惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
GbyAI
GbyAI
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
月光博客
月光博客
腾讯CDC
Recent Announcements
Recent Announcements
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
The GitHub Blog
The GitHub Blog
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Martin Fowler
Martin Fowler
A
About on SuperTechFans
博客园 - 叶小钗

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Illinois Governor Signs Frontier AI Model Law
2026-07-17 · via Privacy & Cybersecurity Law Blog

On July 6, 2026, Illinois Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act (the “Act”), into law, making Illinois the third state, after California and New York, to enact comprehensive safety and transparency requirements for developers of the largest AI systems. The  Act positions Illinois as an aggressive player in the fast-growing patchwork of state-level AI regulation, and notably goes further than similar statutes in one key respect: it is the first in the nation to mandate annual independent third-party audits of covered developers' safety practices.

The Act, certain provisions of which start to become effective on January 1, 2027, passed the General Assembly with bipartisan support and drew backing from both AI safety advocates and industry players.

Who Is Covered

The Act applies to "frontier developers," defined as companies that train AI models using more than 10^26 integer or floating-point operations of computing power, with the most substantial obligations reserved for "large frontier developers," defined as frontier developers (together with affiliates) with more than $500 million in annual gross revenue in the preceding calendar year.

Key Obligations

Frontier AI Framework: Beginning January 1, 2028, large frontier developers must publish and maintain a "frontier AI framework" describing how:

  • The large frontier developer incorporates relevant national and international best standards and industry practices into its frontier AI framework;
  • It defines and evaluates thresholds, including any tiered thresholds, for determining whether a frontier model could pose catastrophic risk;
  • It applies mitigations based on those assessments;
  • It reviews both the assessments and the adequacy of mitigations when deciding whether to deploy a model or use it extensively internally;
  • It uses independent third parties to evaluate catastrophic risks and the effectiveness of mitigations;
  • It revisits and updates the framework over time, including what triggers updates and how it determines when a frontier model has been substantially modified enough to require renewed review;
  • It implements cybersecurity practices to protect unreleased model weights from unauthorized modification or transfer by internal or external parties;
  • It identifies and responds to critical safety incidents;
  • It institutes internal governance practices to ensure implementation of these processes;
  • It assesses and manages catastrophic risk arising from internal use of its frontier models, including risks that a model could circumvent oversight mechanisms.

Frameworks must be reviewed at least annually, with material updates published within 30 days.

Transparency Reports: Before, or concurrently with, deploying a new or substantially modified frontier model, developers must publish a transparency report covering, among other requirements, intended uses, supported languages and modalities, and points of contact. Large frontier developers must also summarize their catastrophic-risk assessments and the extent of third-party involvement in those assessments.

Independent Audits: Starting in 2028, large frontier developers must retain independent third parties to annually audit compliance. Audit reports, summarized and appropriately redacted, must be published and shared with the Illinois Emergency Management Agency and Office of Homeland Security (the “Agency”) and the Illinois Attorney General.

Critical Safety Incident Reporting: Developers must report "critical safety incidents," including harm resulting from the materialization of a catastrophic risk or if, outside a controlled test, the frontier model uses deception against its developer to evade oversight or controls in a way that shows a materially higher risk of catastrophic harm. Reports must be made to the Agency and Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that such an incident occurred, or within 24 hours if the incident poses an imminent risk of death or serious injury.

Whistleblower and Internal Reporting Protections: The Act bars developers from contractually or otherwise preventing, or retaliating against, “covered employees” that report safety concerns or violations of the Act to regulators, and requires large frontier developers to maintain an anonymous internal reporting channel with monthly status updates to the reporting employee.

Disclosure and Registration: Beginning January 1, 2027, large frontier developers must file an annual disclosure statement with the Agency. Disclosures must cover corporate identity, ownership, and points of contact, and developers must pay associated fees before developing, deploying or operating a frontier model in Illinois.

Internal Use Risk Reporting: A large frontier developer must provide the Agency with a summary of any assessment of catastrophic risk arising from internal use of its frontier models every three months (or on another reasonable schedule the developer submits in writing to the Agency and the Attorney General and the Agency accepts), with written updates as appropriate.

False or Misleading Statements: A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or about its management of catastrophic risk. A large frontier developer also may not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.

Enforcement: The Attorney General has exclusive authority to bring civil enforcement actions. Violations, including false or misleading statements about catastrophic risk, failure to conduct required audits or failure to report critical safety incidents carry civil penalties of up to $1 million for a first violation and up to $3 million for subsequent violations. The Act does not create a private right of action.

Implications for AI Developers: Companies developing frontier-scale models should begin evaluating whether they meet the Act’s revenue and compute thresholds in advance of the Act’s effective date. Given the law's alignment with, and expansion upon, similar frameworks in California and New York, multistate developers may find it efficient to build compliance programs designed around the strictest common denominator across all three regimes, particularly the audit and incident-reporting timelines.