Illinois AI Safety Measures Act (SB 315): First US Law Requiring Annual Third-Party AI Audits

Illinois enacted the AI Safety Measures Act on July 6, 2026, the first US law mandating annual independent safety audits of frontier AI models. Who is covered, what the law requires, penalties, and why OpenAI and Anthropic backed it.

Illinois AI Safety Measures Act (SB 315): First US Law Requiring Annual Third-Party AI Audits

Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315) into law on July 6, 20261. The law requires the largest AI developers to undergo annual safety audits by independent third parties — the first requirement of its kind in the United States12. The core obligations take effect on January 1, 202823.

Notably, OpenAI and Anthropic — companies the law will regulate — supported the bill2. With no comprehensive federal AI statute in place, state law continues to shape how frontier AI companies operate, and Illinois just moved that line forward.

Who Is Covered

The law targets “frontier models,” defined as AI models trained using more than 10^26 floating-point operations (FLOPs)3. Developers of such models whose annual gross revenues exceeded $500 million in the preceding calendar year are classified as “large frontier developers” and carry the heaviest obligations3.

In practice, the law is aimed at the biggest AI developers — OpenAI, Anthropic, Google. Smaller AI companies, and ordinary businesses that merely use AI, are not covered.

What the Law Requires: Audits, Frameworks, Incident Reporting

The main obligations for large frontier developers are as follows.

First, starting January 1, 2028, they must undergo annual audits by independent third parties examining model risks and mitigations3. According to Capitol News Illinois, California and New York laws include audit provisions but only require a single audit; Illinois is the first state to mandate them annually2.

Second, developers must publish, implement, and annually update an AI safety framework documenting how they assess and mitigate catastrophic risks, deploy cybersecurity, and identify and respond to critical safety incidents3. A “catastrophic risk” is defined as a foreseeable and material risk of death or serious injury to more than 50 people, or more than $1 billion in property damage, from a single incident4.

Third, before deploying a new model or substantially modifying an existing one, developers must publish transparency reports covering the release date, supported languages, modalities, intended uses, and applicable restrictions3. Critical safety incidents must be reported within 72 hours of establishing a reasonable belief that one occurred — or within 24 hours if the incident poses an imminent risk of death or serious physical injury3.

The law also prohibits retaliation against employees, contractors, and affiliates who report safety concerns, and requires internal anonymous reporting channels3.

Penalties and Enforcement

Enforcement falls to the Illinois attorney general, with civil penalties of up to $1 million for a first violation and up to $3 million for subsequent ones23. There is no private right of action, except in connection with the whistleblower protections3.

The Backstory: States Are Leading on AI Regulation

With federal AI legislation stalled, states have led. New York’s RAISE Act cleared the legislature in June 2025 and was signed into law that December, and California enacted the Transparency in Frontier AI Act in September 2025, establishing transparency frameworks for frontier AI3. Illinois builds on that with the annual third-party audit requirement. “We are not willing to wait for Congress to act,” said State Senator Mary Edly-Allen, the bill’s sponsor2.

“States have a responsibility to protect our people from dangers of AI,” Pritzker said at the signing1. Support was bipartisan — only five Republican senators voted no, and the House passed the bill unanimously2. Industry reaction was split: OpenAI and Anthropic backed the bill, with Anthropic representatives attending the signing2, while trade group TechNet warned that “Illinois would effectively be requiring private actors to make highly subjective determinations…without established national standards”2.

Rulemaking around AI safety is advancing internationally too: the United Nations launched a Global Dialogue on AI Governance with more than 170 countries, the UN’s ITU stood up an AI for Good Global Commission, and on the industry side, Google began disclosing when ads are made with AI alongside the European Commission’s code of practice for labeling AI-generated content — transparency keeps emerging as the common thread.

Published Safety Documents Become Primary Sources for Vendor Comparison

The law does not directly apply to companies or individuals outside the US — Japan, by contrast, has chosen a light-touch AI policy approach rather than mandatory audits. But it regulates the developers behind ChatGPT, Claude, and other major AI services, and the required safety frameworks and transparency reports will be public. If you evaluate AI vendors, those documents become primary sources for comparing safety practices.

More broadly, public oversight is increasingly built into how frontier models ship — GPT-5.6 went through a US government safety review before general availability. The pattern of “transparency, third-party verification, incident reporting” is becoming the standard template across state law, federal practice, and international bodies — a structure worth borrowing when drafting internal AI governance rules.

Sources

  1. Gov. Pritzker Signs Nation-Leading Artificial Intelligence Safety Law - Illinois Governor’s Office official announcement (July 6, 2026)
  2. Pritzker signs landmark AI regulation bill that aims to mitigate risks - Capitol News Illinois (July 6, 2026)
  3. Illinois AI Safety Measures Act SB 315: What Frontier AI Developers Must Do Before January 2028 - Crowell & Moring LLP client alert
  4. Illinois SB 315: A State Strategy for Enduring National AI Safety Standards - Akerman LLP analysis

We publish the latest AI news every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →