Illinois has thrust itself to the front of American AI regulation. On July 6, 2026, Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315), a law that imposes governance, transparency, audit and incident-reporting duties on developers of the most advanced AI systems — and, in a first for any U.S. state, requires mandatory annual independent third-party safety audits. With federal legislation stalled, Illinois has joined a small cluster of states effectively writing the rules for frontier AI on their own.
Who the Law Covers
SB 315 is deliberately narrow in scope but heavy in obligation. It targets "frontier models" and places the most demanding requirements on "large frontier developers" — companies with annual gross revenues exceeding $500 million that build the most advanced and costly AI systems. In practice, that means the handful of labs at the top of the industry, such as OpenAI and Anthropic, rather than the thousands of startups and enterprises deploying AI downstream.
By anchoring the law to revenue and capability thresholds, Illinois aims to regulate systemic risk at its source without sweeping small developers into a compliance regime built for the largest players.
What It Requires
The Act builds a framework around disclosure, verification and accountability:
- Safety and transparency plans: Frontier developers must publish and annually update a plan addressing catastrophic risks, explaining how they meet industry safety standards, describing model capabilities and potential for "catastrophic risk," and detailing their response to safety incidents whenever they deploy a new or substantially modified frontier model.
- First-in-the-nation third-party audits: The law requires annual independent third-party audits of safety practices — a stronger standard than New York's version, which required only a single audit at the point a developer became large enough to qualify.
- Incident reporting: Developers must report significant safety incidents and maintain robust compliance processes.
- Whistleblower protections: The Act creates confidential reporting channels and legal protections for employees raising AI safety concerns.
The reporting standards are aimed at grave harms specifically, including the risk that a model could help a user create chemical, biological or nuclear weapons or carry out large-scale cyberattacks.
Why It Matters
The audit mandate is the provision most likely to reshape industry behavior. Publishing a safety plan is a disclosure exercise; submitting to recurring independent verification is an accountability mechanism with teeth. It moves frontier oversight from self-reported assurances toward external checking — the kind of structural requirement safety advocates have argued is necessary as models grow more capable.
Just as important is the de facto national standard these state laws are creating. Illinois becomes the third state to set frontier-model rules, following New York and California, whose comparable laws were signed in late 2025. Lawmakers estimate that the three states account for roughly 40% of the U.S. AI market — a share large enough that compliance in Illinois, New York and California effectively sets the floor nationwide, regardless of what Washington does.
- Verification over promises: Recurring audits raise the bar from disclosure to independent scrutiny.
- State-led framework: Three states now cover roughly 40% of the market, shaping national practice.
- Targeted scope: Revenue and capability thresholds concentrate obligations on the largest developers.
The Politics of Federal Inaction
Pritzker framed the law explicitly as a response to congressional paralysis. "Congress and the president ought to be passing similar legislation, but they've so far been unwilling, because many are captive to special interests that profit from the industry having no regulation," he said before signing. The bill's Senate sponsor, Sen. Mary Edly-Allen, added that states cannot afford to wait: "We are not willing to wait for Congress to act."
That state assertiveness is colliding with a federal push in the opposite direction. The Federal Trade Commission has been challenging state AI laws — arguing, for example, that Colorado's AI Act improperly coerces companies into altering model outputs — and has invited public comment through July 31 on a policy statement rooted in a December executive order directing it to address state rules that require changing the "truthful outputs of AI models." The result is a widening preemption fight between states writing safety mandates and a federal government skeptical of them.
What Comes Next
For frontier developers, the compliance clock is now running on multiple fronts at once — Illinois and New York obligations, California's earlier framework, and the EU AI Act's transparency and general-purpose-model duties taking effect in early August. Companies will need audit-ready safety programs that satisfy overlapping and not always identical regimes.
The unresolved question is whether this patchwork hardens into a durable standard or triggers a federal preemption showdown that unwinds it. What is already clear is that, with SB 315, Illinois has done more than add another statute to the pile. By making independent, recurring audits a legal requirement for the industry's largest players, it has set a benchmark other states — and possibly Congress — will now have to measure themselves against.
