Illinois Becomes First US State to Require Annual Third-Party Audits of Frontier AI Models
Governor JB Pritzker has signed a landmark bill requiring the developers of the world's most powerful AI systems to submit to independent safety audits. The bipartisan law establishes a new national compliance standard for the AI industry in the absence of federal regulation.
By Factlen Editorial Team
- State Regulators & Advocates
- Argue that in the absence of federal action, states must protect the public from catastrophic AI risks through verifiable oversight.
- Frontier AI Labs
- Support the bill because it establishes clear, achievable baselines that leading labs already follow voluntarily.
- Tech Industry Coalition
- Oppose the audit provision, arguing it forces highly subjective safety determinations without established national standards.
- Legal & Compliance Analysts
- View the law as a pragmatic, incremental approach that avoids constitutional landmines by focusing on disclosures.
What's not represented
- · Open-source AI developers
- · Independent AI safety auditors
Why this matters
Because frontier AI models are deployed globally, a strict compliance requirement in a major US state effectively sets a national operational standard. Any major tech company developing advanced AI will now have to build audit-ready safety structures into their systems, fundamentally changing how the industry operates.
Key points
- Illinois has enacted the Artificial Intelligence Safety Measures Act, targeting AI developers with over $500 million in revenue.
- The law is the first in the US to mandate that developers hire independent third parties to audit their AI safety frameworks.
- Companies must report critical safety incidents, such as threats involving biological weapons or cyberattacks, within 72 hours.
- The legislation received overwhelming bipartisan support and was publicly backed by leading AI labs OpenAI and Anthropic.
Illinois has become the first US state to mandate independent, third-party safety audits for the developers of the world's most powerful artificial intelligence models. Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315) into law on Monday, establishing a new compliance floor for the AI industry in the absence of federal regulation.[1]
The legislation targets "large frontier developers"—companies that generate more than $500 million in annual revenue and train their AI systems using massive computing power. Under the new law, developers of advanced models like ChatGPT and Claude must publish comprehensive safety frameworks detailing how they assess and mitigate catastrophic risks before those models are released to the public.[2][3]
While California and New York passed similar transparency laws in 2025, Illinois is the first to require that companies open their hoods to outside verification. Beginning in 2028, covered developers must retain independent auditors to evaluate their compliance with their own safety frameworks. These auditors must be granted access to unredacted versions of the AI models and cannot have a financial conflict of interest with the developer.[5]

The law defines catastrophic risks as severe threats to public safety, including the potential for an AI model to assist in the creation of biological weapons, execute large-scale cyberattacks, or evade human control. If a critical safety incident occurs, developers are required to report it to the Illinois Emergency Management Agency and the Attorney General's office within 72 hours. If the incident poses an imminent risk of death or serious physical injury, the reporting window shrinks to just 24 hours.[1]
Enforcement lies exclusively with the Illinois Attorney General, who can seek civil penalties of up to $1 million for a first violation and $3 million for subsequent offenses. The legislation also establishes confidential reporting channels and robust whistleblower protections for tech employees who raise internal concerns about AI safety or regulatory violations.
The bill's passage reflects a rare moment of political consensus on technology regulation. It cleared the Illinois House of Representatives by a unanimous 110-0 vote and passed the Senate 52-5. Governor Pritzker framed the state-level action as a necessary intervention, citing a "glaring, but not surprising lack of leadership" from the federal government on AI safety.[3]
The bill's passage reflects a rare moment of political consensus on technology regulation.
Unusually for tech regulation, the bill received public backing from the industry's leading players. Both OpenAI and Anthropic supported the legislation throughout the drafting process. Anthropic's head of state and local government relations, Cesar Fernandez, praised the bill for pairing transparency with independent verification, calling it an important step toward accountability that establishes a baseline for the industry.[2]

However, the third-party audit provision faced pushback from other corners of the tech sector. TechNet, a coalition of technology executives, opposed the audit mandate during committee hearings. The group argued that the law forces private auditors to make highly subjective determinations about AI safety compliance without the benefit of established national standards or clear regulatory guardrails.[1][4]
Legal analysts view the Illinois law as a pragmatic, incremental approach designed to survive constitutional scrutiny. By focusing on mandatory disclosures and process audits rather than attempting to dictate what an AI model can or cannot output, the state avoids the legal landmines that have derailed more aggressive attempts to regulate tech platforms' speech and content.
The practical impact of the law will extend far beyond Illinois's borders. Because frontier AI models are deployed globally and cannot be easily geofenced by state lines, a strict compliance requirement in a major US market effectively sets a national operational standard. Any developer crossing the $500 million revenue threshold will now need to build audit-ready governance structures into their development pipelines.[4]

The law's core transparency and reporting requirements take effect on January 1, 2027, giving the industry an 18-month runway to prepare. As the 2028 deadline for the first round of third-party audits approaches, the legislation is expected to spur the rapid growth of a specialized AI assurance industry equipped to evaluate the world's most complex neural networks.
How we got here
2025
California and New York pass laws requiring frontier AI developers to adopt safety frameworks and report critical incidents.
May 2026
The Illinois General Assembly passes SB 315 with overwhelming bipartisan support.
July 6, 2026
Governor JB Pritzker signs the Artificial Intelligence Safety Measures Act into law.
Jan 1, 2027
The core transparency, reporting, and whistleblower protection requirements take effect.
2028
The mandate for annual independent third-party safety audits officially begins.
Viewpoints in depth
State Regulators & Advocates
Argue that in the absence of federal action, states must protect the public from catastrophic AI risks through verifiable oversight.
Proponents of the law emphasize that voluntary safety commitments from tech companies are insufficient when dealing with technologies capable of causing mass harm. By mandating independent audits and establishing steep financial penalties, state officials believe they are replacing blind trust with verifiable disclosure. They view the legislation as a necessary intervention to fill the regulatory vacuum left by a gridlocked federal government.
Frontier AI Labs
Support the bill because it establishes clear, achievable baselines that leading labs already follow voluntarily.
Major developers like OpenAI and Anthropic backed the legislation, viewing it as a codification of the safety practices they have already implemented internally. By supporting a state law that focuses on process and transparency rather than restricting model capabilities, these companies hope to establish a predictable, unified national standard and prevent a fragmented patchwork of conflicting state regulations.
Tech Industry Coalition
Oppose the audit provision, arguing it forces highly subjective safety determinations without established national standards.
Organizations representing broader tech interests, such as TechNet, argue that the third-party audit requirement is premature. They contend that because there are no universally agreed-upon metrics or certifications for AI safety, auditors will be forced to make highly subjective judgments. Critics warn this could create regulatory uncertainty and impose heavy compliance burdens on developers without meaningfully improving public safety.
Legal & Compliance Analysts
View the law as a pragmatic, incremental approach that avoids constitutional landmines by focusing on disclosures.
Legal experts note that the Illinois law is intentionally modest in its mechanics, functioning more like federal securities law than a content restriction. By requiring companies to disclose their safety frameworks and auditing their adherence to those frameworks—rather than dictating what the AI can say or do—the state avoids First Amendment challenges. This procedural focus makes the law highly enforceable and likely to survive judicial scrutiny.
What we don't know
- How 'industry standards' for AI safety will be defined in practice by the time the audit requirement begins in 2028.
- Which firms will qualify as accredited third-party auditors capable of evaluating highly complex frontier models.
- Whether the federal government will eventually pass comprehensive AI legislation that preempts state-level laws like Illinois's.
Key terms
- Frontier AI model
- A highly capable, large-scale artificial intelligence system that pushes the boundaries of current technology and requires massive computing power to train.
- Third-party audit
- An independent examination of an organization's practices and compliance by an outside entity with no financial conflict of interest.
- Catastrophic risk
- In the context of AI, a severe threat to public safety, such as the model assisting in the creation of biological weapons or executing large-scale cyberattacks.
- Model weights
- The numerical parameters within a neural network that determine how the AI processes information and generates outputs.
Frequently asked
What makes a company a 'large frontier developer'?
The law applies to AI companies that generate over $500 million in annual revenue and train their models using massive amounts of computing power.
When does the Illinois AI law take effect?
The core transparency and reporting requirements take effect on January 1, 2027, with the mandatory third-party audits beginning in 2028.
Did AI companies oppose this regulation?
Surprisingly, leading frontier labs like OpenAI and Anthropic publicly supported the bill, though the industry coalition TechNet opposed the third-party audit requirement.
What happens if a company violates the law?
The Illinois Attorney General can seek civil penalties of up to $1 million for a first violation and up to $3 million for subsequent offenses.
Sources
[1]Capitol News IllinoisTech Industry Coalition
Pritzker signs landmark AI regulation bill that aims to mitigate risks
Read on Capitol News Illinois →[2]WAND TVState Regulators & Advocates
Governor Pritzker signs bill creating safety standards for large AI developers
Read on WAND TV →[3]WTTWState Regulators & Advocates
Illinois Enacts Artificial Intelligence Safety Measures Act
Read on WTTW →[4]Tech Policy PressTech Industry Coalition
State AI Laws in 2026: Trends and Preemption
Read on Tech Policy Press →[5]NTDState Regulators & Advocates
Illinois Governor Signs First-in-Nation AI Audit Law
Read on NTD →
More in ai
See all 5 stories →AI Regulation
How 42 State Attorneys General Are Using Consumer Law to Regulate OpenAI
6 sources
Silicon Sovereignty
$1 Trillion AI Chip Selloff Follows Wave of Custom Silicon Shipments, Reshaping Compute Market
7 sources
Macroeconomics
Federal Reserve Raises US Growth Forecast, Citing Surging AI Infrastructure Investment
4 sources
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.








