Illinois AI Safety Act

Artificial Intelligence Safety Measures Act

United States • Illinois

RAI-US-IL-SB31500-2026

SB 315

Possible change, not yet verified. An automated check on 8 Sep 2026 found an official page, which our systems cannot read, suggesting that this instrument may now be Awaiting Entry. We could not confirm it. The status shown is the last verified. Source page. If you know this instrument, use “Report an issue” to confirm or correct it.
Adopted(Adopted)Checked 9 Sep 2026

Illinois AI Safety Act is Adopted in United States as of 9 Sep 2026, according to ilga.gov.

ActSafety, Testing, and EvaluationRisk ManagementTransparency and Disclosure
Export PDF

The Illinois Artificial Intelligence Safety Measures Act mandates independent third-party audits for frontier AI models, setting a national precedent for AI safety and accountability.

Summary

The Illinois Artificial Intelligence Safety Measures Act (SB 315) establishes comprehensive safety and accountability standards for advanced AI models, making Illinois the first state to mandate independent third-party audits of frontier AI safety protocols. It requires large frontier developers to implement robust frameworks for risk assessment, mitigation, and transparent reporting to prevent catastrophic risks, taking effect January 1, 2027.

Full article

Read full text ↗

Overview

The Illinois Artificial Intelligence Safety Measures Act, designated as Senate Bill 315 (SB 315) during the 104th General Assembly (2025-2026), represents a landmark legislative effort in the United States to establish comprehensive safety and accountability standards for advanced artificial intelligence models. Having successfully passed both the Illinois House of Representatives and the Senate, the bill was sent to Governor J.B. Pritzker, who has publicly indicated his intent to sign it into law. This Act is poised to make Illinois the first state in the nation to mandate independent third-party audits of frontier AI model safety protocols, setting a new precedent for the responsible development and deployment of powerful AI systems. The legislation is specifically designed to address the catastrophic risks associated with these advanced models, ensuring that large frontier developers implement robust frameworks for risk assessment, mitigation, and transparent reporting.

The primary objective of the Artificial Intelligence Safety Measures Act is to balance the immense potential of AI for societal benefit with the imperative to prevent severe harms. It targets the largest and most capable AI models, often referred to as 'frontier models,' which are developed by 'large frontier developers.' The Act introduces a series of stringent requirements, including the creation and annual update of comprehensive AI safety frameworks, the submission of transparency reports prior to deploying new or substantially modified models, and the establishment of robust whistleblower protections. By focusing on preventative measures and external oversight, Illinois aims to create a roadmap for responsible innovation, safeguarding public safety while fostering technological advancement. The Act is slated to take effect on January 1, 2027, marking a significant step in state-level AI regulation.

Definitions

The Artificial Intelligence Safety Measures Act establishes several key definitions essential for its application and enforcement. "Artificial intelligence" or "AI" is defined with reference to Section 5 of the Digital Voice and Likeness Protection Act, and explicitly includes generative artificial intelligence. This broad definition ensures that the Act covers a wide array of modern AI technologies, particularly those capable of generating new content or data. A crucial term is "catastrophic risk," which refers to a foreseeable and material risk that a frontier developer's activities related to a frontier model could materially contribute to the death or serious injury of more than 50 people, or over $1,000,000,000 in property damage or loss from a single incident. This definition further specifies scenarios such as providing expert-level assistance in creating chemical, biological, radiological, or nuclear weapons; engaging in autonomous cyberattacks or criminal acts; or evading the control of its developer or user.

The Act also defines "frontier model" as a highly capable AI model that could pose severe or catastrophic risks to public safety, and "large frontier developer" as an entity that develops or deploys such models, typically characterized by significant computational resources and revenue thresholds. These definitions are critical for delineating the scope of the Act, ensuring that its stringent requirements are applied to the most powerful and potentially impactful AI systems and their creators. The legislation also defines "Agency" as the Illinois Emergency Management Agency and Office of Homeland Security, which plays a central role in the Act's administration. Understanding these precise definitions is paramount for compliance and for interpreting the regulatory obligations imposed by the Act on AI developers and related entities.

Governance and Institutional Framework

The governance and institutional framework for the Artificial Intelligence Safety Measures Act centers around the Illinois Emergency Management Agency (IEMA) and the Office of Homeland Security (OHS), in close consultation with the Attorney General. These bodies are empowered to administer the reporting mechanisms established by the Act, issue necessary guidance, and prepare annual reports on the implementation and impact of the legislation. This collaborative approach ensures that the regulatory oversight is informed by both technical expertise in emergency management and homeland security, as well as legal enforcement capabilities. The Agency's role includes developing and maintaining systems for collecting critical safety incident reports and summaries of internal-use risk assessments from large frontier developers, thereby creating a centralized repository of information crucial for monitoring AI safety.

Furthermore, the Act grants IEMA and OHS the authority to issue rules that will operationalize the various provisions of the legislation, ensuring that the requirements for frontier AI frameworks, transparency reports, and audits are practically implementable and effective. The Attorney General's involvement underscores the enforcement aspect of the Act, providing legal authority for addressing violations and imposing civil penalties. This multi-agency structure is designed to provide comprehensive oversight, from establishing technical standards and reporting protocols to ensuring legal compliance and accountability. The annual reports prepared by the Agency will offer valuable insights into the evolving landscape of AI safety and the effectiveness of the Act in mitigating catastrophic risks, facilitating continuous improvement of the regulatory framework.

Key Focus Areas

The Illinois Artificial Intelligence Safety Measures Act places significant emphasis on several key areas to ensure the responsible development and deployment of frontier AI models. A core requirement is for large frontier developers to establish, implement, publish, and annually update a comprehensive "frontier AI framework." This framework must meticulously address catastrophic-risk assessment, outlining methodologies for identifying, analyzing, and evaluating potential severe or catastrophic risks associated with their AI models. It also mandates detailed mitigation strategies to prevent or reduce these risks, covering aspects such as model design, deployment protocols, and operational safeguards.

Beyond risk management, the Act focuses on robust cybersecurity practices to protect AI systems from malicious attacks or unauthorized access that could lead to catastrophic outcomes. Internal governance mechanisms are also a critical component, requiring developers to establish clear lines of responsibility and accountability within their organizations for AI safety. Furthermore, the Act mandates third-party evaluations and addresses risks arising from the internal use of frontier models, recognizing that even internal deployment can pose significant dangers. Transparency is another cornerstone, with requirements for developers to submit transparency reports before deploying new or substantially modified frontier models, and to provide summaries of catastrophic-risk assessments, ensuring that regulators and the public have insight into potential hazards and mitigation efforts.

Implementation Framework

The implementation framework of the Illinois Artificial Intelligence Safety Measures Act is structured to ensure proactive compliance and continuous oversight of large frontier AI developers. A central tenet is the requirement for these developers to create, implement, publish, and annually update a comprehensive frontier AI framework. This framework serves as a foundational document, detailing how developers will address catastrophic risks, implement mitigation strategies, maintain cybersecurity, establish internal governance, conduct third-party evaluations, and manage risks from their internal use of frontier models. The public availability of these frameworks promotes transparency and allows for scrutiny by regulators and other stakeholders, fostering a culture of accountability within the AI development community.

A groundbreaking aspect of the Act's implementation is the mandate for annual independent third-party audits. These audits are designed to rigorously assess the safety protocols and risk management practices of frontier AI models, evaluating their potential for severe or catastrophic risks. The legislation establishes specific requirements for the access, reporting, retention, and publication of audit results, ensuring that the findings are transparent and actionable. This independent verification mechanism is a first in the nation for state-level AI regulation, distinguishing Illinois's approach from other jurisdictions. By requiring external validation, the Act aims to instill greater confidence in the safety claims made by AI developers and provide an objective assessment of their compliance with the established safety measures.

Monitoring and Evaluation

Monitoring and evaluation under the Artificial Intelligence Safety Measures Act are multifaceted, designed to ensure ongoing adherence to safety standards and to track the evolving risks associated with frontier AI models. A cornerstone of this process is the requirement for annual independent third-party audits. These audits are not merely a one-time assessment but a continuous mechanism for evaluating the effectiveness of a developer's frontier AI framework, risk mitigation strategies, and overall safety posture. The results of these audits, including access, reporting, retention, and publication requirements, provide critical data for regulators to assess compliance and identify areas for improvement. This systematic external review adds a layer of accountability that is unprecedented in state-level AI regulation.

In addition to audits, the Act mandates robust reporting mechanisms for critical safety incidents. Frontier developers are required to report such incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours of discovery, or within 24 hours if the incident poses an imminent risk of death or serious physical injury. This rapid reporting ensures that potential threats are promptly addressed and allows regulatory bodies to intervene swiftly if necessary. Furthermore, large frontier developers must submit periodic summaries of their internal-use risk assessments, offering insights into how they identify and manage risks associated with their own deployment of AI models. The Agency, in consultation with the Attorney General, is tasked with compiling annual reports based on this collected data, providing a comprehensive overview of AI safety trends and the Act's effectiveness.

Penalties, Liability, and Appeals

The Artificial Intelligence Safety Measures Act establishes clear provisions for penalties and liability, while also outlining mechanisms for appeals and protections for individuals. For violations of the Act's requirements, civil penalties can be imposed, serving as a deterrent against non-compliance and ensuring that developers take their safety obligations seriously. The specific amounts and circumstances of these penalties would likely be detailed in subsequent rules and guidance issued by the Illinois Emergency Management Agency and Office of Homeland Security in consultation with the Attorney General. The enforcement authority primarily rests with the Illinois Attorney General, who can initiate actions against developers found to be in violation of the Act.

Crucially, the Act clarifies that it does not create a private right of action. This means that individuals cannot directly sue AI developers under the provisions of this Act for damages. Instead, enforcement is channeled through state regulatory and legal bodies, aiming to provide a consistent and centralized approach to addressing violations. To further enhance accountability and safety, the Act includes robust whistleblower protections. It amends the Whistleblower Act to prohibit retaliation against covered employees who make good-faith disclosures of violations of the Artificial Intelligence Safety Measures Act. This provision encourages internal reporting of safety concerns without fear of reprisal, fostering a more transparent and safety-conscious environment within AI development companies.

Relationship to Other Instruments

The Illinois Artificial Intelligence Safety Measures Act draws inspiration from, and builds upon, existing AI transparency and safety frameworks established in other states, notably California's SB 53 (Transparency in Frontier AI Act) and New York's RAISE Act. While acknowledging these pioneering efforts, Illinois's SB 315 goes a significant step further by introducing a strict and legally binding system of independent third-party audits for frontier AI models. This mandates an external, objective evaluation of safety protocols, distinguishing it from the self-attestation or less stringent reporting requirements found in other state laws. The Illinois Act aims to establish a new national standard by introducing this robust audit mechanism, pushing the envelope for AI accountability and risk mitigation.

By incorporating elements from these earlier state laws while adding its unique audit mandate, the Illinois Act contributes to an evolving patchwork of state-level AI regulations across the United States. This dynamic landscape reflects the urgency and complexity of governing rapidly advancing AI technologies in the absence of comprehensive federal legislation. The interoperability with certain regulatory regimes is also established, suggesting that while Illinois sets a high bar, it also considers the broader regulatory environment to avoid undue burdens where possible. The Act's provisions, particularly concerning whistleblower protections, also interact with and amend existing state statutes, such as the Whistleblower Act and the Freedom of Information Act, to ensure a cohesive legal framework for AI safety and transparency.

National/Federal Alignment

In the absence of comprehensive federal AI regulation, states like Illinois are stepping into the regulatory void, and the Artificial Intelligence Safety Measures Act is a prime example of this trend. The Act is seen by many as a potential de facto national standard, particularly with its innovative requirement for independent third-party audits of frontier AI models. This proactive state-level action highlights a growing recognition of the need for robust governance over powerful AI systems, especially as federal legislative efforts remain stalled or are still in early stages. The fragmented regulatory landscape, with individual states enacting their own AI laws, presents both opportunities for experimentation and challenges for developers operating across state lines.

While the White House has previously expressed concerns about a potential patchwork of state laws complicating corporate compliance, Illinois's move is a significant attempt to establish stringent safety measures. The Act's sponsors and supporters, including major AI developers like OpenAI and Anthropic, have voiced hope that other states and the federal government will build upon Illinois's dedication to AI safety. The legislation's focus on catastrophic risk and frontier models aligns with broader national and international discussions about advanced AI governance. By setting a high bar for accountability and transparency, Illinois aims to influence the trajectory of future AI regulation at both state and federal levels, contributing to a more harmonized and effective approach to managing AI-related risks.

Implementation Timeline

MilestoneDateNotes
Bill Passed Senate2026-05-21Unanimous approval by the Illinois Senate.
Bill Passed House2026-05-27Unanimous approval by the Illinois House of Representatives.
Sent to Governor2026-05-27Bill sent to Governor J.B. Pritzker for signature.
Governor's Expected SignatureBefore 2026-07-26Governor Pritzker has indicated he will sign the bill into law. (Typically, governors have 60 days to act on bills sent to them when the legislature is in session).
Effective Date of Act2027-01-01The Artificial Intelligence Safety Measures Act will officially take effect.

Sources and References

SourceType
Illinois General Assembly - Bill Status of SB0315legal
Illinois General Assembly - Full Text of SB0315legal

Requirements for a company

What an organisation has to do under Illinois AI Safety Act, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

8
  • Create, implement, publish, and annually update a comprehensive frontier AI framework.Large frontier developers
  • Undergo annual, independent third-party safety audits to evaluate severe or catastrophic risks.Large frontier developers
  • File transparency reports before deploying new or substantially modified frontier models.Large frontier developers
  • Report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security.Frontier developers
  • Prohibit retaliation against employees who make good-faith disclosures of Act violations.Entities employing covered employees
  • Ensure audit results comply with access, reporting, retention, and publication requirements.Large frontier developers
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Illinois AI Safety Act, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Large frontier developersCreate, implement, publish, and annually update a comprehensive frontier AI framework.
“A core requirement is for large frontier developers to establish, implement, publish, and annually update a comprehensive 'frontier AI framework.'”
By 2027-01-01 and annually thereafterKey Focus AreasCritical
2Large frontier developersUndergo annual, independent third-party safety audits to evaluate severe or catastrophic risks.
“A groundbreaking aspect of the Act's implementation is the mandate for annual independent third-party audits.”
AnnuallyImplementation FrameworkCritical
3Large frontier developersFile transparency reports before deploying new or substantially modified frontier models.
“Transparency is another cornerstone, with requirements for developers to submit transparency reports before deploying new or substantially modified frontier models.”
Before deploying new or substantially modified modelsKey Focus AreasCritical
4Frontier developersReport critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security.
“Frontier developers are required to report such incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours of discovery, or within 24 hours if the incident poses an imminent risk of death or serious physical injury.”
Within 72 hours of discovery, or 24 hours for imminent risksMonitoring and EvaluationCritical
5Entities employing covered employeesProhibit retaliation against employees who make good-faith disclosures of Act violations.
“It amends the Whistleblower Act to prohibit retaliation against covered employees who make good-faith disclosures of violations of the Artificial Intelligence Safety Measures Act.”
By 2027-01-01Penalties, Liability, and AppealsCritical
6Large frontier developersEnsure audit results comply with access, reporting, retention, and publication requirements.
“The legislation establishes specific requirements for the access, reporting, retention, and publication of audit results”
Annually, after audit completionImplementation FrameworkCritical
7Large frontier developersSubmit periodic summaries of internal-use catastrophic-risk assessments.
“large frontier developers must submit periodic summaries of their internal-use risk assessments”
PeriodicallyMonitoring and EvaluationImportant
8Large frontier developersFollow guidance and rules issued by the Illinois Emergency Management Agency and Office of Homeland Security.
“the Act grants IEMA and OHS the authority to issue rules that will operationalize the various provisions of the legislation”
OngoingGovernance and Institutional FrameworkImportant

© Regulations.AI — created on 9 Jun 2026 using Gemini 2.5 Flash · updated on 5 Aug 2026 · reviewed against official sources on 9 Sep 2026