On July 6, OpenAI backed the Artificial Intelligence Safety Measures Act as Governor JB Pritzker signed it into Illinois law. That same OpenAI had spent the preceding months shepherding a companion bill through Springfield — one that would have shielded AI companies from liability lawsuits over mass-casualty events. That second bill stalled. Illinois got annual mandatory AI audits. The industry left without the immunity it came for.
Senate Bill 315 is the first state law in the country to require annual independent third-party safety audits of frontier AI models. It passed with overwhelming bipartisan support — five Republican senators voted against it; the House vote was unanimous. Pritzker framed it as a statement about federal inadequacy: “As AI systems become more powerful and the federal government is unwilling to step in, states have a responsibility to protect our people from the dangers of AI.” What the governor’s statement doesn’t mention, and what most coverage omitted, is the specific political economy that produced this outcome — and what it means for a field that thought it could trade accountability for protection.
What the Law Actually Requires
SB 315 draws two definitions that determine who it governs. A frontier model is any system trained on more than 1026 floating-point operations — a threshold higher than the EU AI Act’s 1025 FLOPs. A large frontier developer is any company that clears both that compute bar and more than $500 million in annual revenue. At current numbers, that list is short: OpenAI, Anthropic, Google DeepMind, and perhaps two or three others depending on how revenue is attributed to specific model families.
The obligations on those companies are substantial. Before deploying a new model or any substantial modification of an existing one, they must publish a transparency framework addressing how the product could pose a “catastrophic risk” — defined as events capable of killing or seriously injuring more than 50 people, or causing more than $1 million in property damage, or causing more than $1 billion in damages through a cyberattack or malfunction. They must also disclose their incident response procedures, maintain internal compliance programs, and protect employees who raise safety concerns through confidential channels and whistleblower protections.

The audit clause is what makes Illinois different. California and New York have both passed frontier model transparency frameworks. New York requires a single independent audit once a developer grows large enough to qualify. California requires no comparable audit at all. Illinois requires annual audits, indefinitely, by independent third parties who must demonstrate frontier AI expertise and have no financial conflicts of interest. The results must be published. Civil penalties for noncompliance run to $1 million for first violations, $3 million for each subsequent offense, enforced by the state attorney general’s office. The audit mandate and safety frameworks take effect January 1, 2028. Notably, the law covers internal use of frontier models — not just what a company deploys publicly, but how it uses these systems within its own operations. An audit that only examines the product and not the development process has an obvious gap; SB 315 attempts to close it.
Incident reporting is immediate: companies have 72 hours to report a critical safety incident once they have reasonable grounds to believe one occurred. If the incident poses an imminent risk of death or serious physical injury, the deadline drops to 24 hours. Both clocks start not from the incident itself but from the point of internal awareness — a distinction that matters considerably for how companies structure their safety reporting chains.
The Package Deal That Came Apart
That OpenAI and Anthropic both endorsed the audit law is true and, stripped of context, reads as a sign that the industry has matured past reflexive opposition to oversight. The context is that the labs were already complying with California and New York frameworks — SB 315 adds audit obligations but doesn’t introduce a compliance regime from scratch. The marginal cost of adding Illinois to an existing CA-NY compliance infrastructure is real but bounded. Companies with $500 million or more in annual revenue can absorb it.
What they cannot absorb so easily is liability exposure as capabilities grow. OpenAI faces multiple ongoing lawsuits. Its most capable models now periodically trigger government risk designations. The gap between what frontier AI can do and what tort law holds companies responsible for is narrowing, and from OpenAI’s perspective, narrowing in the wrong direction. The liability shield bill it backed in Springfield would have protected AI companies from civil lawsuits over catastrophic-harm events — mass casualties, financial system failures, the categories that keep safety researchers awake at night. Compliance with an approved audit regime would, presumably, have provided the legal foundation for that protection. The audits buy safety credibility; the safety credibility limits lawsuit exposure. That was the deal.

It is a coherent deal. The EU’s GDPR created a similar implicit structure in data protection: companies that demonstrably comply with the regulation’s technical requirements are better positioned in litigation. The difference in Springfield was Anthropic.
Anthropic publicly broke with OpenAI on the liability bill, and the opposition was substantive rather than tactical. The company has spent years building its public identity around constitutional AI and responsible scaling — positioning that attracts safety-conscious enterprise customers, alignment researchers, and employees for whom the mission is not purely commercial. Backing broad liability protections for AI companies would have contradicted that positioning in ways that were difficult to recover from. The company stated the law “helps establish a baseline that every leading AI developer is expected to meet” — a quote about the audit law, not the liability bill, and a reminder that Anthropic’s preferred regulatory frame is baseline obligations for everyone, not liability ceilings for the well-funded.
The liability bill stalled. Whether that outcome reflects principled disagreement about accountability, or Anthropic’s recognition that imposing audit burdens on competitors without immunizing them from lawsuits is good competitive strategy, or both simultaneously, is something the company’s statements cannot resolve. The outcome is the same: the AI industry got mandatory accountability and no immunity to go with it.
The 40% Standard
Illinois did not act in isolation. Connecticut enacted two AI bills in the same legislative window — one regulating data brokers and geolocation tracking, another establishing a broad AI framework with a regulatory sandbox for testing new approaches to automated decision-making. New York included its Safe By Design Act in its 2027 budget. The coordination is not formal, but the timing is not coincidental. These states are building a regional framework by convergence rather than treaty.
Illinois, California, and New York together account for roughly 40% of the US AI market, according to estimates from lawmakers who pushed the bills. A company that wants to operate legally in those three states now faces a coherent, overlapping set of frontier model obligations — transparency frameworks, incident reporting, and, in Illinois, annual independent audits. The compute threshold across all three laws uses the same definition: 1026 FLOPs. That alignment is not accidental. The Transparency Coalition’s Steve Wimmer said plainly after the signing that Illinois had “created a new template for responsible AI governance that we expect other states, and eventually Congress, to follow.” What Wimmer described as an expectation is, for the labs, already a compliance reality.
Congress has produced no equivalent. The federal government’s approach to frontier AI risk has been a mixture of voluntary commitments, executive orders with uncertain longevity, and the high-risk model designation process that has operated primarily through phone calls rather than written legal frameworks. Pritzker’s statement about federal unwillingness to act is not a political taunt — it is an accurate description of the legislative environment in which the states are operating. The 40% standard exists because the 100% standard hasn’t materialized.
TechNet, which lobbied against SB 315, argued that the law would ask companies to make “highly subjective safety calls without clear national standards.” That objection is accurate and also somewhat beside the point. The auditors who assess AI safety practices will work from varying professional standards because those standards don’t yet exist at the federal level. Companies will face audit-to-audit variation in what counts as adequate risk mitigation. The definition of a critical safety incident depends on 72-hour clocks that start from internal awareness, which means the companies most motivated to miss the clock are the ones with the most to lose from incident disclosure. These are real structural weaknesses in the law.
They are also exactly what happens when states build oversight infrastructure that federal regulators declined to build. SB 315 is imperfect the way all first drafts are imperfect. The enforcement mechanism is an attorney general with limited AI expertise and $1 million per-violation authority against companies that generate $500 million or more annually. The audit process doesn’t specify what qualified frontier AI expertise looks like, which means the first two years of implementation will be lawyers and auditors improvising in a field that the law created but didn’t define. None of this stops the law from being real. It is in effect. The clocks are running.
The AI labs came to Springfield expecting that endorsing accountability would buy them protection from what accountability is supposed to prevent. Anthropic’s refusal to complete that trade has left the industry with mandatory audits and no immunity. The audits start January 1, 2028. The lawsuits don’t wait for a start date.

AI-generated editorial illustration · TemperatureZero · July 12, 2026
Keep reading the signal
Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.
Subscribe FreeContinue the archive