Policy

Illinois Passes the Toughest AI Safety Law in America. The Vote Was 110 to Zero.

SB 315 requires frontier AI companies with over $500 million in annual revenue to submit to mandatory independent third-party safety audits, publish annual safety plans, and report incidents within 72 hours. Governor Pritzker is expected to sign. No US state has gone this far before.

By Patrick T ·

Illinois Passes the Toughest AI Safety Law in America. The Vote Was 110 to Zero.

While Silicon Valley's lobbying apparatus was focused on preventing federal AI regulation, the Illinois House of Representatives voted 110 to 0 to pass SB 315, the Artificial Intelligence Safety Measures Act. The bill had already cleared the Illinois Senate on 21 May 2026. Governor J.B. Pritzker has indicated he will sign it. When he does, Illinois will become the first US state to require mandatory independent third-party safety audits of frontier AI systems — a provision that the AI industry has resisted at every level of government for the past three years.

In a political environment where virtually nothing achieves bipartisan consensus, every single member of the Illinois House voted in favour of requiring AI companies to prove their models are safe.

The unanimity of the vote is as significant as the content of the bill. Illinois is a large, politically divided state. A 110-0 vote in the House on any piece of technology legislation is unusual. That every member of the chamber — Republican and Democrat, from Chicago and from rural downstate districts — voted in favour of holding AI companies accountable suggests that the political calculus around AI regulation has shifted in ways that the industry may not have fully registered.

What SB 315 Actually Requires

The bill applies to companies with more than $500 million in annual gross revenue that deploy frontier models capable of catastrophic risk. This threshold captures OpenAI, Anthropic, Google DeepMind, and Meta AI, while exempting smaller AI companies and startups. The capability-based filter — 'frontier models capable of catastrophic risk' — adds a second layer that targets specifically the companies building the most powerful AI systems, not every company that uses AI in its products.

Covered companies must do three things. First, they must create, publish, and annually update detailed safety plans that identify specific risks from their models, describe mitigation strategies, and explain how the company monitors for emerging threats. Second, they must submit to annual independent third-party audits of their safety practices — conducted by accredited auditors with no financial relationship to the company, with results made publicly available. Third, they must report AI safety incidents to relevant authorities within 72 hours of identification.

The Illinois State Capitol in Springfield. The House voted 110–0 to pass SB 315, the Artificial Intelligence Safety Measures Act, on 28 May 2026.
The Illinois State Capitol in Springfield. The House voted 110–0 to pass SB 315, the Artificial Intelligence Safety Measures Act, on 28 May 2026.

The Third-Party Audit Provision: Why It Matters

The mandatory third-party audit is the centrepiece of SB 315 and the provision that the AI industry is most concerned about. Currently, AI safety assessments are largely self-reported. Companies publish model cards, safety reports, and red-teaming results that they control and curate. Critics — including many AI safety researchers at the labs themselves — have argued for years that self-assessment is inherently conflicted, since companies have strong financial incentives to downplay risks and overstate safety measures.

Independent audits would change this dynamic fundamentally. An accredited third-party auditor would have access to a company's internal safety documentation, testing results, and incident records. They would evaluate whether the company's safety practices match its public claims. The audit results would then be published, creating a permanent public record that regulators, researchers, and the public could use to hold companies accountable.

The practical challenge is that the field of AI safety auditing barely exists yet. There are few organisations with the technical expertise to meaningfully evaluate frontier AI systems, and standards for what constitutes a thorough AI safety audit have not been established. SB 315 will need to address these gaps through the development of accreditation standards and audit frameworks — a process that will likely take most of the 12 to 18 month implementation period before full enforcement begins.

The 72-Hour Reporting Window

The incident reporting requirement is modelled on frameworks from aviation and nuclear energy, where rapid disclosure of safety events is considered essential for learning from failures and preventing recurrence. The National Transportation Safety Board requires immediate reporting of aviation accidents and incidents. The Nuclear Regulatory Commission mandates prompt disclosure of safety events at nuclear facilities. SB 315 applies this logic to AI, acknowledging that frontier AI systems have become critical infrastructure whose failures can have far-reaching consequences.

The European Parliament in Brussels — Illinois legislators cited EU AI Act provisions as a partial model for SB 315's third-party audit requirements.
The European Parliament in Brussels — Illinois legislators cited EU AI Act provisions as a partial model for SB 315's third-party audit requirements.

California Tried and Failed. Why Did Illinois Succeed?

California's SB 1047, which would have imposed safety requirements on frontier AI developers, was vetoed by Governor Gavin Newsom in September 2024 after intense lobbying from the AI industry and from Silicon Valley's political network. The Illinois bill passed the same industry opposition and cleared both chambers with no dissenting votes. The difference appears to be a combination of factors: Illinois is not home to the major AI labs, reducing the direct economic pressure on legislators; Governor Pritzker has been more willing than Newsom to position himself as a check on Big Tech; and the political environment in 2026 is different from 2024, with AI incidents and public concern about AI safety having accumulated over the intervening two years.

The Illinois bill is also more carefully drafted than California's SB 1047. It targets a specific set of large companies rather than imposing broad requirements on the entire AI ecosystem, and the third-party audit framework is more operationally specific than the liability provisions that made SB 1047 controversial. Whether this precision helped it survive industry opposition or whether the political environment simply changed enough to make any well-drafted AI safety bill passable is difficult to determine from the outside.

What Comes Next

New York, Connecticut, and several other states are watching the Illinois bill closely. If Pritzker signs it and the implementation process proceeds without major legal challenges, it is likely to serve as a template for similar legislation in other states. The AI industry's preferred outcome — a federal framework that pre-empts state-level regulation — has not materialised, and the window for achieving it is narrowing as more states move toward their own regulatory frameworks.

For the major AI labs, the immediate practical question is compliance. The $500 million revenue threshold captures all of them, and the third-party audit requirement will require building compliance infrastructure that does not currently exist at most companies. The 12 to 18 month implementation timeline is generous, but the work of establishing audit standards, selecting accredited auditors, and preparing the first round of public safety disclosures will begin immediately after the bill is signed.