web analytics
New York City AI Laws

NYC Local Law 35

City Agency AI Disclosure

The one-paragraph answer

NYC LL 35 (Local Law 35) is part of NYC's automated decision systems (ADS) framework. It requires city agencies to disclose their use of automated decision-making tools that materially affect New Yorkers' access to city services, benefits, or opportunities. Effective through the Mayor's Office of Data Analytics, it shapes procurement contracts for AI vendors selling to NYC agencies, since agency disclosure obligations flow through vendor contracts.

The pain NYC LL 35 is causing our customers

NYC is one of the largest single AI buyers in the country. City agencies use AI in benefits administration, tenant screening for city-owned housing, criminal justice, education, and hundreds of other functions. NYC Local Law 35 forces these agencies to inventory, disclose, and publicly report on their AI use. The pain lands on vendors: to sell AI to NYC agencies, vendors must support the agencies' disclosure obligations. This means clear documentation, transparency about how the AI works, and cooperation with public information requests.

What NYC LL 35 requires

Agency inventory

NYC agencies must maintain and publicly disclose an inventory of automated decision systems in use, including purpose, vendor, and category of decisions the ADS influences.

Impact assessment

Certain high-impact ADS use requires an impact assessment covering fairness, accuracy, and privacy considerations.

Public reporting

Agencies must publish periodic reports about ADS performance and any changes to how ADS is used. This is what generates the vendor-cooperation obligations flowing through procurement.

Complaint mechanism

Members of the public have channels to raise concerns about ADS decisions and request review.

Why NYC LL 35 matters to you

If you sell AI to any government (NYC or otherwise), NYC Local Law 35 foreshadows the disclosure obligations you will face. NYC's ADS framework is being studied by other US municipalities and by states. Building vendor documentation and cooperation practices that support agency disclosure is now table stakes for the government AI market.

For non-vendor businesses, NYC Local Law 35 matters because it produces public information about how AI is being deployed in government contexts. This information shapes public expectations about what AI transparency looks like in private-sector contexts too.

What the research says about NYC LL 35

The academic literature on NYC LL 35 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“The introduction of AI algorithms in public services modifies the chain of responsibility.”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about NYC LL 35 arrives from the board, the buyer, or the regulator.

How to get compliant with NYC Local Law 35: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under NYC LL 35. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities NYC LL 35 reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation NYC LL 35 expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, NYC LL 35 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about NYC Local Law 35

Does NYC Local Law 35 apply to private companies?

Not directly. It applies to NYC agencies. It flows to private companies through vendor contracts and disclosure cooperation obligations.

How does NYC Local Law 35 interact with Local Law 144?

Local Law 144 covers private employers using AEDT for NYC positions. Local Law 35 covers NYC agencies' own AI use. Different actors, different scope.

Where does NYC Local Law 35 fit in SRJ's work?

The AI Vendor Risk Inventory™ and vendor questionnaires from The Operating Discipline for AI Library™ are designed to support cooperation with agency disclosure obligations, including NYC and other jurisdictions.

What Local Law 35 means for vendors in practice

The obligation sits on the agency, but the work lands on the vendor. An agency cannot describe how its automated decision system works if the vendor will not explain it. So Local Law 35 converts into contract terms: documentation deliverables, cooperation with public information requests, notice when the model changes, and often a right for the agency to publish a plain-language description of what the system does.

Vendors who treat this as a compliance nuisance lose government work. Vendors who build the documentation once, and reuse it across every public-sector bid, win it. The disclosure package is an asset, not a cost.

What to prepare before bidding

Four artifacts cover most of what a NYC agency will need from you under Local Law 35: a plain-language description of the system's purpose and decision role, a summary of the data it uses and where that data comes from, a statement of known limitations and tested failure modes, and a named contact who can answer public questions. None of these require disclosing proprietary model weights. All of them require having thought about the questions before the agency asks.

Frequently asked questions about Local Law 35 for vendors

Does Local Law 35 force us to disclose our source code?

No. It requires the agency to disclose what the system does and how it affects New Yorkers, not how it was built. Purpose, data categories, decision role, and limitations are the disclosure surface.

What happens if we refuse to cooperate?

Nothing legally, because the law does not bind you directly. Commercially, the agency cannot meet its obligation with your product in place, so your product gets replaced.

Primary sources on NYC LL 35

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning NYC LL 35 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including NYC Local Law 35, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation