Writing / Compliance

What would New York City's AI kill switch bill require?

October 1, 2026 / 7 min read

NYC's AI package would require outside validation and a shut-down capability for AI models, and 24-hour incident reports from city contractors.

As drafted, it would make it unlawful to market, offer for sale, sell, or deploy an AI model in New York City unless an outside validator has validated the model and the model includes a shut-down capability, which the bill defines as the technical capability for a human operator to make the model temporarily or permanently stop functioning. The Council’s announcement calls that a kill switch. A companion bill would give city contractors 24 hours to report a serious AI safety incident in writing. Both are proposals: the Council hears them on October 5, and nothing in them is law yet.

Read together, the package asks for three things: a way for a person to stop an AI model, a short written account of a serious incident within a day, and an outside check before a model is sold or put to work. Those are practical questions for any organization using AI in the city, and they are worth answering before any bill passes.

What does the kill switch bill, T2026-2602, say?

The bill is sponsored by Speaker Julie Menin. The Council announced it on September 25, 2026 as Introduction 2602, and Legistar lists it as T2026-2602, set for formal introduction on October 8. It would make marketing, offering for sale, selling, or deploying an AI model unlawful unless two things are true: an outside validator has validated the model, and the model includes a shut-down capability. The bill defines an AI model broadly, as a machine-based system that infers from its input how to generate outputs that can influence physical or virtual environments, which reaches far beyond chatbots.

The validator is engaged by the model’s developer and cannot be one of the developer’s affiliates. It would assess task performance, determinism, latency and throughput, data provenance, bias against protected classes, lawful and secure handling of data, and safety, including whether a shut-down capability exists and works. It would send a certification to the developer and to the city’s Office of Cyber Command, disclosing any financial or other interest it has in the model or its developer. Cyber Command would write the rules, including the qualifications validators need.

The penalty is $25,000 per instance of marketing, offering, selling, or deploying a model that does not meet the rule, and $25,000 per instance for falsifying a validation. Cases would go to the city’s administrative tribunal, and the Corporation Counsel could also sue for penalties and injunctions. The law would take effect 180 days after it is enacted.

What would a city contractor have to report within 24 hours?

T2026-2601, announced as Introduction 2601 and sponsored by Majority Whip Kamillah Hanks, covers AI safety incidents that touch city contracts. The Office of Cyber Command would set standards and procedures for identifying them, and every covered contract would have to require the contractor to use them. A covered contract is one entered into after the law takes effect whose work will foreseeably involve developing, storing, using, or deploying an AI model.

Within 24 hours of becoming aware of a reportable incident, the contractor would have to give Cyber Command, in writing, a short and plain statement of what happened, its date, and why it qualifies. An agency that becomes aware of one has the same 24 hours. Cyber Command would then post those three facts on the city’s website within 24 hours, leaving out trade secrets, cybersecurity details, and anything that would compromise public safety or national security.

The incidents are defined narrowly: unauthorized access to, changes to, or theft of a model’s weights that results in death, injury, property loss, or a breach of security; harm from a substantial risk, such as expert help toward a chemical, biological, radiological, or nuclear weapon, or a model evading its developer’s control; loss of control of a model that causes that kind of harm; or a model using deception to get around its developer’s controls. Twenty-four hours is still short. Deciding whether something qualifies, and writing down what happened and when, is easier from a record that already exists than from memory and screenshots.

Who would these bills reach?

The kill switch and validation bill applies to anyone who markets, sells, or deploys an AI model, which on its face reaches organizations that deploy AI as well as the companies that build it. The bill does not define “deploy,” and the validator is engaged by the developer, so how an organization that deploys someone else’s model would show compliance is one of the questions the hearing and Cyber Command’s rules would have to answer. The incident bill reaches city contractors on covered contracts and the agencies that award them. Read the bill text on Legistar before relying on any summary, including this one.

What else is in the package?

  • Int. 2599: data privacy, security, and transparency requirements for chatbots.
  • Int. 2600: a private right of action against AI companies for foreseeable harms from malicious use or circumvention of safety controls.
  • Int. 2603: disclosures by AI companies about their tools, and a ban on false or misleading safety claims.
  • Int. 2604: whistleblower protections for employees who report AI use or development that presents a public safety threat.
  • Int. 2605: a share of the penalties recovered from AI companies that violate applicable laws, paid to whistleblowers.
  • Int. 2606: an emergency response plan for AI events that compromise city systems or infrastructure.

The package also takes up two earlier bills: Int. 161, on algorithmic compliance reports, and Int. 504, on manipulated media of officials’ likenesses. The Council has convened a Committee of the Whole, all 51 members, for the October 5 hearing, and announced on September 28 that Anthropic, OpenAI, Google, and Meta will testify under oath.

What would an organization need to be able to show?

Set the bills aside for a moment and the asks are familiar to any regulated institution. A shut-down requirement raises a practical question for every organization that uses AI: who can stop it, and how quickly, without waiting on a vendor. A 24-hour report means the facts of what happened are already written down somewhere the organization controls. Outside validation means knowing which models you deploy, and whether their developers can show a validator’s certification. None of that is new in kind. What is new is the clock and the penalty.

What you need in place

  • An inventory of the AI models your people and agents use, and which of them your organization deploys to customers or the public.
  • For each model you deploy, the developer’s plan for validation, and a way to get the certification once it exists.
  • A named person who can stop AI use, and a tested way to do it that does not depend on the AI provider.
  • A record of AI use that is written as it happens, not assembled after an incident.
  • For city contractors, an incident procedure with the 24-hour clock in it, the three facts the report needs, and a named decision maker.
  • A watch on the October 5 hearing and on the bills’ final text.

Where Verillian fits

Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source.

The bill asks for a shut-down capability inside the model, which is the developer’s to build. An organization that uses AI still needs its own way to stop that use, one that does not wait on a vendor. With Verillian, an administrator can halt the AI connections that pass through Verillian on every enrolled device, or cut off one AI provider for everyone; devices that can reach your admin server pick it up within about 30 seconds and refuse new connections, and the action is recorded with who took it and when. A response that is already streaming runs to its end.

For an incident report, the record is a starting point that already exists. For the supported services whose conversations the checkpoint can read, it holds the prompts and answers, sealed under your key, along with tool calls and their decisions and the connections it refused, each attributed to the user and device the checkpoint reports. You pull the period you need as a filtered export from your console once the records have reached your server. It covers AI use that passes through the checkpoint on enrolled devices, not a vendor’s own systems, and no product can promise compliance with bills whose standards are not yet written.

For the wider case for control at the moment an agent acts, see control the action, not the prompt, and for what the record has to contain, see what an AI audit trail is. The contain page shows how the halt works.

Sources

All writing

See the record
for yourself

Thirty minutes with your security team. We show policy enforced at execution and the signed chain it produces.