Illinois SB 315 · Artificial Intelligence Safety Measures Act · Signed into law · 6 July 2026
The statute is written. The evidence isn't.
SB 315 makes Illinois the first U.S. state to require annual independent third-party audits of frontier AI developers — alongside published safety frameworks, pre-deployment transparency reports, and 72-hour critical-incident reporting to the Attorney General. A safety log on your own servers is self-attested: editable by you, discounted by examiners. The audit chain SB 315 creates needs evidence it can verify by machine.
Each obligation maps to a field an auditor's tooling checks without trusting the developer — post-quantum signature, consensus timestamp on a public ledger, free verification. That is what machine-verifiable means when the reader is the Illinois Attorney General's audit chain.
What SB 315 requires. And what it asks of your records.
| Obligation | Requirement | The evidence question |
|---|---|---|
| Safety framework | Create, implement, publish, and annually update a frontier AI framework covering catastrophic-risk assessment, mitigations, and cybersecurity. | Which version was in force, when? |
| Transparency reports | Publish before deploying new or substantially modified frontier models. | Published before deployment — provably? |
| Incident reporting | Report critical safety incidents to the Illinois AG and Emergency Management Agency within 72 hours of reasonable belief. | When did the 72-hour clock start? |
| Third-party audit | Annual independent audit against your own framework — a first in U.S. AI law. | Can the auditor verify without trusting you? |
| Penalties | Up to $1M first violation · $3M subsequent · daily penalties for disclosure failures · enforced by the Attorney General. | What survives adversarial review? |
Everyone logs. Nobody can prove.
Most AI governance evidence today is a folder of PDFs, dashboards, and mutable logs — records the developer produced, stores, and can silently alter. Under a voluntary framework that was tolerable. Under SB 315 it isn't: the statute's architecture is independent verification, backed by an Attorney General with enforcement authority and seven-figure penalties.
An auditor confronted with a self-attested log has one option: trust the developer. An auditor confronted with a cryptographically signed record, timestamped on a public ledger neither party controls, has a second option: check it. That difference — trust versus verification — is the difference between an audit finding and an audit pass.
The same gap runs through the 72-hour incident clock. Without an independent timestamp, "when we formed a reasonable belief" is a negotiation. With one, it's a lookup.
One call per obligation. Verifiable without us.
Every governance event — a framework publication, a deployment decision, an incident determination — becomes a post-quantum signed attestation anchored to Hedera mainnet. What leaves your network is a 32-byte commitment; the decision, the data, and the model never do. Anyone, including a regulator, verifies for free — with or without Rubric.
Post-quantum signatures
ML-DSA-65 today, so evidence created in 2027 still verifies when it's litigated in 2035. RSA and ECDSA won't survive the retention window.
Independent timestamps
Consensus timestamps on a public ledger neither developer nor auditor controls. The 72-hour clock becomes a lookup.
Evidentiary standard
PDF reports built to the self-authenticating standard, with SHA3-256 sidecar — suitable for regulatory submission and legal proceedings.
Fits your stack
OSCAL 1.1.2 assessment-results export, Splunk HEC and CEF streaming, 17 live SDK integrations, MCP server for agent-native workflows.