SB 315 Audit Requirements: What Illinois's AI Safety Law Actually Certifies
Illinois's SB 315 mandates the first annual third-party AI safety audits in the U.S., effective 2028. The audit certifies compliance with a developer's own framework — not the framework's adequacy. Here's what that distinction means for compliance and legal teams.
Illinois SB 315 requires annual third-party audits of frontier AI developers starting 2028 — but the audit checks framework compliance, not safety adequacy. Here's what that distinction means before treating a passed audit as a safety signal.
What you need to know
- The change: Illinois becomes the first state to require annual independent third-party audits of frontier AI developers, building on 2025 disclosure laws in New York and California.
- Who is affected: "Large frontier developers" — companies with over $500 million in annual revenue that train models using more than 10^26 floating-point operations of compute.
- Why it matters: The audit mechanism has a specific, limited scope that differs from how "independent audit" is commonly understood in other regulated industries.
- What to do first: Compliance and legal teams should read the statute's actual definitions before treating any SB 315 compliance claim as an outcome-based safety signal.
- Key date or trigger: Two separate effective dates — January 1, 2027 for disclosure-statement filing; January 1, 2028 for the framework, transparency-report, and audit requirements.
Want the full decision layer?
Paid members receive deeper analysis, early-warning signals, and scenario breakdowns on how AI and policy shifts play out in practice.