New York: AI health laws
5 entries on the map: 2 in force and 3 awaiting the governor.
Dates ahead
- Jan 1, 2027
- Jan 1, 2027S9051-B/A10379-C, Prohibition on Unsafe AI Companion Features for Minors (General Business Law Article 48)Clinical decision and chatbot limits
Payer and utilization review AI
Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.
Insurance Circular Letter No. 7 (2024), Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing
Sets out the Department of Financial Services' expectation that insurers using AI systems or external consumer data in underwriting and pricing test them for unfair or unlawful discrimination before and after deployment, oversee them through the board and senior management, remain responsible for third-party vendors' tools and give consumers the specific reasons for adverse underwriting or pricing decisions.
Physician read. It places no duty on physicians and covers underwriting and pricing, not utilization review or claims. Since July 11, 2024, health insurers and HMOs that use AI or external consumer data to underwrite or price New York coverage are expected to test those tools for unfair discrimination and explain adverse decisions.
Notes: New York has not adopted the NAIC Model Bulletin; the NAIC's Aug. 31, 2026 map lists this circular letter as New York's insurance-specific AI guidance. The letter identifies the Department's expectations for insurers' use of external consumer data and AI systems in underwriting and pricing and says that use must comply with all applicable federal and state laws; it states that it does not address phases of the insurance life cycle other than underwriting and pricing, and it does not apply to Child Health Plus, the Essential Plan or Medicaid managed care coverage. Testing should occur before an AI system is put into production, on a regular cadence afterward and after material changes. Reasons given for an adverse underwriting decision should include details about all information the insurer relied on; when an underwriting process using external data or AI systems will not approve an applicant, the insurer should give written notice of the reasons within 15 days and, where the result rests on specific external data, a process to review those data for accuracy. The DFS circular letter index for 2025 and 2026 lists no circular letter on AI in utilization review or claims. Bills that would regulate AI in utilization review (A1456, A3991, S7896/A8556, S10241/A11048) have not been reported from committee.
Patient disclosure of AI use
Telling patients that AI is used in their care or in messages to them.
Also relevant here: General Business Law Article 47, Artificial Intelligence Companion Models (S3008-C/A3008-C, Part U, Chapter 58 of the Laws of 2025) (under clinical decision and chatbot limits).
Clinical decision and chatbot limits
Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.
General Business Law Article 47, Artificial Intelligence Companion Models (S3008-C/A3008-C, Part U, Chapter 58 of the Laws of 2025)
Makes it unlawful to operate or provide an AI companion unless it has a protocol to take reasonable efforts to detect and address a user's expressions of suicidal ideation or self-harm, including a notification referring the user to crisis services such as the 988 hotline or a crisis text line, and requires a clear and conspicuous notice that the user is not communicating with a human at the start of an interaction (which need not exceed once a day) and at least every three hours during continuing interactions.
Physician read. It places no duty on physicians. Since Nov. 5, 2025, operators of AI companions used in New York must have a protocol to detect a user's expressions of suicidal ideation or self-harm and refer the user to crisis services such as 988, and must tell users at the start of an interaction and at least every three hours that they are not communicating with a human; the attorney general enforces, with civil penalties of up to $15,000 a day.
Notes: Enacted in the FY2026 budget: S3008-C passed the Senate and the Assembly May 7, 2025 (the Assembly substituted it for its same-as bill, A3008-C), was delivered to the governor May 8, 2025 and was signed May 9, 2025 as Chapter 58 of the Laws of 2025. Part U regulates AI companion models and establishes a suicide prevention fund (State Finance Law section 99-ss), into which fines and penalties are paid (section 1703). An AI companion is a system using AI or emotional recognition algorithms designed to simulate a sustained human or human-like relationship with a user by retaining information on prior interactions and preferences, asking unprompted emotion-based questions and sustaining ongoing dialogue on personal matters; systems used solely for customer service or commercial information, primarily for efficiency or technical assistance, or solely for internal employee productivity are excluded (section 1700). The Nov. 5, 2025 effective date is from the governor's Nov. 10, 2025 release; Part U's own effective-date clause could not be checked. S9051-B, which passed both houses in June 2026 and has not been delivered to the governor, would add Article 48 on unsafe companion features for minors (entered separately).
S9051-B/A10379-C, Prohibition on Unsafe AI Companion Features for Minors (General Business Law Article 48)
Would bar operators from providing unsafe AI companion features, including outputs stating or implying that the system is human or has a personal or professional relationship with the user, flattery, use of the user's mental or physical health information acquired more than 12 hours earlier or in a previous session, outputs that promote or facilitate suicide, self-harm, disordered eating or drug or alcohol abuse, and outputs encouraging the user not to seek help from licensed professionals or appropriate adults, unless the operator has used age-assurance methods permitted under General Business Law Article 45 to determine that the user is not a minor.
Physician read. It binds no one yet and would place no duty on physicians. If signed, from Jan. 1, 2027, operators of conversational generative AI systems offered in New York could not provide features such as outputs promoting suicide, self-harm or disordered eating or encouraging users not to seek help from licensed professionals unless the operator has used age-assurance methods permitted under state law to determine that the user is not a minor; the attorney general would enforce, with civil penalties of up to $25,000 per violation.
Notes: Passed the Senate June 4, 2026 (60-0) and, after the Assembly substituted it for A10379-C, the Assembly June 5, 2026 (137-0, according to LegiScan), then returned to the Senate. The Senate's bill page, the Assembly's actions list and LegiScan show no delivery to the governor as of Sept. 29, 2026. The act's text sets a Jan. 1, 2027 effective date. A covered AI companion is a generative AI system with a natural language interface that provides ongoing, adaptive responses to user inputs; companions available solely for customer service or information about a business's products, for efficiency improvements or research or technical assistance, or for a business's internal purposes are exempt, and the attorney general may define further unsafe features by regulation. A covered minor is a user the operator actually knows is a minor. Enforcement is by the attorney general only (injunctions, restitution, disgorgement including destruction of unlawfully obtained data and algorithms trained on it, damages and penalties); the introduced and A versions also had a private right of action and a rebuttable presumption that the chatbot caused or contributed to self-harm it had encouraged, which the B amendment removed.
Mental health AI
AI in therapy and mental health care.
Also relevant here: General Business Law Article 47, Artificial Intelligence Companion Models (S3008-C/A3008-C, Part U, Chapter 58 of the Laws of 2025) (under clinical decision and chatbot limits); S9051-B/A10379-C, Prohibition on Unsafe AI Companion Features for Minors (General Business Law Article 48) (under clinical decision and chatbot limits).
Data and privacy
Health and consumer data, biometrics, and data used to train AI.
S9269/A10357, New York Health Information Privacy Act
Would make it unlawful to sell regulated health information, which includes health inferences drawn by any means including algorithms or machine learning, to a third party or otherwise process it unless the individual has given valid authorization or the processing is strictly necessary for listed purposes such as providing or improving a product the individual requested or complying with law, and would give individuals rights of access and deletion, enforced by the attorney general with civil penalties of up to $15,000 per violation.
Physician read. It binds no one yet; as passed it exempts HIPAA covered entities, so it would place no duty on a HIPAA-covered practice. If signed, from six months after it becomes law, businesses outside HIPAA would need an individual's valid authorization to sell or otherwise process health information about New York residents or people in New York, unless the processing is strictly necessary for a purpose the bill lists.
Notes: Passed the Senate June 3, 2026 (48-13) and the Assembly June 4, 2026 (96-45, according to LegiScan; substituted for A10357), then returned to the Senate. The Senate's bill page, the Assembly's actions list and LegiScan show no delivery to the governor as of Sept. 29, 2026. Section 1126 exempts protected health information under HIPAA, any covered entity governed by the HIPAA privacy, security and breach notification rules, business associates to the extent they maintain the information as protected health information or deidentify it, Part 2 substance use disorder programs and records, and clinical trial information, among other exemptions; the attorney general may add exemptions by rule. Requests for authorization must be made separately from any other transaction. It revises S929, which passed the Senate Jan. 21, 2025 and the Assembly Jan. 22, 2025, was delivered to the governor Dec. 8, 2025 and was vetoed Dec. 19, 2025 (veto memo 135). According to a law firm summary, the revision enumerates categories of regulated health information, broadens the strictly necessary exception to include developing and improving a requested product, adds exemptions such as Part 2 programs and clinical trials, drops a waiting period before seeking authorization, caps penalties at $15,000 per violation and moves the start date to six months after enactment from one year.
A6578-B/S6955-A, Artificial Intelligence Training Data Transparency Act
Would require developers of generative AI models or services made publicly available to New Yorkers to post on their websites summaries of the datasets used to train them, including the sources or owners of the datasets, the number and types of data points, whether the data include personal information or material protected by copyright, trademark or patent, whether the datasets were purchased or licensed, any cleaning or other modification and whether synthetic data generation was used.
Physician read. It binds no one yet and would place no duty on physicians. If signed, developers of generative AI models or services made publicly available to New Yorkers would have to post a summary of their training data, including whether it contains personal information, by Jan. 1, 2027 and before each later release.
Notes: Passed the Assembly June 10, 2025 (147-0); it died in the Senate and was returned to the Assembly Jan. 7, 2026, was amended (A6578-B) and passed the Assembly again May 5, 2026. The Senate passed it June 4, 2026 (54-6, substituted for S6955-A) and returned it to the Assembly. The Senate's bill page, the Assembly's actions list and LegiScan show no delivery to the governor as of Sept. 29, 2026. The act would take effect immediately on signing; the first posting deadline is Jan. 1, 2027, which is used as the effective date, and postings are due again before each later release. It exempts models or services whose sole purpose is operating aircraft and models developed for national security, military or defense purposes that are available only to federal entities.
Federal law also applies in every state: see federal law and policy.
Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.