Our county and state have taken several small steps to protect their citizens, but comprehensive legislation at a local, state or federal level is nonexistent.
Is it even possible?
By Cristiana Caruso
Artwork by Justin Negard
Artificial intelligence has made its way into nearly every aspect of our lives, creeping into our daily coffee orders, Google searches and even scheduling doctor’s visits. It drafts emails, summarizes meetings, generates artwork, assists physicians, screens job applicants and powers everything from customer service chatbots to smartphone search engines. As the technology moves at breakneck speed, lawmakers across the country are grappling with increasingly urgent questions: Who is responsible when these systems make mistakes? How much transparency should the public expect? How can governments encourage innovation without sacrificing accountability? These concerns are growing faster than lawmakers can figure out how to regulate them. But why?
In theory, the primary reason is simple: there is a huge degree of difficulty in policing constantly evolving systems. Some state and local governments are establishing guardrails for specific uses of AI, but broader questions surrounding privacy, copyright, misinformation, bias, labor and corporate accountability remain largely unresolved, leaving our legislators struggling to keep pace with the technology’s rapid evolution. So what are our local and state governments doing to protect us from bad actors?
Westchester’s answer, at least for now, has been to start where it can.
Legislating a moving target
New York lawmakers have begun taking steps to address AI-related concerns, and Westchester County has adopted measures aimed at governing how artificial intelligence is used. In February of last year, County Executive Ken Jenkins signed legislation prohibiting the use of digitally deceptive information (videos, images, audio or text) that has been manipulated with AI to falsely represent an individual or a business. Now, “digitally deceptive content” is considered a Class B misdemeanor, punishable by imprisonment, a fine or both. And if a person simultaneously commits another crime, or if they have a prior conviction for the same offense within the last 10 years, the charge increases to a Class A misdemeanor. It was a first step, and behind the scenes, the county has assembled an interdisciplinary task force to evaluate how artificial intelligence can improve public services while protecting sensitive government data from misuse.
While the county’s AI legislation fills a void that was mostly outside the reach of the law, Jenkins says that legislation is only one piece of a much broader effort. Rather than waiting for a crisis to occur, Jenkins says the county has focused on building safeguards around how artificial intelligence is used internally. For example, Westchester’s Department of Information Technology has established strict policies governing internal AI use and created a cross-departmental task force to evaluate new technologies before they are adopted across the county government. The goal, says Jenkins, is to ensure innovation doesn’t come at the expense of cybersecurity or public trust. “It was not one incident that precipitated this,” Jenkins explains, describing the county’s effort to proactively manage emerging technology.
That concern extends beyond the legislation itself. As AI tools become increasingly accessible, Jenkins, who worked at companies like Apple and AT&T, worries many users don’t fully understand what they’re giving away when they rely on free platforms. “Free isn’t free,” he says. “Whatever data you’re putting into a system, you’re giving to someone else.” That philosophy has shaped the county’s cautious approach to adopting new AI technologies, particularly those that interact with confidential government information. And those concerns are hardly theoretical.
Municipal governments across the country have become frequent targets of ransomware attacks and other cybersecurity threats. Jenkins pointed to incidents in neighboring communities where local governments temporarily lost access to critical systems after cyberattacks, underscoring why Westchester emphasizes prevention rather than reaction.
While Jenkins encourages caution, he and other county officials recognize artificial intelligence offers enormous potential benefits, too. Departments are already exploring AI-powered tools capable of improving customer service, helping residents navigate government services and reducing administrative burdens for employees. Even technologies many residents already use—automated phone systems that route callers to the correct department, for example—represent early forms of artificial intelligence. The challenge is determining which tools can safely be incorporated into government operations without exposing sensitive information or creating unintended consequences.
Yet, counties can only extend the arm of the law so far. Jenkins believes the technology ultimately demands a much broader regulatory framework. “We need a national model,” he says, arguing that meaningful oversight cannot be the sole responsibility of counties or states. AI companies operate globally, and the technologies they’re developing don’t recognize jurisdictional boundaries. Without consistent federal standards, local governments fill the gaps one ordinance at a time.
That sentiment is echoed throughout New York’s business community. Michael Romita, president and CEO of the Westchester County Association, views Westchester’s legislation less as an isolated local initiative than as part of a growing national pattern. “I think it’s one example of a broader problem of state and local governments feeling like they have to step in due to the absence of any kind of a cohesive federal strategy,” Romita says. But he doesn’t believe Westchester’s deepfake legislation will dramatically change the way most businesses operate. Instead, Romita sees it as a practical response to an immediate problem. “Everybody is using AI,” he says, “whether they recognize it or not. But nobody, not even leaders in AI technology, understands where the technology is headed. The technology community is still working to understand what guardrails need to be implemented to control AI technology.”
While Congress continues to debate comprehensive AI legislation, states and municipalities have begun creating their own rules to govern everything from deepfakes and political advertising to data centers and consumer protections. New York has already adopted several AI-related measures, including the recently enacted RAISE Act (which stands for Responsible AI Safety and Education); it requires developers to provide transparency and data safety protocols when creating new AI software. They’ve also created policies addressing AI algorithms that require businesses to use personalized algorithmic pricing (pricing that changes based on an individual’s personal data) and to clearly disclose that the price was generated by an algorithm using the consumer’s personal information. Rather than banning dynamic pricing itself, the law focuses on transparency, ensuring consumers know when AI has influenced the price they’re being offered.
Keeping up with the catalysts
Healthcare providers now use AI to document patient visits and organize medical records. Universities are debating how students should use generative AI. Businesses increasingly rely on AI-powered search engines, for customer service platforms and data analysis tools. Unlike previous technological revolutions that largely transformed a single industry, AI touches nearly every aspect of modern life. Every sector is governed by its own existing rules, regulations and legal standards.
The question is no longer whether artificial intelligence should be regulated; it’s how. “Pandora’s box has been opened,” Romita says. “We can’t pretend that this new age of AI does not exist.”
Westchester’s legislation reflects the first steps toward governing artificial intelligence, but the harder work is still ahead. “AI permeates literally every aspect of people’s lives and every industry,” says Paul Wooten, a partner at Abrams Fensterman who advises clients on emerging technology issues through a very niche lens: he was once a legal engineer who helped build these systems. “It’s a step in the right direction, but it’s not the last step. There are going to be different ways that people use AI, and they’re going to find new and interesting ways to misuse it. Laws can be really slow to catch up to reality.” That mismatch, he explains, is already creating legal challenges.
Wooten offers the example of a medical practitioner. “They might say, ‘I’ve never seen anything like this before. I’m going to upload this patient’s file to (the public version of) ChatGPT to get a starting point.’ The problem is they’ve now violated patient privacy laws.” Similarly, attorneys who ask AI to summarize confidential legal documents unknowingly breach attorney-client privilege by sharing protected information with a third party. Comparable ethical quandaries are emerging across finance, education and other industries as organizations race to adopt new technology before legal standards have evolved. “It’s not necessarily that existing laws don’t apply,” Wooten explains. “It’s that AI is beginning to intersect with virtually every area of law at once.”
In many cases, he says, lawmakers are relying on decades-old legal frameworks to address problems no one envisioned when those statutes were written. Westchester’s deepfake legislation was created for exactly that reason. Existing fraud laws prohibited deception. Identity theft laws criminalized impersonation. But AI-generated images, voices and videos capable of convincingly imitating real people created a gap that older laws never contemplated. Rather than replacing those criminal statutes, the county’s legislation filled one of the growing number of spaces where technology outpaced the legal system. “I guarantee you that the foundational lawsuits in this space are still working their way through the courts,” Wooten says. “There just hasn’t been enough time.”
What should come next
Computer scientist Christelle Scharff, Ph.D., director of Pace University’s AI Lab, says the conversation extends beyond legal compliance; it is ultimately about trust. “We need legislation to protect humans,” Scharff says. “The industry is growing very fast. Therefore, every government is taking a more reactive approach rather than planning. The positioning is always responsive, rather than thinking about the future.”
“The United States is a country of innovation; in Europe there’s more caution with the technology,” Scharff continues, explaining there’s a greater emphasis on issues like data sovereignty and limiting AI’s role in high-stakes decisions (like hiring) overseas. Regardless of the regulatory model, however, she argues the same principles should guide future legislation: transparency, explainability and most importantly, human oversight.
Scharff believes people deserve to know when governments or businesses rely on AI to make decisions affecting their lives. “There should be transparency because we need to know where a decision comes from,” she notes. “We need explainability.” Technology should support human judgment—not replace it, she contends. “The last word should always be the human.”
That philosophy extends beyond government. As more companies build proprietary AI systems, Scharff believes organizations should demonstrate how those systems were evaluated, what data they were trained on and how potential bias has been addressed before asking the public to trust their decisions. Trust, she says simply, “is crucial,” as bias remains one of the biggest concerns with AI.
To fully grasp why experts believe transparency is crucial, it’s important to understand how AI systems are built. Artificial intelligence learns from historical data. If data reflects existing inequities, AI systems can unintentionally reproduce them. Wooten points to hiring software as one of the clearest examples. Some companies have attempted to train AI using resumes from employees who previously succeeded within the organization. On its surface, the strategy appears logical. However, in practice, the results can be discriminatory. If a company’s workforce historically lacked diversity, an AI model trained exclusively on those employees may conclude that applicants with similar backgrounds are more likely to succeed while disproportionately screening out qualified women, younger applicants or candidates from underrepresented groups. The algorithm isn’t intentionally discriminating; it’s reproducing patterns embedded within training data. “The AI is doing what it’s told,” Wooten says. “The problem is the inputs.” That example is one of many that underscores why experts increasingly argue AI regulation should focus less on the technology itself and more on how it’s deployed.
Wooten would like to see legislation that prioritizes consumer protections. Lawmakers, he says, should focus on protecting residents from misleading AI-generated content, safeguarding personal data and ensuring companies are transparent about how information is collected and used.
Romita hopes governments avoid another potential mistake: writing legislation without involving the people building the technology. Rather than viewing the industry as an adversary, he argues lawmakers should establish working groups that bring together government officials, universities, researchers and technology companies to develop thoughtful regulations before problems become crises. Westchester, he notes, already possesses many of those resources, from IBM’s headquarters to colleges expanding AI education and research. “The biggest concern is that legislators make uninformed or misinformed decisions without consulting the experts working in this space,” Romita says. “They have to draw a very fine line.”
You’re on your own, for now
There are so many nuances and intricacies about how AI has and will impact society that legislating it seems like an overwhelming responsibility. It’s a vast root system that spreads in endless tendrils. As Wooten notes, “its place in everyday life has become nearly unavoidable.”
Westchester’s AI legislation is an important first step, but it also illustrates a broader national challenge: Can we regulate a technology that is evolving faster than policies can be made while also balancing public trust, economic competitiveness and innovation? So far, the answer is no, but some lawmakers are trying. What our county has accomplished is one small piece of what needs to become a larger group of policies locally, statewide and nationally. And just like the technology they’re regulating, these laws must be able to protect businesses and consumers alike.
Whether you’re just starting to experiment with ChatGPT or were early to the AI party, we’re all in the same policy vacuum, and we must protect ourselves. So as you explore this unregulated technological revolution, we recommend you heed County Executive
Ken Jenkins’ warning: “Free isn’t free.”
This article was edited by Isabella Aranda Garcia and fact-checked by Virna Sandler. Photography was captured with Panasonic Lumix optics and edited in Adobe Creative Suite.
This article was published in the September/October 2026 edition of Connect to Northern Westchester.