for the same incident would pull safety teams away from the response itself and produce premature, unreliable reports.

Unworkable Technical Mandates and the Need for Functional Deference

The lead bill in this package, Introduction 2602, would mandate a third-party audit of all AI systems prior to deployment in NYC as well as universal human-operated “kill switches” or shutdown mechanisms enforced by steep civil penalties. This demonstrates the risk of applying broad municipal rules to highly specialized software. Compelling third-party audits and technical validation is particularly premature; the measurement science required to reliably evaluate these systems is still in development, rendering third-party certification functionally impossible.

New York City is the financial capital of the world and home to globally significant institutions in financial services, insurance, and healthcare, among others. These industries already operate under functional comprehensive federal and state regulatory frameworks designed to oversee algorithmic risk, consumer protection, and systemic stability. 

For example, financial institutions subject to the jurisdiction of the U.S. Securities and Exchange Commission (SEC), FINRA, the Federal Reserve, and the NYS Department of Financial Services (DFS) must adhere to rigorous risk management frameworks, fiduciary duties, predictive data analytics rules, anti-money laundering controls, and real-time fraud monitoring systems. Mandating local, municipal-level intervention over these intricate financial architectures creates dangerous operational friction. A broad local requirement risks triggering unintended interruptions in automated trading, cross-border settlement systems, and security detection mechanisms that safeguard global markets. 

To maintain market stability and avoid conflicting mandates, the city should defer to existing functional regulators—such as the SEC and New York State financial authorities. 

Conclusion

Effective oversight of artificial intelligence requires clear, harmonized standards administered by experts with sector-specific expertise. Because existing state and federal law—alongside federal financial oversight—already protects consumers and markets from harm, the city should defer to existing functional regulators and oppose this package. At a minimum, we urge the Council to take the time to study the implications of these bills before moving forward. Sweeping legislation passed in haste risks unintended consequences for New Yorkers that will be difficult to undo. 

Thank you for your time and consideration. 

Sincerely, 

Tyler Fields 
Government Affairs Associate, NetChoice (The views of NetChoice expressed here do not necessarily represent the views of all NetChoice members.)

NetChoice is a trade association that works to protect free expression and promote free enterprise online.