Insights / Commercial

Illinois Didn't Just Add an AI Law. It Changed Who Gets to Grade the Homework.

← All insights

Every other state AI law runs on the honor system: a company writes its own safety framework and tells regulators to take its word.

Illinois' Artificial Intelligence Safety Measures Act (SB 315), signed July 6, breaks that pattern. Large frontier developers must publish a safety framework and hire an independent, conflict-free third party to audit it annually, with results going to the state and the Attorney General.

Why this shift matters

Self-attestation and independent audit look similar on paper. They produce opposite incentives. Under disclosure, the company grading its own framework has no cost for optimistic language. An audit moves the liability: a named auditor certifies the result under their own professional standing. That's the SOX playbook, run on catastrophic-risk claims instead of earnings.

One wrinkle shows real audit sophistication: SB 315 requires the auditor to both certify compliance and recommend improvements. That's the same independence conflict that ended Arthur Andersen and split audit from consulting after Enron. The statute hasn't resolved it. Neither has the auditor market, yet.

What the audit actually requires

  1. Independence — no financial interest between auditor and developer.
  2. Competence — demonstrated frontier-model safety expertise, not general IT audit credentials.
  3. Standard — "generally accepted auditing standards," which don't yet formally exist for this domain; expect early reliance on NIST AI RMF and ISO 42001.
  4. Access — auditors see unredacted documentation, not just the published framework.
  5. Disclosure — a redacted summary goes public in 30 days; the full report goes to regulators, trade secrets or not.

What to do about it, by tier

Near or above $500M and training frontier-scale models: the 18 months to January 2028 is short given how thin the qualified-auditor pool is. Scope your exposure, formalize catastrophic-risk assessment in writing, build the 72-hour incident playbook, and start auditor conversations before the market gets crowded.

Everyone else — most companies buying AI rather than building it — your compliance move is with your vendors, not Illinois:

  • Ask vendors whether their compliance claim is self-reported or audited, in writing.
  • Add audit-report access language to contracts and DPAs now.
  • Build internal AI governance that survives outside review, even without a legal mandate yet.

Watch for who copies the auditor requirement. That's what turns AI governance into an assurance function.

States that follow Illinois won't copy the penalty figures. The companies treating that distinction as semantic now are the ones explaining it to a regulator later.

Next Step

Start with a working session.

Thirty minutes with the principal. Bring one AI deployment — in use or planned — and leave knowing whether its record would survive review.

Book a Call