Illinois mandates AI audits by 2028

- Illinois Governor JB Pritzker signed SB 315 on July 6, 2026, requiring frontier AI developers to meet safety, transparency and audit duties before 2028. (crowell.com) - The Illinois law adds what Crowell called the first annual independent third-party audit requirement for large frontier developers, alongside reporting and whistleblower protections. (crowell.com) - California’s frontier AI transparency law was signed on September 29, 2025, while EU AI Act compliance deadlines now extend into 2027 and 2028. (crowell.com)

Illinois on July 6 became the latest U.S. state to impose binding rules on the makers of the most powerful AI systems. Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, creating state-level duties on safety, transparency and accountability for frontier models and adding a requirement for annual independent third-party audits for large frontier developers. (crowell.com) Crowell & Moring said the measure goes further than comparable state laws in California and New York on the audit point. The law’s compliance clock runs toward January 2028. ### Which companies does the Illinois law actually reach? Illinois defined the law around “frontier models,” not ordinary software products. Crowell said the Illinois act, like related laws in California and New York, applies to a narrow class of systems trained using more than 10^26 floating-point operations, a technical threshold aimed at the largest and most capable models. (crowell.com) California used a similar structure in its Transparency in Frontier Artificial Intelligence Act, signed by Governor Gavin Newsom on September 29, 2025. Crowell said that law applies to “frontier developers,” with extra duties for “large frontier developers” whose annual gross revenue exceeded $500 million in the prior calendar year. (crowell.com) ### What is new in Illinois beyond transparency filings? Illinois added an audit obligation that legal analysts described as the first of its kind among these state frontier-model laws. Crowell said SB 315 requires annual independent third-party audits for large frontier developers, on top of transparency reports, AI safety frameworks, incident reporting requirements and whistleblower protections that now appear across Illinois, California and New York. (crowell.com) OpenAI publicly backed the Illinois bill, according to Crowell, calling it “one of the strongest frontier AI safety laws in the country.” Crowell also said OpenAI described California, New York and Illinois as the beginning of a “de facto national framework” and released a Frontier Governance Framework on the same day the Illinois House passed SB 315. (crowell.com) ### How does California fit into the same compliance picture? California’s law was earlier and disclosure-focused. Crowell said the state’s TFAIA requires large AI developers to publish a safety framework using widely accepted safety standards, explain a model’s capacity to create and mitigate catastrophic risks, release transparency reports on intended uses and restrictions, and summarize catastrophic-risk assessments. (crowell.com) Those California requirements matter because many of the companies likely to fall under Illinois’s law already operate in California and internationally. Crowell said California’s statute also requires reporting of “critical safety incidents,” includes whistleblower protections and creates a consortium to build “CalCompute,” a public cloud computing cluster. (crowell.com) ### Why are companies also watching Europe at the same time? The European Union already has a binding cross-border regime in force. Foley & Lardner said the EU AI Act entered into force in August 2024, classifies systems by risk level and imposes obligations on companies that develop or deploy AI in European markets. (crowell.com) Foley said anticipated legislative changes would push key EU deadlines into late 2027 and 2028, but foundational requirements are already active. The firm said providers must implement risk-management systems, maintain technical documentation and conduct conformity assessments, and that penalties can reach as much as 7% of global revenue. (crowell.com) ### What does this change inside companies building advanced models? The compliance burden is moving from policy papers to operating systems. Foley said regulatory compliance for AI is now “a contractual and governance priority,” and not only a technology issue, because companies may face different classifications and obligations for the same system across jurisdictions. (foley.com) In practice, that means developers covered by Illinois will need audit-ready documentation, incident reporting processes and governance structures before the January 2028 deadline. Companies selling or deploying AI in Europe will also need technical documentation and conformity-assessment records on the EU timetable that Foley said now runs into late 2027 and 2028. (crowell.com) (foley.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.