Illinois SB 315 (Public Act 104-0538) requires annual third-party audits of major frontier AI developers. The law creates substantial evidence, but it does not clearly identify who accepts residual risk and authorizes deployment.

Illinois Governor J.B. Pritzker approved Senate Bill 315, (Public Act 104-0538), the Artificial Intelligence Safety Measures Act, on July 6, 2026. The law establishes transparency, incident-reporting, internal-governance, and independent-audit requirements for developers of the largest frontier AI models.

Its most consequential provision requires qualifying developers to retain an independent third party each year to audit compliance with the Act’s frontier AI framework requirements.

Illinois has moved the legislative model beyond developer disclosure. The audit must assess substantial compliance, material deviations, internal controls, and whether senior personnel have been designated and empowered to implement the required processes.

That creates a serious evidentiary record.

It does not fully answer the next governance question:

When the evidence identifies unresolved risk, who accepts that risk and authorizes deployment?

The Illinois Artificial Intelligence Safety Measures Act strengthens verification. The remaining gap is the defined, transparent ownership of the decision made after verification. This is the verification gap the Name Standard℠ is designed to test.

What the Illinois Artificial Intelligence Safety Measures Act Requires

The Act applies its principal obligations to large frontier developers with more than $500 million in annual gross revenue and frontier models trained above the statutory computing threshold.

Beginning January 1, 2028, a large frontier developer must write, implement, comply with, and publicly maintain a frontier AI framework addressing catastrophic-risk thresholds, assessments, mitigations, third-party evaluations, cybersecurity, critical safety incidents, internal governance, and risks created by extensive internal use.

The framework must address how assessments and the adequacy of mitigations are reviewed as part of the decision to deploy a frontier model or use it extensively inside the company.

Before deployment, the developer must also publish a transparency report summarizing catastrophic-risk assessments, results, third-party involvement, and other steps taken under the framework. Those summaries must be machine-readable to facilitate verification of model claims.

Critical safety incidents generally must be reported to the Illinois Emergency Management Agency and Office of Homeland Security and the Attorney General within 72 hours. An incident presenting an imminent risk of death or serious physical injury must be disclosed within 24 hours to an appropriate authority with jurisdiction.

The Act takes effect January 1, 2027. The frontier AI framework requirements begin January 1, 2028. The annual audit requirement begins January 1, 2028, or 90 days after a developer first qualifies as a large frontier developer, whichever is later.

The Audit Tests Compliance, Not Risk Threshold

The annual audit is broader than a review of whether the developer followed a voluntary safety promise.

The auditor must evaluate whether the developer substantially complied with Section 10 of the Act. The report must describe material deviations, explain their rationale, recommend improvements, and provide a detailed assessment of internal controls.

It must also examine the designation and empowerment of senior personnel responsible for implementation. The lead auditor must sign the report and certify its results.

Those requirements create more than paper disclosure. They create external scrutiny of whether the developer built and operated the processes Illinois requires.

But the audit does not impose one uniform substantive threshold determining when catastrophic risk is too high for deployment.

The developer still defines much of the framework used to identify capability thresholds, assess risks, select mitigations, and determine when those mitigations are adequate. The auditor can determine whether the company substantially complied with that framework and the statute. The audit does not necessarily determine whether the company’s chosen risk threshold was sufficiently protective.

That is the first accountability distinction:

Compliance with the process is not the same as independent approval of the deployment decision.

Responsibility Is Not the Same as Accountability

Illinois requires the audit to assess whether senior personnel were designated and empowered to implement the statutory processes.

That matters. The law does not leave internal responsibility entirely unnamed.

But responsibility for implementation is not necessarily accountability for accepting residual risk.

A senior officer may be responsible for maintaining the framework. A model-safety team may conduct the assessment. Legal may interpret the statute. Compliance may monitor deviations. An auditor may verify substantial compliance.

Someone must still decide whether an unresolved deficiency is material, whether remediation is adequate, whether deployment should be delayed, and whether the remaining risk is acceptable.

The Act does not clearly require the audit report or deployment record to identify the particular officer, executive body, or board committee that made that final determination.

The organization may therefore prove:

  • that a framework existed;
  • that required assessments occurred;
  • that senior personnel were empowered;
  • that an independent audit was completed;
  • that deviations and recommendations were recorded.

It may still lack a traceable record naming who accepted the remaining risk and authorized the model to proceed.

The Name Standard℠ Gap

The Name Standard℠ tests whether an AI-assisted decision remains traceable to a responsible human or institutional actor with the capacity, information, authority, documentation, and formal right of refusal required to own the outcome.

SB 315 creates substantial evidence across that chain. It requires internal controls, senior-personnel accountability, audit findings, incident reporting, public summaries, and a signed auditor certification.

The missing layer is narrower but consequential:

  1. Who received the final audit findings?
  2. Who determined whether a deviation was material?
  3. Who approved the remediation?
  4. Who had authority to delay deployment?
  5. Who accepted unresolved catastrophic risk?
  6. What record preserves that approval?

The lead auditor’s name establishes responsibility for the audit opinion. It does not establish responsibility for the developer’s deployment decision.

The designated senior personnel establish responsibility for implementation. They do not necessarily establish who authorized the company to proceed after reviewing unresolved findings.

Without that final record, the company can prove that evidence was produced, but does not have proof of a person who made the decision

The Committee Ownership Problem

The Act also creates a board-governance question.

A frontier-model audit can implicate technical controls, cybersecurity, regulatory compliance, enterprise risk, public safety, and disclosure. Those subjects may cross several committee charters.

The audit committee may receive the report because it concerns assurance and controls. A risk committee may oversee catastrophic-risk exposure. A technology committee may oversee model development. The full board may retain responsibility for the most consequential deployment decisions.

Receipt of the report does not establish ownership of the decision.

The Committee Ownership Map separates information flow from governance responsibility. It asks which committee must challenge management, confirm remediation, escalate unresolved findings, and exercise authority when the company proposes to proceed.

An annual audit can reduce information asymmetry while leaving decision ownership fragmented.

What Illinois Gets Right

The Illinois Artificial Intelligence Safety Measures Act materially strengthens frontier-model governance.

It requires recurring independent review rather than exclusive reliance on self-attestation. It requires auditors with relevant competence, protects auditor independence, gives auditors access to necessary materials, and requires examination of internal controls and empowered senior personnel.

The audit report must be retained while the model remains deployed and for five additional years. A high-level summary and redacted report must be published and transmitted to state authorities.

Enumerated violations by a large frontier developer can result in civil penalties of up to $1 million for a first violation and $3 million for a subsequent violation. Enforcement belongs exclusively to the Illinois Attorney General.

Illinois has therefore moved the legislative pattern from disclosure toward verification and institutional control.

That is significant.

But verification is not the final layer of accountability.

The Accountability Question After the Audit

The Illinois Artificial Intelligence Safety Measures Act requires major frontier developers to produce evidence showing whether they substantially complied with the law and whether senior personnel were empowered to implement its requirements.

Boards must ask the next question:

When the audit identifies unresolved risk, who has authority to stop deployment, who accepts the risk if the company proceeds, and whose name remains attached to that decision?

An audit creates evidence. Governance determines what happens because of it.

Illinois has strengthened the first function. Companies still need an accountability architecture for the second.

Lozen Advisory’s Board AI Name Standard Advisory evaluates whether AI-assisted decisions remain attributable, reviewable, and supported by evidence the board can rely on.