
TLDR
Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on 6 July 2026, making Illinois the first US state to require independent third-party safety audits for frontier AI systems. Large frontier developers must register with the Illinois Emergency Management Agency from 1 January 2027 and submit to annual audits from 1 January 2028, with civil penalties reaching $3 million for repeat violations. The law goes well beyond the Trump administration's voluntary-only federal approach, set out in Executive Order 14409 in June 2026, and exceeds existing state laws in California and New York. Illinois has set a new floor for AI accountability that other states are likely to measure themselves against.
KEY TAKEAWAYS
What the law actually requires
Governor JB Pritzker signed SB 315 on 6 July 2026, and the text is specific about what changes and when.[1] From 1 January 2027, large frontier developers must file a disclosure statement and pay a fee to the Illinois Emergency Management Agency before developing, deploying or operating a frontier model in the state.verifiedVerified Source: gov-pritzker-newsroom.prezly.com[2] Annual independent third-party safety audits follow on 1 January 2028, or 90 days after a company qualifies, whichever is later.[1]
Before deploying any new or substantially modified frontier model, developers must also publish a transparency report covering catastrophic risk assessments, audit results, the extent of third-party involvement and other mitigation measures.[2] Both the audit obligation and the transparency reporting apply simultaneously once a developer crosses the threshold; one does not substitute for the other.
Who the law covers
SB 315 targets what it calls "large frontier developers" operating "high-risk" frontier models. Illinois legislators debated multiple AI bills through early 2026, including proposals focused on child protection and risk reporting, before advancing SB 315 as a bipartisan compromise. The bill passed unanimously before reaching Pritzker's desk.
Nick Beckstead, CEO of the Secure AI Project, said the scope of the mandate is what sets it apart. Illinois is the first state to mandate independent third-party evaluations of AI safety practices, Beckstead said, making its AI law the strongest in the country.[1] The key word is "independent": existing state laws require safety frameworks and disclosures, but stop short of demanding an external auditor sign off on the results.
Penalties and enforcement
Under Section 25 of SB 315, a first violation carries a civil penalty up to $1 million; subsequent violations attract penalties up to $3 million, recovered through civil action by the Illinois Attorney General.verifiedVerified Source: ilga.gov[2] The Attorney General structure mirrors what New York built into its RAISE Act, so enforcement depends on prosecutorial prioritisation rather than a dedicated AI regulator with standing investigative powers.
Illinois Emergency Management Agency becomes the registration body, an unusual choice that signals the legislature views advanced AI failure as an emergency-management problem as much as a consumer-protection one. Developers that miss the 1 January 2027 filing deadline face exposure before the audit clock even starts.
The federal backdrop
President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," on 2 June 2026.[3] The order establishes a voluntary framework under which the federal government may review frontier AI models for up to 30 days before public release to screen for national security risks. Participation is not compulsory.
That gap became visible in the same month, when a US export-control directive temporarily disabled Anthropic's Fable 5 and Mythos 5 models for foreign nationals, illustrating how federal intervention in AI can be reactive and ad hoc rather than systematic. Governor Pritzker said that as AI systems become more powerful and the federal government is unwilling to step in, states have a responsibility to protect their people from the dangers of AI while still harnessing the unique potential of the technology.[1]
Where Illinois sits among state laws
California moved first. Governor Newsom signed SB 53, the Transparency in Frontier Artificial Intelligence Act, on 29 September 2025.[4] California's SB 53 requires large frontier developers to publish a frontier AI framework, report catastrophic risk assessments to the Office of Emergency Services, disclose critical safety incidents and protect whistleblowers.verifiedVerified Source: gov.ca.gov Independent third-party audits are not required.
New York followed on 19 December 2025, when Governor Hochul signed the RAISE Act.[5] New York's law requires large AI developers to create and publish safety frameworks, report critical harm incidents within 72 hours, and subjects non-compliance to civil enforcement by the Attorney General, with penalties matching Illinois at up to $1 million for a first offence and $3 million for subsequent ones. Like California, it stops short of mandatory independent auditing.
What comes next
Illinois developers and their legal teams now face a two-stage compliance calendar: disclosure and IEMA registration by 1 January 2027, then a functioning third-party audit programme in place before 1 January 2028. Companies operating across California, New York and Illinois will need to satisfy three distinct state regimes simultaneously, with no federal harmonisation in sight under the current executive posture.
Other state legislatures are watching. The bipartisan, unanimous passage of SB 315 in Illinois, a state that does not typically lead technology regulation, signals that frontier AI oversight has moved beyond partisan framing. The Illinois Attorney General retains civil enforcement authority from the date of enactment, 6 July 2026.
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
What is SB 315 and when does it take effect?
Who has to comply with Illinois's new AI law?
How does Illinois's law differ from California's and New York's?
What are the penalties for non-compliance?

Takeshi Mori covers startups and technology for Bushletter. He is impatient with hype and interested in how products actually get built.



