Illinois Just Passed the Toughest US State AI Safety Law — And It Won't Bite Until 2028
Illinois has enacted the Artificial Intelligence Safety Measures Act, requiring transparency, mandatory independent audits, and whistleblower protections for frontier AI developers. The phased rollout is deliberately slow, but the audit requirement is unprecedented.
On 6 July 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act — a comprehensive state-level AI safety framework that, when it takes full effect in January 2028, will impose obligations on frontier AI developers that no US state has previously required. Most provisions begin on 1 January 2027; the heaviest requirements, including mandatory independent third-party audits, begin a year later on 1 January 2028. The phased rollout is deliberately slow. The bill's sponsors have been explicit that the 18-month delay is meant to give companies time to build the documentation and governance infrastructure the law expects. But the substance of the law — particularly the audit requirement — represents a meaningful shift in how US states are approaching frontier AI safety, and it sets a precedent that other states will be pressed to match. What the law actually requires The Illinois framework has several distinct tracks, each with its own trigger thresholds and effective dates. Transparency reporting (effective 1 January 2027) For all frontier developers operating in the state, the law requires a transparency disclosure before or at the time a new or substantially revised model is deployed. The disclosure must include: The model's release date
Its intended uses and supported languages
Output types
Restrictions placed on the model
A developer contact point This part of the law is straightforward and not particularly controversial. California and New York's parallel frontier-AI transparency laws require substantially similar disclosures. Incident reporting (effective 1 January 2027) Critical safety incidents must be reported to state authorities within 72 hours of discovery. If there is imminent risk of death or serious injury, the deadline shortens to 24 hours. The 24-hour deadline is more aggressive than California's 15-day reporting window and is closer to the EU AI Act's incident reporting rules than to most US state approaches. Whistleblower protections (effective 1 January 2027) Covered employees who raise safety concerns or report possible violations are protected from retaliation. Frontier developers must maintain anonymous internal reporting channels and provide monthly updates to whistleblowers about the status of their reports. This is the strongest state-level whistleblower protection specifically targeted at AI safety work, and it tracks the EU AI Act's whistleblower protections more closely than any other US state has. Frontier AI framework and mandatory audits (effective 1 January 2028) This is the part that is genuinely new. From January 2028, large frontier developers must publish and follow a frontier AI framework explaining how the company identifies, assesses, and responds to catastrophic risks. The framework must cover: Mitigation measures for identified risks
Cybersecurity for unreleased model weights
Internal governance structures
Use of external evaluators
Accountability procedures The framework must be reviewed at least annually, and material changes must be posted publicly within 30 days. In addition, large frontier developers face annual independent third-party audits of their compliance with the framework. This is the most distinctive feature of the Illinois law. Legal commentators have noted that this audit requirement sets the state apart from California and New York, which have introduced similar transparency regimes but stopped short of mandatory third-party verification. What "frontier developer" actually means The law's obligations attach to "covered frontier developers" — a defined category based on training compute, parameter count, or capability thresholds. As of the law's enactment, the thresholds align roughly with the AI Executive Order's definition of "dual-use foundation model": Training compute above a specified FLOP threshold
Model parameter count above a specified value
Capability benchmarks above specified levels on standardised evaluations The thresholds are not technically static; the law gives a rulemaking body the authority to update them as the field evolves. For 2027, the practical effect is that the obligations attach to the largest handful of US-based frontier labs. Over time, the same obligations could apply to a wider set of developers as capability thresholds become reachable by smaller training runs. Why the audit requirement matters Mandatory third-party audit is the structural change that makes the Illinois framework distinct. Voluntary disclosure regimes — even strong ones, like California's SB-53 — depend on the disclosing company telling the truth in its disclosures. The Illinois audit requirement creates a structural check on that. What an audit actually catches depends on what the auditor is empowered to look at. The Illinois law requires audit of "compliance with the framework" — which means the auditor verifies that the company is doing what its publicly stated framework says it does. That is a meaningful check, even if it does not directly verify that the framework itself is adequate. A more aggressive audit framework would require auditors to evaluate whether the company's framework is actually sufficient to address the identified catastrophic risks. The Illinois law stops short of that — the audit verifies compliance with the framework, not adequacy of the framework — but it is the first state-level statute to require external verification of any kind for frontier AI safety work. The honest limitations This is a state law, and it has the limits that come with that: The law can only bind developers operating in Illinois, in the same way that California's SB-53 binds developers operating in California. Federal preemption would require an act of Congress, which has so far been unable to pass comprehensive AI safety legislation.
Enforcement sits exclusively with the Illinois Attorney General. There is no private right of action, and the AG's office has finite resources. The civil penalties — up to $1 million for a first violation, $3 million for repeat breaches — are meaningful but not catastrophic for the largest frontier developers.
The audit verifies compliance with the framework, not the framework's adequacy. A frontier developer could in principle write a thin framework, comply with it perfectly, and pass the audit. The law does not require the auditor to judge whether the framework itself is sufficient.
The 2028 effective date is far enough out that the regulatory environment may shift significantly before the audit requirement actually applies. A federal law, a Supreme Court decision, or a change in the federal-state balance could all change the operative landscape before the audit regime takes effect. These are real limitations, but they are also why the law's structure is the way it is. Illinois is not trying to be the EU. It is trying to create a structural incentive for frontier developers operating in its jurisdiction to take safety seriously, with an enforcement mechanism that survives political turnover. What this changes for the rest of the country The most likely follow-on effect is not direct — Illinois cannot regulate OpenAI's behaviour in California — but it is significant: State AG coordination. State attorneys general have shown increasing willingness to coordinate on cross-state enforcement of privacy and consumer protection. A working Illinois audit regime would create a template that other AGs could adopt.
Federal momentum. The bipartisan CASE Act and other federal AI safety proposals have stalled in part because state action reduces the federal pressure. The Illinois law, paired with California's SB-53 and New York's RAISE Act, builds the patchwork that Congress has so far failed to assemble.
Industry compliance posture. The largest frontier developers will not run separate compliance programmes for Illinois versus California versus federal. They will adopt the most demanding standard that applies anywhere they operate and apply it everywhere. That means Illinois's framework, once operational, will pull compliance practice across the industry. For companies that operate in multiple US states, the practical compliance path is to assume that the most demanding state-level AI safety law applies everywhere. Illinois now sets that bar. What this does not fix Honest limits worth noting: The law does not address open-source models. Frontier developers are covered; the long tail of small labs and open-source projects is not.
The law does not address the deployment side. A company using a frontier model in production is not directly covered. The obligations attach to the developer, not to the deployer.
The law does not address foreign frontier developers that don't operate in Illinois. OpenAI, Anthropic, Google, Meta, and xAI all operate in Illinois. Companies based in jurisdictions where they don't sell or serve users are not bound.
The thresholds may be too static. Capability-based thresholds based on training compute or parameter count are vulnerable to progress making them trivially exceeded. The law gives the rulemaking body authority to update them, but does not require continuous review. For Illinois residents and policymakers, the law is a meaningful step forward. For the broader US debate, it is one more data point in a patchwork that is converging slowly on a workable framework for frontier AI safety. The 2028 audit regime, if it actually takes effect, will be the first real test of whether state-level audit requirements produce material changes in frontier developer behaviour. That is still almost two years away. A lot can change between now and then. The law is, for now, a credible commitment to a specific kind of oversight, with teeth scheduled to arrive in late 2027 and 2028.