AI Law Watch / Illinois

Illinois SB 315: The $3 Million Safety-Audit Rule for Frontier AI

A covered frontier-AI developer can face up to $1 million for a first violation and $3 million after that. Illinois also requires annual independent audits.

By Santosh Singh · 8 August 2026Checked against sources 8 August 2026
The law at a glance
LawArtificial Intelligence Safety Measures Act (SB 315; Public Act 104-0538)
First deadlinesState disclosure, incident-reporting, and employee-notice duties begin 1 January 2027. Framework and audit duties begin 1 January 2028.
PenaltyUp to $1 million for a first violation and $3 million for each later violation. A missing or false state disclosure can also cost $1,000 per day.
Who it reachesA frontier model uses more than 10^26 training operations. Most duties apply to developers with more than $500 million in annual gross revenue, including affiliates.
Enforced byIllinois Attorney General for Section 25 civil penalties; Illinois Emergency Management Agency and Office of Homeland Security administers disclosures.

A covered frontier-AI developer can face a civil penalty of up to $1 million for a first violation and up to $3 million for each later violation.

Illinois Senate Bill 315 also adds a quieter cost: an annual independent third-party audit. The auditor gets access to material needed to test compliance, the company must keep the unredacted report while the model is deployed and for five more years, and a redacted report must reach the State within 30 days.

The Artificial Intelligence Safety Measures Act takes effect on 1 January 2027. Its largest obligations arrive in two waves, not one.

You do not need an Illinois company or office. Beginning in 2027, a covered large frontier developer cannot develop, deploy, or operate a frontier model, in whole or in part, in Illinois without a current disclosure filed with the State. But an ordinary application company does not become a frontier developer merely because it calls a model through an API.

What Illinois SB 315 requires

The coverage test starts with compute. A frontier model is a foundation model trained with more than 10^26 integer or floating-point operations. The count includes the original training run plus later fine-tuning, reinforcement learning, and other material modifications.

Most of the heavier duties apply to a "large frontier developer." That means a frontier developer whose annual gross revenue, together with affiliates, exceeded $500 million in the previous calendar year.

Beginning 1 January 2027, a large frontier developer operating inside the Illinois trigger must file a current disclosure statement with the Illinois Emergency Management Agency and Office of Homeland Security and pay its assigned fee. Missing the filing, leaving false information uncorrected, or failing to pay can produce a $1,000 daily penalty plus unpaid assessments.

Frontier developers must report a critical safety incident to the Agency and the Illinois Attorney General within 72 hours after learning facts sufficient to support a reasonable belief that one occurred. An incident that poses an imminent risk of death or serious physical injury must reach an appropriate authority within 24 hours.

The incident definition is narrow and severe. It covers matters such as model-weight theft that causes injury, a catastrophic-risk event, loss of control that causes injury, or deceptive model conduct that subverts developer controls and materially increases catastrophic risk.

Employee protections also begin with the Act. A frontier developer cannot block or punish a covered employee for a protected safety disclosure. Large developers must offer an anonymous internal process, give the reporting employee a monthly status update, and share disclosures and responses with officers and directors at least quarterly, subject to the statute's wrongdoing exception.

The second wave begins on 1 January 2028. A large frontier developer must write, follow, publish, and update a frontier-AI framework at least once each year. The framework must address catastrophic-risk thresholds, safeguards, cybersecurity, governance, third-party evaluations, and risks from the company's own use of its models.

Before or at the time it deploys a new or substantially modified frontier model, the developer must publish a machine-readable transparency report. A large developer must add summaries of catastrophic-risk assessments, results, third-party participation, and the steps taken in response.

The company must also retain a qualified independent auditor each year. Payment cannot depend on the audit result, and neither side can hold a financial interest in the other. Within 30 days after receiving the report, the company must publish a high-level summary and a properly redacted copy, then send the redacted report to the Agency and Attorney General.

Why this lands inside the product and enterprise deals

Building in one of these categories? Send me one message about what you're building and I'll name the laws you're inside — which documents they demand, and what covers you. Free, usually within a day or two. Start here.

— Santosh

SB 315 turns a policy file into tested evidence.

An auditor cannot verify a safety framework from slogans. The developer needs records that connect each stated control to model evaluations, access controls, incident criteria, responsible staff, exceptions, and management decisions. If the published framework says one thing while the production process does another, the difference can become an audit finding or enforcement evidence.

The rule also reaches commercial relationships. Model developers will need evaluation firms, red-team providers, cloud vendors, security partners, and specialist advisers to preserve evidence and permit controlled audit access. Enterprise customers will ask whether their model supplier can produce the framework, transparency report, incident process, and independent-audit record.

Downstream AI startups are usually outside SB 315's direct developer duties when they only use a third-party model. They are still likely to feel the contract effect. A covered model provider may add incident cooperation, security evidence, audit access, and notice terms to supplier and customer agreements.

In August 2025, the Federal Trade Commission approved a final consent order against Workado after alleging that the company misrepresented the accuracy of its AI-content detector. The order requires competent and reliable evidence for future accuracy claims. This was not an SB 315 case and did not concern a frontier model. It shows why a published claim about an AI control needs evidence behind it before a regulator asks.

The national rule is being built in layers

Illinois is not acting alone. California's SB 53 requires frontier-AI safety frameworks, transparency, incident reporting, and whistleblower protection. New York's RAISE Act requires safety frameworks and 72-hour reporting for critical-harm incidents. Illinois adds mandatory annual independent audits for large frontier developers.

That creates a multi-state document problem. A company may be able to reuse one core risk framework, but recipients, reporting channels, publication rules, and audit requirements differ by state. The Connecticut SB 5 guide shows how another state has divided duties across AI products. StartEase maps the required files by product and jurisdiction through its AI document services.

Where you incorporate does not protect you

A Delaware C-Corporation or Wyoming LLC does not create an exemption. Illinois ties the filing rule to developing, deploying, or operating a frontier model, in whole or in part, in the State.

The practical question is not where the certificate of incorporation sits. It is whether the company meets the compute and revenue tests and has an Illinois operational connection. That connection should be mapped across model development, deployment, personnel, infrastructure, users, and contracts before the first deadline.

Three things to fix before you scale

1. Write a coverage memo. Record the model's training-compute calculation, what later training is included, affiliate revenue, and the facts that create or avoid an Illinois connection. Revisit the memo after a material training run or acquisition.

2. Build one evidence map for the framework and audit. Link every public safety statement to an owner, control, evaluation, result, retained record, and exception process. Give the auditor access without exposing model weights, trade secrets, or security material beyond what the law requires.

3. Test the incident clock and employee channel. Define who decides that facts support a reasonable belief, who sends the 72-hour report, and when the 24-hour emergency route applies. Give covered employees the required notice and test anonymous reporting before the Act starts.

The one-line summary for each founder

Frontier-model developers: calculate the training threshold and affiliate revenue before treating SB 315 as a Big Tech issue.

AI application companies: API use alone usually does not make you the frontier developer, but your provider may pass audit and incident terms into the contract.

Evaluation and red-team firms: define independence, evidence access, confidentiality, methods, and report ownership before accepting an Illinois audit engagement.

Enterprise buyers: ask for the current framework, transparency report, incident process, and audit status instead of accepting a general statement that the model is safe.

Illinois has not created a general licence for every AI startup. It has created a high-threshold regime with unusually sharp documentation and audit duties. The first filing wave starts in 2027. The framework and independent audit wave starts in 2028. Waiting for the auditor to arrive is too late to build the record the auditor must test.

Building a frontier model? Send me one message about what you're building, and I'll name the rules you're inside.

Questions founders ask

My company is incorporated in Delaware. Does Illinois SB 315 apply?

It can. Incorporation does not decide coverage. A large frontier developer may trigger the state filing rule when it develops, deploys, or operates a frontier model, in whole or in part, in Illinois.

Is every AI startup with Illinois users covered?

No. The Act's frontier-model threshold is more than 10^26 training operations. Its framework, audit, and main civil-penalty provisions focus on large frontier developers with more than $500 million in prior-year annual gross revenue, including affiliates. Other Illinois and federal laws can still apply to smaller AI companies.

Does using an OpenAI, Anthropic, or other model API make us a frontier developer?

Ordinarily, no. The Act defines a frontier developer as the person that trains or starts training the frontier model. An application company should still check whether it fine-tunes or materially modifies a model, and whether its provider contract passes through incident, security, or audit duties.

What should a potentially covered developer prepare first?

Start with a coverage memo, Illinois nexus map, state-disclosure file, frontier-AI framework, transparency-report template, incident runbook, whistleblower channel, evaluation register, audit evidence map, and auditor engagement terms. Product and training facts can change the list. Tell me what you're building and I'll map yours.

Source trail

Illinois General Assembly, Public Act 104-0538 · Illinois General Assembly, SB 315 bill status · Office of Governor JB Pritzker, signing announcement · Governor of California, SB 53 signing announcement · Governor of New York, RAISE Act signing announcement · Federal Trade Commission, Workado case and final consent order

This is a founder-facing note, not a legal opinion or legal advice. StartEase Agent is not a law firm. Verify statute text before any client-specific decision. Companies named as category examples illustrate the product space, not any violation.

Santosh Singh helps founders form US companies and keep their AI products legal. He tracks 74 US AI laws across 84 startup domains — new ones land here first.