Written and maintained by CASRAI Editorial Board
Last updated
On September 17, 2026, New York Attorney General Letitia James issued an industry alert urging current and former workers at AI companies with knowledge of unsafe or unlawful development practices to come forward. The alert did not stand up a new, AI-specific complaint form — it directed AI-industry workers to the Office of the Attorney General’s existing whistleblower portal at ag.ny.gov/i-want/use-whistleblower-portal, the same intake channel OAG uses across its civil enforcement docket, and stated that complaints can be filed anonymously and confidentially. What’s new is the target, not the tool: this is the first time a state Attorney General has publicly pointed that general-purpose mechanism at AI safety specifically, citing New York’s SHIELD Act, the federal Computer Fraud and Abuse Act, OAG’s general civil enforcement authority over fraud and privacy violations, and New York’s Responsible AI Safety and Education (RAISE) Act — even though the RAISE Act itself does not take effect until January 1, 2027.
That timing matters, because it lands in the middle of a fast-moving story that has nothing to do with statutory incident-reporting deadlines. It is the convergence of three separate threads: a two-year-old cross-industry advocacy movement asking AI labs to protect employees who speak up about risks no statute yet covers, a whistleblower provision buried in the EU AI Act that most compliance teams have never had reason to open, and a viral resignation post that put the words “AI” and “whistleblower” in front of a mainstream news audience for the first time. This guide covers that broader advocacy-and-enforcement layer. CASRAI’s existing coverage of SB 53’s and the RAISE Act’s own statutory whistleblower mechanics lives in SB 53 Critical Safety Incident Reporting, Accountable Decision-Makers Under SB 53, and the SB 53 vs. RAISE Act comparison — this piece is about the territory outside those two statutes.
The “Right to Warn” letter: where the employee-advocacy movement started
The current wave of AI whistleblower advocacy traces back to June 4, 2024, when a group of current and former employees of OpenAI and Google DeepMind published an open letter titled “A Right to Warn about Advanced Artificial Intelligence.” Seven signatories put their names to it; four current and two former employees signed anonymously, citing fear of retaliation. AI researchers Yoshua Bengio and Geoffrey Hinton endorsed it publicly, though they were not employees of the companies in question.
The letter’s core argument is that ordinary whistleblower law does not reach the risks its signatories were worried about. In its own words, “ordinary whistleblower protections are insufficient because they focus on illegal activity, whereas many of the risks we are concerned about are not yet regulated.” A statutory whistleblower channel — like the one SB 53 later created in California, or the general OAG portal New York pointed at AI companies in 2026 — only protects a report that alleges a violation of law. The 2024 letter was written for a gap statute drafters hadn’t filled yet: a researcher who believes a frontier model poses a catastrophic risk that no law yet defines as illegal has, under ordinary whistleblower frameworks, nothing to point to.
The letter asked AI companies to make four voluntary commitments, none of which required new legislation:
- Not enter into or enforce any agreement that prohibits “disparagement” or criticism of the company over risk-related concerns, and not retaliate against employees who raise such concerns.
- Facilitate a verifiably anonymous process for current and former employees to raise risk-related concerns to the company’s board, to regulators, and to independent organizations with relevant expertise.
- Support a culture of open criticism, allowing employees to raise risk-related concerns publicly about the company’s technology, so long as trade secrets and other intellectual-property interests are appropriately protected.
- Not retaliate against employees who publicly share risk-related confidential information after other processes have failed — provided trade secrets and IP interests are still appropriately protected.
Those four asks are a useful yardstick for everything that has happened since, because they describe what a company-level whistleblower channel would need to cover if it were designed for AI-safety concerns specifically rather than adapted from a generic compliance-hotline template: anonymity, protection against non-disparagement clauses, a path that survives the internal process failing, and a scope that isn’t limited to what’s already illegal.
The EU AI Act’s own whistleblower provision
Unlike SB 53 and the RAISE Act, the EU AI Act does not write its own free-standing whistleblower regime. Article 87, titled “Reporting of infringements and protection of reporting persons,” instead incorporates an existing instrument by reference. Its operative text is a single sentence: “Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.” Directive (EU) 2019/1937 is the EU’s general Whistleblower Protection Directive, adopted in 2019 to set minimum protections — confidential reporting channels, a ban on retaliation, legal remedies — for people who report breaches of EU law across a defined list of policy areas.
Article 87’s effect is to add “infringements of the AI Act” to that list rather than build a parallel structure. Practically, that means an employee reporting an EU AI Act violation inside a company operating in the EU gets the Directive’s general protections — not a bespoke AI-safety carve-out, and not the broader catastrophic-risk-even-if-not-yet-illegal scope the 2024 Right to Warn letter asked for. It is, in that sense, closer in kind to SB 53’s Labor Code section 1107.1 than to the open letter’s asks: a protection tied to reporting an actual legal infringement, not a general safety concern.
What’s actually new versus what’s being amplified
Laid side by side, the picture as of September 2026 is:
- Statutory, in force: SB 53’s Labor Code section 1107.1 whistleblower provision (California, in force since January 1, 2026) and the EU AI Act’s Article 87 (incorporating Directive 2019/1937). Both protect reports of an actual legal violation.
- Statutory, not yet in force: New York’s RAISE Act, signed December 19, 2025 but not effective until January 1, 2027 — and, per CASRAI’s existing SB 53 vs. RAISE Act comparison, the RAISE Act as enacted contains no whistleblower or anti-retaliation provision at all; an earlier Senate draft had one, and it was dropped before the bill Governor Hochul signed became law.
- Enforcement posture, not a new statute: the NY Attorney General’s September 17, 2026 industry alert, which uses OAG’s existing general whistleblower portal and existing civil-enforcement authority (the SHIELD Act, the federal CFAA, and general fraud/privacy jurisdiction), and cites the not-yet-effective RAISE Act as a forward-looking basis rather than a currently enforceable AI whistleblower statute.
- Voluntary, cross-lab advocacy: the 2024 Right to Warn letter’s four asks, which remain requests directed at companies, not law, and which explicitly target the gap that all of the above statutory mechanisms leave open — a concern that isn’t yet a defined legal violation.
The NY AG’s move is best read as an enforcement agency signaling where it intends to point existing tools, not as New York creating a new AI whistleblower right. That distinction is easy to lose in headline coverage, and it’s the one this section exists to preserve.
Why this surfaced now: a viral resignation post
The immediate news hook behind the AG’s alert was a wave of coverage earlier in September 2026 around Jacob Coxon, a researcher who resigned from Anthropic and published a public warning, on X, about the risk that advanced AI could cause human extinction absent stronger industry-wide controls. The post and Coxon’s subsequent comments were picked up widely — including by mainstream outlets such as the Guardian, the BBC, and Newsweek — and also drove coverage from outlets like Fox News under headlines emphasizing that “AI extinction warnings dominate headlines” in the wake of the post.
Worth flagging for anyone using this moment as a citation: Coxon’s claims are his own stated views on catastrophic risk, amplified through a viral social-media post and subsequent interviews, not a filed legal complaint, an audited finding, or a company disclosure under any of the statutes above. Some of the outlets that drove the story’s broader reach cover AI-safety claims in a more sensational register than the reporting from established science and technology desks; treat headline-level “AI could kill us all” framing from that tier of coverage as an attention-getting gloss on Coxon’s own warning, not as an independently verified fact pattern. What is independently verifiable is that the post generated enough sustained public attention, cutting across both mainstream and tabloid-adjacent press, that it plausibly shaped the timing of a sitting state Attorney General’s public statement eight days later.
How CASRAI’s NIKOLAI tracks this
CASRAI’s own NIKOLAI project — an independent, unendorsed frontier-AI-safety reference dictionary, not a standard adopted or approved by any lab, regulator, or evaluator — defines this territory as an element in its Commitments and Governance track (N9): Noncompliance and Whistleblower Reporting, described as “a proposed record of the channel, protections, and reporting line staff can use to report noncompliance or catastrophic-risk concerns, anonymously if offered.” That definition is deliberately broader than any single statute’s whistleblower clause — it asks an organization to document the reporting channel, what protections attach to it, and who the report actually reaches, regardless of whether the underlying concern is a defined legal violation or a catastrophic risk that (as the 2024 Right to Warn letter put it) “isn’t yet regulated.”
N9 also pairs that element with a second one, Accountable Decision-Maker and Sign-Off — “a proposed record of the named role or person who approves a risk, deployment, or framework decision, and what was approved, by whom, and when,” covered in depth for the SB 53 context in CASRAI’s accountable decision-maker guide. Read together, the two elements ask the same underlying question the Right to Warn letter and the NY AG’s alert are both circling from different directions: when a report of noncompliance or catastrophic risk is filed, who is on record as accountable for what happens to it, and does the reporting channel actually reach that person rather than dead-ending with whoever the report is about. NIKOLAI does not adjudicate whether any specific company’s channel meets that bar — it is a proposed vocabulary an organization can use to document its own practice, not a certification, and no organization’s use of it implies CASRAI’s or any regulator’s endorsement.
Frequently asked questions
Did New York launch a new AI whistleblower portal on September 17, 2026?
Not a new one. Attorney General Letitia James issued an industry alert on that date directing AI-industry workers to the Office of the Attorney General’s existing, general-purpose whistleblower portal. What changed is that the alert explicitly names AI development practices as a category OAG wants reported through that channel — not the creation of a new form, statute, or AI-specific complaint mechanism.
Does the RAISE Act give New York AI workers whistleblower protection right now?
No. The RAISE Act as signed contains no whistleblower or anti-retaliation provision — an earlier draft had one and it was removed before enactment — and the statute itself is not in force until January 1, 2027. The NY AG’s September 2026 alert cites the RAISE Act as a forward-looking basis for its interest in AI safety, but the underlying whistleblower complaint mechanism it points to is OAG’s existing general portal, used under other, already-effective authority such as the SHIELD Act and the federal Computer Fraud and Abuse Act.
What did the 2024 “Right to Warn” letter actually ask for?
Four voluntary commitments from AI companies: no non-disparagement or retaliation clauses covering risk-related criticism, a verifiable anonymous internal reporting channel, a culture that allows employees to raise risk concerns publicly (subject to protecting trade secrets), and no retaliation against employees who go public with risk-related information after internal channels have failed. It was signed by current and former OpenAI and Google DeepMind employees and publicly endorsed by Yoshua Bengio and Geoffrey Hinton.
Does the EU AI Act have its own whistleblower statute?
Not a standalone one. Article 87 incorporates the EU’s existing 2019 Whistleblower Protection Directive (Directive (EU) 2019/1937) by reference, extending its confidential-reporting and anti-retaliation protections to reports of AI Act infringements specifically.
Is the viral ex-Anthropic researcher story a verified safety finding?
No. It is a former employee’s public statement of his own risk assessment, made after resigning, amplified through a viral social post and follow-on interviews and press coverage — not a regulatory filing, an audited disclosure, or a peer-reviewed finding. Some of the coverage that drove its reach used sensational framing; readers relying on it for anything beyond “this is a notable moment in public AI-safety discourse” should go to primary reporting rather than headline aggregation.








