Skip to main content

IL SB 315

Artificial Intelligence Safety Measures Act

Frontier-model AI safety law requiring large AI developers to publish and annually update catastrophic-risk frameworks, undergo independent third-party safety audits, report safety incidents to the state, and protect whistleblowers. Would be the first US law mandating independent third-party audits of frontier AI developers.

Jurisdiction

Illinois

Enacted

Jul 6, 2026

Effective

Jan 1, 2027

Enforcement

Illinois Attorney General (exclusive)

Signed by Governor JB Pritzker July 6, 2026; enacted as Public Act 104-0538. Effective January 1, 2027.

Illinois General Assembly

Why It Matters

First US state measure to require independent third-party safety audits of frontier AI developers, extending the catastrophic-risk transparency model established by California SB 53 and New York's RAISE Act.

Recent Developments

Passed the Illinois Senate 52-5 (May 21, 2026) and House 110-0 (May 27, 2026). Signed by Governor Pritzker on July 6, 2026 as Public Act 104-0538, making Illinois the first state to require regular independent third-party safety audits of frontier AI developers. Modeled on California SB 53 (TFAIA) and New York's RAISE Act; NetChoice had requested a veto.

At a Glance

Applies to

Foundation Model

Who Must Comply

  • Large frontier AI developers with more than $500,000,000 in annual gross revenue building models above a frontier-scale compute threshold

Applicability thresholds:

500M USD/annual (frontier) — Subject to frontier AI safety framework, audit, incident-reporting, and whistleblower obligations

Safety Provisions

  • Large frontier developers must create, publish, and annually update a frontier AI safety framework addressing catastrophic-risk assessment, mitigations, governance, and cybersecurity
  • Annual independent third-party audits of frontier-model safety practices (effective January 1, 2028)
  • Pre-deployment transparency reports for new or substantially modified frontier models
  • AI safety incident reporting to state officials within 72 hours of discovery
  • Whistleblower protections for employees raising safety concerns

Compliance & Enforcement

Key Dates

Jan 1, 2028

Annual independent third-party safety audits of frontier developers required

Penalties

$3M/violation

View on map

Illinois

Focus Areas

Algorithmic accountability

Cite This

APA

Illinois. (2026). Artificial Intelligence Safety Measures Act.

Related Regulations

In Effect US-IL

IL WOPR Act

Illinois law prohibiting licensed professionals from using AI systems to make independent therapeutic decisions, directly interact with clients in therapeutic communication, or detect emotions/mental states. AI limited to administrative and supplementary support with licensed professional oversight.

In Effect US-IL

IL AI Employment Law

Amends Illinois Human Rights Act to make it a civil rights violation for employers to use AI that discriminates based on protected classes in employment decisions. Requires notice to employees and applicants when AI is used in hiring, firing, promotion, or discipline.

Enacted US-NE

NE LB 525

Adopts the Conversational Artificial Intelligence Safety Act, imposing disclosure duties on operators of conversational AI services and requiring protocols addressing crisis situations and behavioral health care, enforced by the Attorney General with civil penalties.

Enacted US-NJ

NJ Kids Code

Codifies a New Jersey Age-Appropriate Design Code requiring covered online service providers to design services likely to be accessed by minors around minors' safety and wellbeing, including high-privacy defaults, limits on engagement-maximising design features, and data protection impact assessments. Enforced by the Attorney General with a private right of action for minors and their parents.

Enacted US-NY

NY SAFE Act

Restricts algorithmically personalized ("addictive") feeds and overnight notifications for under-18 users without parental consent.

Enacted US-VT

VT AADC

Vermont design code structured to be more litigation-resistant: focuses on data processing harms rather than content-based restrictions. AG rulemaking authority begins July 2025.

Last updated July 13, 2026. Verify against primary sources before relying on this information.