Skip to content
Menu ▾
Patent pending

The law library · Illinois, United States · US state law

Illinois SB 315, the Artificial Intelligence Safety Measures Act

Public Act 104-0538 · signed by Governor JB Pritzker on 6 July 2026 · effective 1 January 2027

Page verified 13 August 2026 against the General Assembly bill status (Public Act 104-0538). Signing and effective dates confirmed against the Governor’s own newsroom release; the obligation summary is drawn from the enacted bill as reported by counsel, and we say so.

The first American state law to require an independent third-party audit of a frontier AI developer. It does not reach law firms, and it does not reach most companies. It reaches a handful of the largest model developers, and it is the template other states will copy.

Who it applies to

  • Threshold“Large frontier developers”: annual gross revenues above $500 million, training models using more than 1026 operations of compute. Both limbs.
  • In practiceA small number of named developers, on the reporting: OpenAI, Anthropic, Google, Meta and xAI.
  • Not youIf you are a law firm, an agency or an enterprise deploying someone else’s model, this Act does not impose duties on you. Its relevance is that your vendor will now have a published framework and an audit you can ask to see.

What it requires

  • FrameworkPublish a frontier AI framework.
  • TransparencyPublish a transparency report and annual disclosures.
  • AuditObtain an independent third-party audit. This is the provision with no prior US state analogue.
  • IncidentsReport critical safety incidents.

Why it is on this list

Because of the audit clause, and because of what an auditor will ask for. A published framework is a claim. An independent audit is someone testing whether the claim held on a given day, which means the developer needs a record of what the system actually did, not a policy describing what it should do. That is the same gap this record has been documenting on the courts side, arriving from the regulatory side.

It also sits directly alongside the EU AI Act obligations that became applicable on 2 August 2026. Regulation (EU) 2026/1744 has since deferred the Chapter III high-risk obligations to 2 December 2027 and 2 August 2028; the Article 50 transparency duties are the limb that bites on this comparison. A developer in scope of both now owes a published framework and a third-party audit in Illinois, and transparency duties under Article 50 in the European Union, on overlapping evidence.

What to do about it

This is an estate problem, not a document problem.

An independent third-party audit is answered with records, not policies. Whatever an auditor is entitled to ask for, the cheapest form to produce it in is one sealed at the time the work happened. Regulayer records the decision as it is taken, outside the system being governed, content-free, and verifiable by anyone holding the file with public mathematics, without a call to us.

Regulayer for enterpriseThe AI audit trail →

For an individual practitioner, the same engine is $349 a month with a free week: start sealing. See also the law library and every jurisdiction we track.

Sources

Related

Checked 13 August 2026. Dates verified at source. Obligations are summarised from counsel analysis; section numbers live in the enrolled bill and are not carried here. Information, not legal advice.

Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.