Big tech, meet big oversight: An overview of Illinois' Artificial Intelligence Safety Measures Act

On July 6, 2026, Illinois Governor JB Pritzker signed SB 315, the “Artificial Intelligence Safety Measures Act,” into law. This new law establishes some of the most comprehensive state-level AI safety frameworks in the country, positioning Illinois as a national leader in AI oversight at a time when federal action on AI regulation remains absent. The bipartisan legislation takes effect on January 1, 2027.

Who is covered

The new law targets “large frontier developers”, AI companies with annual gross revenues exceeding $500 million that train models using computing power greater than 1026 operations. This means that SB 315 is likely to impact industry giants such as OpenAI, Anthropic, Google, Meta, and xAI. While the direct obligations fall on these developers, businesses operating in Illinois that procure or utilize frontier models should pay attention to potential downstream compliance implications, especially regarding contractual liability for privacy incidents or breaches.

Key requirements

SB 315 imposes several significant obligations on covered developers:

  • Transparency frameworks. Developers must create, implement, publish, and update annually a “frontier AI framework” that addresses catastrophic-risk assessment, mitigations, cybersecurity internal governance, third-party evaluations, and risks from internal use of frontier models. The framework must also explain how developers apply industry standards to promote safety, assess model capabilities and catastrophic risk, and respond to safety incidents.
  • Mandatory third-party audits. The new law requires annual independent third-party safety audits of covered AI systems, conducted by qualified experts without financial conflicts of interest. The audits must be submitted to both the administering agency and the Attorney General.
  • Incident reporting. Developers must report critical safety incidents[1] within 72 hours to the Illinois Emergency Management Agency and the Attorney General. In instances where the incident posts an imminent risk of death or serious physical injury, authorities must be notified within 24 hours and extend to any law enforcement or public safety agency with jurisdiction. Developers must also provide periodic summaries of internal-use catastrophic risk assessments.
  • Pre-deployment transparency reports. Companies must issue transparency reports before deploying new or substantially modified frontier models, including summaries of catastrophic-risk assessments
  • Whistleblower protections. The law creates confidential reporting channels and legal protections for employees raising AI safety concerns. Protections include requiring notice to every employee by posting and displaying a notice with employee rights, or by sending the notice and employee acknowledgement once a year. SB 315 also amends the Illinois Whistleblower Act to prohibit retaliation for good-faith disclosures of violations.
Enforcement and oversight

In consultation with the Illinois Attorney General, the Illinois Emergency Management Agency and Office of Homeland Security will administer reporting mechanisms, provide guidance, and prepare annual reports. SB 315 establishes civil penalties for violations but does not provide a private right of action. Large frontier developers are also required to file disclosure statements and pay fees.

Most notably, the new law provides an interoperability provision stating that a developer that complies with designated federal requirements (should they be enacted) is deemed in compliance with SB 315. However, failure to meet the federal standards is still considered a violation of Illinois law, potentially allowing the Attorney General to enforce federal requirements that the federal government itself declines to enforce.

The broader landscape

SB 314 builds on AI accountability framework already passed in California and New York, but it goes further by mandating independent audits rather than self-certification. For data privacy practitioners, the law signals to an a new trend: states are not wanting for Congress to act, and organizations in Illinois that develop, deploy, or integrate frontier AI models should begin evaluating how their vendor management and incident response frameworks may need to evolve before January 2027.

McDonald Hopkins will continue to monitor developments and guidance from applicable regulators as we near SB 315’s effective date.

If you have questions about the latest legislative updates, how to keep your organization in compliance, or if you would like to discuss proactive measures to protect against cyber threats, please reach out to a member of our national data privacy and cybersecurity team.

[1] A “critical safety incident” is defined as: (1) unauthorized access to, modification of, or exfiltration of a frontier model’s weights that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model using deceptive techniques against its developer to subvert controls or monitoring in a manner that demonstrates materially increased catastrophic risk.

Jump to Page

McDonald Hopkins uses cookies on our website to enhance user experience and analyze website traffic. Third parties may also use cookies in connection with our website for social media, advertising and analytics and other purposes. By continuing to browse our website, you agree to our use of cookies as detailed in our updated Privacy Policy and our Terms of Use.