What Illinois SB 315 Actually Requires
On July 6, 2026, Illinois Governor JB Pritzker signed SB 315 — the Artificial Intelligence Safety Measures Act (AISMA) — making Illinois the third US state to impose binding obligations on frontier AI developers, and the first to mandate independent third-party audits. The signing drew immediate attention from legal teams at every major AI lab. It should.
The law targets a specific and narrow category: “large frontier developers.” To qualify, a company needs annual gross revenues exceeding $500 million and must train AI models using more than 10²⁶ floating-point operations. In practice, that means OpenAI, Anthropic, Google, Meta, and xAI are almost certainly covered. Smaller labs and enterprise AI vendors are not — at least not yet.
Illinois accounts for roughly 4% of US GDP, but together, California, Illinois, and New York — all three now with frontier AI laws — represent nearly 40% of the US AI market by economic activity. When three of the largest state economies align on regulatory direction, the industry has to respond regardless of what happens at the federal level.
Who Gets Audited — and When
The law takes effect in two waves. January 1, 2027 activates most provisions: whistleblower protections, initial disclosure obligations, and the incident reporting requirements. The heavier lift — publishing a frontier AI framework and submitting to annual independent audits — doesn’t kick in until January 1, 2028.
Companies that newly cross the “large frontier developer” threshold after the 2028 deadline have a 90-day window to retain an auditor. The law does not specify which auditing firms are qualified; that detail is deferred to regulatory guidance the Illinois AG’s office is expected to issue before 2027. Covered companies should not wait for that guidance before selecting candidates — audit capacity in this space is already constrained.
Incident reporting has tight timelines that apply starting January 1, 2027. A “critical safety incident” must be reported to the Illinois Emergency Management Agency and the Attorney General within 72 hours. If the incident poses an imminent risk of death or serious physical injury, that window shrinks to 24 hours — and the company must also notify “an appropriate authority,” a phrase the law leaves intentionally undefined, likely encompassing federal agencies or law enforcement.
The Frontier AI Framework: More Than a Document
The law’s most substantive ongoing obligation is the frontier AI framework — a public document each covered developer must write, implement, and update annually beginning January 1, 2028. The framework must explain how the company identifies “catastrophic risks” from its models, what thresholds it uses, and how it incorporates third-party assessments into its safety processes.
Under AISMA, “catastrophic risk” means risks that could plausibly cause mass casualties, attacks on critical infrastructure, or irreversible societal harms. Developers must define what specific capabilities would trigger that threshold for their own models — and document the controls in place to prevent or mitigate those capabilities. That level of specificity is substantially more demanding than a general safety policy statement.
The annual transparency report, also required, must cover training compute, model capabilities, known hazards, and the company’s incident history. Crucially, it must be published on the company’s public website — not buried in a regulatory filing. This is designed to create accountability pressure from researchers and civil society, not just from regulators.
Whistleblower protections extend broadly: the law prohibits retaliation against employees, contractors, and affiliates who report safety concerns or legal violations. It also mandates internal anonymous reporting channels — a requirement more commonly seen in financial compliance programs than in technology governance. For AI labs that have recently downsized compliance teams, this creates a meaningful staffing and process requirement.
How Illinois Goes Further Than California and New York
Illinois didn’t write this law without looking at what California and New York had already done. California enacted the Transparency in Frontier Artificial Intelligence Act (TFAIA) in September 2025. New York passed the Responsible AI Safety and Education (RAISE) Act in December 2025. Both impose broadly similar requirements: AI safety frameworks, transparency reports, incident reporting, and whistleblower protections.
The critical difference is audits. Neither California nor New York requires covered companies to submit to independent third-party compliance audits. Illinois added that requirement explicitly — making AISMA the first US state law to mandate that an independent auditor assess whether the frontier AI framework and incident reporting processes are being followed, and whether the transparency reports are accurate. This shifts the model from “trust but disclose” to “trust but verify.”
Penalties also diverge at the upper end. All three states cap initial violations at $1 million. Illinois and New York both allow penalties up to $3 million for repeat violations. California’s TFAIA has no repeat-violation enhancement. Illinois also has a broader definition of who the Attorney General can pursue: the law’s enforcement provisions extend to officers and directors who direct violations, not just the developer entity itself.
All three laws use the same technical threshold to define a frontier model: more than 10²⁶ FLOPs of training compute. That alignment is not accidental — it mirrors the compute thresholds embedded in the EU AI Act’s high-risk definitions and in US export control frameworks. It creates a de facto standard that future state and federal legislation is likely to reference. For more on the EU-side regulatory picture, see our earlier piece on what the EU AI Act’s August 2026 provisions mean for businesses.
What AI Companies Need to Do Now
The practical near-term compliance challenge isn’t the 2028 audit requirement — it’s incident reporting infrastructure, which goes live January 1, 2027. That gives covered companies roughly five months to define what a “critical safety incident” means internally, build detection and escalation workflows, and establish legal contacts with the Illinois AG and IEMA. Five months sounds like enough time. For organizations without existing AI governance programs, it likely isn’t.
The audit requirement demands a longer runway. Third-party AI auditors capable of assessing frontier model compliance programs are a new and limited category. Demand is already exceeding supply following the California and New York laws. Companies that wait until late 2027 to select auditors risk not finding qualified firms available for January 2028 audits.
For companies below the $500M revenue threshold, the law is still worth tracking. Illinois has a history of expanding regulatory scope once initial frameworks prove workable — the state’s Biometric Information Privacy Act (BIPA) started as a narrow law targeting fingerprint scans and became the basis for hundreds of millions of dollars in class-action settlements against technology companies. AISMA’s threshold could follow a similar trajectory.
The Transparency Coalition, which backed the bill throughout its legislative passage, called AISMA “the nation’s most protective AI law” at signing. Whether that holds depends on enforcement — which rests entirely with Illinois Attorney General Kwame Raoul. No enforcement actions under any of the three state frontier AI laws have been filed yet. The first one will establish how serious these frameworks actually are. For context on how state AI laws fit into the broader governance picture, see our coverage of why AI governance is lagging deployment.
Further Reading
- Skadden’s AISMA analysis — the clearest breakdown of the audit requirement and how it differs from California and New York, with specific attention to the enforcement provisions
- Crowell & Moring compliance timeline — a practical breakdown of the 2027 and 2028 obligation waves, with guidance on what covered companies should be doing now
- Capitol News Illinois on the signing — original reporting on the bill’s passage, including the governor’s framing and context from the legislative debate

