Illinois’ New AI Safety Law Takes Effect: What Residents and Businesses Should Know
Illinois has enacted a frontier-artificial-intelligence safety law, but its reach is narrower than a general AI ban or a rule covering every business that uses an AI product.
Gov. JB Pritzker signed Senate Bill 315 on July 6, 2026. The measure became Public Act 104-0538, the Artificial Intelligence Safety Measures Act, and takes effect Jan. 1, 2027.
The law primarily targets companies developing exceptionally powerful foundation models and operating, developing or deploying those models, in whole or in part, in Illinois. Most residents, schools, employers and ordinary businesses will not have to register simply because they use an AI service.
Which companies are covered
The law defines a “frontier model” as a foundation model trained with more than 1026 integer or floating-point operations. The calculation includes the original training run as well as qualifying fine-tuning, reinforcement learning and other material modifications.
A “frontier developer” is a person that trains, or initiates the training of, a frontier model using that level of computing power. A “large frontier developer” is a frontier developer whose affiliates collectively had more than $500 million in annual gross revenue during the preceding calendar year.
That combination of technical scale, revenue and an Illinois connection is important. The law does not regulate all artificial intelligence or all companies that purchase, integrate or use AI tools.
What begins Jan. 1, 2027
Starting Jan. 1, 2027, a large frontier developer may not develop, deploy or operate a frontier model, in whole or in part, in Illinois without a current disclosure statement filed with the Illinois Emergency Management Agency and Office of Homeland Security and payment of the required fee or assessment.
The disclosure must be filed in the form and manner prescribed by the agency. It must identify the developer, business names, principal and Illinois office addresses, required ownership information and primary, secondary and tertiary contacts. The ownership disclosures differ depending on whether the company or its ultimate parent is privately held or publicly traded.
The statement must be renewed annually, after a model ownership transfer or after a material change to the reported information, whichever comes first. The statute directs the agency to charge large frontier developers their pro rata share of the cost of administering the Act, including certain prior-year deficits. It does not set a single dollar amount in the statute.
The agency must publish a list of large frontier developers that have filed disclosure statements, but the public list cannot include the required contact information. A company that fails to file, correct false information or pay an assessment can face a $1,000 daily civil penalty, plus the amount of unpaid assessments.
What changes in 2028
Beginning Jan. 1, 2028, large frontier developers must write, implement, follow and conspicuously publish a frontier-AI framework. The framework must be reviewed and, when appropriate, updated at least once a year.
The framework must explain how the company will:
- Set and assess thresholds for catastrophic risk;
- Apply mitigations based on those assessments;
- Use third-party evaluations;
- Review safety assessments before deploying a model or using it extensively internally;
- Protect unreleased model weights from unauthorized modification or transfer;
- Identify and respond to critical safety incidents;
- Maintain internal governance; and
- Manage risks from extensive internal use of frontier models.
Under the law, catastrophic risk means a foreseeable and material risk that a single qualifying incident could materially contribute to the death or serious injury of more than 50 people, or cause more than $1 billion in property damage or loss. The statute identifies examples including certain weapons assistance, uncontrolled cyberattacks or criminal conduct, and a model evading the control of its developer or user.
The annual independent-audit requirement begins Jan. 1, 2028, or 90 days after a developer first qualifies as a large frontier developer, whichever is later. The audit must be conducted by an independent third party with relevant technical competence and without a disqualifying financial interest in the developer.
More public model information, with limits
Before or concurrently with deploying a new frontier model or a substantially modified version of an existing model, a frontier developer must publish a transparency report. The report must include the release date, supported languages, output modalities, intended uses, generally applicable use restrictions or conditions, the developer’s website and a way for a person to contact the developer.
For large frontier developers, the report also must include machine-readable summaries of catastrophic-risk assessments, assessment results, the involvement of third-party evaluators and other steps taken under the company’s safety framework.
Large frontier developers must retain an independent third party for an annual compliance audit. Within 30 days after receiving the audit, the developer must publish a high-level summary and a redacted copy, and send the redacted report to the state agency and Attorney General.
Transparency is not unlimited. The law permits redactions needed to protect trade secrets, cybersecurity, public safety, national security or compliance with another state or federal law. Critical-incident reports, internal-use risk-assessment reports, unredacted audit reports and covered-employee reports held by the agency or Attorney General are exempt from disclosure under the Illinois Freedom of Information Act.
Incident reporting and employee protections
The law defines a critical safety incident to include unauthorized access to or exfiltration of model weights resulting in death or bodily injury, harm from a catastrophic risk, loss of model control causing death or bodily injury, or certain deceptive conduct by a model that demonstrates materially increased catastrophic risk.
A frontier developer must report a critical safety incident to the state agency and Attorney General within 72 hours after learning facts sufficient to establish a reasonable belief that an incident occurred. If the incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to an appropriate authority, which may include law enforcement or a public-safety agency.
The agency, in consultation with the Attorney General, still must establish the reporting mechanism and related procedures. The law also allows members of the public to use the state reporting mechanism once it is established.
Covered employees are workers responsible for assessing, managing or addressing the risk of critical safety incidents. A frontier developer may not retaliate against a covered employee who reports a suspected violation or a specific and substantial danger to public health or safety arising from catastrophic risk. Large frontier developers must provide a reasonable internal process for anonymous reports and monthly status updates to the reporting employee.
Enforcement and what residents should watch
The Attorney General may bring civil actions for violations involving required documents, audits, incident reporting, prohibited false or misleading statements or failure to follow a company’s own safety framework. A first violation can bring a civil penalty of up to $1 million; a subsequent violation can bring up to $3 million per violation. The Act does not create a private right of action.
For Illinois residents, the near-term consequence is mainly oversight rather than a new obligation. People may eventually have access to more information about covered models’ uses, restrictions, risk assessments and audit findings, while sensitive details may remain redacted or confidential.
The next practical step is implementation. State agencies must establish disclosure, fee and incident-reporting procedures. They may also designate equivalent or stricter federal laws, regulations or guidance for certain compliance purposes if a developer follows the required declaration process.
The first major date is Jan. 1, 2027, when the Act takes effect and large frontier developers face disclosure and fee requirements for covered activity in Illinois. The frontier-AI framework begins Jan. 1, 2028, while the annual-audit obligation follows the later qualification trigger when applicable.
Sources
- Illinois Public Act 104-0538, Artificial Intelligence Safety Measures Act
- Capitol News Illinois: Pritzker signs landmark AI regulation bill that aims to mitigate risks
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.