Illinois Enacts AI Safety and Transparency Law for Frontier AI Developers
Summary
Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (AISMA) into law on July 6, 2026, establishing new requirements for large frontier AI developers. Effective in waves starting January 1, 2027, and January 1, 2028, AISMA mandates public disclosure of catastrophic risk mitigation plans and, uniquely among U.S. state AI laws, requires independent third-party audits of compliance. The law largely mirrors California's TFAIA and New York's RAISE Act, covering developers using >10^26 operations and with \$500 million annual revenue. Similar provisions include adopting AI safety frameworks, publishing transparency reports, incident reporting to IEMA-OHS and the AG within 72 hours (24 hours for imminent risk), internal-use risk assessments, and whistleblower protections. Distinctly, AISMA requires machine-readable report summaries and offers a broader federal safe harbor mechanism.
Key takeaway
For large frontier AI developers operating in Illinois, navigating state-level AI regulations, you must prepare for mandatory independent third-party audits of your AI safety frameworks, a unique requirement among U.S. state laws. Ensure your compliance strategy accounts for these annual audits, effective January 1, 2028, and the broader federal safe harbor provisions, which require matching Illinois' catastrophic risk assessment and audit obligations.
Key insights
Illinois' AISMA uniquely mandates independent third-party audits for large frontier AI developers' safety compliance.
Principles
- Large frontier AI developers must adopt and publicly disclose AI safety frameworks.
- Whistleblower protections are crucial for identifying catastrophic risks.
Method
Developers must annually retain a third party to audit AI framework compliance, providing access to necessary materials and publishing a redacted report summary.
In practice
- Publish model-level transparency reports before deployment.
- Report critical safety incidents to authorities within 72 hours, or 24 hours for imminent risks.
- Maintain anonymous internal reporting channels.
Topics
- AI Regulation
- Illinois AISMA
- Frontier AI
- AI Safety Frameworks
- Independent Audits
- Whistleblower Protections
Best for: CTO, Executive, VP of Engineering/Data, Legal Professional, Policy Maker, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by The Data Advisor.