Illinois has become the first U.S. state to require independent third-party audits of large frontier AI developers after Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, into law. The measure, signed in early July 2026 and widely reported on July 9, establishes what advocates are calling the strongest AI safety framework in the nation, pushing transparency and accountability rules onto the companies building the world's most powerful models.

The signing caps a remarkably bipartisan journey through the state legislature. The bill passed the Illinois House 110-0 and cleared the Senate 52-5, drawing support from lawmakers who argued that Washington's inaction on AI regulation has left states with no choice but to act. For more context on this story, see our ongoing artificial intelligence updates.

What the Law Requires

At its core, SB 315 imposes a layered set of obligations on developers of "frontier models" — the most computationally intensive AI systems in existence. According to a detailed client alert from the law firm Crowell & Moring, the law distinguishes between ordinary "frontier developers" and "large frontier developers," with the latter defined as those with annual gross revenues exceeding $500 million.

Beginning January 1, 2028, large frontier developers must publish, implement, and annually update an AI safety framework documenting how they assess and mitigate catastrophic risks, secure their models against cyberattacks, respond to critical safety incidents, and share the results of third-party evaluations. Developers must also publish transparency reports before deploying a new model or substantially modifying an existing one, disclosing details such as release dates, supported languages and modalities, intended uses, and usage restrictions.

The law defines "catastrophic risk" with unusual specificity. It covers foreseeable risks that a model could lead to the death or injury of more than 50 people, cause more than $1 billion in property damage, provide "expert-level" assistance in creating a weapon of mass destruction, operate without meaningful human oversight, or evade the control of its developer or user. A "critical safety incident" includes the unauthorized access or modification of model weights, harm resulting from catastrophic risk, or a model that "uses deceptive techniques" to subvert its developer's control.

A First: Mandatory Independent Audits

What sets Illinois apart from every other state is the audit requirement. While California and New York have already passed their own frontier AI laws — California's Transparency in Frontier Artificial Intelligence Act in September 2025 and New York's Responsible AI Safety and Education (RAISE) Act in December 2025 — neither mandates independent third-party audits. Beginning in January 2028, Illinois will require large frontier developers to undergo annual audits by independent firms examining model risks and mitigations, conducted according to generally accepted auditing standards.

The law also creates whistleblower protections and reporting processes for AI company employees, giving workers a safe channel to surface safety concerns. Oversight and enforcement are vested in the Illinois Emergency Management Agency and the state attorney general.

Which Models Are Covered

Like its California and New York predecessors, SB 315 attaches its obligations to a narrow, technically defined class of systems. A "frontier model" is one trained using more than 10^26 floating-point operations (FLOPs) — a mathematical baseline measuring the compute used in training. That threshold is higher than the European Union's 10^25 FLOPs cutoff for general-purpose AI models, meaning Illinois regulates fewer systems than the EU AI Act.

Today, only a handful of models exceed that compute threshold. But analysts cited by Crowell & Moring project roughly 30 such models will exist by 2027 and more than 200 by 2030, suggesting the law's reach will expand steadily as the industry scales up.

Crucially, the geographic scope is not limited to companies based in Illinois. Any developer whose models are accessible to users in California, New York, or Illinois is subject to the new rules — effectively capturing every major frontier developer in the world.

Industry Reacts

The response from leading AI companies has been notably supportive. NBC News reported that both OpenAI and Anthropic publicly backed the bill. Anthropic's head of state and local government relations, Cesar Fernandez, said Illinois is "on track to become the first state to require independent, third-party audits of large frontier AI developers' safety practices," adding that the law takes voluntary practices and "helps establish a baseline that every leading AI developer is expected to meet."

OpenAI spokesperson Jamie Radice praised the "thoughtful framework for frontier AI safety," while the same day the Illinois House passed the bill, OpenAI released its own Frontier Governance Framework — a voluntary structure explicitly designed to align with the requirements of all three states. A trade organization representing other AI companies opposed the measure, while Google, xAI, and Meta did not immediately respond to requests for comment.

A De Facto National Standard

With Congress yet to pass comprehensive AI legislation, the combined weight of California, New York, and Illinois is effectively creating a national compliance standard from the ground up. Crowell & Moring concluded that the three states have built what is "essentially a national framework for AI safety and transparency," regardless of federal action.

Democratic Representative Daniel Didech, who sponsored the bill in the Illinois House alongside Senate sponsor Mary Edly-Allen, acknowledged the awkwardness of state-by-state regulation. "The best way to regulate these types of catastrophic risks would be a federal approach," he told NBC News. "The reality is that Congress has not taken up this issue yet, and the technology is developing at such a rapid pace that states have had no choice but to step in."

For the AI industry, the message is now unmistakable: with three of the largest U.S. markets aligned on overlapping transparency, audit, and incident-reporting rules, frontier developers will need to meet a rising baseline of safety accountability well before Washington ever acts.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →