AI Policy - 6 min read - 17 July 2026

Illinois just made AI labs prove their safety claims to an outside auditor. Most enterprise vendor contracts still don't.

SB 315 makes Illinois the first US state to require frontier AI developers to submit their safety plans to an independent auditor every year, with a 72-hour clock on reporting serious incidents. The interesting part isn't the law - it's how far ahead of most enterprise vendor terms it now sits.

On 6 July, Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, making Illinois the first US state to require third-party safety audits of frontier AI systems, according to The Hill. The law applies to developers with more than $500 million in annual gross revenue and requires them to publish an account of how their models could pose a "catastrophic risk" and how those risks are being managed, alongside annual audits carried out by evaluators with no financial relationship to the company being reviewed. Cesar Fernandez of Anthropic, quoted by StateScoop, called it the first state law to "pair AI transparency requirements with independent verification" - which is a fair description, and also an admission that most existing AI safety claims haven't been independently verified at all.

What the law actually asks for

Two obligations matter more than the headline. First, covered developers must disclose how they identify and respond to what the law calls "critical safety incidents," and must report a suspected incident to the Illinois Attorney General's office within 72 hours of having sufficient reason to believe one occurred - a materially faster clock than most breach notification regimes, and one that assumes a developer already has the internal tooling to recognise a safety incident quickly rather than discovering it weeks later through a customer complaint or a researcher's writeup. Second, the audits themselves must be genuinely independent: an evaluator with a commercial stake in the outcome doesn't satisfy the requirement, which rules out the kind of vendor-commissioned "safety report" that currently passes for assurance in a lot of enterprise AI procurement packs. Penalties for non-compliance run to $1 million for a first violation and $3 million for repeat offences, enforced by the state Attorney General. Most of the substantive requirements take effect from 1 January 2028, giving covered developers roughly eighteen months to build the compliance function the law assumes already exists.

The gap this exposes is already sitting in your vendor file

Here's the uncomfortable read-across for any enterprise that isn't headquartered in Illinois and isn't waiting on this law to apply to it directly. Illinois has just formally decided that a vendor's own account of its safety posture is not sufficient evidence of that safety posture - that claim needs independent verification, on a clock, with real penalties attached. Very few enterprise AI vendor contracts we review currently meet that bar internally. Most rely on a security questionnaire completed by the vendor, a SOC 2 report scoped to infrastructure controls rather than model behaviour, and marketing language about "responsible AI" that no outside party has tested. If a state legislature has concluded that self-attestation isn't good enough for the vendors themselves, it's a reasonable moment for enterprise risk and procurement teams to ask why self-attestation has been good enough for the customers.

This also lands three months after the Future of Life Institute's Summer 2026 AI Safety Index gave every major AI lab a grade of C+ or below, a result we covered in detail here - so the regulatory direction and the independent assessment evidence are now pointing the same way at the same time. That alignment is worth paying attention to, because it rarely happens with new AI legislation, which is more often ahead of or behind the evidence than sitting squarely on top of it.

  • Ask your current AI vendors directly whether any element of their safety or evaluation claims has been reviewed by an auditor with no commercial relationship to them - not a partner, not a certification body they pay to be certified by.
  • Build a 72-hour internal notification expectation into your own AI vendor contracts now, regardless of whether SB 315 applies to your organisation directly, since the standard it sets is likely to spread to other jurisdictions.
  • Separate infrastructure security assurance (SOC 2, ISO 27001) from model behaviour assurance in your vendor due diligence - they answer different questions, and most vendor packs currently only cover the first.
  • Track which of your AI vendors cross the $500 million revenue threshold this law targets, since their compliance posture from January 2028 gives you a genuine external benchmark to hold smaller vendors against too.
  • Revisit any AI procurement decision made primarily on a vendor's own safety documentation, and ask what independent evidence, if any, actually sits behind it.

Laws like SB 315 rarely change vendor behaviour on their own - what changes it is enterprise customers asking the same question the law is now asking, before the compliance deadline forces the issue. If you'd like help building AI vendor due diligence that would hold up against a standard like this one, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources