Illinois Law Requires Annual Frontier AI Audits Starting in 2028

Illinois enacted the Artificial Intelligence Safety Measures Act on July 6. The law takes effect January 1, 2027, while annual independent audits begin January 1, 2028 or 90 days after a developer first qualifies, whichever is later. It covers frontier models trained above 10^26 operations when the developer and its affiliates exceed $500 million in annual revenue.
Illinois enacted the Artificial Intelligence Safety Measures Act on July 6, 2026, when Gov. JB Pritzker signed SB 315. The law takes effect January 1, 2027, but its annual independent-audit requirement begins on January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, whichever is later.
Illinois is the first state to require recurring third-party compliance audits for this class of frontier-model developer, according to the governor's office, the statute, and Capitol News Illinois. California and New York have related frontier-AI transparency and safety laws, but Illinois adds the annual audit mechanism.
Who the law covers
The statute defines a frontier model as a foundation model trained using more than 10^26 integer or floating-point operations, including the original training run and later fine-tuning, reinforcement learning, or other material modifications. A large frontier developer is one whose combined annual gross revenue with affiliates exceeded $500 million in the preceding calendar year.
Beginning in 2028, covered developers must publish and follow a frontier AI framework addressing catastrophic-risk assessment, mitigations, model-weight security, incident response, governance, and the use of third parties. The law also requires model disclosures, critical-safety-incident reporting, and protections for workers who raise safety concerns.
What the annual audit requires
The statute provides more detail than a general instruction to hire an auditor. The third party must use generally accepted auditing standards and best practices, demonstrate competence that includes access to frontier-model safety expertise, and have no financial interest in the developer. Payment cannot depend on the audit result.
Auditors must receive materials reasonably necessary for the review and assess both compliance and the developer's internal controls. Their report must explain whether the developer substantially complied, describe deviations, and recommend improvements. The developer must publish a redacted report and summary within 30 days, send them to Illinois authorities, and retain the report for the life of the model plus five years.
The law does not name a single frontier-AI audit framework or a government-approved auditor roster. That leaves room for implementing guidance and professional practice to shape evidence formats, testing depth, and how technical safety expertise is demonstrated. But the statute already establishes baseline standards for competence, independence, access, reporting, and retention.
Why it matters for AI governance teams
The January 2027 effective date starts with disclosure obligations, while the more extensive framework and audit duties begin in 2028. Teams likely to cross the compute and revenue thresholds will need traceable model inventories, training-compute records, risk evaluations, incident processes, internal controls, and evidence that published safety statements match operational practice.
Illinois can impose civil penalties of up to $1 million for a first violation and up to $3 million for later violations. The practical question is now implementation: whether regulators, developers, and audit providers converge on review methods that are technically credible and consistent across the overlapping Illinois, California, and New York regimes.
Key Points
- 1Illinois requires annual independent audits beginning in 2028 for frontier-model developers above the law's compute and revenue thresholds.
- 2The statute sets baseline auditor competence, independence, access, reporting, publication, and retention requirements.
- 3Covered teams will need evidence connecting model inventories, risk frameworks, incident handling, and internal controls to their public disclosures.
Scoring Rationale
Illinois introduces the first reported state requirement for recurring independent audits of large frontier AI developers and specifies baseline competence, independence, evidence-access, reporting, and retention duties. Its overlap with California and New York can shape governance and assurance practices beyond Illinois.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

