Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Illinois Enacts Comprehensive AI Safety and Transparency Law, Mandating Third-Party Audits for Frontier AI Developers

Certain provisions effective January 1, 2027

Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act into law on July 6, 2026. This legislation makes Illinois the third state, following California and New York, to implement extensive safety and transparency requirements for developers of large AI systems. Notably, Illinois's Act is the first in the nation to mandate annual independent third party audits of covered developers' safety practices. Certain provisions of the Act will become effective on January 1, 2027.

Today's question

Your company trains a general purpose foundation model using roughly 1.5 x 10^26 floating point operations of compute and plans to make it available to enterprise customers in Illinois from early 2027. Reviewing the new Illinois Artificial Intelligence Safety Measures Act against the comparable California and New York regimes, which obligation is the most distinctive new burden you should plan and budget for first?

  1. Filing a pre release algorithmic impact assessment with the state Attorney General before every model version
  2. Annual independent third party audits of the developer's safety practices
  3. Appointing a state registered AI compliance officer resident in Illinois
  4. Mandatory public disclosure of full training data provenance for each model

Answer this question on the site

Worth knowing

  1. New Jersey Implements Data Broker Registration and Sensitive Data Sale Restrictions

    New Jersey Governor Mikie Sherrill signed A.5328 into law on June 30, 2026, establishing a new regime for data brokers and data collectors. The Act mandates annual registration, fee payment, specific disclosures, and prohibits the sale or licensing of sensitive data. The initial registration period for covered entities will run from April 1 through June 30, 2027.

  2. CISA to Finalize Cyber Incident Reporting Regulations for Critical Infrastructure by September 2026

    The Cybersecurity and Infrastructure Security Agency (CISA) is on track to finalize regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) by September 2026. These rules will require covered critical infrastructure entities to report cyber incidents within 72 hours and ransomware payments within 24 hours. The goal is to enhance CISA's ability to respond to and prevent cyberattacks across sectors.

  3. Flock Halts Rollout of Audio 'Distress Detection' Technology Following Advocacy Efforts

    Flock has ended the deployment of its audio 'distress detection' technology, which aimed to identify human voices in distress. This decision follows advocacy from organizations like the Electronic Frontier Foundation (EFF), who raised concerns about the privacy implications and potential for misuse of such surveillance systems. The outcome highlights the impact of public and organizational pressure on the development and deployment of surveillance technologies.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.