← Blog
compliancefinancial-servicesgovernance

How to Build the NYDFS Part 500 File for an AI Agent Platform

Build the exam file that maps three NYDFS AI letters onto 23 NYCRR Part 500: risk assessment, access, vendor contracts and incident-response evidence.

MightyBot ·
Three frost-white letter sheets folding into a single navy binder, joined at the spine by an amber ring.

Summary: NYDFS told covered entities to fold an AI agent platform into the existing 23 NYCRR Part 500 program. The three industry letters add no new requirements. The CCO and COO exam file is a Part 500 evidence index for risk assessment, access, the third-party AI risk vendor file, and incident-response evidence, including the May 2026 frontier-model items.

Why Part 500 is the rule and the letters add no new obligations

DFS promulgated Part 500 on March 1, 2017 as the cybersecurity rule for Banking, Insurance, and Financial Services Law licensees. The letters tell covered entities how to use that framework for AI.

The 16 October 2024 letter states that the guidance does not impose any new requirements beyond obligations already in Part 500. The 21 October 2025 letter states that it does not impose new requirements and that it clarifies section 500.11. The 21 May 2026 advisory states that it does not impose any new requirements for regulated entities. That advisory is addressed to CISOs of DFS-regulated entities. The exam file still belongs to the CCO, the COO, and the Senior Governing Body.

Risk assessment, inventory, and NPI controls for an agent platform

Risk assessments must account for deepfakes and other AI threats, including the entity’s own use of AI, AI used by third-party service providers (TPSPs) and vendors, and AI-application vulnerabilities. Update the assessment at least annually and whenever a new agent platform causes a material change.

File four artifacts: a risk assessment that names own-use AI, TPSP AI, and deepfakes; a data inventory of NPI used for AI; an inventory of Information Systems that use or rely on AI; and Senior Governing Body minutes recording AI-related cybersecurity reports. Those minutes are AI governance evidence.

Access, MFA, and deepfake-resistant authentication

The 2024 letter names AI-enabled social engineering and deepfakes as a significant threat.

MFA is required. As of November 2025 it must cover all Authorized Users on Information Systems or NPI, including customers, employees, contractors, and TPSPs. Prefer digital-based certificates and physical security keys over SMS, voice, or video authenticators that deepfakes can impersonate. The 2024 letter also says to limit each Authorized User’s access privileges to those necessary for the job function, and to limit the number of Authorized Users with elevated permissions and access to NPI. Review agent service accounts against both limits, and keep non-human identity records for agent credentials.

The TPSP file: AI vendors, fourth parties, and training-data clauses

Section 500.11 requires written policies for information systems and NPI accessible to or held by TPSPs. The 2025 letter walks diligence, contracting, oversight, and termination, and names AI among TPSP technologies.

Diligence includes fourth parties. Contracts should state acceptable use of AI and whether the covered entity’s data may be used to train AI models. Where a TPSP uses AI, the 2024 letter says to consider additional representations and warranties on the secure use of the covered entity’s NPI.

Covered entities may not delegate Part 500 compliance to an affiliate or a TPSP. Senior Governing Bodies and Senior Officers remain responsible.

Frontier-model vigilance and the incident-response evidence examiners will ask for

AI-enhanced attacks amplify the potency, scale, and speed of existing cyberattacks. Incident-response plans should address Cybersecurity Events relating to AI.

The May 2026 advisory says the best preparation is a robust Part 500 program and points to sections 1, 2, and 3.2 of the companion heightened-threat guidance.

File five IR artifacts: expedited vulnerability timelines; dependency maps and TPSP coordination; human oversight of AI-generated code before production; logging that flags suspicious activity, supported by agent audit trails; and tested resilience procedures under section 3.2.

Notify DFS no later than 72 hours after determining that a Cybersecurity Incident has occurred at the covered entity, an affiliate, or a TPSP. The advisory adds no new notice clock.

FAQ

Frequently Asked Questions

Does NYDFS have a separate AI rule for banks?

23 NYCRR Part 500 is the binding cybersecurity rule for DFS licensees. The October 2024, October 2025, and May 2026 industry letters each state that they add no new requirements.

What did the 21 May 2026 frontier-model advisory actually require?

The 21 May 2026 advisory does not impose any new requirements for regulated entities. It tells entities to update risk assessments, stay in full Part 500 compliance, and consider companion guidance sections 1, 2, and 3.2.

How should a covered entity treat an AI vendor under Part 500.11?

Part 500 section 11 requires written policies for information systems and NPI accessible to or held by third-party service providers. The 2025 letter names AI among those technologies and walks the relationship from diligence through termination.

Can a covered entity delegate Part 500 compliance to an AI platform vendor?

Covered entities may not delegate Part 500 compliance to an affiliate or a third-party service provider. Senior Governing Bodies and Senior Officers remain responsible for oversight and verification.

Do we need an acceptable-use or training-data clause in the AI vendor contract?

The 2025 third-party letter says covered entities should consider including a clause on the acceptable use of AI. That clause should address whether the covered entity's data may be used to train AI models or be otherwise disclosed.

Does the May 2026 advisory create a new notice deadline for AI incidents?

The advisory adds no new requirements and does not create an AI-specific notice clock. Covered entities must still notify DFS no later than 72 hours after determining that a Cybersecurity Incident has occurred.