Illinois Becomes First State to Mandate Independent Third-Party Safety Audits for Frontier AI Models
A landmark Illinois law shifts AI oversight from self-reported compliance to external verification, requiring developers of the most powerful models to open their systems to independent auditors.
By Lila Morgan
- Frontier AI Developers
- Supported the legislation, viewing it as a predictable compliance framework that establishes a competitive moat.
- Tech Industry Coalitions
- Opposed the third-party audit mandate, arguing it relies on highly subjective determinations without established national standards.
- State Regulators
- Argue that self-reported compliance is insufficient for technologies posing catastrophic risks, necessitating independent verification.
On July 6, 2026, Illinois Governor JB Pritzker signed a document that fundamentally alters how the world's most powerful artificial intelligence models will be scrutinized. The Artificial Intelligence Safety Measures Act (SB 315) makes Illinois the first U.S. state to mandate that frontier AI developers open their systems to independent, third-party safety audits.[1][4]
The legislation targets a highly specific tier of the tech industry. It applies only to "large frontier developers" that generate over $500 million in annual revenue and train models using more than 10^26 floating-point operations. This compute threshold mirrors federal definitions, placing companies like OpenAI, Anthropic, Google, and Meta squarely in the crosshairs.[2][8]
While California and New York previously enacted frontier AI transparency laws, Illinois introduces a novel enforcement mechanism. Rather than relying on developer-created documentation and self-reported compliance, the state requires external verification. Beginning January 1, 2028, covered companies must retain an independent auditor to assess their catastrophic-risk mitigations and internal governance.[4][5][7]
The shift from self-attestation to third-party auditing represents a significant regulatory pivot. Legal analysts note this mirrors the evolution of content moderation regimes like the European Union's Digital Services Act, demanding that companies demonstrate their safety processes actually operate as intended rather than merely existing on paper.[5]
The law creates five concrete obligations. First, developers must publish a transparency framework detailing their approach to catastrophic risk. Second, they must release summaries of these risk assessments before deploying any new or substantially modified frontier model—creating a paper trail prior to release, rather than after the fact.[2]
Third, the mandated annual audits must be conducted by entities with "demonstrated competence" in frontier model safety, and the auditor cannot have a financial interest in the developer. The developer is required to publish a high-level summary of the audit report within 30 days of receipt.[4][6][8]
Fourth, the legislation imposes a strict 72-hour window for reporting "critical safety incidents" to state officials. For incidents posing an imminent risk of death or serious injury, that window shrinks to 24 hours. Fifth, companies must file disclosure statements with the Illinois Emergency Management Agency, paying proportional fees to cover oversight costs.[2][7]
Fourth, the legislation imposes a strict 72-hour window for reporting "critical safety incidents" to state officials.
Enforcement rests exclusively with the Illinois Attorney General; the law contains no private right of action. Civil penalties are capped at $1 million for a first violation and $3 million for subsequent violations. However, legal experts suggest the true cost of non-compliance will be the operational disruption and public relations fallout of a state-led injunction.[1][2][7]
The political dynamics surrounding the bill's passage were unusual for tech regulation. The measure cleared the Illinois House by a unanimous 110-0 vote and the Senate 52-5. Notably, both OpenAI and Anthropic publicly supported the legislation throughout the process.[1][2]
Anthropic even claimed "first AI lab" status in backing the bill, a move that effectively fractured industry opposition. By endorsing the framework, the leading labs signaled a willingness to accept compliance costs that smaller competitors might struggle to absorb, effectively building a regulatory moat around the frontier tier.[1][2]
Conversely, TechNet—a coalition representing broader tech industry executives—opposed the third-party audit provision. The group argued that the mandate relies on "highly subjective determinations requiring AI safety compliance without established national standards."[1][2]
The evidence supporting the efficacy of third-party AI audits remains thin. Because frontier models are a novel technology, the industry lacks standardized auditing methodologies comparable to financial accounting's GAAP. The law requires audits to be "consistent with generally accepted auditing standards and best practices," but those practices do not yet exist in a formalized, universally recognized capacity.[4]
This creates a significant implementation gap. The legislation does not define precisely what qualifies an entity as a competent third-party auditor for models trained on 10^26 FLOPS. The assurance firms capable of credibly executing these audits will likely need to build their methodologies concurrently with the developers building the models, constraining the pool of qualified candidates in the short term.[1][6]
Furthermore, the 72-hour incident reporting mandate requires covered companies to build internal classification systems and escalation pathways well before the 2028 audit deadline. Because the bill leaves the exact definition of a "reportable safety incident" somewhat ambiguous, developers face the challenge of calibrating their internal tripwires without federal guidance.[2]
By passing SB 315, Illinois joins California and New York in establishing a de facto national framework for AI regulation. Absent comprehensive federal legislation, these three states have effectively set the compliance floor for the world's most advanced artificial intelligence systems.[3][4]
For the developers building the next generation of generative models, the era of self-graded safety exams is closing. The 18-month runway before the audit requirement takes effect will test whether the nascent AI assurance industry can scale its technical capabilities to match the legal mandates now codified in state law.[1]
- $500M
- Annual revenue threshold for covered developers
- 10^26
- FLOPS compute threshold for frontier models
- 72 hours
- Window to report critical safety incidents
- $3M
- Maximum civil penalty for subsequent violations
Limits of the evidence
- How 'industry standards' for catastrophic risk assessments will be defined in practice by the Illinois Emergency Management Agency.
- What specific technical qualifications will be required for an entity to serve as an 'independent third-party auditor' for frontier models.
- Whether the 72-hour incident reporting window will conflict with federal safe harbor provisions if national standards diverge.
Sources
[1]AI WeeklyFrontier AI DevelopersPritzker signs Illinois SB 315, first US frontier AI audit law
Read on AI Weekly →
[2]ByteIotaFrontier AI DevelopersIllinois lawmakers passed SB 315 this week with a 110-0 House vote
Read on ByteIota →
[3]FOX 32 ChicagoState RegulatorsExpert says AI requires safety audits
Read on FOX 32 Chicago →
[4]Crowell & MoringFrontier AI DevelopersIllinois Governor Pritzker signed SB 315, the AI Safety Measures Act
Read on Crowell & Moring →
[5]CooleyState RegulatorsIllinois' recently enacted Artificial Intelligence Safety Measures Act (AISMA) builds on these existing frameworks by introducing a significant new requirement: independent verification
Read on Cooley →
[6]Latham & WatkinsTech Industry CoalitionsIllinois Senate Bill 315 largely tracks similar frontier AI laws in California and New York
Read on Latham & Watkins →
[7]Greenberg TraurigState RegulatorsIllinois Enacts AI Safety Measures Act, Imposing New Obligations on Frontier Model Developers
Read on Greenberg Traurig →
[8]Morrison FoersterTech Industry CoalitionsIllinois enacts AI Safety Measures Act, making it the first state to mandate third-party audits of frontier AI models
Read on Morrison Foerster →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.

