Illinois joins the growing wave of states regulating AI. The Illinois Artificial Intelligence Safety Measures Act [1] targets developers of the most powerful AI systems – so-called “frontier models” – and creates a new compliance regime for how these tools are built, deployed, and monitored.
Here is what you need to know:
What the Act Does
- Targets “frontier models.” A frontier model is a foundation model trained using computing power exceeding 1026 operations, which are the largest and most capable AI systems. This law is not aimed at the AI tools most businesses build or customize in-house.
- Designates “frontier developers” as regulated entities. A frontier developer trains or initiates training of a frontier model. “Large frontier developers” whose revenues exceed $500 million face heightened obligations.
- Requires a published “Frontier AI Framework” by January 1, 2028. Large frontier developers must publish a framework describing how they assess and mitigate “catastrophic risks,” incorporate industry standards, use third-party evaluators, secure model weights, and respond to safety incidents.
- Mandates transparency reports at deployment. Before deploying a new or modified frontier model, developers must publish a transparency report disclosing intended uses, supported languages, output modalities, and use restrictions. Large developers must also disclose catastrophic risk assessments.
- Imposes annual independent audits. Beginning January 1, 2028, large frontier developers must retain an independent third party to audit compliance. The auditor must have no financial interest in the developer.
- Requires 72-hour incident reporting. Frontier developers must within 72 hours report “critical safety incidents” – unauthorized access to model weights causing harm, loss of control causing injury, or deceptive behavior by a model. Incidents involving risk of imminent death have a 24-hour disclosure window.
- Sets a high threshold for “catastrophic risk.” Covered risks are those that foreseeably contribute to more than 50 deaths, serious injuries, or over $1 billion in property damage. Scenarios include assistance creating WMDs, autonomous criminal conduct, and models evading developer control.
- Carves out exceptions. Catastrophic risk excludes publicly accessible information, lawful federal government activity, and harm the frontier model did not materially cause.
- Requires state registration by January 1, 2027. Large frontier developers may not operate in Illinois without a disclosure statement on file, including ownership details and designated contacts.
- Provides whistleblower protections. Developers cannot retaliate against employees who report dangers or violations. Large developers must maintain an anonymous internal reporting process.
- Penalties reach $1 million ($3 million for repeat violations). Only the Attorney General may bring enforcement actions; there is no private right of action.
- Preempts local regulation. AI frontier model regulation is an exclusive state power, and Illinois municipalities cannot pass their own rules.
- Builds in federal interoperability. If the federal government enacts “substantially equivalent” requirements, compliance with federal law satisfies Illinois law. But failing to meet a designated federal standard is itself an Illinois violation.
Interaction with the Federal Executive Order Landscape
Federal AI policy has favored voluntary, industry-led safety measures, with NIST (the National Institute of Standards and Technology) serving as a standards body rather than an enforcement regulator.
The Illinois Act builds in a bridge to federal harmony and allows developers to satisfy Illinois requirements by complying with substantially equivalent federal standards. If the federal government matches or exceeds Illinois’s floor, developers avoid dual compliance; if not, Illinois requirements apply as a binding overlay.
But that bridge only works if federal policy catches up. Right now, federal policy treats AI safety as a collaborative conversation; Illinois has given that conversation legal teeth. Until Washington enacts comparable requirements, companies operating in Illinois face mandatory compliance even if federal regulators view binding rules as premature.
What if Congress enacts mandatory AI legislation? Federal law can preempt state law, but Illinois’s interoperability provision is designed to minimize conflict because compliance with substantially equivalent federal law satisfies Illinois law automatically. The greater risk is regulatory fragmentation: states layering requirements over a federal floor, creating nationwide compliance complexity.
President Trump’s Executive Order 14365 (Removing Barriers to American Leadership in Artificial Intelligence) adds another wrinkle. It directs the Secretary of Commerce to identify state AI laws that (1) require AI models to alter their truthful outputs, or (2) compel developers to disclose information in ways that violate the First Amendment. Illinois SB 0315 does not implicate the first concern because it does not dictate model outputs. But its disclosure regime – transparency reports, 72-hour incident reporting, annual audits, quarterly risk summaries, and state registration filings – is a plausible candidate for scrutiny under the second. Courts have generally upheld commercial disclosure requirements against First Amendment challenges where the requirements are reasonably related to a state’s interest in preventing consumer deception, but frontier developers should expect the federal government to take a hard look at the Illinois law’s reporting mandates. Given the Trump administration’s broader friction with Illinois over immigration, environmental policy, and fiscal matters, the state’s AI legislation may draw heightened federal attention.
Three Practical Takeaways for Business Executives
1. If you use AI but don’t develop it, take a breath but stay alert. This bill regulates frontier developers, not every company using AI tools. But expect your AI vendors to flow down compliance obligations through contracts. For example, they may require you to use the model only for disclosed purposes, report misuse or safety incidents you observe, and cooperate with audits or investigations. Transparency disclosures and use restrictions will become standard in enterprise AI agreements, and your internal policies will need to track them.
2. Vendor diligence is now a board-level issue. Frontier AI vendors will generate significant public compliance information, such as transparency reports, audit summaries, and incident disclosures. These will need to be incorporated into your procurement and risk management processes.
3. Watch for the dominoes. Illinois is signaling that states will not wait for Congress. Assume a patchwork of state AI safety laws is the near-term reality and build flexible, auditable AI governance programs now.
[1] Signed into law by Governor Pritzker on July 6, 2026 and available at https://www.ilga.gov/Legislation/BillStatus/FullText?GAID=18&DocNum=315&DocTypeID=SB&LegId=0&SessionID=114

