Locations

People Search

Filter
View All
Loading... Sorry, No results.
bscr
{{attorney.N}} {{attorney.R}}
{{attorney.O}}
Page {{currentPage + 1}} of {{totalPages}} [{{attorneys.length}} results]

loading trending trending Insights on baker sterchi

FILTER

Illinois Artificial Intelligence Safety Measures Act: A Bold Step in Regulating High-Powered AI Models

ABSTRACT: Illinois’ Senate Bill 315, which takes effect on January 1, 2027, establishes safety, transparency, reporting, and independent audit requirements for developers of powerful “frontier” AI models, with stricter obligations for large developers. The law focuses on minimizing catastrophic risks while creating a framework for accountability and oversight. In a departure from similar laws enacted by California and New York, Illinois became the first state to require annual independent audits of large frontier AI model developers.

Illinois recently became the third state to regulate AI when Governor JB Pritzker signed SB 315, or the Artificial Intelligence Safety Measures Act, into law. SB 315 establishes transparency, safety, and reporting requirements on developers of cutting-edge “frontier model” artificial intelligence. In a departure from similar laws enacted by California and New York, Illinois became the first state to require annual independent audits of large frontier AI model developers. This law takes effect on January 1, 2027, though certain framework and annual auditing requirements begin on January 1, 2028.

Frontier AI models stand at the forefront of what AI can currently accomplish. SB 315 defines a frontier model as one “that was trained using a quantity of computing power greater than 1026 integer or floating-point operations.” Simply put, these large-scale, cutting-edge AI models require immense computing power to train and operate and are capable of executing more complex tasks than traditional AI. For example, frontier AI models can generate natural language, understand and generate code, interpret images, and create and implement multi-step plans.

Like California’s SB 53 and New York’s RAISE Act, Illinois’ SB 315 does not regulate every single use of AI or even focus on every possible harm that AI could cause. Instead, SB 315 focuses on the catastrophic risks posed by unchecked and uncontrolled frontier AI models. The act defines a catastrophic risk as the “foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than [$1 billion] in damage to, or loss of property arising from a single incident involving a frontier model”. This definition is tightly limited to situations where the frontier AI model:

“(1) provides expert-level assistance in creating or releasing chemical, biological, radiological, or nuclear weapons;

(2) engages in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft . . .; or

(3) evades the control of its frontier developer.”

Notably, SB 315 excludes risks that arise from publicly accessible information, any lawful government activity, and harm caused by other software where the frontier AI model did not substantially contribute.

SB 315 imposes compliance and reporting obligations on all developers of frontier AI models, but imposes more stringent requirements on large frontier developers, or those who, together with their affiliates, report gross revenues in excess of $500 million the preceding year.

A frontier model developer, regardless of size, must clearly and conspicuously publish a transparency report on its website that itself must be clearly and conspicuously published. For large frontier developers, the required summaries of catastrophic-risk assessments must also be provided in a machine-readable format. Among other things, the transparency report must include the frontier model’s release date, the languages supported by the model, the model’s intended uses, the output modalities supported by the model, and any restrictions or conditions of use of the model.

SB 315 poses additional requirements for large frontier model developers. These developers must clearly and conspicuously publish frontier “AI frameworks” that describe how the large frontier developer will identify and assess if its frontier model is capable of posing a “catastrophic risk” and its plan for mitigating any potential catastrophic risk. Large frontier developers must review and, as appropriate, update their frontier AI frameworks at least annually. Beginning January 1, 2028, they must also retain an independent third party to conduct an annual audit of their compliance with SB 315. A large frontier model developer must also include in its transparency report an assessment of catastrophic risks posed by the frontier model pursuant to its AI framework, the results of the assessment, the level of third-party involvement in developing the assessment, and the steps taken by large frontier model developer to satisfy its frontier AI framework.

Beginning on January 1, 2028, an AI developer that qualifies as a large frontier developer must retain an independent third-party by April 1, 2028, to perform yearly audits of the developer’s frontier AI model to ensure compliance with SB 315. (If a developer first becomes a large frontier developer after January 1, 2028, it must retain the third-party auditor within 90 days of attaining that status.) The independent report must disclose whether the large frontier developer “substantially complied” with SB 315 and must also provide an analysis of the developer’s internal controls. The large frontier developer must summarize and publish a redacted copy of the report on its website, and must also provide copies of the annual independent audit to the Illinois Emergency Management Agency and Office of Homeland Security (“EMA”) and the Office of the Illinois Attorney General (“AG”). SB 315 requires that the large frontier developer must retain a copy of the report if the frontier AI model is in use plus five years. Large frontier developers who fail to publish a transparency report or AI framework that complies with SB 315 face up to $3 million in civil penalties.

In addition to SB 315’s reporting and transparency obligations, all frontier developers must report any critical safety incidents within 72 hours to the EMA and AG. On discovery of an imminent risks of death or serious physical injury, the frontier developer must alert the appropriate law enforcement or public safety agency within 24 hours.

Although SB 315 does not create a private right of action, it does empower the AG to pursue civil penalties for failure to comply with the act. For example, large frontier developers who fail to publish a compliant transparency report, report a critical safety incident, or fail to comply with their own AI frameworks face up to $3 million in penalties per violation. SB 315 further protects whistleblowers who report any frontier developer’s failure to comply with the act.

Due to SB 315’s independent audit requirement, frontier AI developers must start planning on how they will comply with the law’s transparency and, if applicable, its internal AI framework provisions. Covered entities need to prepare for how they will handle SB 315’s incident reporting and independent auditing requirements.