Menu

The law layer · Illinois, United States · US state law

Illinois SB 315, the Artificial Intelligence Safety Measures Act

Signed by Governor JB Pritzker on 6 July 2026 · effective 1 January 2027

Page verified 5 August 2026. Signing and effective dates confirmed against the Governor’s own newsroom release; the obligation summary is drawn from the enacted bill as reported by counsel, and we say so.

The first American state law to require an independent third-party audit of a frontier AI developer. It does not reach law firms, and it does not reach most companies. It reaches a handful of the largest model developers, and it is the template other states will copy.

Who it applies to

  • Threshold“Large frontier developers”: annual gross revenues above $500 million, training models using more than 1026 operations of compute. Both limbs.
  • In practiceA small number of named developers, on the reporting: OpenAI, Anthropic, Google, Meta and xAI.
  • Not youIf you are a law firm, an agency or an enterprise deploying someone else’s model, this Act does not impose duties on you. Its relevance is that your vendor will now have a published framework and an audit you can ask to see.

What it requires

  • FrameworkPublish a frontier AI framework.
  • TransparencyPublish a transparency report and annual disclosures.
  • AuditObtain an independent third-party audit. This is the provision with no prior US state analogue.
  • IncidentsReport critical safety incidents.

Why it is on this list

Because of the audit clause, and because of what an auditor will ask for. A published framework is a claim. An independent audit is someone testing whether the claim held on a given day, which means the developer needs a record of what the system actually did, not a policy describing what it should do. That is the same gap this record has been documenting on the courts side, arriving from the regulatory side.

It also sits directly alongside the EU AI Act obligations that became applicable on 2 August 2026. A developer in scope of both now owes a published framework and a third-party audit in Illinois, and transparency duties under Article 50 in the European Union, on overlapping evidence.

What to do about it

This is an estate problem, not a document problem.

An independent third-party audit is answered with records, not policies. Whatever an auditor is entitled to ask for, the cheapest form to produce it in is one sealed at the time the work happened. Regulayer records the decision as it is taken, outside the system being governed, content-free, and verifiable by anyone holding the file with public mathematics, without a call to us.

Regulayer for enterpriseThe AI audit trail →

For an individual practitioner, the same engine is $349 a month with a free week: start sealing. See also the law layer and every jurisdiction we track.

Sources

Related

Checked 5 August 2026. Dates verified at source; obligations summarised from counsel analysis pending a section-by-section read of the enrolled bill. Information, not legal advice.

Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.