On July 6, 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315), positioning Illinois as the first state in the nation to require independent third-party safety audits of frontier artificial intelligence developers. The law takes effect on January 1, 2027, giving covered companies a limited runway to build the governance, documentation, and vendor-management infrastructure necessary to comply. In-house counsel and AI governance teams should begin preparing now, particularly given the novelty of the audit obligation and the reputational stakes of publicly disclosed catastrophic-risk plans.

SB 315 targets what it defines as large frontier developers, meaning companies with more than $500 million in revenue that train models exceeding 10^26 computational operations. This scoping threshold is expected to sweep in the most prominent developers of general-purpose AI systems, including OpenAI, Anthropic, Google, Meta, and xAI. Companies approaching, but not yet meeting, the threshold should also monitor their status closely, as compute-intensive training runs and revenue growth can trigger coverage over the course of a single fiscal year.

Two obligations sit at the core of the statute. First, covered developers must publish annual catastrophic-risk plans describing how they identify, assess, and mitigate severe harms associated with their frontier models. Second, and more novel, they must submit to independent third-party safety audits, marking the first time a U.S. state has required external verification of frontier AI safety practices rather than relying solely on self-attestation. Selecting qualified auditors, defining audit scope, and managing the confidentiality of sensitive technical information will all raise practical questions that counsel should begin addressing well before the effective date.

Illinois now joins California and New York in an accelerating patchwork of state-level frontier AI regulation. In the absence of comprehensive federal legislation, developers and downstream enterprise users alike face a growing compliance mosaic with meaningfully different definitions, disclosure regimes, and enforcement mechanisms. Coordinated cross-jurisdictional strategy, rather than state-by-state reaction, will likely prove essential.

This article is intended for general informational purposes only and does not constitute legal advice. Clients facing questions about SB 315 or related state AI regulations should consult counsel for guidance tailored to their specific circumstances.