AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationUSHigh risk

Illinois AI Safety Measures Act (SB 315)

Issued by

Illinois State Government

liveEffective 2026-07-07IL-AISMAVerified July 2026

The Illinois AI Safety Measures Act, signed into law on July 7, 2026, is the first US state law to require annual independent safety audits of frontier AI models. It applies to AI developers generating more than $500 million in annual revenue. The law mandates public disclosure of audit results and grants the Illinois Attorney General authority to enforce civil penalties.

Applies To

Large enterpriseAI developer

Overview

Signed by Governor Pritzker on July 7, 2026, SB 315 establishes a mandatory annual third-party audit regime for developers of frontier AI models that meet a revenue threshold of $500 million. The law defines audit scope around model safety, with results required to be published and made accessible to the public. Enforcement authority rests with the Illinois Attorney General, who may pursue civil penalties of up to $3 million for repeat violations. The statute is specifically focused on frontier models but creates a structural precedent for third-party safety evaluation that may extend to agentic AI systems in future legislative cycles. Illinois is the first US state to codify this level of mandatory independent oversight for AI model developers. The law adds to a growing patchwork of US state AI regulations and may influence pending federal proposals on AI safety accountability.

Key Requirements

  • Developers of frontier AI models with annual revenue exceeding $500 million must conduct annual independent third-party safety audits
  • Audit results must be published and made publicly available
  • Repeat violations are subject to civil penalties of up to $3 million per violation
  • The Illinois Attorney General is designated as the primary enforcement authority
  • Audits must be conducted by independent third parties, not internal teams
  • Compliance obligations are ongoing on an annual cycle from the effective date
  • Covered developers must maintain a documented safety plan, made available to auditors prior to each audit cycle.

What Your Organization Must Do

  • Determine immediately whether your organization meets the $500 million revenue threshold and develops or deploys frontier AI models covered under SB 315
  • Identify and engage qualified independent third-party auditors with frontier model safety evaluation expertise before the first annual audit deadline
  • Establish an internal process to compile model safety documentation and evidence packages required to support third-party audit procedures
  • Build a public disclosure workflow to publish audit results in a timely and compliant format upon audit completion
  • Review existing AI vendor and developer contracts to assess whether third-party obligations flow through to upstream model providers
  • Monitor Illinois Attorney General guidance and enforcement actions to calibrate your compliance posture and repeat-violation risk management

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does Illinois SB 315 apply to AI companies headquartered outside Illinois?
The statute targets developers of frontier AI models with over $500 million in annual revenue, with no explicit carve-out for out-of-state companies. If your organization develops covered frontier models and meets the revenue threshold, Illinois counsel should evaluate whether your activities create sufficient nexus to trigger compliance obligations.
What is the civil penalty exposure for repeat violations of the Illinois AI Safety Measures Act?
The Illinois Attorney General can pursue civil penalties of up to $3 million per violation for repeat offenses. First-time violations are not explicitly assigned a penalty cap in the current text, making early compliance and documented good-faith efforts strategically important to limit enforcement risk.
Who qualifies as an independent third-party auditor under IL-AISMA?
SB 315 requires audits to be conducted by independent third parties rather than internal teams, but the statute does not yet specify auditor certification standards or approved vendor lists. Organizations should document auditor independence criteria and monitor Illinois Attorney General guidance for further qualification requirements.
What must be included in the safety plan that covered developers submit to auditors?
The law requires covered developers to maintain a documented safety plan made available to auditors prior to each annual audit cycle, but does not enumerate specific plan contents in granular detail. Compliance teams should align plan documentation with recognized frontier model safety frameworks until Illinois issues further implementing guidance.
How does the Illinois AI Safety Measures Act compare to the EU AI Act's obligations for general-purpose AI models?
Both regimes impose third-party evaluation requirements on high-capability AI developers, but IL-AISMA is narrower, focusing solely on frontier model safety audits and public disclosure rather than the EU AI Act's broader conformity assessments, risk classifications, and technical documentation mandates. Organizations subject to both should map overlapping audit evidence to reduce duplicative compliance effort.
When is the first audit due under SB 315 and how frequently must audits recur?
Compliance obligations begin on the effective date of July 7, 2026, with audits required annually from that date. Organizations should engage third-party auditors well in advance of the first deadline to allow sufficient time for safety plan preparation, auditor onboarding, and public disclosure workflows.