Roshni Patel, Alex Cox
Session Time: Wed, Nov 4, 2026: 08:50 AM – 09:50 AM
Financial institutions are facing mounting complexity on three fronts at once. On cybersecurity, NYDFS issued detailed September 2026 guidance on how covered entities must conduct and document risk assessments under Part 500, explicitly previewing that the guidance will shape future examinations and enforcement, and flagging third-party and vendor risk as a recurring area of focus.
On privacy, state law is fragmenting further. New Jersey’s new data broker law imposes an ban on the sale of sensitive data, Connecticut is phasing in new requirements covering surveillance pricing, facial recognition, geolocation, genetic data, and data broker registration, and California just expanded consumer deletion rights to reach personal information a business obtained about a consumer from any source, not just data collected directly from them. For institutions operating nationally, that means no single compliance template works twice.
On AI, NYDFS has already signaled, via a 2024 industry letter to all Part 500-covered entities, that AI-related risks, like deepfake-enabled social engineering and fraud, fall within existing cybersecurity obligations, making it a live issue in DFS examinations. Separately, the Conference of State Bank Supervisors released its own AI Supervisory Framework in September 2026, giving state banking examiners a parallel tool to assess AI use and governance.
Join our panel of practitioners and industry leaders for a candid discussion of what’s actually changing on the ground: building a cybersecurity program that can withstand an NYDFS exam, managing a privacy compliance program across a patchwork of state laws with no common denominator, and standing up AI governance that holds up to regulatory scrutiny.
Roshni Patel, Counsel, Troutman Pepper Locke
Alex Cox, Senior Associate, Troutman Pepper Locke
Reading Materials:


