Illinois Governor Pritzker Signs a Landmark AI Law, Deepening the State-by-State Patchwork
Illinois has become the third — and in some respects the most demanding — state to impose safety rules on the most powerful artificial intelligence systems, a move Gov. JB Pritzker framed as a rebuke to Washington's failure to act.
Pritzker on July 6 signed Senate Bill 315, the Artificial Intelligence Safety Measures Act, at a Chicago ceremony flanked by lawmakers, advocates and industry representatives. The law borrows heavily from bills California and New York enacted in late 2025, and together the three states are attempting to build a de facto national rulebook for frontier AI in the absence of federal legislation.
"Congress and the president ought to be passing similar legislation, but they've so far been unwilling, because many are captive to special interests that profit from the industry having no regulation," Pritzker said before signing. "We can work together to establish thoughtful guardrails in ways that benefit both industry and the public, or we can allow a handful of actors to evade accountability and push the costs and detriment onto ordinary people. Illinois has chosen our path."
What the Law Requires
SB 315 targets only the largest developers — those whose AI models generate more than $500 million in annual revenue and are trained using massive computing power. It does not touch startups or the vast majority of businesses deploying AI tools.
Covered developers must publish a framework describing how they identify and assess "catastrophic risk," defined in the statute as incidents that could cause death or serious injury to more than 50 people, or more than $1 million in property damage. The law is aimed squarely at worst-case scenarios: models that could help a user build a chemical, biological or nuclear weapon, or mount a large-scale cyberattack.
Developers will also have to report qualifying safety incidents to the state within 72 hours of identifying them — or within 24 hours when an incident poses an imminent risk of death or serious physical injury.
The provision that sets Illinois apart is a first-in-the-nation requirement for mandatory annual third-party audits. New York's Responsible AI Safety and Education Act required only a single independent audit once a developer grew large enough to qualify; Illinois makes the outside review recurring. The law also creates confidential reporting channels and whistleblower protections for employees who raise safety concerns.
Enforcement runs through the state attorney general, who can seek civil penalties of up to $1 million for a first violation and up to $3 million for subsequent ones. The law takes effect Jan. 1, 2028.
A Coalition of Willing Regulators
The bill drew unusually broad support. It passed the Illinois House unanimously, and only five Republican senators voted against it. Both OpenAI and Anthropic backed the measure as it moved through the General Assembly, and Anthropic had representatives at the signing.
Senate sponsor Sen. Mary Edly-Allen, D-Libertyville, cast the law as an act of impatience with federal inaction. "We are not willing to wait for Congress to act," she said, before adding a wry twist on a familiar proverb: "Teach AI to fish, though, and it might just empty the whole river trying to figure out how."
House sponsor Rep. Daniel Didech, D-Buffalo Grove, argued the risks are already concrete, pointing to what he described as the first AI-inspired mass shooting and an AI-assisted attack on a municipal water and drainage utility. He also cited Anthropic's Mythos model, which the company said was too powerful a cyberweapon to release publicly. "Every transformative technology in our history, from automobiles to electricity to air travel, has delivered enormous benefits while carrying real risks," Didech said, "and in every case the government responded not by banning the technology and not by taking a hands-off approach, but by building safeguards."
Not everyone was won over. TechNet, a coalition of technology executives, objected to the audit mandate during committee debate. "We remain concerned that Illinois would effectively be requiring private actors to make highly subjective determinations requiring AI safety compliance without established national standards, certifications, or clear regulatory guardrails," TechNet's Ninia Linero told lawmakers in May.
The Patchwork Versus Preemption Fight
Illinois, California and New York account for only about 20% of the U.S. population but roughly 40% of the domestic AI market, according to lawmakers' estimates — enough weight, supporters argue, to set a national floor by default. OpenAI's Caitlin Niedermeyer told a state Senate committee the company could live with that arrangement, saying the three states could "really lead in advancing aligned frameworks, which we believe can absolutely help create a de facto national direction of travel."
That state-led momentum is colliding with a federal countereffort. In June, Reps. Jay Obernolte and Lori Trahan circulated a discussion draft of the Great American AI Act, which would create a federal frontier-AI framework and — most consequentially — preempt state laws regulating how AI models are developed for three years. The draft is not law, but it sets up a direct clash with the very statutes Illinois just joined.
For companies, the practical upshot is mounting complexity. A developer large enough to trigger SB 315 must now reconcile Illinois, California and New York regimes that overlap but differ in the details, all while a federal preemption bill hangs over the whole edifice.
What to Watch
Lawmakers signaled they see SB 315 as a starting point, with Didech naming medical care and education as likely next frontiers. Scott Wisor of Secure AI, who helped shape the bill, said the current audit standard only checks whether a developer follows its own safety framework, not whether that framework is adequate. "This is a huge step forward, but I think there's more we can do," he said.
The broader test arrives soon. On Aug. 2, the European Union's enforcement toolkit for general-purpose AI models and its Article 50 transparency duties become active, giving regulators there information-request and model-access powers. Between Brussels' hard deadline, three states' overlapping rules and a federal preemption bill in play, the question of who ultimately writes the rules for frontier AI is nowhere near settled.
"We can work together to establish thoughtful guardrails in ways that benefit both industry and the public, or we can allow a handful of actors to evade accountability and push the costs onto ordinary people. Illinois has chosen our path."- JB Pritzker, Governor of Illinois