Illinois's New AI Law Starts With Disclosure, Not the Audit It's Known For
SB 315's audit and safety-framework rules wait until 2028 and apply only above $500M revenue. Its disclosure duties start in 2027, for everyone else.
On July 6, 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (Senate Bill 315). Its best-known provision is a requirement for independent third-party audits of frontier AI models. That provision is real. It is not, however, the part of the law that takes effect first, or the part that reaches the most developers.
The Act's own text splits into two separate compliance tracks, binding two different populations of developer, starting on two different dates. One track - a per-deployment transparency report and a 72-hour critical-incident report - applies to any developer whose model crosses the Act's compute threshold, regardless of company size, starting January 1, 2027. The other track - the published safety framework and the annual third-party audit that give the law its headline - applies only to developers clearing a separate revenue threshold, and doesn't start until January 1, 2028. A developer that reads "Illinois audit law" and concludes it has eighteen months before anything applies has read the coverage, not the statute.
Two Definitions, Two Populations
The Act defines a "frontier model" as a foundation model trained using more than 10²⁶ integer or floating-point operations - a compute threshold, with no revenue component. Separately, it defines a "large frontier developer" as a frontier developer that, together with its affiliates, had annual gross revenues exceeding $500 million in the preceding calendar year.
Those are two independent gates, and the Act uses them to sort obligations into different tiers. A developer can clear the compute threshold - and so qualify as a "frontier developer" bound by the Act - without clearing the revenue threshold that makes it a "large frontier developer." The distinction matters because the Act's two most-discussed requirements, the safety framework and the audit, are written to bind only the second category.
What Starts January 1, 2027
Section 10(c) of the Act requires "a frontier developer" - the broader term, with no size qualifier - to publish a transparency report before or concurrently with deploying a new or substantially modified frontier model. Section 15(a) requires "a frontier developer" to report a critical safety incident to the Illinois Emergency Management Agency and Office of Homeland Security and to the Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that one occurred, or within 24 hours where the incident poses an imminent risk of death or serious injury.
Neither section carries a separate effective date of its own. Both take effect when the Act itself does: January 1, 2027, per Section 99. Neither is limited to large frontier developers. Read plainly, a compute-threshold-crossing developer with no path to $500 million in annual revenue owes Illinois a transparency report and incident reports on that date - a full year before any audit obligation exists for anyone.
What Waits Until 2028
Section 10(a) requires that, "beginning January 1, 2028," a large frontier developer write, implement, and publish a frontier AI framework addressing ten specified elements - catastrophic-risk assessment, mitigations, cybersecurity for unreleased model weights, and internal governance among them. Section 10(d) requires that, beginning on that same date (or 90 days after a developer first qualifies as a large frontier developer, whichever is later), a large frontier developer retain an independent third party annually to audit its compliance. A separate disclosure-statement requirement under Section 18(a) - also large-developer-only - starts a year earlier, on January 1, 2027, but is itself distinct from both the framework and the audit.
Violations tied to the framework and disclosure requirements carry real exposure: Section 25 authorizes the Illinois Attorney General to bring civil actions against a large frontier developer that fails to publish or transmit a required compliant document, with penalties up to $1 million for a first violation and $3 million for each subsequent one, recovered exclusively by the Attorney General.
The Gap Between the Two Tracks
This is not stated anywhere in the Act as a design rationale - nothing in the text explains why the legislature sequenced obligations this way, and the Act doesn't say. What the text does establish, directly, is the sequencing itself: a broader disclosure-and-incident-reporting duty that starts in 2027 and reaches any developer past the compute line, sitting alongside a narrower framework-and-audit duty that starts in 2028 and reaches only developers past the revenue line. Treating the two as a single "2028 audit law" erases a compliance obligation that a smaller, compute-intensive developer would otherwise miss for a full year.
That gap is easy to miss precisely because the audit is the heaviest single obligation in the Act - an annual third-party engagement against a ten-element framework, not a form filed once - so it's the natural way to describe SB 315 in one sentence. But a developer sizing up its own exposure under the Act needs to ask two separate questions, not one: does our training run cross 10²⁶ operations, and separately, does our revenue cross $500 million? The first question alone determines whether the January 2027 disclosure and incident-reporting duties apply. The second determines whether the 2028 framework and audit duties will ever apply at all.
What This Changes Operationally
For an AI organization already large enough to be planning for the 2028 audit, the practical change is smaller: the framework Section 10(a) requires is close to what a maturing AI governance function should be building anyway, and 2028 is a real runway. The Act does not say who else it catches off guard - that's this article's own reading of what the two threshold definitions imply together, not a conclusion the statute states about itself. But the reading follows directly from the definitions above: an organization training at frontier compute scale without frontier revenue - a well-funded startup, a research lab, or an AI division inside a larger non-AI company, none named in the Act itself and none confirmed here as currently over the threshold - would clear the compute line without clearing the revenue line, and so would owe Illinois a transparency report and incident reports on the earlier date regardless of size. For an organization in that position, the operative date isn't 2028. It's January 1, 2027 - five months from now.
Source note: Illinois Senate Bill 315, the Artificial Intelligence Safety Measures Act, enrolled text via the Illinois General Assembly. Signing confirmed via the Governor's official announcement, July 6, 2026.
Map your disclosures against AI & Technology.
Noa reads your disclosures, traces every number to its source, and flags what's missing.