Illinois just passed the toughest AI safety law in the United States, and it did so with near-unanimous votes: 110 to 0 in the House, 52 to 5 in the Senate. Governor JB Pritzker has said publicly he intends to sign it. Once he does, the world's biggest AI companies will face a legal obligation they have never faced before: letting an outside auditor check whether their safety promises are real.
The law, SB 315, does three things. First, it requires large AI companies to publish safety plans and update them every year. Second, it mandates that those plans be verified annually by an independent third-party auditor, not by the company itself. Third, it forces companies to report serious safety incidents within 72 hours, or within 24 hours if there is an immediate risk of death or physical harm. Employees who raise safety concerns are protected under the state's existing whistleblower laws.
The law is targeted deliberately narrow. It applies only to companies with more than $500 million in annual revenue that are building the most powerful AI systems. That captures roughly five companies today: OpenAI, Anthropic, Google, Meta, and Elon Musk's xAI. Every other AI developer, including most startups, is unaffected.
The auditors themselves are expected to come from well-known sources. Experts following the bill expect major accounting firms like Deloitte, EY, KPMG, and PwC to be in the running, alongside a coalition of specialist research organizations already doing AI safety evaluations. For now, no formal auditing standards for AI safety exist yet, which is an honest limitation critics have raised.
Two of the companies being regulated, OpenAI and Anthropic, both publicly supported the bill. The logic they offered is strategic, not just altruistic: they would rather have one clear set of rules than face a different set of requirements in every state. A trade group representing Google, Apple, Amazon, and Andreessen Horowitz opposed it, arguing it exposes companies to auditors without established standards.
The federal backdrop matters here. Congress has not passed any meaningful AI legislation. The Trump administration has been actively working to stop state-level AI laws, including setting up a Justice Department task force specifically to challenge them in court. Just days before this bill passed, Trump canceled the signing of a federal executive order that would have set up voluntary AI safety testing, saying he did not want anything that could slow American AI development.
The practical result is that states are filling a regulatory space the federal government has left empty, and Illinois has now set the highest bar of any of them.
There is a precedent for how this plays out. When California passed its data privacy law in 2018, many companies simply applied its standards everywhere rather than manage separate compliance systems for one state. The same logic applies here. A company like OpenAI will not build a special audit process for Illinois residents and ignore it elsewhere. It will audit everything. That means Illinois's rules could effectively become the floor for how the most powerful AI systems are monitored across the entire country, regardless of what Congress eventually does or does not do.
For businesses that use AI tools from these major providers, SB 315 does not directly change anything you are required to do. It sits squarely on the AI companies themselves. But it does mean the tools you buy from those companies will, starting in 2027 when the law takes effect, come with a layer of independent verification behind them. For sectors where trust in AI outputs matters, such as insurance, legal services, healthcare operations, or finance, that is not a trivial change. The safety claims vendors make will have to hold up to external scrutiny.