TL;DR: Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on July 6, 2026. It requires large AI developers (over $500 million in annual revenue) to publish a frontier AI safety framework, report safety incidents within 72 hours (24 hours if there is imminent risk of death or injury), and undergo independent third-party audits starting in 2028, the first US law to mandate that. Penalties reach $1 million per violation and $3 million for repeat violations, enforced only by the Illinois Attorney General. The law targets frontier model developers like OpenAI, Anthropic, Google, and Meta, not their customers, but it hands small teams a new vendor due diligence tool: ask whether your AI vendor is a covered developer, and if so, whether they have published their required framework.
On July 6, 2026, Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, into Illinois law. It is the third state law in the country to directly regulate the companies that build frontier AI models, after California's SB 53 and New York's RAISE Act. It is also the strictest one so far, with a requirement neither of the other two states adopted: mandatory independent audits.
None of this creates a new compliance obligation for the small team reading this article. SB 315 regulates model developers, not model users. But if your team relies on ChatGPT, Claude, Gemini, or any other frontier model in its stack, the vendor on the other end of that contract is about to face new disclosure duties, and those disclosures are about to become useful evidence in your own vendor risk process.
What SB 315 actually requires
SB 315 creates two tiers of obligation. Every "frontier developer," defined as anyone who trains a frontier model, has baseline duties. "Large frontier developers," those with more than $500 million in annual gross revenue, carry the heaviest requirements.
A published frontier AI framework. Large frontier developers must create, publish, and annually update a framework describing how they assess and mitigate catastrophic risk, defined in the law as the likelihood that an incident causes death or serious injury to more than 50 people, or more than $1 million in property damage. The framework has to cover governance, cybersecurity protections for unreleased model weights, use of third-party evaluators, and how the developer accounts for risks from its own internal use of the model.
Transparency reports before deployment. Before releasing a new or materially modified frontier model, developers must publish a report listing the model's release date, supported languages and modalities, intended uses, and any restrictions on use, along with a way for the public to reach the developer about the model.
Independent third-party audits. Starting in 2028, covered developers must hire an independent auditor to verify they are actually following their own published framework, not just that they published one. This is the provision that sets Illinois apart. Neither California's SB 53 nor New York's RAISE Act requires an outside audit; both rely on the developer's own transparency reporting and after-the-fact enforcement.
Incident reporting on a tight clock. Developers must report safety incidents within 72 hours of identifying them, or within 24 hours if the incident poses an imminent risk of death or serious physical injury. That 24-hour window is the shortest of any state frontier AI law currently on the books.
Whistleblower protections. Employees at covered companies who report violations internally or to the Attorney General are protected from retaliation, a provision aimed at the kind of internal safety disagreements that have occasionally become public at frontier labs.
Penalties. Violations carry civil penalties up to $1 million each, rising to $3 million for repeat violations. The Illinois Attorney General has exclusive enforcement authority. SB 315 does not create a private right of action, so individuals cannot sue developers directly under this law.
The effective dates, and why the gap between them matters
SB 315 takes effect January 1, 2027, as a matter of law. But the requirements with the most teeth, the frontier AI framework and the independent audit mandate, phase in by January 1, 2028. That gives covered developers roughly 18 months from signing to build the internal documentation, hire qualified third-party auditors, and run a first audit cycle.
For anyone tracking this law from the outside, that gap matters because it sets the calendar for when you should actually expect to see something. Disclosure statements and frontier AI frameworks should start appearing from large developers around the January 2027 mark. The first independent audit reports, the artifact that is genuinely new to this space, will not exist until sometime after January 2028. Watching for a framework in early 2027 and an audit report a year later is a more accurate expectation than assuming full compliance evidence exists on day one.
How Illinois compares to California SB 53 and New York's RAISE Act
Illinois is not writing on a blank page. California's SB 53, the Transparency in Frontier Artificial Intelligence Act, was the first frontier AI safety law in the country. New York's RAISE Act followed, and was amended in March 2026 to align more closely with California after its original version drew criticism for being out of step. All three now share the same $500 million annual revenue threshold for "large" developers, a convergence that itself is worth noting: state legislatures appear to be coordinating on this number rather than each picking a different one.
Where the three laws diverge:
Independent audits. Illinois is alone in requiring them. California and New York rely on developer self-reporting through published frameworks and transparency reports, with enforcement kicking in only after the fact if a developer's own documents show noncompliance or an incident goes unreported.
Incident reporting speed. Illinois requires 24-hour reporting for incidents involving imminent risk of death or serious injury, and 72 hours otherwise. New York's RAISE Act, after its March 2026 amendment, also uses a 72-hour window. California's SB 53 gives developers up to 15 days, the longest window of the three.
Penalties. Illinois and New York both cap penalties at $1 million per violation and $3 million for repeat violations. That New York figure is itself the result of a walk-back, the RAISE Act as originally enacted proposed $10 million for a first violation and $30 million for repeat violations before the March 2026 chapter amendment brought it down to match the emerging state norm. California's SB 53 caps penalties at $1 million per violation with no separate repeat-violation tier.
Enforcement. All three restrict enforcement to a state authority rather than private lawsuits. Illinois and California use their Attorneys General. New York created a dedicated office inside its Department of Financial Services to handle RAISE Act enforcement and rulemaking.
The pattern across all three laws is the same: large frontier developers publish a safety framework and a transparency report per model, disclose incidents on a fixed clock, and answer to a state regulator rather than to lawsuits from the public. Illinois adds a verification layer none of the others have.
Why this matters if you're not a frontier lab
If your team is not training foundation models with nine-figure compute budgets, none of SB 315's direct obligations land on you. But three second-order effects are worth building into how you evaluate AI vendors.
Your vendor's compliance status is now a legible fact, not a guess. Once large frontier developers start publishing frameworks and, in Illinois's case, audit reports, you have a new document to request in vendor due diligence. Today, when you ask an AI vendor about their safety practices, you're relying on marketing copy, a model card, or a sales conversation. By 2027, if your vendor trains frontier models and qualifies as a large developer under any of these three laws, they should have a published framework you can actually read. If they don't have one and clearly meet the revenue threshold, that gap is now a specific, checkable red flag rather than a vague sense of unease.
Incident reporting deadlines give you a benchmark for vendor incident response. If a frontier model has a safety failure serious enough to trigger SB 315's 24-hour or 72-hour reporting clock, and your team relies on that model in production, you now have a legal reference point for how fast your vendor is required to tell regulators, and by extension, how fast they should be telling you. Vendor contracts that promise slower notification than the law requires of the vendor's own regulator are worth pushing back on.
The patchwork is not slowing down. Illinois becoming the third state to pass a frontier AI safety law in under a year, following California in 2025 and New York in early 2026, signals more states are likely to follow with their own version, most of them converging on the same $500 million revenue threshold. If your team's compliance strategy already tracks multi-state AI obligations, add frontier developer safety law to the list of frameworks you monitor, alongside the employment and consumer-facing AI laws most small teams already watch.
What to actually do now
Add one question to your vendor questionnaire. Ask whether your AI model provider qualifies as a large frontier developer under Illinois SB 315, California SB 53, or New York's RAISE Act, and if so, request a link to their published frontier AI framework once it exists. Most vendors above the $500 million threshold, OpenAI, Anthropic, Google, Meta, and similar scale providers, will be answering this question repeatedly through 2027, so asking it directly is efficient for both sides.
Set a calendar reminder for early 2027 and again for 2028. The first wave of transparency reports and frameworks should appear around SB 315's January 1, 2027 effective date. Independent audit reports, the genuinely new artifact, won't exist until after the January 2028 audit requirement kicks in. Checking too early will just tell you the documents don't exist yet.
Fold this into your existing vendor risk process rather than starting a new one. If your team already runs AI vendor due diligence or maintains a vendor risk register, SB 315 compliance status is one more field, not a new process. The goal is a checkable fact sitting next to your other vendor risk data, not a standalone tracking effort.
Watch for Illinois Attorney General guidance. The AG has exclusive enforcement authority and will likely issue interpretive guidance before the 2027 and 2028 deadlines. That guidance is where ambiguous terms in the statute, exactly what counts as a "materially modified" model, for instance, will get clarified.
SB 315 will not change what your team can build with AI tomorrow. What it changes is what your team can verify about the AI vendors you already depend on, starting with a framework document that, for the first time in Illinois, has to actually exist and be checked by someone other than the company that wrote it.
Related Reading
- AI Vendor Due Diligence Checklist (2026): 30 Questions Before You Sign
- AI Vendor Contract Red Flags: 12 Clauses That Create Liability
- GenAI Vendor Risk Assessment: A Framework for 2026
- Multi-State AI Compliance in 2026
- Colorado SB 26-189 Signed: What Changed in the AI Law
- California SB 1047: What Happened and What's Next
- Does Your AI Vendor Train on Your Business Data? 11 Vendors Compared
- Dario Amodei's AI Regulation Proposals: Binding Rules and What to Watch
Sources: Governor Pritzker Signs Nation-Leading Artificial Intelligence Safety Law, Crowell & Moring, "Illinois Imposes Transparency and Safety Obligations on Frontier AI Systems", Akerman, "Illinois SB 315: A State Strategy for Enduring National AI Safety Standards", Future of Privacy Forum, "The RAISE Act vs. SB 53: A Tale of Two Frontier AI Laws", Morrison Foerster, "New York Amends the RAISE Act to Align More Closely with California Law".
