Category: Finance | Reading time: 4 min
The Phase In Is Over
23 NYCRR Part 500, the New York Department of Financial Services cybersecurity regulation, completed its multi year rollout on 1 November 2025.
The Second Amendment took effect 1 November 2023 and its obligations turned on in stages. The 72 hour cybersecurity event and ransomware payment notice duties under 500.17 landed by December 2023. General controls by April 2024. Governance and CISO reporting under 500.04, encryption under 500.15, and incident response and business continuity under 500.16 by November 2024. Access privilege management under 500.07, vulnerability scanning and training by May 2025. Finally multi factor authentication under 500.12 and asset management and data retention limits under 500.13 by November 2025.
Every one of those dates has passed. Annual certification falls on 15 April.
An entity deploying an AI agent today is deploying it into a fully effective control regime, not building toward a future one.
Part 500 Does Not Mention AI
The regulation contains no AI specific provisions. NYDFS supervises AI through a cybersecurity lens rather than as a separate model governance regime.
The connection was made explicit in a DFS industry letter of 16 October 2024, Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks. A further AI letter followed in May 2026.
The distinction matters and is frequently collapsed. Part 500 is the binding rule. The AI letters are guidance. They interpret how the existing rule applies to AI. They do not create new binding requirements or new deadlines.
Covered entities are expected to fold AI related cyber risk into the Part 500 risk assessment and controls they already run.
What Examiners Look For
AI governance, AI vendor risk management and AI specific incident response have become examination topics across the 2024 to 2026 period, with examiners extending Part 500 expectations to cover AI and machine learning systems that the regulation does not explicitly name.
The controls most directly implicated by agent deployments are access privilege management under 500.07, asset inventory under 500.13, encryption under 500.15, and the 72 hour notification duty under 500.17.
An autonomous agent holding credentials is an access privilege question. An agent operating in production is an asset inventory question. An agent taking an unauthorised action is a notification question with a clock attached.
Third Party Risk
Days before the final requirements took effect, NYDFS issued guidance on managing third party service provider risk, followed by prescriptive FAQs on implementing compliant multi factor authentication.
The third party guidance suggests contractually requiring vendors to adopt MFA to the same level Part 500 requires. For institutions whose agent vendors sit between them and customer data, that contractual position now needs to be documented rather than assumed.
Running Alongside SOC 2
For newer regulated entities, the Part 500 programme increasingly runs alongside SOC 2 Type II so that a single documentation package supports both regulatory examination and counterparty diligence.
That consolidation only works if the underlying evidence is produced continuously. Reconstructing a year of agent activity for two different audiences at once is where most programmes discover their logging was never designed for either.