Illinois Governor signs landmark AI safety law requiring third-party audits of frontier models

Overview of the Illinois Artificial Intelligence Safety Measures Act

On 6 July 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (Senate Bill 315) into law, making Illinois the first state in the United States to mandate independent, third-party safety audits for large frontier artificial intelligence models. The legislation takes effect on 1 January 2027 and represents a material escalation in how governments are choosing to regulate advanced AI systems. Unlike the voluntary frameworks that have dominated AI governance discussions in recent years, Illinois has drawn a hard line: if you develop frontier AI at scale, you will be audited by an independent party with no financial conflict of interest.

The significance of this development extends well beyond American state politics. Illinois joins California, which passed SB-53 in late 2025, and New York, which enacted the Responsible AI Safety and Education Act around the same period. Together, these three states account for roughly 40 per cent of the United States AI market. When jurisdictions of that collective weight align on a regulatory model, it begins to function less like local legislation and more like a de facto industry standard. For Australian enterprises, consultants, and technology procurement teams, that shift carries real consequences for how AI tools are selected, contracted, and governed domestically.

Governor Pritzker was direct about the political context at the signing ceremony in Chicago, stating that Congress and the President ought to be passing similar legislation but had so far been unwilling, with many captive to special interests that profit from the industry having no regulation. His remarks pointed explicitly to the Trump administration’s decision to scale back federal AI oversight in favour of a voluntary 30-day review framework, signalling that progressive states are prepared to act unilaterally where Washington will not. For professional services firms and corporate legal teams operating with US-linked AI vendors, the practical consequence is clear: vendor compliance is no longer a discretionary matter.

Key details of the Illinois Artificial Intelligence Safety Measures Act

The Illinois Artificial Intelligence Safety Measures Act applies to developers of advanced frontier AI models that generate more than 500 million US dollars (approximately 780 million Australian dollars) in annual revenue and whose models are trained using large-scale computing infrastructure. The revenue and compute thresholds are deliberately calibrated to target the largest players in the frontier AI space rather than smaller developers or enterprise software vendors who use AI as a feature within a broader product. This scoping decision is important: it concentrates regulatory burden on organisations with the resources and the risk profile to justify intensive oversight.

The centrepiece obligation under SB 315 is mandatory annual third-party safety auditing. Auditors must be independent and free from financial conflicts of interest with the developer being assessed. This is a meaningful requirement because it rules out the common practice of developers commissioning safety reviews from firms that also hold commercial contracts with them. The audits assess the developer’s safety and security frameworks, not merely their documented policies. Illinois is the first state to codify this requirement into statute, and it does so with an effective date of 1 January 2027, giving covered developers approximately 18 months from the signing date to build compliant audit programmes.

Beyond auditing, the Act requires covered developers to publicly disclose their safety and security frameworks and to report critical safety incidents to regulators. The incident reporting obligation is specifically framed around harms at scale: models that could facilitate large-scale cyberattacks or assist in the creation of biological, chemical, or nuclear weapons trigger mandatory disclosure. This is not a catch-all incident reporting regime. It targets the upper tail of catastrophic risk scenarios that have been central to frontier AI safety debates since at least 2023. Developers must also establish internal compliance programmes with defined accountability structures.

The Act includes whistleblower protections for employees who raise internal AI safety concerns. These provisions establish confidential reporting channels and legal safeguards against retaliation, addressing a documented gap in existing employment law as it applies to AI development environments. Notably, the bill passed with broad bipartisan support and received backing from major frontier AI laboratories including OpenAI and Anthropic. That industry support is unusual and signals a degree of maturity in the regulatory conversation: leading developers appear to have concluded that standardised, audited oversight is preferable to a fragmented and unpredictable patchwork of obligations across fifty different state regimes.

Illinois Governor signs landmark AI safety law requiring third-party audits of frontier models
Image source: Primary source

Australian context: US state AI regulation and its influence on Australian procurement and risk frameworks

Australia does not yet have legislation equivalent to the Illinois AI Safety Measures Act. The federal government’s primary AI governance instrument remains the voluntary AI Ethics Framework published by the Department of Industry, Science and Resources, which establishes eight principles but carries no mandatory audit requirement and no regulatory enforcement mechanism. The Australian Government released its interim response to the Safe and Responsible AI consultation in January 2024 and has signalled intent to introduce mandatory guardrails for high-risk AI applications, but as of mid-2026 binding legislation has not been enacted. Australian organisations therefore operate in a voluntary environment domestically, even as their US-based AI vendors become subject to mandatory audit obligations in multiple American states.

References and related sources

How iEnvi can help

iEnvi integrates technology and data-driven approaches into environmental consulting. We monitor AI and technology developments that affect how environmental professionals deliver services to clients.


This is an iEnvi Machete news summary. Prepared by iEnvi to summarise the source article for environmental professionals tracking AI, data, and technology developments that affect consulting and project delivery.

Published: 08 Jul 2026

Need advice on this topic? Speak to an iEnvi expert at info@ienvi.com.au or 1300 043 684, or contact us online.

Need advice on this issue? iEnvi provides practical, senior-led environmental consulting across contaminated land, remediation, ecology and environmental risk.

Contaminated land advice Remediation services Discuss your site Talk to iEnvi