Illinois AI Safety Act
Artificial Intelligence Safety Measures Act
United States • Illinois
RAI-US-IL-SB31500-2026SB 315
Illinois AI Safety Act is Adopted in United States as of 9 Sep 2026, according to ilga.gov.
ActSafety, Testing, and EvaluationRisk ManagementTransparency and DisclosureThe Illinois Artificial Intelligence Safety Measures Act mandates independent third-party audits for frontier AI models, setting a national precedent for AI safety and accountability.
Summary
The Illinois Artificial Intelligence Safety Measures Act (SB 315) establishes comprehensive safety and accountability standards for advanced AI models, making Illinois the first state to mandate independent third-party audits of frontier AI safety protocols. It requires large frontier developers to implement robust frameworks for risk assessment, mitigation, and transparent reporting to prevent catastrophic risks, taking effect January 1, 2027.
Full article
Read full text ↗Overview
The Illinois Artificial Intelligence Safety Measures Act, designated as Senate Bill 315 (SB 315) during the 104th General Assembly (2025-2026), represents a landmark legislative effort in the United States to establish comprehensive safety and accountability standards for advanced artificial intelligence models. Having successfully passed both the Illinois House of Representatives and the Senate, the bill was sent to Governor J.B. Pritzker, who has publicly indicated his intent to sign it into law. This Act is poised to make Illinois the first state in the nation to mandate independent third-party audits of frontier AI model safety protocols, setting a new precedent for the responsible development and deployment of powerful AI systems. The legislation is specifically designed to address the catastrophic risks associated with these advanced models, ensuring that large frontier developers implement robust frameworks for risk assessment, mitigation, and transparent reporting.
The primary objective of the Artificial Intelligence Safety Measures Act is to balance the immense potential of AI for societal benefit with the imperative to prevent severe harms. It targets the largest and most capable AI models, often referred to as 'frontier models,' which are developed by 'large frontier developers.' The Act introduces a series of stringent requirements, including the creation and annual update of comprehensive AI safety frameworks, the submission of transparency reports prior to deploying new or substantially modified models, and the establishment of robust whistleblower protections. By focusing on preventative measures and external oversight, Illinois aims to create a roadmap for responsible innovation, safeguarding public safety while fostering technological advancement. The Act is slated to take effect on January 1, 2027, marking a significant step in state-level AI regulation.
Definitions
The Artificial Intelligence Safety Measures Act establishes several key definitions essential for its application and enforcement. "Artificial intelligence" or "AI" is defined with reference to Section 5 of the Digital Voice and Likeness Protection Act, and explicitly includes generative artificial intelligence. This broad definition ensures that the Act covers a wide array of modern AI technologies, particularly those capable of generating new content or data. A crucial term is "catastrophic risk," which refers to a foreseeable and material risk that a frontier developer's activities related to a frontier model could materially contribute to the death or serious injury of more than 50 people, or over $1,000,000,000 in property damage or loss from a single incident. This definition further specifies scenarios such as providing expert-level assistance in creating chemical, biological, radiological, or nuclear weapons; engaging in autonomous cyberattacks or criminal acts; or evading the control of its developer or user.
The Act also defines "frontier model" as a highly capable AI model that could pose severe or catastrophic risks to public safety, and "large frontier developer" as an entity that develops or deploys such models, typically characterized by significant computational resources and revenue thresholds. These definitions are critical for delineating the scope of the Act, ensuring that its stringent requirements are applied to the most powerful and potentially impactful AI systems and their creators. The legislation also defines "Agency" as the Illinois Emergency Management Agency and Office of Homeland Security, which plays a central role in the Act's administration. Understanding these precise definitions is paramount for compliance and for interpreting the regulatory obligations imposed by the Act on AI developers and related entities.
Governance and Institutional Framework
The governance and institutional framework for the Artificial Intelligence Safety Measures Act centers around the Illinois Emergency Management Agency (IEMA) and the Office of Homeland Security (OHS), in close consultation with the Attorney General. These bodies are empowered to administer the reporting mechanisms established by the Act, issue necessary guidance, and prepare annual reports on the implementation and impact of the legislation. This collaborative approach ensures that the regulatory oversight is informed by both technical expertise in emergency management and homeland security, as well as legal enforcement capabilities. The Agency's role includes developing and maintaining systems for collecting critical safety incident reports and summaries of internal-use risk assessments from large frontier developers, thereby creating a centralized repository of information crucial for monitoring AI safety.
Furthermore, the Act grants IEMA and OHS the authority to issue rules that will operationalize the various provisions of the legislation, ensuring that the requirements for frontier AI frameworks, transparency reports, and audits are practically implementable and effective. The Attorney General's involvement underscores the enforcement aspect of the Act, providing legal authority for addressing violations and imposing civil penalties. This multi-agency structure is designed to provide comprehensive oversight, from establishing technical standards and reporting protocols to ensuring legal compliance and accountability. The annual reports prepared by the Agency will offer valuable insights into the evolving landscape of AI safety and the effectiveness of the Act in mitigating catastrophic risks, facilitating continuous improvement of the regulatory framework.
Key Focus Areas
The Illinois Artificial Intelligence Safety Measures Act places significant emphasis on several key areas to ensure the responsible development and deployment of frontier AI models. A core requirement is for large frontier developers to establish, implement, publish, and annually update a comprehensive "frontier AI framework." This framework must meticulously address catastrophic-risk assessment, outlining methodologies for identifying, analyzing, and evaluating potential severe or catastrophic risks associated with their AI models. It also mandates detailed mitigation strategies to prevent or reduce these risks, covering aspects such as model design, deployment protocols, and operational safeguards.
Beyond risk management, the Act focuses on robust cybersecurity practices to protect AI systems from malicious attacks or unauthorized access that could lead to catastrophic outcomes. Internal governance mechanisms are also a critical component, requiring developers to establish clear lines of responsibility and accountability within their organizations for AI safety. Furthermore, the Act mandates third-party evaluations and addresses risks arising from the internal use of frontier models, recognizing that even internal deployment can pose significant dangers. Transparency is another cornerstone, with requirements for developers to submit transparency reports before deploying new or substantially modified frontier models, and to provide summaries of catastrophic-risk assessments, ensuring that regulators and the public have insight into potential hazards and mitigation efforts.
Implementation Framework
The implementation framework of the Illinois Artificial Intelligence Safety Measures Act is structured to ensure proactive compliance and continuous oversight of large frontier AI developers. A central tenet is the requirement for these developers to create, implement, publish, and annually update a comprehensive frontier AI framework. This framework serves as a foundational document, detailing how developers will address catastrophic risks, implement mitigation strategies, maintain cybersecurity, establish internal governance, conduct third-party evaluations, and manage risks from their internal use of frontier models. The public availability of these frameworks promotes transparency and allows for scrutiny by regulators and other stakeholders, fostering a culture of accountability within the AI development community.
A groundbreaking aspect of the Act's implementation is the mandate for annual independent third-party audits. These audits are designed to rigorously assess the safety protocols and risk management practices of frontier AI models, evaluating their potential for severe or catastrophic risks. The legislation establishes specific requirements for the access, reporting, retention, and publication of audit results, ensuring that the findings are transparent and actionable. This independent verification mechanism is a first in the nation for state-level AI regulation, distinguishing Illinois's approach from other jurisdictions. By requiring external validation, the Act aims to instill greater confidence in the safety claims made by AI developers and provide an objective assessment of their compliance with the established safety measures.
Monitoring and Evaluation
Monitoring and evaluation under the Artificial Intelligence Safety Measures Act are multifaceted, designed to ensure ongoing adherence to safety standards and to track the evolving risks associated with frontier AI models. A cornerstone of this process is the requirement for annual independent third-party audits. These audits are not merely a one-time assessment but a continuous mechanism for evaluating the effectiveness of a developer's frontier AI framework, risk mitigation strategies, and overall safety posture. The results of these audits, including access, reporting, retention, and publication requirements, provide critical data for regulators to assess compliance and identify areas for improvement. This systematic external review adds a layer of accountability that is unprecedented in state-level AI regulation.
In addition to audits, the Act mandates robust reporting mechanisms for critical safety incidents. Frontier developers are required to report such incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours of discovery, or within 24 hours if the incident poses an imminent risk of death or serious physical injury. This rapid reporting ensures that potential threats are promptly addressed and allows regulatory bodies to intervene swiftly if necessary. Furthermore, large frontier developers must submit periodic summaries of their internal-use risk assessments, offering insights into how they identify and manage risks associated with their own deployment of AI models. The Agency, in consultation with the Attorney General, is tasked with compiling annual reports based on this collected data, providing a comprehensive overview of AI safety trends and the Act's effectiveness.
Penalties, Liability, and Appeals
The Artificial Intelligence Safety Measures Act establishes clear provisions for penalties and liability, while also outlining mechanisms for appeals and protections for individuals. For violations of the Act's requirements, civil penalties can be imposed, serving as a deterrent against non-compliance and ensuring that developers take their safety obligations seriously. The specific amounts and circumstances of these penalties would likely be detailed in subsequent rules and guidance issued by the Illinois Emergency Management Agency and Office of Homeland Security in consultation with the Attorney General. The enforcement authority primarily rests with the Illinois Attorney General, who can initiate actions against developers found to be in violation of the Act.
Crucially, the Act clarifies that it does not create a private right of action. This means that individuals cannot directly sue AI developers under the provisions of this Act for damages. Instead, enforcement is channeled through state regulatory and legal bodies, aiming to provide a consistent and centralized approach to addressing violations. To further enhance accountability and safety, the Act includes robust whistleblower protections. It amends the Whistleblower Act to prohibit retaliation against covered employees who make good-faith disclosures of violations of the Artificial Intelligence Safety Measures Act. This provision encourages internal reporting of safety concerns without fear of reprisal, fostering a more transparent and safety-conscious environment within AI development companies.
Relationship to Other Instruments
The Illinois Artificial Intelligence Safety Measures Act draws inspiration from, and builds upon, existing AI transparency and safety frameworks established in other states, notably California's SB 53 (Transparency in Frontier AI Act) and New York's RAISE Act. While acknowledging these pioneering efforts, Illinois's SB 315 goes a significant step further by introducing a strict and legally binding system of independent third-party audits for frontier AI models. This mandates an external, objective evaluation of safety protocols, distinguishing it from the self-attestation or less stringent reporting requirements found in other state laws. The Illinois Act aims to establish a new national standard by introducing this robust audit mechanism, pushing the envelope for AI accountability and risk mitigation.
By incorporating elements from these earlier state laws while adding its unique audit mandate, the Illinois Act contributes to an evolving patchwork of state-level AI regulations across the United States. This dynamic landscape reflects the urgency and complexity of governing rapidly advancing AI technologies in the absence of comprehensive federal legislation. The interoperability with certain regulatory regimes is also established, suggesting that while Illinois sets a high bar, it also considers the broader regulatory environment to avoid undue burdens where possible. The Act's provisions, particularly concerning whistleblower protections, also interact with and amend existing state statutes, such as the Whistleblower Act and the Freedom of Information Act, to ensure a cohesive legal framework for AI safety and transparency.
National/Federal Alignment
In the absence of comprehensive federal AI regulation, states like Illinois are stepping into the regulatory void, and the Artificial Intelligence Safety Measures Act is a prime example of this trend. The Act is seen by many as a potential de facto national standard, particularly with its innovative requirement for independent third-party audits of frontier AI models. This proactive state-level action highlights a growing recognition of the need for robust governance over powerful AI systems, especially as federal legislative efforts remain stalled or are still in early stages. The fragmented regulatory landscape, with individual states enacting their own AI laws, presents both opportunities for experimentation and challenges for developers operating across state lines.
While the White House has previously expressed concerns about a potential patchwork of state laws complicating corporate compliance, Illinois's move is a significant attempt to establish stringent safety measures. The Act's sponsors and supporters, including major AI developers like OpenAI and Anthropic, have voiced hope that other states and the federal government will build upon Illinois's dedication to AI safety. The legislation's focus on catastrophic risk and frontier models aligns with broader national and international discussions about advanced AI governance. By setting a high bar for accountability and transparency, Illinois aims to influence the trajectory of future AI regulation at both state and federal levels, contributing to a more harmonized and effective approach to managing AI-related risks.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Passed Senate | 2026-05-21 | Unanimous approval by the Illinois Senate. |
| Bill Passed House | 2026-05-27 | Unanimous approval by the Illinois House of Representatives. |
| Sent to Governor | 2026-05-27 | Bill sent to Governor J.B. Pritzker for signature. |
| Governor's Expected Signature | Before 2026-07-26 | Governor Pritzker has indicated he will sign the bill into law. (Typically, governors have 60 days to act on bills sent to them when the legislature is in session). |
| Effective Date of Act | 2027-01-01 | The Artificial Intelligence Safety Measures Act will officially take effect. |
Sources and References
| Source | Type |
|---|---|
| Illinois General Assembly - Bill Status of SB0315 | legal |
| Illinois General Assembly - Full Text of SB0315 | legal |
Requirements for a company
What an organisation has to do under Illinois AI Safety Act, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
8- Create, implement, publish, and annually update a comprehensive frontier AI framework.Large frontier developers
- Undergo annual, independent third-party safety audits to evaluate severe or catastrophic risks.Large frontier developers
- File transparency reports before deploying new or substantially modified frontier models.Large frontier developers
- Report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security.Frontier developers
- Prohibit retaliation against employees who make good-faith disclosures of Act violations.Entities employing covered employees
- Ensure audit results comply with access, reporting, retention, and publication requirements.Large frontier developers
- +2 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Illinois AI Safety Act, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Large frontier developers | Create, implement, publish, and annually update a comprehensive frontier AI framework. “A core requirement is for large frontier developers to establish, implement, publish, and annually update a comprehensive 'frontier AI framework.'” | By 2027-01-01 and annually thereafter | Key Focus Areas | Critical |
| 2 | Large frontier developers | Undergo annual, independent third-party safety audits to evaluate severe or catastrophic risks. “A groundbreaking aspect of the Act's implementation is the mandate for annual independent third-party audits.” | Annually | Implementation Framework | Critical |
| 3 | Large frontier developers | File transparency reports before deploying new or substantially modified frontier models. “Transparency is another cornerstone, with requirements for developers to submit transparency reports before deploying new or substantially modified frontier models.” | Before deploying new or substantially modified models | Key Focus Areas | Critical |
| 4 | Frontier developers | Report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security. “Frontier developers are required to report such incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours of discovery, or within 24 hours if the incident poses an imminent risk of death or serious physical injury.” | Within 72 hours of discovery, or 24 hours for imminent risks | Monitoring and Evaluation | Critical |
| 5 | Entities employing covered employees | Prohibit retaliation against employees who make good-faith disclosures of Act violations. “It amends the Whistleblower Act to prohibit retaliation against covered employees who make good-faith disclosures of violations of the Artificial Intelligence Safety Measures Act.” | By 2027-01-01 | Penalties, Liability, and Appeals | Critical |
| 6 | Large frontier developers | Ensure audit results comply with access, reporting, retention, and publication requirements. “The legislation establishes specific requirements for the access, reporting, retention, and publication of audit results” | Annually, after audit completion | Implementation Framework | Critical |
| 7 | Large frontier developers | Submit periodic summaries of internal-use catastrophic-risk assessments. “large frontier developers must submit periodic summaries of their internal-use risk assessments” | Periodically | Monitoring and Evaluation | Important |
| 8 | Large frontier developers | Follow guidance and rules issued by the Illinois Emergency Management Agency and Office of Homeland Security. “the Act grants IEMA and OHS the authority to issue rules that will operationalize the various provisions of the legislation” | Ongoing | Governance and Institutional Framework | Important |
Related Regulations
More AI regulation in United States
AI regulation in United States: full overview
- Illinois AI Rental Price Coordination Ban
- Illinois AI Regulation Summary
- Indiana AI Health Claims Law
- United States - Indiana - Deepfake Regulation (HB 1133)
- Indiana AI Regulation Summary
- United States - Indiana - Media Alteration Disclosure (Public Law 81/2024)
- Kansas AI Deepfake and Child Exploitation Prevention Act
- United States - Kentucky - AI Governance Act (SB 4)
© Regulations.AI — created on 9 Jun 2026 using Gemini 2.5 Flash · updated on 5 Aug 2026 · reviewed against official sources on 9 Sep 2026