Governor Kathy Hochul is intensifying her efforts to regulate data centre growth in New York State. On Monday, the Governor announced a new set of requirements concerning transparency, security, and incident reporting for data centre developers and operators. These measures follow a moratorium on new data centre developments above a certain size, imposed in July.
Developers and operators are now required to report security incidents at their sites to the newly created Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) within 72 hours. Furthermore, they must submit quarterly reports on potential catastrophic risks to DIGIT and provide disclosure statements to the state government every two years.
Implementation and background of the measures
All aforementioned regulations will come into effect on 1 January, when the Responsible AI Safety and Education (RAISE) Act is fully implemented, as announced by Governor Hochul's office. Hochul commented in a statement: “Donald Trump and Washington Republicans may stand still as AI becomes more unpredictable, but New York will not.” She emphasised that the public has a right to know what steps companies are taking to ensure the security of their technologies, and that these companies should be held accountable when things go wrong.
The Governor indicated that the state's laws will evolve with the advancement of technology. Her office will also urge federal and international leaders to take similar steps as the United Nations General Assembly convenes in Manhattan this week.
Moratorium and future outlook
Hochul's moratorium on new data centres larger than 50 megawatts – which her administration imposed due to concerns about natural resource scarcity and public power supply – is expected to expire in July 2027. These restrictions are intended to ensure that the growth of digital infrastructure proceeds sustainably and responsibly, particularly given the increasing energy demands of modern data centres.
- —Reporting of security incidents to DIGIT within 72 hours.
- —Quarterly submission of various reports on catastrophic risks to DIGIT.
- —Disclosure statements to be sent to the state government every two years.
- —The moratorium on data centres over 50 MW expires in July 2027.














