惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
Tailwind CSS Blog
博客园 - 聂微东
S
Schneier on Security
The Last Watchdog
The Last Watchdog
N
News and Events Feed by Topic
N
News | PayPal Newsroom
Webroot Blog
Webroot Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Schneier on Security
Schneier on Security
PCI Perspectives
PCI Perspectives
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Visual Studio Blog
Blog — PlanetScale
Blog — PlanetScale
Spread Privacy
Spread Privacy
Cisco Talos Blog
Cisco Talos Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
Help Net Security
Help Net Security
P
Proofpoint News Feed
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
博客园 - Franky
N
Netflix TechBlog - Medium
Know Your Adversary
Know Your Adversary
L
Lohrmann on Cybersecurity
F
Fortinet All Blogs
WordPress大学
WordPress大学
U
Unit 42
Hacker News: Ask HN
Hacker News: Ask HN
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
A
Arctic Wolf
酷 壳 – CoolShell
酷 壳 – CoolShell
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Security Affairs
H
Hacker News: Front Page
TaoSecurity Blog
TaoSecurity Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
B
Blog RSS Feed
罗磊的独立博客
Cloudbric
Cloudbric
Y
Y Combinator Blog
B
Blog
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
L
LINUX DO - 最新话题
The Register - Security
The Register - Security
D
DataBreaches.Net
GbyAI
GbyAI

Privacy & Cybersecurity Law Blog

Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure U.S. Supreme Court FTC Ruling Prompts Fresh Scrutiny of EU-U.S. Data Privacy Framework China Issues New Measures for Network Data Security Risk Assessment China Issues Regulations on Internet Content Multi-Channel Network Distribution Services China’s First Regulatory Framework for Virtual Companions Soon to Take Effect UK Data Protection Complaints Obligations Take Effect Vermont Enacts Significant Amendments to Data Broker Legislation Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law Louisiana Enacts Comprehensive Consumer Privacy Law Connecticut Signs Comprehensive AI Bill into Law China CAC Issues Guidance on Conducting Audits Technology Companies Should Prepare for FTC Enforcement of Take It Down Act HHS Reorganizes Office for Civil Rights Oregon Prohibition on Public Body Disclosures to Data Brokers for Federal Immigration Purposes Now In Effect Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations NYDFS Warns of Cybersecurity Risks from Frontier AI Models UK and Australia Announce Memorandum of Understanding on AI Security FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems Colorado AI Act Amended and Effective Date Delayed European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act Texas AG Announces Lawsuit Against Netflix for Alleged Misrepresentations Regarding User Data UK ICO Recommends Targeted Changes to PECR Rules for Online Advertising California AG Announces Record $12.75M Settlement with GM over CCPA Data Minimization and Purpose Limitation Violations Illinois Department of Human Rights Issues Regulations Governing the Use of AI in Employment Decisions Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response Maryland Enacts First-of-its-Kind Ban on Surveillance Pricing for Grocery Sales UK ICO Publishes Guidance on Storage and Access Technologies CIPL Report Discusses Significant Alignment between GDPR and Global CBPR CalPrivacy Announces the Agenda for its April 30–May 1 Board Meeting CalPrivacy Requests Preliminary Comments on Notices & Disclosures, Employee Data COPPA Rule Amendment Compliance Deadline Approaches House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act” Kentucky Classifies Smart TV Data as Sensitive Alabama Becomes 21st State With Comprehensive Consumer Privacy Law CalPrivacy Director Expects CCPA Compliance Audits in 2026 Virginia Bans Sale of Geolocation Data HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data Washington State Enacts Law Regulating AI Companion Chatbots with Private Right of Action Guardrails for Legal AI: What California’s SB 574 Would Require of Attorneys and Arbitrators
Illinois Governor Signs Frontier AI Model Law
2026-07-17 · via Privacy & Cybersecurity Law Blog

On July 6, 2026, Illinois Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act (the “Act”), into law, making Illinois the third state, after California and New York, to enact comprehensive safety and transparency requirements for developers of the largest AI systems. The  Act positions Illinois as an aggressive player in the fast-growing patchwork of state-level AI regulation, and notably goes further than similar statutes in one key respect: it is the first in the nation to mandate annual independent third-party audits of covered developers' safety practices.

The Act, certain provisions of which start to become effective on January 1, 2027, passed the General Assembly with bipartisan support and drew backing from both AI safety advocates and industry players.

Who Is Covered

The Act applies to "frontier developers," defined as companies that train AI models using more than 10^26 integer or floating-point operations of computing power, with the most substantial obligations reserved for "large frontier developers," defined as frontier developers (together with affiliates) with more than $500 million in annual gross revenue in the preceding calendar year.

Key Obligations

Frontier AI Framework: Beginning January 1, 2028, large frontier developers must publish and maintain a "frontier AI framework" describing how:

  • The large frontier developer incorporates relevant national and international best standards and industry practices into its frontier AI framework;
  • It defines and evaluates thresholds, including any tiered thresholds, for determining whether a frontier model could pose catastrophic risk;
  • It applies mitigations based on those assessments;
  • It reviews both the assessments and the adequacy of mitigations when deciding whether to deploy a model or use it extensively internally;
  • It uses independent third parties to evaluate catastrophic risks and the effectiveness of mitigations;
  • It revisits and updates the framework over time, including what triggers updates and how it determines when a frontier model has been substantially modified enough to require renewed review;
  • It implements cybersecurity practices to protect unreleased model weights from unauthorized modification or transfer by internal or external parties;
  • It identifies and responds to critical safety incidents;
  • It institutes internal governance practices to ensure implementation of these processes;
  • It assesses and manages catastrophic risk arising from internal use of its frontier models, including risks that a model could circumvent oversight mechanisms.

Frameworks must be reviewed at least annually, with material updates published within 30 days.

Transparency Reports: Before, or concurrently with, deploying a new or substantially modified frontier model, developers must publish a transparency report covering, among other requirements, intended uses, supported languages and modalities, and points of contact. Large frontier developers must also summarize their catastrophic-risk assessments and the extent of third-party involvement in those assessments.

Independent Audits: Starting in 2028, large frontier developers must retain independent third parties to annually audit compliance. Audit reports, summarized and appropriately redacted, must be published and shared with the Illinois Emergency Management Agency and Office of Homeland Security (the “Agency”) and the Illinois Attorney General.

Critical Safety Incident Reporting: Developers must report "critical safety incidents," including harm resulting from the materialization of a catastrophic risk or if, outside a controlled test, the frontier model uses deception against its developer to evade oversight or controls in a way that shows a materially higher risk of catastrophic harm. Reports must be made to the Agency and Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that such an incident occurred, or within 24 hours if the incident poses an imminent risk of death or serious injury.

Whistleblower and Internal Reporting Protections: The Act bars developers from contractually or otherwise preventing, or retaliating against, “covered employees” that report safety concerns or violations of the Act to regulators, and requires large frontier developers to maintain an anonymous internal reporting channel with monthly status updates to the reporting employee.

Disclosure and Registration: Beginning January 1, 2027, large frontier developers must file an annual disclosure statement with the Agency. Disclosures must cover corporate identity, ownership, and points of contact, and developers must pay associated fees before developing, deploying or operating a frontier model in Illinois.

Internal Use Risk Reporting: A large frontier developer must provide the Agency with a summary of any assessment of catastrophic risk arising from internal use of its frontier models every three months (or on another reasonable schedule the developer submits in writing to the Agency and the Attorney General and the Agency accepts), with written updates as appropriate.

False or Misleading Statements: A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or about its management of catastrophic risk. A large frontier developer also may not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.

Enforcement: The Attorney General has exclusive authority to bring civil enforcement actions. Violations, including false or misleading statements about catastrophic risk, failure to conduct required audits or failure to report critical safety incidents carry civil penalties of up to $1 million for a first violation and up to $3 million for subsequent violations. The Act does not create a private right of action.

Implications for AI Developers: Companies developing frontier-scale models should begin evaluating whether they meet the Act’s revenue and compute thresholds in advance of the Act’s effective date. Given the law's alignment with, and expansion upon, similar frameworks in California and New York, multistate developers may find it efficient to build compliance programs designed around the strictest common denominator across all three regimes, particularly the audit and incident-reporting timelines.