Skip to Main Content Subscribe

Illinois AI Law Could Test Emerging Federal Approach to Frontier AI

Share

Illinois’ frontier AI audit requirements arrive as the Trump administration takes a more active approach to advanced AI risks.

4m read
Written by:
Illinois Capitol
The Illinois State Capitol building. Photo Credit: Grindstone Media Group/Shutterstock

Illinois’ new frontier-AI safety law is becoming a test case for how state experimentation with AI regulation will inform an evolving federal approach to frontier AI.

The Artificial Intelligence Safety Measures Act (AISMA), which takes effect Jan. 1, requires large frontier AI developers to undergo independent third-party audits designed to assess their compliance with new safety, transparency and risk-management requirements.

It’s a similar stance in a White House June executive order that directs agencies to develop a framework for AI developers to collaborate with the government on cybersecurity evaluations before releasing new models, albeit on a voluntary basis.

Congress has yet to establish a comprehensive national framework governing AI, so AI oversight is being handled individually by states. The administration’s March legislative framework for AI outlined recommendations for Congress to create one balancing innovation, national security and consumer protection.

The Illinois law is among the nation’s strongest AI laws that makes this a requirement. Specifically, AI developers must “identify, disclose and mitigate risks.”

That strength initially seemed to conflict with White House AI directives seeking to eliminate unnecessary regulatory burdens on developers, but a recent change in the Trump administration’s stance on AI regulation indicates a potential merging of federal and state views.

“Beginning in 2026, … we’ve seen a shift in how the administration is thinking about regulating AI. It seems much more open to taking some kind of action to regulate frontier AI,” Aalok Mehta, director of the Wadhwani AI Center at the Center for Strategic and International Studies, told GovCIO Media & Research.

Such an alignment of viewpoints seemed unthinkable in 2025, Mehta said. He added that at the time the administration was considering some type of licensing process for frontier AI models with the goal of streamlining how frontier AI developers could build and deploy their models. However, the introduction of powerful new AI models and recent incidents of some of those models escaping confinement and operating autonomously raised concerns in government and from the public, he said.

A First-of-Its-Kind Law

Signed by Illinois Gov. JB Pritzker on July 6, AISMA is the first law in the U.S. requiring third-party audits for AI developers. Companies must also publicly disclose their safety practices, report safety incidents and maintain robust compliance efforts. Employees raising AI safety concerns are also covered under the law through confidential reporting channels and whistleblower protections.

Third-party independent audits are a key feature of the law. It requires regular safety audits of covered AI systems by independent third parties. Gov. Pritzker’s office said the goal is to ensure “oversight is conducted by qualified experts without financial conflicts of interest.”

“As AI systems become more powerful and the federal government is unwilling to step in, states have a responsibility to protect our people from the dangers of AI while still harnessing the unique potential of the technology,” Pritzker said in a statement.

Building on Other State AI Laws

AISMA builds on laws passed by California and New York regulating “large frontier developers” — companies training AI models using massive computing power and with annual gross revenues of $500 million or more.

“Those companies should start thinking about developing the written AI framework required under the law and making sure it is operational, ensuring that they have the required incident escalation process internally and establish internal channels for whistleblowers, among other requirements,” said Maneesha Mithal, a partner at Wilson Sonsini Goodrich & Rosati and former associate director of the Federal Trade Commission’s Division of Privacy and Identity Protection.

All three laws require frontier developers to adopt and comply with a publicly available framework. This document describes how they identify, assess and mitigate “catastrophic risks” from their AI models. These frameworks must be reviewed and updated at least annually.

The laws also require AI developers to publish transparency reports before or when they deploy a new or upgraded frontier model.

Like the New York legislation, AISMA requires any critical safety incidents to be reported to the Illinois Emergency Management Agency and Office of Homeland Security and state attorney general within 72 hours. Additionally, developers have 24 hours to disclose any incidents posing a risk of imminent death or serious injury to an appropriate authority.

Third-Party Audits

Third-party audits are AISMA’s keystone, requiring large frontier AI developers to have independent third parties perform annual audits of their AI products. This requirement begins on Jan. 1, 2028. Once enacted, companies meeting the qualification as large frontier developers will have 90 days to comply with the law.

Developers must provide auditors access to all materials needed to complete the audit. The resulting report details whether the developer complies with the law, highlights any material deviations, recommends improvements and assesses the developer’s internal controls.

Frontier developers must keep the unredacted audit report for as long as their AI model is deployed plus five years. Within 30 days of receiving the report, developers must publish a high-level summary and redacted copy of the report on their website and transmit the redacted report to IEMA-OHS and the state attorney general.

Potential Federal Challenges

President Trump’s executive order Promoting Advanced Artificial Intelligence Innovation and Security directs the departments of War, Treasury, Homeland Security, the National Security Agency, Cybersecurity and Infrastructure Security Agency and the Office of the Attorney General to have a more active role in assessing AI-related risks.

Mithal noted that the executive order “is consistent with the administration’s preference for voluntary engagement with the private sector.” This includes the administration’s policy to promote AI and manage related risks without imposing “overly burdensome regulation.”

While the California and New York laws have not had any legal challenges to date, the Illinois law is potentially more exposed because of the third-party audit requirement, said Mithal.

“I think Illinois legislators would say that the law does not contradict White House directives because it promotes trust in AI and thus enhances the potential for adoption. At the same time, the administration would likely take the position that this kind of additional state-level compliance layer can impede AI innovation and create an undesirable regulatory patchwork. That makes the Illinois law a candidate for federal scrutiny, particularly with the annual third-party audit requirement,” Mithal said.

State Legislation Influencing Federal Bills

State experimentation with legal concepts often percolates up to the federal level. AI legislation in California and New York informed the Illinois law, Mehta explained. He noted AISMA’s requirement for independent verification organizations is now influencing new AI legislation in California.

This work is now being echoed at the federal level with the introduction of the Frontier Act, which would create a system of independent third-party auditors to review large frontier developers’ AI models and establish an Under Secretary of Commerce for AI Security for oversight.

“I think this shows a much more appropriate relationship between what happens with state policymaking and how it should intersect with federal policymaking,” Mehta said.

Related Content