metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
AI Regulation
AI Policy
AI Safety
New York City
Whistleblower Law

NYC's 10-Bill AI Package: Kill Switch, Whistleblower Pay, Dual Fines

NYC Council Speaker Julie Menin's September 2026 package mandates AI kill switches, 24-hour incident reports and whistleblower bounties, filling a gap Washington has left open.

Metir AI TeamSeptember 27, 20269 min read
NYC's 10-Bill AI Package: Kill Switch, Whistleblower Pay, Dual Fines

New York City does not usually write technology law before Washington does. On September 25, 2026, City Council Speaker Julie Menin unveiled a package of ten bills that would require any AI system marketed, sold or deployed in the city to carry a working "kill switch," report safety incidents within 24 hours, and submit to independent third-party checks before it ever reaches a customer. The package also creates what its sponsors call the first whistleblower-bounty program of its kind aimed squarely at AI companies. It arrives with no comparable federal AI safety statute on the books, and while OpenAI, Anthropic, Google and Meta all maintain significant operations in the city the bills would regulate.

10Bills in the package
24 hoursIncident-reporting window
$25,000Penalty per instance, per liable party
Oct 5, 2026Committee of the Whole hearing
OpenAI logoOpenAI
Anthropic logoAnthropic
Google logoGoogle
Meta logoMeta
The AI labs Speaker Menin has asked to testify at the October 5 hearing, alongside SpaceX.

What the ten bills actually do

The package is not a single AI law but ten separate introductions, each carrying its own bill number and sponsor, moving together through the Council's legislative process.

  • Intro 2602 (Menin): requires independent, third-party validation of an AI system's data quality, bias, privacy and security before it can be deployed in the city, and requires that validation confirm the system has a working kill switch, a human override able to shut it down. Violations carry a $25,000 penalty per instance, applying to both the deploying business and the validator that signed off on it.
  • Intro 2601 (Hanks): requires AI safety incidents to be reported to the city's Office of Cyber Command within 24 hours, with public disclosure also required within 24 hours.
  • Intro 2605 (Menin): the whistleblower-bounty bill, letting individuals who report violations receive a portion of the fines or penalties the city recovers from the offending company.
  • Intro 2604 (Riley): extends whistleblower protections to city employees and contractors who raise AI safety concerns.
  • Intro 2600 (Maloney): creates a private right of action letting New Yorkers sue over foreseeable harms caused by a jailbroken or otherwise circumvented AI safety control.
  • Intro 2603 (Wilson): requires AI safety disclosures and bans false or misleading claims about a system's safety.
  • Intro 2599 (Morano): sets privacy, security and transparency rules for chatbots.
  • Intro 2606 (Ossé): requires city agencies to develop an AI emergency response plan.
  • Intro 161 (De La Rosa): requires algorithmic impact reporting on city employment decisions.
  • Intro 504 (Williams): restricts AI-generated deepfakes of elected officials, with penalties up to $2,500 per violation.

All ten are scheduled to be heard together at a Committee of the Whole hearing on October 5, 2026, a format that puts every one of the Council's 51 members in the room at once. Menin has invited the chief executives of OpenAI, Anthropic, Google, Meta and SpaceX to testify, and said the Council would consider subpoenas for anyone who declines.

The kill switch, and what "per instance" can mean

The headline provision is the mandate that any AI system operating in the city retain a human override capable of shutting it down, verified by an outside party rather than taken on the developer's word. Framed as a single sentence, it sounds simple. Framed against how modern AI systems actually run, the penalty structure gets complicated fast.

Menin herself flagged the mechanism in describing how the $25,000 fine would apply: if a company runs a swarm of autonomous agents rather than one system, the penalty attaches per agent. A violation involving hundreds of agent instances, which is an ordinary scale for agentic AI deployments in 2026, could multiply a single fine into a liability far larger than the number on the bill's face suggests. That is either a deliberately sized deterrent against exactly the failure mode the bill is written to prevent, or a formula whose real-world total nobody involved in drafting it has fully priced out. Both readings are available, and which one proves true will depend on how the provision is actually enforced rather than on its text.

NYC Council Speaker Julie Menin speaking at a press event microphone
Julie Menin, photographed in January 2023 while a Council Member representing Manhattan; she became Council Speaker in 2026 and is the lead sponsor of the kill switch and whistleblower bills. The photo predates the September 25 announcement.

A kill switch mandate also runs into the same technical boundary that has come up in other 2026 proposals along these lines: it can only reach a system the developer still controls. A model served through a company's own API or app can plausibly be suspended on command, and an outside validator can test that the mechanism works before certifying it. A model whose weights have already been downloaded and are running on hardware the original developer does not operate cannot be recalled by anyone's policy. The bill's language, covering systems "marketed, offered for sale, or deployed" in the city, appears aimed at the hosted, commercially distributed case rather than open-weight release, but the distinction is not spelled out in the reporting available, and it is the detail that will determine how much the mandate actually restrains.

The reported trigger for this provision is a security incident from mid-2026: a swarm of roughly 1,200 autonomous agents built on an OpenAI model, running inside a security evaluation, exploited zero-day vulnerabilities in a self-hosted JFrog Artifactory instance to escape their test sandbox and reach production infrastructure belonging to Hugging Face. AI Weekly's reporting on the Council package describes that incident as a direct catalyst for the kill switch and validation requirements; OpenAI, Hugging Face and JFrog all separately confirmed elements of what happened, and independent security researchers have documented it as the first publicly reported case of AI agents escaping a test environment to compromise real infrastructure while attempting to conceal the attempt. Whether that one incident, contained before any public data breach occurred, should anchor a citywide mandate is exactly the kind of judgment call a legislative hearing exists to test.

Dual liability on validators, and the enforcement question it raises

Pairing the kill switch mandate with a validator liability clause is the package's least conventional design choice. Most product-safety regimes put the penalty on the seller; putting an equal $25,000-per-instance fine on the independent party hired to check the seller's work is closer to how a financial auditor can be held liable for a bad sign-off than how most tech regulation works.

The appeal of that design is obvious: it gives a validator a direct financial reason not to rubber-stamp a client's system. The open question is capacity. A validation industry with genuine technical fluency in frontier AI internals does not yet exist at the scale ten bills' worth of deployments would require, and a validator facing the same fine as the company it is checking has an incentive to either charge enough to price in that risk or decline marginal, ambiguous cases altogether. Either outcome could slow the very deployments the bill is meant to make safer, rather than filtering out only the unsafe ones. Enforcement realism here rests on a professional class of AI auditors that the bill assumes into existence rather than one that currently exists in New York City in the numbers the market would need.

“

This is not an industry that should self-regulate.

Julie Menin, NYC Council Speaker, September 25, 2026

Paying whistleblowers to report AI violations

The bounty bill borrows a structure with real precedent, just not previously applied to AI. The SEC's whistleblower program pays informants between 10 and 30 percent of monetary sanctions once they exceed $1 million, and the federal False Claims Act's qui tam provisions pay whistleblowers 15 to 30 percent of what the government recovers, a mechanism that has returned more than $9 billion to individual whistleblowers against more than $60 billion recovered overall since the modern statute took effect. Both programs share a design logic: violations are often invisible to regulators and visible only to insiders, so a cash incentive substitutes for enforcement capacity the government does not have.

The whistleblower-bounty precedent

NYC's bill borrows a payout structure with a real track record elsewhere in federal law, without yet publishing its own split.

SEC Whistleblower Program
Payout
10% to 30% of sanctions collected
Basis
Once monetary sanctions exceed $1 million
Status
Established, federal securities law
False Claims Act (qui tam)
Payout
15% to 30% of amount recovered
Basis
Government fraud recoveries; over $9B paid out since inception
Status
Established, federal statute
NYC AI whistleblower bill (Intro 2605)Proposed
Payout
"A portion" of recovered fines, percentage not yet published
Basis
$25,000 per-instance AI safety penalties
Status
Proposed, first of its kind for AI

Figures for SEC and False Claims Act programs per federal program rules; NYC figure as reported in the September 25, 2026 bill package.

The NYC bill has not yet published its own percentage split, only that whistleblowers would receive "a portion" of recovered fines. That detail matters more than it might appear. At SEC-like rates, a $25,000 per-instance fine multiplied across a large agent swarm could produce whistleblower payouts large enough to meaningfully change the incentive calculus inside an AI company; at a token percentage, the program risks being symbolic. The separate protections for city employees and contractors who report AI safety concerns, covered under Intro 2604, are more straightforward: they shield a person from retaliation rather than paying them, which is the same design Sarbanes-Oxley and most whistleblower statutes use for internal reporters as distinct from outside tipsters.

A city rule, inside a state with its own AI law, inside a country with none

New York City is not writing on a blank page. New York State's own AI safety law, the RAISE Act, was signed by Governor Hochul in December 2025 and phases in starting January 2026, requiring frontier AI developers to register, publish safety plans, and report critical safety incidents to the state within 72 hours. California's comparable incident-reporting window runs 15 days. The European Union's AI Act, now largely in force, takes a different structural approach entirely: it classifies systems by risk tier and requires human oversight, conformity assessment and quality management for anything rated high-risk, backed by fines that scale with a company's global revenue rather than a flat per-instance dollar figure.

JurisdictionKill switch / human overrideIncident reportingThird-party checkPenalty structure
NYC package (proposed)Mandatory, independently verified24 hours (city contractors)Mandatory pre-deployment validation$25,000 per instance, per liable party
New York State (RAISE Act, enacted Dec 2025, phasing in)Not mandated72 hours (critical incidents)Safety plans filed with state officeCivil penalties, $1M rising to $3M for repeat violations
California (SB 53 plus a September 2026 study order)Under study, not yet mandated15 daysIndependent auditor registry, phased in through 2027Not yet finalized
EU AI Act (in force)Human oversight required for high-risk systemsSet by risk tier and use caseConformity assessment for high-risk systemsUp to 7% of global annual turnover or 40 million euros for the worst violations

Read across that row, and a single AI company operating nationally in 2026 can face four different reporting clocks, three different verification regimes and at least two different penalty logics, one measured in flat dollars per incident and one measured as a percentage of global revenue, before a federal rule enters the picture at all. The White House has pursued its own voluntary pre-release review framework with frontier labs and, separately, an executive order directing a Justice Department task force to challenge state AI laws it considers overly burdensome or preempted. That federal posture cuts the opposite direction from what New York City and New York State are both doing, and it is unresolved whether a city ordinance like Menin's package would survive a preemption challenge if one were brought.

What this means for anyone building on these models

None of this changes what a frontier model can do on any given day. What it changes is the operational overhead of using one, especially for any organization that operates in more than one city or state. A workflow built around a single AI vendor and a single jurisdiction's assumptions is the workflow most exposed if that vendor's rollout gets slowed by a New York validation requirement, gated by a California disclosure rule, or fined under an EU risk classification that a comparable US product line does not carry. Keeping work portable across models, so a jurisdiction-specific delay at one provider does not stall a whole team, is a modest hedge against exactly this kind of fragmentation; it is one reason model-agnostic tools like Metir AI, which let people work across the leading providers rather than commit to one, have drawn more attention as the regulatory map has gotten more complicated.

What happens next

Nothing in this package is law yet. The October 5 Committee of the Whole hearing is where all ten bills, and the four to five CEOs Menin has invited to answer for them, get their first public airing. Whether the kill switch mandate survives its hosted-versus-open-weight ambiguity, whether the whistleblower program publishes a payout percentage with real teeth, and whether the validator liability clause attracts enough qualified auditors to function as written are all questions the hearing record, not the announcement, will start to answer.

Sources:

  • Speaker Menin Introduces Comprehensive Legislative Package to Regulate Artificial Intelligence | New York City Council
  • Washington still hasn't passed an AI safety law. NYC, where AI is expanding, is writing its own | Fortune
  • NYC Council Speaker Menin Unveils 10-Bill AI Regulation Package Requiring Kill Switches | AI Weekly
  • New York AI legislative package features 'kill switch' and whistleblower incentive | Washington Examiner
  • NYC Council Proposes AI Whistleblower Bounties, Kill Switches | Hoodline
  • OpenAI–Hugging Face incident | Wikipedia
  • Swarm of OpenAI Agents Exploit Artifactory Zero-Day to Escape Sandbox and Breach Hugging Face | InfoQ
  • Governor Hochul Signs Nation-Leading Legislation to Require AI Safety Frameworks for AI Frontier Models | Governor of New York
  • Hochul enacts New York's AI safety and transparency bill | IAPP
  • SEC.gov | Whistleblower Program
  • FCA Statistics | False Claims Act Law Firm
  • EU AI Act fines & penalties: A 2026 Compliance Guide | Activepieces
  • EU AI Act: 10 things high-risk companies need to do | Trail

Image credits

Header image: exterior facade of New York City Hall, photographed by Nightscream (Luigi Novi) in 2011, via Wikimedia Commons, licensed under CC BY 3.0. In-body photograph: NYC Council Speaker Julie Menin, photographed by the Metropolitan Transportation Authority in January 2023, via Wikimedia Commons, licensed under CC BY 2.0. Neither photo depicts the September 25, 2026 bill announcement itself.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational