The law layer · Illinois, United States · US state law
Illinois SB 315, the Artificial Intelligence Safety Measures Act
Signed by Governor JB Pritzker on 6 July 2026 · effective 1 January 2027
Page verified 5 August 2026. Signing and effective dates confirmed against the Governor’s own newsroom release; the obligation summary is drawn from the enacted bill as reported by counsel, and we say so.
The first American state law to require an independent third-party audit of a frontier AI developer. It does not reach law firms, and it does not reach most companies. It reaches a handful of the largest model developers, and it is the template other states will copy.
Who it applies to
- Threshold“Large frontier developers”: annual gross revenues above $500 million, training models using more than 1026 operations of compute. Both limbs.
- In practiceA small number of named developers, on the reporting: OpenAI, Anthropic, Google, Meta and xAI.
- Not youIf you are a law firm, an agency or an enterprise deploying someone else’s model, this Act does not impose duties on you. Its relevance is that your vendor will now have a published framework and an audit you can ask to see.
What it requires
- FrameworkPublish a frontier AI framework.
- TransparencyPublish a transparency report and annual disclosures.
- AuditObtain an independent third-party audit. This is the provision with no prior US state analogue.
- IncidentsReport critical safety incidents.
Why it is on this list
Because of the audit clause, and because of what an auditor will ask for. A published framework is a claim. An independent audit is someone testing whether the claim held on a given day, which means the developer needs a record of what the system actually did, not a policy describing what it should do. That is the same gap this record has been documenting on the courts side, arriving from the regulatory side.
It also sits directly alongside the EU AI Act obligations that became applicable on 2 August 2026. A developer in scope of both now owes a published framework and a third-party audit in Illinois, and transparency duties under Article 50 in the European Union, on overlapping evidence.
What to do about it
This is an estate problem, not a document problem.
An independent third-party audit is answered with records, not policies. Whatever an auditor is entitled to ask for, the cheapest form to produce it in is one sealed at the time the work happened. Regulayer records the decision as it is taken, outside the system being governed, content-free, and verifiable by anyone holding the file with public mathematics, without a call to us.
Regulayer for enterpriseThe AI audit trail →
For an individual practitioner, the same engine is $349 a month with a free week: start sealing. See also the law layer and every jurisdiction we track.
Sources
- Office of the Governor, signing announcement (6 July 2026)
- Illinois General Assembly, SB 315, 104th General Assembly
- Obligation summary drawn from counsel analyses of the enacted text (Crowell & Moring; Norton Rose Fulbright; Akerman). We have not yet quoted the section numbers, and we say so rather than invent them.
Related
- The 124 laws AI rules by country
- EU AI Act, Article 50, applicable since 2 August 2026
- California AB 2013, training-data transparency
Checked 5 August 2026. Dates verified at source; obligations summarised from counsel analysis pending a section-by-section read of the enrolled bill. Information, not legal advice.
Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.
