This month two people I read closely made the same analogy. Dario Amodei, the chief executive of Anthropic, argued in We Must Pace the Frontier that frontier AI companies should give embedded third-party evaluators ongoing, employee-like access to verify safety practices and report incidents, and he grounded the idea in banking, where regulatory supervisors are sometimes embedded alongside employees. Michael Hsu, the former Acting Comptroller of the Currency, responded in Trust, but verify with the lesson he learned supervising investment banks at the SEC before the 2008 financial crisis: verification without authority to compel remediation is a program with a short shelf life.

Both essays argue at the federal altitude. Neither mentions that a state financial regulator has already been handed frontier AI oversight, and that the statute doing it reads exactly the way you would expect a supervisor to write one. I spent my career on the other side of that table, first at the New York State Department of Financial Services (NYDFS), then as a senior IT and cybersecurity examiner at the Office of the Comptroller of the Currency (OCC). The view from the state seat adds something the federal debate is missing.

What the embedded seat actually gives you

Amodei's proposal is specific: desks, badges, company laptops, permissions comparable to internal risk teams, and the right to publish findings without editorial control. Anyone who has done supervisory work recognizes the design, because proximity is the entire point of examination.

What you get from being in the building is not more documents. It is the answer to a question you did not know to ask. You learn more from how a question is handled than from the answer itself, from who gets pulled into the room, from whether the risk function speaks freely or checks a face before answering. Sitting with a team for three weeks tells you whether the control described in the policy is the control people actually run.

The limits are just as real, and worth naming honestly. You get managed. Information flows are curated for you whether or not anyone intends it. And the value of anything you observe collapses to zero if it cannot travel, either to someone with authority to act or to other reviewers who can tell you whether what you are seeing is normal. Hsu makes the second point well. The first is why access alone was never the whole job.

What New York built while the federal conversation continued

The Responsible AI Safety and Education Act, New York's frontier AI law, was signed on December 19, 2025. Governor Kathy Hochul then negotiated a chapter amendment, signed March 27, 2026, that aligned much of the statute with California's SB-53 and narrowed its reach. The law takes effect January 1, 2027. It applies to models trained using more than 1026 integer or floating-point operations, counting the original training run and any material modifications after it, with the heaviest obligations falling on developers whose annual gross revenue exceeded $500 million in the prior year.

The obligations are familiar to anyone who has read a supervisory letter. A large frontier developer must publish a frontier AI framework covering risk thresholds, mitigations, cybersecurity for unreleased model weights, internal governance, and the use of third-party assessors. It must submit a written summary to the state every three months of any catastrophic risk assessment arising from internal use of its own models. It must report a critical safety incident within 72 hours, and within 24 hours to law enforcement where there is imminent risk of death or serious injury.

Then comes the sentence that stopped me. Among the violations the Attorney General can pursue, at up to $1 million for a first offense and $3 million after that, is a large frontier developer's failure to comply with its own published framework.

That is the examination standard, written into statute. It is what I wrote about in August in a different context: an examiner does not evaluate whether your architecture was well chosen, because that is a management decision. What gets evaluated is whether you did what your own policy said you would do, and whether you can demonstrate it. New York has now attached a penalty to that question for frontier developers, and it did so without needing anyone embedded anywhere.

The tells of a supervisor

Three features of the RAISE Act give away the institution that drafted it.

The oversight body is a new Office inside DFS with rulemaking authority. Large frontier developers cannot operate a frontier model in New York without a current disclosure statement on file, renewed every two years, naming their New York offices, their beneficial owners at 5 percent or greater, prior owners over five years, and three points of contact. They pay a pro rata assessment to fund the program. That is a registration regime funded by the regulated entities, which is how financial supervision has been paid for in this state for over a century. Hsu's map puts formal licensing off in the distance. Something with its shape is already on the books.

Second, the Office may designate federal laws, regulations, or guidance as substantially equivalent to or stricter than the state's incident reporting requirements, and a developer that declares its intent to comply that way is deemed compliant. That is the state-federal dovetail mechanism, borrowed directly from financial regulation, and it is the most underdiscussed provision in the law. It is also the answer to the fragmentation worry, built in by people who have lived with fragmentation for decades.

Third, the confidential channel. Quarterly internal-use risk summaries come in through a mechanism the Office must build for confidential submission, and reports are exempt from public disclosure. Supervisors have always understood that the most useful information is the information an institution will only share if it will not appear in tomorrow's paper. That instinct sits in direct tension with Amodei's transparency rationale, and both instincts are defensible. Banking has spent a century arguing about where the line goes.

What a report cannot show you

Here is why the two ideas are complements and not rivals.

New York will see what developers determine and characterize. A quarterly summary tells you the conclusion of an assessment. A 72-hour incident report tells you that something crossed a threshold someone defined. Neither tells you how the threshold was set, who argued against it, or whether the people raising concerns were heard or routed around. Hsu's account of 2007 is precisely a story about risk managers who agreed with supervisors and were getting overruled inside their own firms, which is not a fact that appears in any filing.

Embedded reviewers see that. They cannot compel anything, and New York did not include the whistleblower protections California put in SB-53, so neither mechanism covers the other's blind spot completely. But call reports never replaced examiners in banking, and they will not here. The interesting question is not which model wins. It is whether a reviewer sitting inside a lab and an office sitting inside DFS ever end up looking at the same thing, and today nothing connects them.

What this means before January 2027

The law takes effect on January 1, 2027, a little over three months from now. The obligation it creates is easy to misread as a mandate to build a safety program, and for most organizations doing frontier work that program already exists. The harder obligation is the second one: publish a framework, then be able to show you followed it.

Those are different problems. A published framework converts every commitment inside it into an evidentiary burden. Each threshold you name, each review you promise before deployment, each third-party assessment you describe becomes something a regulator can ask you to demonstrate actually happened, on a date, decided by someone with the authority to decide it. Organizations routinely fail that test while governing carefully, because the decisions were distributed across people who each acted reasonably and none of whom wrote anything down.

So the work between now and January is unglamorous and entirely available: inventory every commitment the framework makes, assign a named owner to each one, record the decision, the rationale, and the date, and confirm that the published document describes what the organization does rather than what it intends to do. A framework that overstates practice is worse than a modest one, because in New York the mismatch is itself the violation.

The gap that shows up in examinations is almost never missing controls. It is missing evidence of controls that exist. Whoever ends up asking the questions, an embedded evaluator with a badge or an office in Albany with a filing deadline, that is what they will be asking for.

Sources