Illinois Governor Signs Frontier AI Model Law

· Source: Privacy & Cybersecurity Law Blog · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, short

Summary

On July 6, 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (Senate Bill 315) into law, making Illinois the third state, following California and New York, to establish comprehensive AI safety and transparency requirements. This Act uniquely mandates annual independent third-party audits for covered developers' safety practices. Effective January 1, 2027, for some provisions, the law targets "frontier developers" using over 10^26 integer or floating-point operations of computing power, with "large frontier developers" (those with over \$500 million in annual gross revenue) facing the most stringent obligations. Key requirements include publishing a "frontier AI framework" by January 1, 2028, detailing catastrophic risk management, transparency reports for new models, and reporting critical safety incidents within 72 hours. Developers must also file annual disclosures, protect whistleblowers, and face civil penalties up to \$3 million for violations.

Key takeaway

For Directors of AI/ML evaluating compliance for frontier AI models, Illinois's Artificial Intelligence Safety Measures Act introduces mandatory annual third-party audits and stringent reporting. You should immediately assess your models against the 10^26 operations and \$500 million revenue thresholds. Develop a comprehensive "frontier AI framework" and internal reporting channels, aligning with the strictest multi-state requirements to streamline compliance and avoid civil penalties up to \$3 million.

Key insights

Illinois's new AI law sets a precedent for mandatory annual third-party safety audits for large frontier AI developers.

Principles

Method

Large frontier developers must establish a "frontier AI framework" by January 1, 2028, detailing risk evaluation, mitigation, cybersecurity, incident response, and internal governance, subject to annual review and third-party audits.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Policy Maker, Director of AI/ML

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Privacy & Cybersecurity Law Blog.