22 July 20266 minute read

The Artificial Intelligence Safety Measures Act: Illinois becomes the first state to require third-party audits of AI models

On July 6, 2026, Illinois Governor JB Pritzker signed SB 0315, the Artificial Intelligence Safety Measures Act (AISMA), making Illinois the third state to require frontier model developer transparency and the first state to require third-party audits of artificial intelligence (AI) models.

Like California’s Transparency in Frontier Artificial Intelligence Act (TFAIA) and New York’s Responsible AI Safety and Education Act (RAISE) Act, AISMA focuses on AI safety and imposes transparency obligations on large developers of frontier AI models. The scope and substance of the three laws are very similar, with the prominent exception of AISMA’s audit provisions.

Among other common provisions, covered developers must implement, comply with, and publish frontier AI frameworks, which consist of documented protocols to manage any “catastrophic risks” of their frontier models. Such developers must also publish transparency reports and submit two kinds of reports to state officials: assessments of catastrophic risks and reports of critical safety incidents.

As suggested in our earlier client alert comparing TFAIA and the RAISE Act, these state laws signal an emerging de facto national standard for developer transparency regarding the most advanced AI models.

Third-party audits

Beginning January 1, 2028, a large frontier developer must retain, on an annual basis, “a third party to perform an independent audit of compliance” with the section of the law relating to frontier AI frameworks.

The auditor must produce a report that:

  • Describes the developer’s compliance (or lack thereof) with that section

  • Provides “recommendations for how the developer can improve its policies and processes for ensuring compliance”

  • Assesses in detail the developer’s “internal controls, including its designation and empowerment of senior personnel responsible for such implementation”

The Act does not otherwise define “internal controls,” and “such implementation” appears to be a reference to implementation of the developer’s frontier AI framework. 

After making any permissible redactions, the developer must send the redacted version of the report to the Illinois Attorney General and the state’s Emergency Management Agency – Office of Homeland Security (Agency). The developer must also “conspicuously publish” a summary of the audit findings and a redacted copy of the report on its website.

The law permits frontier developers to exercise discretion in making redactions as “necessary to protect [their] trade secrets, [their] cybersecurity, public safety, or the national security of the United States or to comply with any federal or State law.” The published version of the redacted report must describe the character and justification of the redaction “to the extent permitted by the concerns that justify redaction.”

The law does not contain any provision by which the Agency – or any other state body – has an explicit right to access unredacted copies of the reports. Nonetheless, developers must retain each unredacted audit report for as long as they deploy a frontier model, plus an additional five years.

Other provisions ensure that the auditor maintains independence, has appropriate experience, gains access to all necessary materials, and abides by the developer’s security protocols and confidentiality requirements.

While AISMA is the only AI law in the US with a third-party audit requirement, independent audits are under consideration elsewhere. As detailed in a recent client alert, a bipartisan duo of federal legislators released a discussion draft of the “Great American AI Act,” which would require the federal government to license and oversee independent verification organizations (IVOs) that large frontier model developers would retain to perform audits. Further, a recently enacted Virginia law, SB 384, directs state officials to evaluate the feasibility and impact of an IVO framework.

Other differences

In developing AISMA, Illinois legislators made choices between the few differences that separate TFAIA and the RAISE Act, generally opting for the more robust version of any given provision. A significant example is the inclusion of the whistleblower protections of TFAIA, which are not present in the RAISE Act. Another example is the civil penalty provision. All three laws provide for penalties of up to $1 million for initial violations, but AISMA adopts the RAISE Act’s approach of allowing penalties of up to $3 million for repeat violations, whereas TFAIA does not include a similar enhancement.

The three laws also differ in how they describe the scope of their territorial jurisdiction. Like TFAIA, AISMA does not specify any threshold for developer activity in the state, whereas the RAISE Act states that its provisions apply “to frontier models that are developed, deployed, or operating in whole or in part in New York state.” AISMA does contain a prerequisite for covered developers to operate in Illinois, providing that they may not “develop, deploy, or operate a frontier model, in whole or in part in this State, without having a current disclosure statement filed with the Agency and paying the required fee.”

As for effective dates, AISMA and the RAISE Act both take effect on January 1, 2027, though, as noted above, AISMA’s audit provisions do not take effect until January 1, 2028. TFAIA went into effect on January 1, 2026.

Takeaways

For AI models and other products that are not geographically confined, state transparency requirements can have national effects, because the resulting disclosures are publicly available. The US now has three large states with very similar transparency laws governing frontier AI models, arguably reflecting an emerging de facto national standard in the absence of a federal statute. These laws reflect a legislative focus on transparency and reporting rather than substantive restrictions on model development and deployment.

AISMA is most notable for its addition of third-party audits, a topic that has long been under debate by legislators, researchers, and advocates. The impact of these audits remains to be seen, including whether and to what extent the public versions of the audit reports will have downstream impacts on vendors and customers that offer AI tools built with the models in question. 

Developers of AI models that may be covered under AISMA, the RAISE Act, or the now-in-effect TFAIA are encouraged to take immediate steps to determine their specific compliance obligations.

Find out more

DLA Piper’s team of AI lawyers, data scientists, and policy professionals helps organizations navigate the complex workings of their AI systems and comply with current and developing regulatory requirements. Our team continuously monitors global developments in AI and related business impacts across industries.

For more information on AI and emerging legal and regulatory standards, visit DLA Piper’s focus page on AI.

Gain insights and perspectives to help shape your AI strategy through our AI ChatRoom series.

For more information, please contact the authors.

*The authors thank Abraham Cumming, a Raja Gaddipati Fellow at DLA Piper, for his contributions to this client alert.