Skip to content
BetaNYC home

NYC Council Committee of the Whole, October 5, 2026 › What each group talked about

What the City said: Council questions to the administration

Oversight - Examining the Risks Posed by Artificial Intelligence. The administration's panel came after the AI companies and before public testimony. It ran about 1 hour 11 minutes. Sarah Milstein read the opening statement for OTI and DCWP, then Council Members asked questions. In the video it runs from 05:18:48 to 06:30:13.

Each Council Member's questions are listed first, then the full exchange from the transcript. Shaded turns are labeled as the administration.

Who asked questions

  1. Speaker Julie Menin (6)
  2. Chair Carmen De La Rosa (9)
  3. Council Member Jennifer Gutiérrez (3)
  4. Council Member Shirley Aldebol (2)
  5. Council Member Virginia Maloney (1)
  6. Council Member Julie Won (2)
  7. Majority Whip Kamillah Hanks (1)
  8. Council Member Gale Brewer (4)
  9. Council Member Chi Ossé (2)
  10. Council Member Shahana Hanif (2)
  11. Deputy Speaker Nantasha Williams (1)
  12. Council Member Selvena Brooks-Powers (read by the chair) (1)

What the City said it would follow up on · The City's position on each bill · Opening statement · How this page was made

Who spoke for the City

NameTitle
Sarah MilsteinDeputy Commissioner for Strategic Advisory Services, Office of Technology and Innovation (OTI). Oversees the Office of Algorithmic Accountability and NYC Cyber Command.
CJ DixonDeputy Commissioner, NYC Cyber Command (OTI), and the City's Chief Information Security Officer.
Samuel LevineCommissioner, Department of Consumer and Worker Protection (DCWP).
Benjamin KrakauerFirst Deputy Commissioner, NYC Emergency Management (NYCEM).
Carlos OrtizChief of Staff and Deputy Commissioner for External Affairs, DCWP. Sworn in; we could not tell whether he spoke.

Titles as introduced at the hearing.

Speaker Julie Menin

Questions asked (click one to jump to it):

  1. Has the City met with OpenAI, Anthropic or other frontier AI companies about how they would coordinate in a serious AI incident? 05:33:03
  2. Press reports say the City's AI director resigned. The office was due to be running in June; why isn't it? 05:35:55
  3. The Speaker says OTI issued guidance instead of the rulemaking her law requires. When will rules come? 05:37:55
  4. What stops City staff from putting confidential data into AI tools? 05:40:27
  5. Is OTI measuring AI's effect on the City workforce? 05:41:46
  6. How many people work at Cyber Command, and how many jobs are open? 05:54:02

The exchange, from the transcript

Julie Menin 05:33:03

Great. Thank you so much for your testimony. We appreciate it. I've got a number of questions. So OpenAI sent the City Council a letter on October 1 recommending that New York City better connect its existing cyber and emergency management capabilities, and I'm just reading from the letter, with the escalation, containment, and recovery capabilities of frontier AI companies. So has the city of New York this year met with OpenAI, Anthropic, or any other frontier AI company to discuss how the city would coordinate with them in the event of a serious AI related cyber or public safety incident?

Sarah Milstein 05:33:47

Thank you for the question. I'm going to defer to my colleague, CJ Dixon.

CJ Dixon 05:33:52

Thank you. So I would like to note that New York City Cyber Command follows the NIST cybersecurity framework for all of our cyber programming that is everything from identify, protect, detect, respond, and recover. The basic first principles in cybersecurity have not changed even with the advent of artificial intelligence. And we have been in conversations with various frontier models about how we may integrate their tools and software to better enhance the functions that we already deliver to the city. So in reference to your question, yes, we have been in conversation with the frontier AI companies to enhance the way that we perform cybersecurity. However, those basic cybersecurity controls have functionally remained the same. So you've met with OpenAI and Anthropic in particular? We have met with Anthropic. I have not met with OpenAI since coming on board on May 5.

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Julie Menin 05:34:41

Okay. Are you planning on meeting with OpenAI?

CJ Dixon 05:34:45

Only dependent on our needs right now. We do not know definitively if there is a valid reason for us to meet with any frontier

Julie Menin 05:34:56

AI company in the service concerned of by the statement that nothing has changed in your protocols given that we're now dealing with a rapidly escalating technology that as we certainly heard today and we've been hearing now for the last couple weeks to months that there are serious safety concerns. So I just want to get an answer in terms of what proactive steps is cybersecurity taking to meet with some of these frontier companies and ensure that our systems are safe.

CJ Dixon 05:35:27

Acknowledged. It does not mean that we have not changed our protocols. Some of the risks in hand with artificial intelligence are unrelated to cybersecurity. In those situations where an AI model presents a cybersecurity risk, those AI models will still exploit the exact same software vulnerabilities that are inherent in computer technology as they've always been. So our protocols have not had to change to address the fundamental issues

Julie Menin 05:35:55

inherent in computer technology, only the speed by which we must react in a cyber attack? Okay. I am concerned by news that city and state reported on Friday that the AI czar, Jaihao Chen, who is our chief technology officer, resigned, I think, a week to week and a half ago and reports saying that he resigned in frustration that a lot of positions were being not hired or being held up by OMB. And that relates to my second question, which is Council Member Gutiérrez. I think she's still here. Yes. And I, passed bills last year to create the Office of Algorithmic Accountability. And so it appears that Mr. Chen's resignation from what we're reading in the press was related to that and the fact that office was supposed to be up and running by the city in June, but it is not up and running. And in fact, in your testimony, you said you're now posting for the positions. It's now October.

Sarah Milstein 05:36:56

Thank you for the question, speaker. Ji Hao Chen served as director of AI and ML at OTI for two and a half years. He did important work in the previous administration to help define and understand AI use throughout the city. He's been very helpful in getting new OTI administration up to speed, and we wish him the best. We are very excited, to be staffing up OAA. The law went into effect in December. I was brought in this summer to help stand up the office. We got funding in June in the FY27 budget, and we've been actively working to hire for the roles, for the director role for OAA and look forward to announcing something quite soon. We're really, grateful to the council for having stood up, for having helped us stand this up. I think the work is going to be excellent.

Julie Menin 05:37:55

It just seems that this is an inopportune time for his resignation, and I am concerned that the office was under Council Member Gutiérrez's bill, supposed to be up and running in June. In addition, the companion bill, which was my bill, which we passed a year ago, required OTI to engage in rule making around this Office of Algorithmic Accountability. But OTI did no rule making whatsoever, so it did not comply with that bill. Instead, OTI issued updated guidance, ignored the rule making process. There's been no proposed rule, no public hearing, no public comment period, and no adoption into the rules of the city Of New York.

Sarah Milstein 05:38:37

Thank you. Thank you for the question, speaker. So OTI is fully compliant with the law. The rulemaking piece of the law, had us, this year, submit the initial, I don't want to say paperwork, but the initial points for our rulemaking and the actual rulemaking will happen in this fiscal year. We are also, fully compliant with Local Law 35, which was brought under the office of OAA as part of the December 25 law. We've been in the process of fulfilling that report for five years. We've done it on time for five years in a row. That's the law that requires agencies to disclose their use of public impacting algorithmic tools. And we're on track now for on time reporting for March 2027. So we're really excited actually with doing that work. Very proud of it. We just last week sent out the email to all of the city agencies to kick off this reporting cycle and are holding on this Thursday the orientation meeting that gets everybody rolling.

Julie Menin 05:40:00

Okay. I mean, just to clarify for the record, we don't believe that's in compliance at all. The office was supposed to be up and running in June. I'm sure Council Member Gutiérrez will talk about her bill, the office was not up and running in June and was supposed to do the rulemaking. When do you feel then the Law Department will... You've mentioned Law Department. Can we expect to actually see the rulemaking? This is in the March 2027 deadline?

Sarah Milstein 05:40:25

Yeah. Okay.

Julie Menin 05:40:27

So what safeguards are currently in place to prevent, city employees from entering, confidential private city data, whether authorized or unauthorized, into AI systems such as Copilot that are being controlled by outside corporations?

Sarah Milstein 05:40:45

Thank you for the question. Our contract with Microsoft, which runs Copilot Chat, prevents them from using city worker data to train their models. And the way they host data for us also is ensures that we're HIPAA compliant, CJIS compliant, that the data is kept, carefully and securely, that there isn't risk of the data being

Julie Menin 05:41:22

leaked either to Microsoft or to the public. So you can confidently say that no private or confidential city data has ever been obtained by an AI company and then used to train an AI model?

Sarah Milstein 05:41:36

Thank you for the question. I'm confident that our agreements with Microsoft, prevent them from taking such actions.

Julie Menin 05:41:46

Is OTI currently measure the impact that AI tools are having on the city's workforce?

Sarah Milstein 05:41:53

Yeah. Thank you for the question. Per Local Law 12/25/2025, we are engaged in a workforce study to understand the impact of algorithmic tools on city workers and automated, employment decision tools. And we will have results from that to share next year.

Julie Menin 05:42:16

Okay. Alright. I'm going to pass it over to Chair De La Rosa. Thank you. Thank you so much. And just continuing on that same question,

Julie Menin 05:54:02

I just want to ask one follow-up. How many people are working in Cyber Command right now? 121. And how many vacant positions do you have?

CJ Dixon 05:54:12

I will need to go back and find that exact number for you, speaker.

Julie Menin 05:54:15

Okay. Thank you. If you could please provide that. Thank you.

Back to the list of Council Members

Chair Carmen De La Rosa

Questions asked (click one to jump to it):

  1. Her Int 161 would make the workforce report yearly. What do you know now? 05:42:25
  2. What protects City workers from being replaced by AI? 05:44:15
  3. Where are City agencies on using AI internally? 05:47:01
  4. Agencies report their own AI use. What tools will the new office have to check, including for NYPD? 05:48:17
  5. How ready is the City for AI-driven cyberattacks? 05:50:15
  6. Should a kill switch live in Cyber Command? 05:51:24
  7. Should "AI control" be a cybersecurity specialty? 05:53:09
  8. To DCWP: what AI misuse worries you most? 05:54:20
  9. To DCWP: are you staffed for this? Would a private right of action help? 05:55:50

The exchange, from the transcript

Carmen De La Rosa 05:42:25

you all testified that my bill, 161, basically does the same thing as Local Law 25. One, we look forward to seeing the report. Local Law 25, to my knowledge, requires a onetime report that's going to come out of that study. 161 is more comprehensive and is requiring that report to be updated yearly. And as this and as this technology is evolving, in my opinion, hence why I put the bill forward more consistent reporting is going to be needed, especially as we begin to see how the workforce is impacted. Before I was a technology chair, I was the labor chair. We have a wonderful labor chair in the house, and I'm grateful to her leadership. But this is an issue that impacts not only organized labor, but I also see it as an issue where we're leading, the nation, really, in how the workforce will, react to this evolving technology. And so is there anything that you can share with us right now on where the workforce is and what those impacts will look like? I know you're working on the study, but is there anything you can give us forthcoming?

Sarah Milstein 05:43:40

Thank you for the question, council member. So the initial stages of the report are in part about determining how we even define impact. It's a it's a pretty broad term and could mean many different things. So we're in the phase of determining that now so that we're able to produce a report that's really meaningful for city workers. We certainly support the intent of your bill, and I would be interested in further conversation about the annual nature of the reporting.

Carmen De La Rosa 05:44:15

I appreciate that. Some of the information that we're looking for example, is, I think, an important question. How many funded agency positions, for example, will be eliminated due to the use of these tools? The agency vacancies has been something that this council has really been looking at especially as we look at civil service reform across the board and bringing people into municipal service. So we do want to understand sort of displacement and what that looks like for the workforce. We want to also understand reduction of hours over time, which this council has not been shy about questioning past administrations and present administrations about. We also want to know about subcontractors. Right? There's a ton of city contracts that are in play right now and want to know what the impacts are. So I look forward to continuing this conversation with you all and building on what we will see from the report of Local Law 25. I also want to say that while my bill doesn't specifically speak to worker protections, this council does believe that worker protections are important, especially as we look at that displacement and what could happen. Right? We just questioned the companies for the better part of the day about whistleblower protections and what happens when this technology gets out of control. So we want to understand how those protections are also extended to municipal workers. Do you have anything in place right now that protects our city's workforce?

Sarah Milstein 05:45:54

Yes. Thank you for the question. Because this is a little technical, I want to make sure I get exactly the right, information, which is that the, New York State civil Service Law section eighty ten establishes a moratorium on discharge, displacement, or the transfer of existing duties and functions currently performed by employees of the New York City and the New York City school district to an artificial intelligence system until 2028. The Civil Service Law also stipulates that the use of AI shall not alter existing collective bargaining rights, terms of employment, or civil service status. Further, collective bargaining agreements may offer employment protections beyond 2028. So with that law in place, we have a little bit of time, and we really appreciate the intent of this law and the fact that it gives us in New York City a little bit of time to figure out, how we understand the potential for displacements, for deskilling, for the use of subcontractors

Carmen De La Rosa 05:47:01

that might be, displacing other city workers and the sorts of things you were raising. So I really appreciate that question. Great. So we'll continue that conversation. I also want to give you a preview. I have a bill that creates a civil service title for AI within our city agencies. And one of the things that I'm curious about is like, this interagency communication around AI. Can you speak to us where are you right now when it comes to each of the city agencies and evaluating where the agencies are in terms of the use of AI, internally?

Sarah Milstein 05:47:34

Yes. Thank you for the question. So one of the privileges that we have at OTI as the agency that runs the reporting for Local Law 35 is that we learn from agencies throughout the city how they are using algorithmic tools that have, direct public impact. And in the process of collecting that data, we have a fair amount of contact with agencies to be able to learn more, and to establish relationships with them so that we can also serve as advisers to them and understand their challenges as this technology unfolds. In the last cycle last year, we had 56 agencies participating.

Carmen De La Rosa 05:48:17

Our first hearing as technology chair was around surveillance. And one of the things that we pretty much grew these companies about was about self regulation. And I think from the tone and tenure of this council, we don't believe in self regulation. However, we've given the grace to our city agencies to self report the use of AI. I want to ask you, and I understand that OTI is not an agency that's going to impose penalties on other agencies for not reporting. But there is a specific concern that my colleagues and I have around self reporting, especially when it comes to the NYPD's reporting of surveillance technologies. This council has had many hearings on that. I wonder under the Office of Algorithmic Accountability, what accountability tools will be put in place to make sure that we are properly regulating the use of surveillance technology in the NYPD and other technology. This council held a hearing just in June around the Department of Education and the use of AI. So what are some of those tools that we can look forward to seeing? Yeah. Thank you for that question, council member.

Sarah Milstein 05:49:29

So in advance of having full time staff at OAA, we have been doing research to understand some of the types of risk assessment and risk management that organizations like ours can do in a situation where self reporting is what we have been relying on. We're a little bit early to say how we would implement that in the city, but we are very actively hiring for a director who understands that set of problems and can help us figure out how we come up with effective risk assessment and management that includes, a view into city agencies perhaps beyond self reporting.

Carmen De La Rosa 05:50:15

Thank you for that answer. And, of course, we will continue that conversation. Absolutely. I did want to ask you, how prepared would you say we are for enterprise security system for autonomous AI driven attacks? Not just attacks by human, but AI autonomous attacks. How prepared do you all feel we are as a city?

Sarah Milstein 05:50:37

Yeah. Thank you for the question. I'll let CJ Dixon answer that.

CJ Dixon 05:50:41

And that is a great question. And I will acknowledge that this is a very dynamic environment. It is always changing that's just the nature of technology. New York City Cyber Command, however, provides 24/7 detection and response capabilities through our 24/7 security operation center. We have provided that service to the city since the establishment of New York City Cyber Command. We provide that service whether or not the attacker is human or an artificial intelligence based attacker. That attacker would still attack the exact same vulnerabilities in the system, and therefore, we would still respond functionally in the same manner. We would just have to do it faster. We continue to evolve with the technology, and we will continue to do so with the best of our ability as the technology continues to evolve.

Carmen De La Rosa 05:51:24

The speaker, rightfully so, in my opinion, asked the companies about the possibility of a kill switch and where that kill switch should live. Do you have any opinions if the kill switch should live in Cyber Command?

CJ Dixon 05:51:38

I agree in principle with the idea of a kill switch. I will say there are some technical, barriers that would prevent a kill switch as conceptualized living in any agency within New York City, whether that is New York City Cyber Command, OTI, or anywhere else. The reason being is the technical reality for these models is they are deployed on distributed systems, on distributed architecture. With a singular button or with a kill switch or anything of that concept for that to actually work functionally, we would need to be able to coordinate across multiple stakeholders that are not actually regionally colocated to be able to turn off everything at the exact same time. New York City Cyber Command or OTI does not have the authorities or the technical capability to do that. And this runs us up against a similar challenge that we've had with other kill switch bills as it relates to computer technology in general. Mhmm. As this technology gets more distributed, it gets harder and harder for any singular solitary entity to turn it off specifically. That is not to say that there is not technical means by which a group of entities with the legal authority to do so could not disconnect a given model from a given function. But in this particular case, we agree on principle, but it would not be able to be implemented at New York State Cyber Command in practice, not with the technical barriers that are in place.

Carmen De La Rosa 05:53:09

Okay. I'm sure there'll be more on that. Let's see. In your opinion, should AI control be a recognized cybersecurity specialty? If so, what should be the training and curriculum included in that?

CJ Dixon 05:53:29

I do not believe every function related to artificial intelligence is necessarily going to be a cybersecurity specific challenge. There are some intersections between artificial intelligence and cybersecurity as a particular domain. And when those, two domains interact, that is where certain things should fall within Cyber Command and a cybersecurity professional's purview. And that is any instance of a cyber attack or cybersecurity regardless of if the perpetrator is a human or an artificial intelligence.

Carmen De La Rosa 05:54:20

Thank you. I have a question for our DCWP, commissioner and team. What types of AI misuse are you seeing that harm consumers that you're most concerned about?

Samuel Levine 05:54:36

Well, thank you, council member. Thank you, chair. And it's great to have the opportunity to be here. We're concerned about a wide range of misuse, whether it's people using voice cloning technology that these AI companies make fully available to scanner seniors, whether it's grocery stores using AI technology to fix prices or to personalize prices, something that the speaker has introduced to build or prohibit. We're seeing widespread misuse of these tools. And the other thing we're seeing across the board is an attitude by these AI companies that they bear no responsibility for the downstream consequences. I have to just say, chair, I was struck by the final answer I heard by the witness for OpenAI who, when asked a basic question about AI safety, responded that she works in policy, not safety. How are you running a company like OpenAI set to go public introducing trillion dollar tools and you don't have safety as part of your policy division? Deeply disheartened by what we heard at the hearing earlier today. Mhmm. Absolutely. You should've heard their first answer. It went something like, I don't know. There were a lot of I there were a lot of I don't knows. And on behalf of the admin, we hope to give you more fulsome answers. Thank you. And we look forward to engaging with you in that more broad conversation as well. In your opinion, is DCWP

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Carmen De La Rosa 05:55:50

sufficiently staffed to combat this AI misuse? And, would adding, in your opinion, a private right of action strengthen the ability to enforce against violators? Thank you, sir. I'll be candid. I feel that even as we've...

Samuel Levine 05:56:05

As under the Mamdani administration, we are adding to our ranks, I believe we are capable of taking on many of the misuses of AI, whether that's DoorDash using algorithms to underpay its workers, something we remedied in the largest labor enforcement action in history, whether it's companies using AI to harm consumers through surveillance pricing, we're strongly supporting the speaker's bill on this. I think we have strong tools. That said, no enforcement agency, and I've worked at the state, federal, and municipal level, will ever have the resources to take on every possible misuse of this technology. That is why, chair, I would strongly support a private right of action as contemplated by a number of these bills to give ordinary people, workers, and businesses the opportunity to hold these companies accountable. I can guarantee you, though, these companies, as soon as the city does that, are going to run to Washington asking for preemption. Regardless of what they might be saying at this hearing, what really speaks is where their lobbying dollars are going, and that is to DC congress asking to hit delete on all of these city and state, AI safety laws.

Carmen De La Rosa 05:57:11

Thank you, commissioner and team. I'm going to pass it on to my colleagues, Council Member Gutiérrez, followed by Aldebol, followed by Maloney.

Back to the list of Council Members

Council Member Jennifer Gutiérrez

Questions asked (click one to jump to it):

  1. Will the new AI reporting be on time? How many staff, and at what stage? 05:57:22
  2. To DCWP: how is Local Law 144 on AI hiring tools working? 05:57:22
  3. Do you have someone for the director role? 06:02:20

The exchange, from the transcript

Jennifer Gutiérrez 05:57:22

Thank you. Good to see everyone. My first question is for deputy commissioner. Good to see you. Going off of the speaker's line of questioning regarding the Office of Algorithmic Accountability. I know you said you're excited about this report. You're setting up an orientation meeting. It feels like not a lot of time. I guess, before the report is scheduled to be released, what can you share about the cadence of how often you're going to be able to meet? Do you expect the report to be released on time? This is not a reflection of you, but I really felt like the previous administration under the previous OTI leadership was delayed in many things. And we certainly don't want compliance to be one of those things. So if you can just share with me a little bit about the cadence, how many people, you said the funding you got in June, how many people will the office be able to employ, Where you are in that process currently? Oh, okay. That was it for you. I had a question for DCWP. I can come back. Go ahead. Go ahead. Okay. And then for DCWP, I just wanted to ask, if you can share a little bit about how the implementation of Local Law 144 is going, the automated deployment decision tools. Just wanted to see how the implementation of that law is going, and that's it. Fair enough. Thank you.

Samuel Levine 05:58:47

Well, thank you councilmember. Let me start by 01:44. I think this is a really well intentioned bill to regulate the use of automated decision making systems for hiring. I think it does have some flaws, though, especially in that it requires companies that use AI systems for hiring to conduct audits. It doesn't actually require that those audits come up clean. That's really a civil rights question. That is why our administration put out a policy statement last week on behalf of DCWP Commission on Human Rights and Taxi and Limousine Commission, making clear that existing laws apply. But I do want to circle back to a broader point that this hearing reveals, which is that bias in decision making produced by AI systems is a very real concern you're addressing. These companies would like an exemption from the law. The companies that testified earlier want to assert that if decisions are made in a black box, nobody can be held accountable for. I applaud this council's effort to actually impute responsibility for these harms to the companies making billions of dollars on it, and we would be very happy to work with the council to work on a revised, expanded, strengthened automated decision making bill that places the responsibility to remove bias from hiring where it belongs. Are there instances where the harm is happening amongst the city agencies using these tools? I would defer to OTI and to those in hiring. I don't believe that the city is using AI tools to sort resumes, but I would defer to others in the admin... I can tell you it in my agency, we have people reviewing applications. Just as starting in January when delivery workers get deactivated, we have people reviewing that. When consumers file complaints, we have people reviewing it. We are a big believer in our administration that the people of New York should be served by the people of the city government. Thank you. Part of the package of bills that the speaker mentioned that we passed last December

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Jennifer Gutiérrez 06:00:44

on Christmas was, to get the city and to get OTI to report on all those AI tools that every city agency is reporting on. So we'll know soon enough. But please, deputy commissioner, thank you.

Sarah Milstein 06:00:56

Yeah. Thank you for the question, council member. So I think there's a couple of reports we're talking about here. Want to give a little bit of context. Local Law 35 is the report that requires agencies to tell us about the algorithmic tools they're using that have public, impact. And that report, we have, delivered on time every year for the past five years. The, process court kicked off last week Mhmm. And we'll be collecting data over the course of the next few months with the plan to publish it in March 2027. We have all the indications that will come in on time as it has in each of the past five years. So we're feeling good about that. I'm just referring to the report back from intro 199.

Jennifer Gutiérrez 06:01:41

I'm sorry. Could you I was just referring to the report, required by intro 199. So that's the package of bills from last fall. Yeah. Thank you for clarifying. So we

Sarah Milstein 06:01:53

are... The director of OAA, which we hope to be able to announce quite soon, will be, primarily responsible for the additional reporting that will be required in March 2027. And in part because we have this good experience internally understanding process with Local Law 35, we think we're in a good position to move quickly on the additional reporting that will be due in March 2027.

Jennifer Gutiérrez 06:02:20

Okay. And you said announcement. Do you have someone already for the role?

Carmen De La Rosa 06:02:26

We will have an announcement, and I hope that we'll be about the announcement. Okay. Thank you. Thank you, chair. Thank you. We have, Council Member Aldebol, followed by Maloney, followed by Won.

The transcript labels this turn as the chair, but the first sentence sounds like Sarah Milstein's answer.

Back to the list of Council Members

Council Member Shirley Aldebol

Questions asked (click one to jump to it):

  1. Where is hiring for the six new positions, and what is slowing it? 06:02:38
  2. How is the office protecting City workers as AI changes? 06:03:50

The exchange, from the transcript

Shirley Aldebol 06:02:38

Thank you, chair and Speaker Menin. So you said the hiring process for the six new positions that were created in the adopted budget, are actively underway. Like, specifically, where are you in the process? How many people have already been hired? How many people are left to be hired? And what have been the challenges in being able to hire people quickly?

Sarah Milstein 06:03:08

Yeah. Thank you for the question, council member. So we hope to be announcing a director for the office quite soon, in the next week or two. And we are in the process of defining the additional roles so that they can be brought on quite quickly. We certainly are challenged to find people who have the right combination of AI expertise and understanding of city systems to be able to like, hit the ground running. That has been a little bit of a challenge, but I think bringing in a strong leader is going to help us draw good people who are going to want to do this work with us.

Shirley Aldebol 06:03:50

If I may, chair. Part of the role is to analyze algorithmic tools submitted by the agencies to determine whether there's risk that the proposal could result in discriminatory decision making. What is your office what is your office doing or thinking about in terms of protecting the city's workforce as AI develops and evolves and you're kind of like the gatekeeper

Unidentified 06:04:27

Yeah. AI.

Sarah Milstein 06:04:29

Yeah. Thank you for the question. So in parallel with some of the risk assessment that we can do of the software, we are doing the research associated with Local Law 25, which has us researching how algorithmic tools and automated employment decision tools might be impacting city workers. And believe that we should have results from that in 2027, and we'll have a much better sense of the landscape of how workers in the city are impacted.

Back to the list of Council Members

Council Member Virginia Maloney

Questions asked (click one to jump to it):

  1. What is New York's AI "win"? Is OTI's AI guidance binding? Is there an approved tool list? How should buying AI work? 06:05:12

The exchange, from the transcript

Virginia Maloney 06:05:12

Thank you, chair. As we all know, generative AI technology is changing how we communicate, work, and how businesses operate. And the same could be said of our government offices, both how we work and operate either officially or unofficially. So I want to know how New York City agencies are adapting to the new reality. The first on the opportunity side, there are plenty of examples of government wins of adopting useful technologies for the public good. In Connecticut, they have real time translation in 80 languages for these kinds of public meetings to increase accessibility in California. They automatically check permit applications against 18,000 pages of building code in order to speed up reviews. So my first question is what is our equivalent win in New York? And if we don't have one yet, what's the plan to identify those opportunities? And the second question is around oversight. If I may wrap up, OTI published generative AI guidance for agencies last December. So as we're exploring these opportunities, is that guidance binding or is it advice? What happens if agencies ignore that guidance? Has OTI been prescriptive about a list of generative AI or agentic AI tools that have been reviewed and approved for city use that are use cases that the city officially supports? And then, how are we thinking about procurement when these models are constantly iterating and changing every few months, every few days, truly, and when new technologies are being introduced? Thank you.

Sarah Milstein 06:06:58

Thank you for those questions, council member. I'm so glad you brought up the question about wins because we're really interested in both effective and responsible use of AI, and effective would cover the wins. I don't have, a perfect list here, and I'd like to follow-up with that because we'd really like to represent the agency as well. In terms of tools that we have approved, broadly, there are two sets of tools, that OTI approves centrally, Microsoft Office Suite and other Microsoft tools, and that includes their Copilot chat. And some of their some of their other tools have AI features built in. And we also have a central, license for Adobe Creative Cloud, and many of those tools have AI features built in. Other software tools that are used by agencies are reviewed for the most part on a one off basis by OTI, and we are still determining the best way to move forward with that process to make sure that we are identifying and managing risk appropriately. I think your question about procurement is an excellent one. And part of what we have started to research ahead of having staff at OAA. We started to talk with various experts in risk management to understand some of the ways that we might think about risk in an ongoing way when traditionally all kinds of procurement, there's a gate at the beginning for various concerns, and then it's rolling. I think you're right. That's not appropriate for this situation, and we should have more to discuss on that in the coming months. But it's an active question that we have as well.

Back to the list of Council Members

Council Member Julie Won

Questions asked (click one to jump to it):

  1. She says agencies are using ChatGPT, Claude and other tools. What is the policy? Do contracts protect constituent data? 06:09:00
  2. Who is responsible for staff using tools that are not approved? 06:10:56

The exchange, from the transcript

Julie Won 06:09:00

followed by Brewer. Thank you so much, Chair De La Rosa. So for the panel, what I have questions about is building off of what Council Member Maloney just said. The agencies are allowed to currently use Microsoft products and also Adobe. But it's clear to me and the public that they are using other AI tools. So not just the passive tools like using Zoom to transcribe their notes and for follow ups, but in addition to that, they're using ChatGPT, they're using Claude, they're using Nano Banana Pro because we're seeing it for agencies like HPD, DOE, DEP. They're creating flyers for public consumption. They're using it for their public emails. They're using it for public messaging. So what are you actually doing? Because I want to know what the public policy is from the mayor on how the agencies are using AI and how you are regulating it internally as well. And, also, I would like to build off of that for city contracts. What are you doing currently for data privacy riders and city contracts for all procurement of AI companies for making sure that our constituent data is not being used to train their AI models? And is there a clause at all or a rider in the city contract, especially with copilot since that's the only real one that you have? And people are just using their own personal accounts or free accounts for everything else that they're currently using for their day to day jobs.

Sarah Milstein 06:10:22

Thank you for the question, council member. So let me first address the question about the AI rider. We shared, that with general councils across the city this summer with an updated AI rider, and I want to just make sure I've got the right language here, so I'm going to pull that up. Let's see.

Julie Won 06:10:42

Yeah. Because my privacy concerns are not just for the contracts that exist, but it is for the free willing use of agency staff that are using non city enterprise licensed AI.

Sarah Milstein 06:10:56

Yeah. So I'll first address the rider and then we'll talk about the shadow use. So, the rider, as I said, was distributed to city agencies citywide this summer, and it's intended to mitigate risks and apply the city's policies and standards to AI products and features. It's available for all city software contracts, and our legal team recommends that agencies use it even where no AI component is currently contemplated. The rider includes terms relating to intellectual property, security, how the city's data may be used, and privacy. And, so that is now active and in use, with also a proactive component of recommending that it's used for all manner of technology. In terms of the shadow use, which I think is probably both at the individual and at the agency level, we are not in a technical position to monitor that. We, as an agency, share concerns about that, and part of what we're interested in doing is making sure that agencies have the tools that they need that are properly regulated. Microsoft tools, for example, where data can't be shared or used to train their models, that agencies have the tools that they need to do the jobs that they have so that they are not turning to outside tools. So who is responsible if you aren't able to regulate shadow use of AI tools for a day to day use, especially with constituent data? Who is willing to regulate that? Like to follow-up with you on that question.

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Back to the list of Council Members

Majority Whip Kamillah Hanks

Questions asked (click one to jump to it):

  1. You said not all threats to AI systems are cyberattacks. What do you mean? 06:12:50

The exchange, from the transcript

Kamillah Hanks 06:12:50

We have our majority whip, Council Member Hanks. Thank you so much, chair. I'll be very, very brief. With so you testified, with all the technology that's changing rapidly, even the best can't keep up. In your testimony, you said the administration is continuing to evolve your strategies to keep our city's infrastructure safe, But not all threats to AI systems are necessarily cyber attacks. Can you expand on that?

CJ Dixon 06:13:20

Yes. So when looking at the way that it is currently described by the National Institute of Science and Technology as well as some of the universities and academics who've created some of these systems, there are functionally two baskets of AI risk. There is risk related to AI when an AI is attacked as a computer system just like any other piece of software. And then there are risks related to artificial intelligence that are truly novel to this new technology inherent in the way that these artificial intelligence models may interact with society when deployed. That second category of risk is a function of how much society may trust the artificial intelligence and how reliable that artificial intelligence system may be. Those two things can run afoul of what we may expect as consumers or as a government entity, completely agnostic of whether or not the system for which those AIs are deployed are actually cyber secure. So a system can be completely cyber secure, but the AI model itself in interactions with other humans in society writ large may take an action that is unexpected and therefore result in some sort of disruption, agnostic of a cybersecurity incident. That's functionally the two categories. That's a very broad breakdown of those two categories of risk.

Kamillah Hanks 06:14:42

So I'm going to keep my question just to that. I think that we should talk offline because my legislation requires the 24-hour reporting requirement to Cyber Command in which your testimony has some issues, and you talk about how we're going to push this through to federal and state

Back to the list of Council Members

Council Member Gale Brewer

Questions asked (click one to jump to it):

  1. How does an agency start using a new AI model? 06:14:58
  2. Does the City run models in its own data centers or on vendor clouds? 06:16:33
  3. What do you do about an AI product that misbehaves? 06:17:18
  4. How much does the City spend on outside AI consultants? 06:18:16

The exchange, from the transcript

Gale Brewer 06:14:58

and what specific role do they play in that, how can we make this better, but I will relinquish that. Thank you, Chen.... You so much. Up next, we have Brewer followed by Jose. Thank you very much. I know you talked about the Microsoft and the Adobe, but if an agency wants to begin using a new AI model, how do they go about it? Number two, does the city run these models on its own data centers or only on the ones that are on the control of vendor clouds? And then if you have a problem, like there's a criteria, what is it for testing to identify the malicious, misaligned AI product? And then how much does the city spend each year on outside AI consultants? I could go on but those are three, four questions. I have 10 pages here. Okay.

Sarah Milstein 06:15:47

Thank you for the questions. Let's see. So... The process. Yeah. Typically, when agencies want to buy software, a part of the process is discussing with OTI what they are buying and what they will be using it for. And we have a cybersecurity review process that is part of that to ensure that the software that is either going to be bought or built, will be safe. And as my colleague has said, cybersecurity includes the typical AI concerns. So that's process. You had...

Gale Brewer 06:16:33

Next question, the clouds. Whose clouds are they on? Whose data centers? Where are they? Yeah. Are you running them or is it outside vendors?

Sarah Milstein 06:16:45

So to the best of my knowledge, there are no city agencies running their own models. It's vendor clouds, basically.

Gale Brewer 06:16:58

Vendor clouds. Vendor clouds. Yes.

Sarah Milstein 06:17:01

So, for example, Microsoft host software that agencies use. But I'd like to follow-up after the hearing to make sure I've got the exact right information for you. Okay. And if there's something unexpected,

Gale Brewer 06:17:18

misaligned AI product behavior, what do you do?

Sarah Milstein 06:17:21

That is a question for my colleague, CJ Dixon.

CJ Dixon 06:17:25

Councilwoman, that depends on what the misaligned behavior is. If that misaligned behavior, specifically a cyber incident, we take appropriate action based on what any cyber professional may do. There are novel misalignments that are born of this technology that do have to be unpacked, and we look forward to working with the council as well as our partners across New York City to understand when those misalignments do arise unrelated to existing risks that the city already deals with how do we actually engage with those particular novel risks. Have you had some in the last, since you started your job? None related to what Cyber Command's purview is. And that is primarily cyber security issues. We've had no misalignments related to cyber security that have resulted in negative consequences for the city from an AI model very specifically.

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Gale Brewer 06:18:16

Alright. That sounds very... I don't know what it sounds. How much outside AI consultant dollars are being spent?

Sarah Milstein 06:18:29

Council member, could you clarify what you mean by AI consultants? Yeah.

Gale Brewer 06:18:33

How many people are you paying? I mean, I've been doing this work a long time, so I know sort of the answer. But how much outside consultants are being paid on terms of AI? In other words, how many people are you paying to work with you on AI issues outside vendors, consultants?

Sarah Milstein 06:18:55

None that I'm aware of but I would like to follow-up with you to make sure that we can accurate information....

Gale Brewer 06:19:00

House. Is that what you're saying? Everything to do in terms of strategy, thought process, future, it's all in house?

Back to the list of Council Members

Council Member Chi Ossé

Questions asked (click one to jump to it):

  1. If an AI agent hacked a City system, is the City ready? Do AI companies have a contact for incidents? 06:19:14
  2. Does an AI emergency plan already exist? 06:21:16

The exchange, from the transcript

Chi Ossé 06:19:14

Thank you so much. I just wanted to refer to the recent hacking situation in Australia. That was proof that AI agents do have that ability to hack into our government systems. As I'm sure in June, a rogue OpenAI agent hacked into an Australian government statistics portal containing private data from Australia's universal health care system. At this current moment, if a similar hack that happened to Australia happened here in New York, do you feel that the city and the admin has a sufficient plan to defend against the hacks and protect any sensitive data? And two, does the city currently have a responsive liaison from each of these companies to speak to in case of a hack?

CJ Dixon 06:19:58

To the first question, yes. We do have the people process technology and some of the policies in place to deal with an incident similar to what happened in Australia. The reason being is even though an AI was involved, the hacking process, the attack chain, if you will, happen in the same way that if a human being were to execute that attack. At the end of the day, the underlying infrastructure, I will use air quotes here, doesn't actually care if the person at the end of the other end of the keyboard is a human or a silicon based entity. The attack chain still remained functionally the same. Therefore, our team is equipped and trained very specifically to identify these indicators of compromise, identify the attack patterns, and then be able to respond accordingly at multiple points. So we are prepared to address those types of issues, and we do have points of contacts when we are working as city agencies with vendors who are under our contract to engage with third parties as they get breached or if their product is the result of a breach. So if they are under contract within the city by their service level agreements are required to keep us informed of when they have downtimes or when their products are involved in a breach.

Chi Ossé 06:21:16

Thank you for that response. And in regards to my legislation on an emergency plan, and I know that you indicated that there's already a plan in case an emergency takes place. Am I correct with that assumption?

CJ Dixon 06:21:29

Yes. So there are cyber incident response plans as well as my colleagues from NYCEM. There's also ongoing work for risk, response plans in general across the board, and that is for every category of risk that the city may deal with that might disrupt city infrastructure or city services. Is that publicly available, or is that shared with the council? No. That is by design. We do not want to share that publicly because the more public... Of course. Aware that someone is of an incident response plan, the more likely they can circumvent it because that's something that you do want to keep close hold and classified. Okay. Thank you very much. Thank you so much.

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Back to the list of Council Members

Council Member Shahana Hanif

Questions asked (click one to jump to it):

  1. How does OTI keep HRA's automated screening tools from being biased against low-income New Yorkers? 06:22:10
  2. To DCWP: what would you need to handle AI complaints? 06:22:10

The exchange, from the transcript

Shahana Hanif 06:22:10

Oh, I thought the deputy speaker was going before me, but I'm late. I messed up. Okay. No worries. I have a question first for Deputy Commissioner Milstein. How does OTI ensure that the automated prescreening tools and fraud detection algorithms used by the HRA do not create disparate impacts or algorithmic bias against low income applicants? And then a question I have for Commissioner Levine, The testimony indicated that DCWP supports a complaint process, but you all raised concerns about staffing and expertise. What specific resources would you need to investigate AI complaints effectively, and what protections can New Yorkers rely on while that capacity is being built?

Samuel Levine 06:23:00

Sure. Well, thank you, council member. I can start. And I want to be clear. AI complaints can take many different flavors. If we hear from a worker who tells us they believe their pay was incorrect, maybe they didn't hit the minimum pay rate because of an algorithm, that is something we can fully address. If we have someone like Jacob Coxon come to us and say that, Anthropic is developing models that could, lead to catastrophic consequences, that is not something we have the capacity to do. So what we said in our testimony is the New York Attorney General already has an Internet bureau set up. They've already put out a call for whistleblowers. I believe they already have staff capable of processing these complaints. We'd be very happy to work with the council to make sure complaint to get to the AG. As the speaker has said, thousands of these AI employees work right here in the five boroughs. They know that these companies are making reckless decisions in pursuit of profits. We do want to make sure that these employees have a place to go. And if they come to us and it's not something we can handle, we'd want to work with the state to make sure those complaints can be addressed adequately. But right now, is the city working with the AG's office, or is that a relationship that's not formalized? We have a very close relationship with the AG's office. We speak constantly.

This turn also contains a Council Member's words; the transcript did not split the speakers. Check the video.

Sarah Milstein 06:24:20

Can I ask you to repeat the question about HRA? Absolutely. So it's basically trying to understand,

Shahana Hanif 06:24:26

our automated prescreening tools because I understand that humans are not checking all of the applications. There's some level of automated algorithmic formula that is determining how applicants get pooled when it comes to public benefits. So I'm curious if, how OTI ensures that automated prescreening tools, fraud detection algorithms used by HRA are not creating disparate impacts or bias.

Sarah Milstein 06:24:56

Thank you for the question. We really share a concern about the bias and impacts on not only workers but on, New Yorkers. Because this is really detailed and specific, though, I do want to make sure to check back with HRA and make sure I've got the details of this one correct. So we'll come back to you on that for sure. Appreciate it.

Unidentified administration speaker 06:25:19

Thank you so much. Council member, I just wanted to follow-up on one point you had about potential resource impacts. I think on that particular issue, we had identified very preliminarily of 14 lines for approximately 1.2 million. But I Wait. Could you repeat that one more time? 14 lines for approximately 1.2 million. But, again, that's a very preliminary estimate, and we work on the council with the bill for a final version.

An unidentified member of the administration. Possibly DCWP; not named in the transcript.

Back to the list of Council Members

Deputy Speaker Nantasha Williams

Questions asked (click one to jump to it):

  1. What is the timeline for the Local Law 25 workforce study? 06:25:44

The exchange, from the transcript

Nantasha Williams 06:25:44

Thank you, chair. I am looking at your testimony and your comments about the chair's bill. Local Law 25, which was my bill. The study is currently underway. The compliance division of the council reached out, I think, twice. I know it just went into effect in January, but would be helpful to know if you have a timeline. So I know it might take time, but how much time? Because, clearly, I think today's hearing is evidence of the importance of really understanding AI's impact, on the municipal workforce. So just wanted to know if you could share a timeline for us. I know the comments we received back was just that there's no updates, but we haven't received a timeline.

Sarah Milstein 06:26:33

Yeah. Thank you for the question, and thank you for the legislation. I think it's really an important study. I anticipate that we will have pieces of it over the course of 2027, and we will share updates as we have them. Because this is so timely and important, we don't have to just wait till the end. We can be in partnership with you and rolling out information as we learn more.

Back to the list of Council Members

Council Member Selvena Brooks-Powers (read by the chair)

Questions asked (click one to jump to it):

  1. What would an AI attack on emergency systems look like, and is there a plan? How does NYCEM keep its alerts trusted? 06:26:58

The exchange, from the transcript

Carmen De La Rosa 06:26:58

Thank you. I look forward to working with you on that. Thank you. And the last question for this panel. This is from Council Member Selvena Brooks-Powers. She says my district is home to JFK Airport and to the coastal Rockaway neighborhoods that depend on emergency alerts. What might an AI driven attack on emergency systems or major infrastructure look like? Is there currently a plan for an AI driven attack on critical infrastructure and relevant emergency systems? And then for NYCEM, during storms and flooding emergencies, it can be hard for New Yorkers to know what they're seeing on social media is real or AI generated. How is NYCEM working to make their messaging clearly legitimate and to cut through the noise of AI generated rumors?

Sarah Milstein 06:27:49

For the question on notifications, I'll defer to my colleague CJ Dixon.

CJ Dixon 06:27:57

Yes. So for an AI based attack that is specifically a cyber security attack, there are notification requirements that already exist under law. 72 hours for a confirmed breach, 24 hours for a breach related with extortion, and then 30 days for victim notification. So there are plans in place for incident response in the event of a cyber attack against any critical infrastructure owned by the city, and that includes if that attack is perpetrated by an artificial intelligence system.

Benjamin Krakauer 06:28:26

Thanks. And on the, New York City emergency management front, I'll make two two quick points. One, I think that is a real risk. I appreciate the council member raising it. It's one of the reasons that we invest very heavily in backup systems. So several months ago, a very, well known and established, notification provider had a seven hour global outage where notifications were not able to be sent out. That's something that we take very seriously and which is why for over a decade now, New York City Emergency Management has invested in the backup system. So as you went across the country, you saw many large jurisdictions saying to their constituents sign up for this WhatsApp group or follow us on social media if you want alerts tonight. In New York City, we did not have to do that because we had a backup system that continued to work, that disruption was averted. As far as misdis or malinformation generated by AI, that is a valid concern. That's why we recommend that New Yorkers follow us on our official channels, which are verified, through Notify NYC. You can sign up at nyc.gov/notify. You can sign up by short code or download the Notify NYC mobile app that we operate in concert with OTI.

Carmen De La Rosa 06:29:39

Thank you so much. Council Member Brooks-Powers wanted me to note that, for example, during the nor'easter, there was a video that was going around about a tornado, that apparently caused a lot of confusion and chaos. And so she wanted to share that for context.

Back to the list of Council Members

What the City said it would follow up on

Who promisedToWhatTurn
CJ DixonSpeaker MeninHow many jobs are open at Cyber Command05:54:12
Sarah MilsteinCouncil Member MaloneyExamples of City AI "wins"06:06:58
Sarah MilsteinCouncil Member WonWho is responsible for staff using unapproved AI tools06:10:56
Sarah MilsteinCouncil Member BrewerConfirm where City AI models run06:17:01
Sarah MilsteinCouncil Member BrewerCity spending on outside AI consultants06:18:55
Sarah MilsteinCouncil Member HanifBias safeguards on HRA's automated tools06:24:56
Sarah MilsteinDeputy Speaker WilliamsUpdates on the Local Law 25 workforce study as pieces are ready during 202706:26:33

The City's position on each bill

Our short summary of the opening statement. Read the statement itself below.

BillWhat it doesThe City's position
Int 161 (De La Rosa)Adds workforce impact to yearly reporting on City algorithmic toolsAgrees the issue matters, but says the bill would add nothing beyond the larger Local Law 25 workforce study.
T2026-2602 (Menin)No AI model marketed, sold or deployed in NYC without third-party validation and a human shut-offNeither OTI nor Cyber Command is the best choice to lead it. DCWP supports the intent and is unsure third-party validators exist yet.
T2026-2601 (Hanks)City contractors report AI safety incidents, with public notice in 24 hoursNot all AI threats are cyberattacks, and the bill does not address that. Existing breach law applies. 24-hour public notice would compromise an investigation and is inconsistent with current law.
T2026-2606 (Ossé)Cyber Command and NYCEM write an AI emergency response planLaws, policies and protocols for breaches already apply, whatever the actor. Happy to discuss how it already coordinates with NYCEM.
T2026-2605 (Menin)Anyone can file AI complaints with DCWPDCWP strongly supports the intent; concerned about volume, cost and expertise.
T2026-2599 (Morano)Data security, privacy and access rules for chatbot companiesDCWP has concerns: the approach is sound, but enforcing its data security and privacy rules would need technical and investigative capacity outside DCWP's scope.
T2026-2603 (Wilson)AI ads must disclose third-party validation; no false safety claimsDCWP supports the disclosure. Unsure third-party validators exist yet. False ads are already illegal under City law.

Opening statement

Read Sarah Milstein's opening statement for OTI and DCWP (2,013 words, 05:19:42)
Sarah Milstein 05:19:42

Great. Good morning, Speaker Menin, Chair De La Rosa, and council members. My name is Sarah Milstein, and I'm the deputy commissioner for strategic advisory services for the Office of Technology and Innovation, OTI. I'm joined here today by my colleague, CJ Dixon, OTI's deputy commissioner of New York City Cyber Command and New York City's chief information security officer. I'm also joined by Samuel Levine, commissioner of the Department of Consumer and Worker Protection, DCWP, Carlos Ortiz, DCWP's chief of staff and deputy commissioner for external affairs, and Benjamin Krakauer, first deputy commissioner for New York City emergency management, NYCEM. In my role at OTI, I oversee both the Office of Algorithmic Accountability, OAA, and New York City Cyber Command. We appreciate that the council is holding this timely hearing about the risks of AI technology. Thank you, speaker, for getting representatives of the companies that develop, deploy, and sell AI tools to the general public to speak to the capabilities, limits, and risks associated with these systems at this hearing. As a representative of OTI, I'm here today to provide information to the Committee of the Whole about how we serve the city's technology and cyber defense needs and to address the proposed legislation that potentially impacts the administration. For those unfamiliar with our work, OTI's core mission is to use technology, data, and design to make the city work better for New Yorkers. We achieved this through a wide range of digital products, infrastructure, data systems, and shared expertise. In other words, we use technology to help agencies make every New Yorker's experience of city government better. For our discussion today, we can speak to the work we're doing around agency use of algorithmic tools and our cybersecurity program. To touch briefly on the AI arm of OTI, I'm pleased to share that the Office of Algorithmic Accountability, OAA, has been formally established and six new positions have been created in the FY27 adopted budget to staff it up. The hiring process for those roles is actively underway. The OAA's duties include analyzing algorithmic tools submitted by agencies to determine whether there is risk that the proposed tool could result in discriminatory decision making, conducting and publicly reporting on predeployment assessments, creating and maintaining a public facing platform for submission of comments, establishing a protocol with the Department of Investigation for receiving complaints from the public, promulgating rules establishing basic compliance standards that all agencies must meet in developing, procuring, deploying, and use a public impacting artificial intelligence, and reporting the results of predeployment assessments and audits conducted by the office. Overall, the office is progressing as planned, and we remain focused on building the capacity needed to carry out this work effectively. I will now turn to the legislation on today's docket that would impact OTI. Introduction 161 of 2026 would amend annual reporting on algorithmic tools to include their impact on city employment with a focus on potential changes to funded agency positions, salaries, and duties. OTI is currently undertaking a study on the impact of algorithmic tools on municipal employees pursuant to Local Law '25 of 2026. This study will provide insights into the extent to which algorithmic tools, including artificial intelligence, impacts city employees and the administration of their duties, including their hiring and work functions. While we agree that it is important to examine the impact of AI on our workforce, the bill as written would not produce new insights beyond those in the larger, more expansive directive of Local Law 25. The next three bills involve New York City Cyber Command. This office plays a vital role in protecting and defending the city and its residents from the impacts of cyber attacks. On a day to day basis, we provide 24/7 security services and assist agencies in bolstering their cyber maturity. We work collaboratively with agency partners as well as state, federal, and private entities to safeguard the essential services and data New Yorkers depend on daily. Our core mission is to make New York City the most cyber resilient city in the world, and we take this extremely seriously. New York City is a target for cyber attacks with a technology landscape that is unparalleled among other cities and states. This requires a unified comprehensive defense against constant cyber threats. Our key duties include setting information security policies and standards for the city, directing the city's citywide cyber defense and incident response, deploying defensive technical and administrative controls, and providing guidance to City Hall and agencies on cyber defense. In my fairly new role at OTI, it is a privilege to work with our staff and our agency partners in furtherance of this critical mission. New York City Cyber Command's alignment within OTI has placed the team in a strong position to monitor and respond to wide ranging cyber threats. Cybersecurity is continuous work. In my role, I'm confident we can continue to adapt to a constantly evolving threat landscape. Simply put, New York City Cyber Command has a 24/7 apparatus in place to defend the city systems from malicious attacks regardless of the origin. With that in mind, Preconsidered Introduction T2026-2602 would make it unlawful to market, offer for sale, sell, or deploy an artificial intelligence model in New York City that has not received third party validation or does not have a technical capability to be shut down by a human operator. The bill would require the director of the Office of Cyber Command to promulgate rules regarding what the third party validation, assessments, certifications, and disclosure would entail and the qualifications for third party validators. To be clear, Cyber Command's core mission is to defend the cities of New York's infrastructure from cyber attacks. We are not subject matter experts on the qualifications for an entity to be considered a third party validator. Further, neither OTI nor Cyber Command have experience regulating the private sector in the way that this legislation would require and neither would be the best choice to lead this regulatory regime for consumer products. We defer to DCWP to speak about the private sector policy and enforcement piece. To that end, DCWP supports the intent of this legislation. They recommend including robust record keeping requirements to better allow the agency to conduct affirmative enforcement. They also note based on conversations with advocates and sister agencies that the administration is not certain about the availability or ability of such businesses. We look forward to hearing from those stakeholders today, including on whether initiatives like this one could help spur a market for such services. Preconsidered Introduction T2026-2601 require the Office of Cyber Command to establish standards and procedures for contractors to identify the occurrence of a reportable AI safety incident. To take a step back, I'd like to lay out how AI risk and incidents are categorized according to the National Institute of Standards and Technology, NIST. AI under attack, AI cybersecurity incidents are traditional cybersecurity compromises where the AI system is the target. For example, data poisoning or jailbreaks. Misuse or malfunction, AI induced incidents, would be harms resulting from the use or failure of AI aside from a cyber compromise. In this category, the AI system itself behaves exactly as it was built or trained, but the real world outcome causes harm. These incidents are not cyberattacks. We understand the council's intent here given the publicized instances of AI systems operating outside the bounds of their intended use. As I noted earlier, the risk landscape is constantly evolving, and we are continuing to evolve our strategies to keep the city's infrastructure safe. But not all threats related to AI systems are necessarily cyber attacks, and the legislation as written does not address that. Cyber command would be a critical stakeholder in this discussion, but it is important to emphasize that we need to work with our state and federal partners to address these issues holistically. I also want to provide further context on breaches of security generally. Agency disclosure of a breach of security in any form is governed by Section 10-502 of the administrative code. There are extensive protocols for interagency coordination in the event of any breach of security. These protocols are aligned with the New York State Stop Hacks and Improve Electronic Data Security (SHIELD) Act. Current law policies and protocols are in place for incidents described in the legislation. Further, the threshold of 24-hour public notice is inconsistent with current law and would compromise the city's investigation of a cyber incident. Preconsidered Introduction T2026-2606 would require the Office of Cyber Command in coordination with NYCEM to develop or update an emergency response plan concerning AI system related threats to New York City's infrastructure, operations, public health, and welfare. I'd once again like to emphasize that there are laws, policies, and protocols in place for breaches and security regardless of actor. However, we are happy to discuss more broadly with council how we already coordinate with NYCEM to coordinate and engage with partners to restore services. Finally, I will provide DCWP's feedback on the remaining legislation that would impact the administration. Preconsidered Introduction T2026-2605 would allow any person to submit a complaint to DCWP alleging that a person or entity has violated certain provisions of law related to artificial intelligence. DCWP strongly supports the intent of this bill to establish a civilian enforcement structure for AI violations, especially given widespread reporting that concerns being raised by AI companies employees are being ignored. However, there are fiscal and operational concerns with the volume of complaints that the agency would receive and the resources and expertise required to handle each individual complaint. Therefore, the administration believes it would be important to coordinate closely with mission aligned enforcement agencies at the state level. The New York State Attorney General just recently announced its secure whistleblower portal for New Yorkers to report unsafe and illegal conduct related to AI technology. This could be an opportunity to partner on this existing program to more effectively enforce complaints on behalf of New Yorkers. Preconsidered Introduction T2026-2599 would impose requirements and restrictions on companies that provide chatbots, including requirements related to data security and privacy, the right of chatbot users to access their own data, and restrictions on how chatbot providers can use chatbot user data. DCWP has concerns about this bill. While we support council's goal to better regulate companies deployment of AI chatbots and believe the approach taken by this bill is sound, the implementation and enforcement of this bill's data security and privacy requirements would require a deep technical understanding and investigative ability that is outside of the agency's scope. To be clear, DCWP is committed to regulating harmful practices, including relating to chatbots that fall within the agency's investigative ability. To that end, the administration is working on rules related to the use of AI chatbots to better regulate the space for consumers. The administration has also invested in supporting the New York Attorney General in their efforts to rein in data abuses for which this bill may serve as a model. Preconsidered Introduction T2026-2603 would require any advertisement that promotes an artificial intelligence AI model in the city to disclose whether such a model has undergone validation by a third party. It also would prohibit any such advertisement from including any materially false or misleading statement regarding the safety of an AI model. DCWP supports this bill to require disclosure of third party validation of any advertisement of an AI model. However, as mentioned above, the administration is not certain about the availability or abilities of such businesses, and we want to be clear that any advertising that uses false or misleading statements is currently prohibited under the city's consumer protection law and will be enforced with the full scope of DCWP's authority. We look forward to working with counsel to ensure the law includes effective enforcement mechanisms and to continue addressing issues within DCWP's scope of work as it relates to AI. Thank you for the time. This panel will now take questions.

How this page was made

The exchanges are copied from BetaNYC's machine transcript of the Council's video, in its clean edition: an AI-assisted edit that removes filler words, stutters and false starts and corrects words the transcription clearly misheard. They are not the Council's official transcript.

Speaker names come from the transcript's speaker labels. Sometimes one labeled turn holds words from more than one speaker, including a Council Member's question inside an official's answer. Those turns carry a note. Check the video before quoting anyone.

The question headlines, titles, bill-position summary and follow-up list were written by BetaNYC from the transcript.