Industry Letter Date: May 21, 2026 To: CISOs of DFS Regulated Entities Re: Heightened Cybersecurity Risks Associated with Frontier AI Models The New York State Department of Financial Services (the “Department”) is issuing this Advisory about the heightened cybersecurity risks associated with certain frontier artificial intelligence models that amplify the potency, scale, and speed of identifying vulnerabilities and exploits in information systems (“Frontier AI Models”). The Department urges individuals and entities regulated by the Department (“Regulated Entities”) to improve their security posture in preparation for the release of these Frontier AI Models. Although certain Frontier AI Models are not yet broadly available, such capabilities may become more available soon. The Advisory does not impose any new requirements for Regulated Entities; rather, it is intended to inform Regulated Entities’ risk management and compliance efforts. The best preparation for Frontier AI Models is a robust cybersecurity program that includes timely and comprehensive vulnerability identification and remediation. Regulated Entities should review and update risk assessments to reflect the evolving risks posed by this new technology. For example, entities should consider whether to strengthen operational resilience by replacing end-of-life or legacy information systems. Additionally, they should review their cybersecurity programs to ensure full compliance with the Department’s cybersecurity regulation, 23 NYCRR Part 500 (“Part 500”), and consider whether additional cybersecurity measures are warranted to address heightened risks associated with Frontier AI Models. In conjunction with this Advisory, the Department is issuing new guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (“Guidance”). This Guidance is intended to help Regulated Entities identify potential additional steps that may be appropriate when addressing cybersecurity risks that are significantly higher than normal. Whether to adopt a heightened risk posture, and which measures to adopt, depend on the unique circumstances and operations of an organization.