Illinois Becomes First State to Mandate Independent Third-Party Safety Audits for Frontier AI Models
Illinois has enacted the Artificial Intelligence Safety Measures Act, establishing the nation's first requirement for large AI developers to undergo annual independent compliance audits. The law, which takes effect in 2027, adds a strict verification layer to the emerging state-level framework for frontier AI regulation.
By Ishani Patel
- State Regulators and Lawmakers
- Argue that self-reported safety frameworks are insufficient for technologies capable of catastrophic harm, necessitating independent verification.
- Frontier AI Labs
- Support clear, harmonized state rules to establish predictable compliance standards and avoid a fragmented regulatory landscape.
- Legal and Compliance Analysts
- Focus on the operational challenge of building audit-ready frameworks and the reality that state laws are creating a de facto national standard.
- Tech Industry Coalitions
- Express concern that mandatory third-party audits are premature given the lack of established auditing standards and qualified assurance firms.
Key terms
- Frontier Model
- A highly capable, general-purpose artificial intelligence model that can perform a wide variety of tasks and matches or exceeds the capabilities present in today's most advanced models.
- Floating-Point Operations (FLOPs)
- A measure of computational power used to quantify the massive amount of processing required to train an advanced artificial intelligence model.
- Catastrophic Risk
- A legally defined threshold where an AI model could foreseeably contribute to mass casualties, over $1 billion in property damage, or the creation of weapons of mass destruction.
- Third-Party Audit
- An independent evaluation conducted by an external organization to verify that a company is complying with its own stated safety and risk-management protocols.
Key points
- Illinois is the first U.S. state to mandate independent third-party safety audits for large frontier AI developers.
- The law applies to AI companies with over $500 million in annual revenue that train models using more than 10^26 floating-point operations.
- Developers must report critical safety incidents within 72 hours, or 24 hours if there is an imminent risk of physical injury.
- The audit provisions take effect on January 1, 2028, giving developers an 18-month compliance runway.
Illinois has fundamentally altered the regulatory landscape for artificial intelligence, becoming the first U.S. state to mandate independent third-party safety audits for the industry's most powerful systems. On July 6, 2026, Governor JB Pritzker signed Senate Bill 315, known as the Artificial Intelligence Safety Measures Act (AISMA), into law. The legislation establishes a comprehensive governance framework designed to force transparency and accountability onto the developers of frontier AI models. While other states have recently passed their own AI safety bills, Illinois is the first to demand that companies open their internal safety protocols to outside verification.[1][2][4]
The core tension driving the Illinois legislation was the perceived inadequacy of self-regulation. Over the past year, California and New York enacted laws requiring frontier AI developers to publish safety frameworks and disclose how they manage severe risks. However, those frameworks relied entirely on developer-created documentation and self-reported compliance. Illinois lawmakers argued that for models capable of causing catastrophic harm, self-reporting is insufficient. By requiring external audits, the state is shifting the regulatory paradigm from asking companies to document their risk management to forcing them to prove those processes actually work.[2][5]
The mechanics of the Artificial Intelligence Safety Measures Act are highly targeted, focusing exclusively on what the law defines as "large frontier developers." To fall under this classification, a company must meet two specific thresholds. First, the developer and its affiliates must have generated more than $500 million in annual gross revenue during the preceding calendar year. Second, the company must train a general-purpose AI model using a massive quantity of computing power—specifically, greater than 10^26 integer or floating-point operations (FLOPs). This dual threshold ensures the law applies only to the most advanced and well-resourced actors in the sector, such as OpenAI, Anthropic, Google, and Meta, rather than open-source startups or downstream application builders.[1][3][4]
For the companies that meet these criteria, the most significant new obligation is the annual audit. Beginning January 1, 2028, large frontier developers must retain an independent third party to perform a comprehensive compliance audit. The auditor will evaluate whether the developer is actively adhering to its own published safety framework and effectively assessing catastrophic risks. To prevent conflicts of interest, the law stipulates that the auditor must possess demonstrated competence in frontier model safety, and neither the developer nor the auditor may have a financial interest in the other.[2][4][5]
The legislation provides a highly specific definition of the "catastrophic risk" these frameworks and audits are meant to prevent. Under the law, a catastrophic risk is a foreseeable and material threat that a model's deployment could materially contribute to a single incident causing the death or serious injury of more than 50 people, or resulting in more than $1 billion in property damage. It also explicitly covers scenarios where a model provides expert-level assistance in the creation of chemical, biological, radiological, or nuclear weapons, or engages in harmful autonomous conduct without meaningful human oversight.[2][6]
Beyond the annual audits, the law imposes strict, time-sensitive incident reporting requirements. If a developer discovers that a model has been involved in a "critical safety incident," they are legally obligated to report it to the Illinois Emergency Management Agency and the Illinois Attorney General within 72 hours. If the incident poses an imminent risk of death or serious physical injury, that reporting window shrinks to just 24 hours. These reports must include a plain statement describing the incident and whether it was associated with the internal use of a frontier model.[3][4]
Beyond the annual audits, the law imposes strict, time-sensitive incident reporting requirements.
To ensure that safety concerns surface before they escalate into critical incidents, the Artificial Intelligence Safety Measures Act includes robust whistleblower protections. Large frontier developers are required to establish and maintain anonymous internal reporting channels for their employees. The law strictly prohibits companies from retaliating against workers who report potential violations or raise good-faith safety concerns. Furthermore, developers must actively notify employees of their rights under the law through monthly status updates and workplace postings.[2][3][4]
Enforcement of the new framework rests exclusively with the Illinois Attorney General, as the law deliberately excludes a private right of action. The financial penalties for noncompliance are steep, designed to be more than a mere cost of doing business. A first violation can result in a civil penalty of up to $1 million, while subsequent infractions can trigger fines of up to $3 million. Additionally, operating in the state without filing the required disclosure statements can result in daily fines of $1,000.[1][3][4]
Recognizing that state-level regulations could eventually be superseded by federal action, Illinois lawmakers included a unique interoperability clause. If the federal government enacts laws or regulations that impose substantially equivalent or stricter requirements—crucially including a mandate for independent third-party audits—a developer can declare its intent to rely on the federal regime. Compliance with the designated federal standard will then be deemed sufficient to satisfy the Illinois law, preventing duplicative regulatory burdens.[4][6]
The political dynamics surrounding the bill's passage were unusual for a tech-regulation measure. The legislation cleared the Illinois House by a unanimous 110-0 vote and passed the Senate 52-5. Notably, leading frontier AI labs, including OpenAI and Anthropic, publicly supported the bill throughout the legislative process. However, the third-party audit provision did face pushback from broader tech industry coalitions, who argued that the mandate was premature given the nascent state of AI auditing standards.[1][3]
While the law officially takes effect on January 1, 2027, the legislature built in a significant compliance runway. The most operationally demanding provisions, including the publication of the frontier AI framework and the mandatory third-party audits, do not become enforceable until January 1, 2028. This 18-month grace period is intended to give developers time to build audit-ready governance structures and integrate the Illinois requirements with their existing compliance programs for California and New York.[1][2][4]
Despite the long runway, significant uncertainties remain about how the law will function in practice. The most pressing unknown is the capacity of the auditing industry itself. The law requires auditors to evaluate compliance against "industry standards," but those standards are still being actively debated and defined by organizations like the U.S. AI Safety Institute and international bodies. It remains unclear whether a mature ecosystem of independent assurance firms exists with the technical capability to credibly audit models trained on tens of thousands of GPUs.[1][5][6]
Ultimately, the Illinois law highlights the growing impact of state-level action in the absence of a comprehensive federal AI policy. Because frontier models are inherently borderless and deployed nationally, developers cannot easily geofence their safety architectures. By establishing the most rigorous verification requirements in the country, Illinois has effectively set a new de facto national compliance standard. Any lab crossing the $500 million revenue threshold must now build its internal safety protocols with the expectation that an outside auditor will eventually inspect them.[2][3][5]
Frequently asked
When does the Illinois AI audit requirement take effect?
While the broader law takes effect on January 1, 2027, the mandatory third-party audit provisions are delayed until January 1, 2028, giving developers an 18-month compliance runway.
Which companies are affected by the new law?
The law targets 'large frontier developers'—companies with over $500 million in annual revenue that train AI models using more than 10^26 floating-point operations (FLOPs).
What happens if a company violates the Artificial Intelligence Safety Measures Act?
The Illinois Attorney General can levy civil penalties of up to $1 million for a first violation and up to $3 million for subsequent infractions.
Does this law apply to AI developers located outside of Illinois?
Yes. The law applies to any covered developer whose models are accessible to users within the state of Illinois, effectively capturing all major national and global AI labs.
Why this matters
By mandating third-party audits, Illinois is shifting AI regulation from self-reported safety claims to independent verification. Because frontier models are deployed nationally, this state-level requirement effectively forces major AI labs to build audit-ready safety architectures for their entire U.S. operations.
Sources
[1]AI WeeklyFrontier AI LabsPritzker signs Illinois SB 315, first US frontier AI audit law
Read on AI Weekly →
[2]Davis Wright TremaineState Regulators and LawmakersIllinois adopts a comprehensive frontier AI safety law with mandatory independent audits
Read on Davis Wright Tremaine →
[3]Fisher PhillipsLegal and Compliance AnalystsStrict AI Safety Rules Coming to Illinois: 5 Key Takeaways for Businesses on New State Law
Read on Fisher Phillips →
[4]Morrison FoersterLegal and Compliance AnalystsIllinois Raises the Bar on Frontier AI: What Developers Need to Know
Read on Morrison Foerster →
[5]AkermanState Regulators and LawmakersIllinois is on the cusp of enacting what may prove to be one of the most consequential pieces of artificial intelligence legislation
Read on Akerman →
[6]Factlen Editorial TeamLegal and Compliance AnalystsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.
