AI Governance Institute
Must ComplyRegulationUS

Illinois AI Safety Measures Act (SB 315)

Issued by

Illinois State Government

liveEffective 2027-01-01IL-AISMAUpdated October 2026 · Last verified October 1, 2026

The Illinois AI Safety Measures Act was signed on 6 July 2026 and takes effect on 1 January 2027. Frontier AI developers with over $500 million in annual revenue must publish a frontier AI framework and undergo annual independent compliance audits from 2028. The Attorney General enforces it.

Applies To

Large enterpriseAI developer

Overview

Governor Pritzker signed SB 315 on 6 July 2026, and it takes effect on 1 January 2027. It applies to large frontier developers, meaning developers of frontier AI models with more than $500 million in annual revenue. From 1 January 2028, or 90 days after a developer first qualifies if later, covered developers must write, follow, update yearly, and publish a frontier AI framework. It must address catastrophic-risk thresholds, mitigations, cybersecurity, internal governance, and third-party evaluations. On the same timeline, they need annual independent third-party audits. The audit checks compliance with the Act, not model safety as such. The report states whether the developer substantially complied, explains material deviations, and assesses internal controls. The law also creates confidential reporting channels and whistleblower protections for employees raising AI safety concerns. The Illinois Attorney General enforces it, with civil penalties of up to $1 million for a first violation and $3 million for later ones. There is no private right of action.

Key Requirements

  • •Applies to large frontier developers: frontier model developers with over $500 million in annual revenue.
  • •Publish and follow a frontier AI framework covering catastrophic-risk thresholds, mitigations, cybersecurity, governance, and third-party evaluations.
  • •Update the framework every year.
  • •Undergo an annual independent third-party compliance audit.
  • •Framework and audit duties start on 1 January 2028, or 90 days after first qualifying if later.
  • •The Attorney General enforces, with penalties up to $1 million for a first violation and $3 million for later ones.

What Your Organization Must Do

  • →Check whether your organization develops frontier AI models and exceeds $500 million in annual revenue.
  • →Draft a frontier AI framework covering catastrophic-risk thresholds, mitigations, cybersecurity, internal governance, and third-party evaluations.
  • →Plan to publish the framework and schedule a yearly review and update cycle.
  • →Book an independent third-party compliance audit before the 1 January 2028 start date.
  • →Set up confidential reporting channels and whistleblower protections for employees raising AI safety concerns.
  • →Map audit evidence shared with EU AI Act obligations to avoid duplicated compliance work.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does Illinois SB 315 apply to AI companies headquartered outside Illinois?
The statute targets developers of frontier AI models with over $500 million in annual revenue, with no explicit carve-out for out-of-state companies. If your organization develops covered frontier models and meets the revenue threshold, Illinois counsel should evaluate whether your activities create sufficient nexus to trigger compliance obligations.
What is the civil penalty exposure for repeat violations of the Illinois AI Safety Measures Act?
Up to $1 million for a first violation and up to $3 million for each later violation. Only the Illinois Attorney General can enforce the Act, and there is no private right of action.
Who qualifies as an independent third-party auditor under IL-AISMA?
SB 315 requires audits to be conducted by independent third parties rather than internal teams, but the statute does not yet specify auditor certification standards or approved vendor lists. Organizations should document auditor independence criteria and monitor Illinois Attorney General guidance for further qualification requirements.
What must be included in the safety plan that covered developers submit to auditors?
The Act calls it a frontier AI framework. It must address catastrophic-risk thresholds, mitigations, cybersecurity, internal governance, and third-party evaluations, and developers must publish it on their website and update it yearly.
How does the Illinois AI Safety Measures Act compare to the EU AI Act's obligations for general-purpose AI models?
Both regimes impose third-party evaluation requirements on high-capability AI developers, but IL-AISMA is narrower, focusing solely on frontier model safety audits and public disclosure rather than the EU AI Act's broader conformity assessments, risk classifications, and technical documentation mandates. Organizations subject to both should map overlapping audit evidence to reduce duplicative compliance effort.
When is the first audit due under SB 315 and how frequently must audits recur?
Audits are annual, starting 1 January 2028 or 90 days after a developer first qualifies, whichever is later. The rest of the Act takes effect on 1 January 2027.