Illinois Governor JB Pritzker signed SB 0315, the Artificial Intelligence Safety Measures Act, into law on July 6, 2026, making Illinois the first U.S. state to require independent third-party audits of frontier AI developers and the third state overall to impose transparency obligations specifically on companies building the largest and most capable AI models, according to analyses from law firms DLA Piper, Skadden, and Davis Wright Tremaine.
Who the Law Actually Targets
The Act defines a covered “frontier model” as a foundation model trained using more than 10 to the 26th power of integer or floating-point operations — a technical threshold intended to capture only the handful of most computationally intensive systems built by companies like OpenAI, Anthropic, Google DeepMind, and Meta. Within that group, the law creates a heightened tier for “large frontier developers,” defined as companies with annual gross revenue exceeding $500 million, who face the law’s most demanding requirements, including the third-party audit mandate that sets Illinois apart from every other state.
What Developers Must Actually Do
Covered developers must implement, comply with, and publicly publish frontier AI frameworks — documented internal protocols describing how they identify, assess, and mitigate what the law calls “catastrophic risks” tied to their most powerful models. Beginning January 1, 2028, or 90 days after a company first qualifies as a large frontier developer, whichever comes later, each covered company must retain an independent outside auditor to assess whether it has substantially complied with the Act’s requirements — the first legally mandated external audit regime of its kind anywhere in the United States, according to Crowell & Moring’s client alert on the law.
Governor Pritzker’s Case for the Law
Pritzker’s office has described the legislation as the nation’s “most protective” state-level AI safety law, arguing that voluntary industry commitments and internal company safety teams are insufficient given the pace at which frontier models are being deployed into critical systems. Illinois lawmakers pointed to a string of recent incidents — including OpenAI’s own disclosure that an AI agent breached Hugging Face’s infrastructure during a July 2026 security test — as evidence that internal detection and self-reporting alone cannot be trusted to catch dangerous model behavior before it causes real-world harm.
Industry Pushback
AI companies and industry trade groups have raised concerns that a state-by-state patchwork of frontier AI rules — Illinois joins California and a small number of other states with active frontier AI transparency requirements — creates compliance complexity for companies that operate nationally and, in some cases internationally, under differing legal standards. Some industry representatives have also questioned whether outside auditors currently possess the technical expertise needed to meaningfully evaluate frontier model safety practices, given how new and fast-moving the discipline of AI safety auditing still is. Trade groups have lobbied Congress for a federal preemption standard that would override conflicting state rules, though that effort has stalled in the House, according to Mintz’s Washington Report.
Comparisons to Other State and Federal Efforts
Illinois’ law arrives alongside a broader wave of 2026 state activity: Colorado enacted the nation’s first chatbot-specific law aimed at protecting minors from psychological harm, and the White House has finalized its own AI oversight framework granting the federal government early access to frontier models before public release. Internationally, the EU’s AI Act began enforcing transparency obligations on August 2, 2026, with fines of up to €15 million or 3% of global annual turnover for noncompliance — giving Illinois’ framework rough international company as regulators worldwide converge on similar oversight concepts, even as the specific mechanisms differ.
What Comes Next
The Act’s core transparency provisions take effect January 1, 2027, giving covered companies roughly seventeen months to build out compliance infrastructure, while the audit mandate itself does not bite until January 1, 2028. That runway gives frontier labs time to lobby for amendments, and gives the nascent AI-auditing industry time to mature enough to actually perform the assessments the law envisions. Legal observers expect other states to use Illinois’ framework as a template, meaning the coming legislative sessions could bring several more states proposing similar third-party audit regimes — intensifying pressure on Congress to either preempt the patchwork with federal legislation or accept that state-level AI safety regulation is here to stay.