A 110-0 vote in the Illinois House of Representatives on 27 May 2026 sent Senate Bill 315 to Governor J.B. Pritzker's desk, making Illinois the first US state to require annual independent third-party safety audits of large frontier AI developers. That claim needs a qualifier: Illinois is the third state to enact frontier model standards of any kind, following California's SB 53 and New York's RAISE Act. Where Illinois breaks new ground is in requiring covered companies to submit to an external auditor each year. It is a distinction that was enough to drive a bipartisan supermajority and divide the industry.

What the Law Actually Requires

SB 315, the Artificial Intelligence Safety Measures Act, targets a deliberately narrow slice of the industry: companies with more than US$500 million in annual gross revenue that train or deploy frontier-scale models. That threshold captures a small cohort — among them OpenAI, Anthropic, and Google — while leaving smaller developers untouched.

Covered companies must do four things. First, they must create, publish, and update annually a frontier AI safety framework addressing catastrophic-risk assessment, cybersecurity, internal governance, and red-team evaluations. Second, they must publish transparency reports before deploying any new or substantially modified frontier model. Third — and this is the provision with no precedent in American law — they must retain an independent third-party auditor each year to verify those safety practices, with results made public. Fourth, according to Capitol News Illinois and corroborated by multiple news outlets, covered companies must report critical safety incidents to state authorities within 72 hours of having sufficient reason to believe one has occurred; an accelerated 24-hour window applies where incidents pose imminent risk of death or serious harm. Whistleblower protections cover employees who raise safety concerns internally or to regulators.

The Illinois Attorney General holds exclusive enforcement authority. Civil penalties reach up to US$3 million per violation. There is no private right of action — citizens cannot sue directly.

A Tri-State Compliance Map Is Taking Shape

Illinois is the third state to enact frontier model standards, following California's SB 53 and New York's RAISE Act. Both earlier laws set transparency and risk-assessment obligations, but neither required companies to submit to an external auditor. That gap is what SB 315 closes. Compliance teams at the affected companies now face a tri-state framework across California, New York, and Illinois. In the absence of federal legislation, this combination is becoming a de facto national benchmark.

The law takes effect on 1 January 2028, giving covered companies roughly 18 months to establish audit programmes, appoint third-party auditors, and build the internal documentation trails those auditors will need. That timeline is tight for organisations that have never operated under mandatory external safety review.

Rare Bipartisan Consensus — and a Divided Industry

The voting record is striking. The House passed the bill 110-0; the Senate, 52-5 on 21 May 2026. In a legislature that struggles to agree on much, those margins suggest AI safety has found a political formula that works across the aisle.

Industry was less unified. OpenAI and Anthropic publicly supported the bill. Anthropic's head of state and local government relations, Cesar Fernandez, said: "As these models grow more powerful, this kind of enforceable accountability matters more than ever." The trade coalition TechNet, which counts other AI developers among its members, opposed the bill, citing concerns about subjective determinations made without established national standards.

That split is instructive. The companies most directly regulated supported the law; the opposition came from a broader coalition that includes developers who do not yet meet the threshold but may in future.

What Changes for Frontier Labs

The audit mandate is the sharpest edge of this legislation. Safety frameworks and transparency reports are self-certifications; an independent auditor is not. Labs will need to open their evaluation methodologies, red-team findings, and governance structures to outside scrutiny — and keep records sufficient to support that scrutiny annually. For companies whose safety work has been largely internal, this is a structural change, not just another paperwork exercise.

The incident reporting requirement adds operational pressure. Companies must have clear internal definitions of what constitutes a "critical safety incident," escalation processes that reach a decision-maker within hours, and a legal team ready to notify Illinois authorities before the full picture of an incident may even be clear.

Governor Pritzker has stated he will sign the bill. Once he does, Illinois joins a short list of jurisdictions worldwide — the EU AI Act being the most prominent — that have moved from voluntary AI safety norms to enforceable legal obligations backed by financial penalties.

Signed on 6 July, in force from January

The bill went to the governor's desk after the 110-0 House vote. Governor Pritzker signed it on 6 July 2026, and the Artificial Intelligence Safety Measures Act takes effect on 1 January 2027.

One detail of the scope is worth stating more precisely than the passage coverage did. The obligations reach developers above US$500 million in annual revenue that also cross a frontier-scale compute threshold. Revenue alone does not capture a company; the two conditions apply together, which keeps large software firms that do not train frontier models outside the statute.

The auditor requirement still has no auditors

An annual independent third-party audit was described as the provision with no precedent in American law, and that remains true. What it does not yet have is a profession to perform it.

Financial audit works because there is an established body of standards, a regulator that inspects the auditors, a liability regime, and several decades of case law about what an opinion means. Frontier AI safety auditing has none of that infrastructure. There is no agreed standard for what an audit tests, no accreditation for the auditors, and no settled answer to what an auditor is signing when they attest that a risk assessment was adequate.

January 2027 is when covered companies must be retaining auditors. Between now and then, either a credible independent audit capability exists or the requirement is satisfied by whoever is willing to sign. That practical question — who is qualified to audit, and to what standard? — is more consequential than the disclosure provisions that attracted most of the attention.

Two states moved in opposite directions in the same quarter

Illinois added binding obligations by bipartisan supermajority. Colorado repealed the most ambitious state AI law in the country and replaced it with a disclosure framework, signed on 14 May.

The Colorado retreat is the more instructive half, because it did not achieve what a retreat is for. xAI sued to block the original statute, the Department of Justice intervened in support for the first time in a challenge to a state AI law, and a federal court granted a stay on 27 April. That stay reaches the replacement as well as the law it replaced, and runs until fourteen days after the court rules on the preliminary injunction motion. As of late August no ruling had issued.

So Colorado currently has neither its original duty-of-care regime nor its lighter successor in force, having legislated twice. Illinois has a signed statute with a January date and no litigation against it.

Why the audit provision may be what survives

The federal posture is the variable neither state controls, and the DOJ's intervention in Colorado signalled a willingness to treat state AI regulation as constitutionally suspect.

The key distinction in SB 315 is what it regulates. Colorado's original act imposed a duty of care against algorithmic discrimination in deployment, which reaches into how firms use models and invites the preemption and speech arguments xAI has run. Illinois requires a narrow cohort of very large developers to publish a framework and have somebody check it. That is closer to a disclosure and record-keeping regime than a conduct rule, and disclosure regimes have historically been the durable part of American technology regulation.

Whether that distinction holds up in court is untested. It is, however, the reason a 110-0 vote was available in Illinois for a measure the industry opposed, and it is why the audit requirement rather than the transparency reports is the part of this law worth watching.