William A. Tanenbaum Wrote an Article Titled, "Illinois Audit Law Will Make AI Clauses Enforceable," Which was Published in Law 360
In negotiating artificial intelligence services agreements, the most difficult provisions I see involve operationalizing responsible AI obligations.
Often the parties tend toward a compromise that is both easy to breach and hard to enforce. This is because there have been no external benchmarks to rely on. On July 6, Illinois Gov. JB Pritzker signed S.B. 315, a statute that requires AI foundation model developers — such as OpenAI and Anthropic — to undergo annual, independent third-party AI safety audits.[1]
The under-the-radar result is that the specificity of the audit requirements supplies the missing objective standards for defining responsible AI standards in agreements. While the act directly regulates only a dozen or so large AI companies, it affects thousands of companies using AI. And more particularly, it provides a way to use precise responsible AI contractual provisions to govern provider-customer arrangements.
This article addresses what the Illinois Artificial Intelligence Safety Measures Act requires, why the act's lack of a private right of action makes the contract the exclusive source of customer remedies, and how the statute combines with the New York and California AI laws to create a de facto national standard.
It also discusses the changes to make in AI services agreements from both the vendor and customer perspectives; how the standards change the structure of merger and acquisition agreements, and how they can be used in due diligence; the risk of proposals that exceed these standards while invoking them as requirements; and the absorption of these U.S. state statutes into European Union compliance practices.
What the Illinois Act Requires
The act applies only to large frontier developers, a class defined by a two-part test. The test asks whether a developer's training compute is greater than 10 to the 26th power and whether their revenues are above $500 million. These are the same thresholds used in the California and New York AI statutes discussed below.
Covered developers must create, publish and annually update a frontier AI framework addressing catastrophic-risk assessment and mitigation, cybersecurity for model weights, internal governance and third-party evaluations.[2]
Developers must issue transparency reports before deploying new or substantially modified frontier models, and must report critical safety incidents to the state within 72 hours, or 24 hours when an incident poses an imminent risk of death or serious physical injury.[3]
The act's signature feature is a first-in-the-nation requirement of annual independent third-party audits testing developers' adherence to their own published frameworks.[4] Developers must publish a summary and redacted copy of each audit report within 30 days of receipt. The Illinois attorney general enforces the act, which takes effect Jan. 1, 2027, with audits commencing in 2028.[5]
No Private Right of Action
Significantly, the act provides no private right of action.[6] For enterprise customers, this is critical: It makes contracts their key remedy. By incorporating standards from the statute and backing up the standards with commercially effective remedies, the parties can solve problems with drafting responsible AI requirements.
Contract drafting also rewards an understanding of how AI foundation models operate and how AI service providers use them as tools — not as direct customer-facing technology. This understanding focuses negotiations at the intersection of technology and contractual remedies, thereby improving the allocation of commercial risk. In my experience, current contract proposals often misallocate the risk
One Framework, Three Statutes, One Audit
The Illinois act is modeled on California's Transparency in Frontier AI Act[7] and New York's Responsible AI Safety and Education Act.[8] Lawmakers estimate that the three states account for roughly 40% of the U.S. AI market.[9]
It is highly unlikely that a developer covered by all three statutes will write three safety frameworks. Because the statutes' content requirements substantially overlap, each developer will probably draft a single document to satisfy all of them.
Only Illinois conducts audits. Its audits test the very document doing the compliance work in California and New York, even though those states do not mandate audits. The result is that Illinois audits provide the verification engine for the entire three-state regime. A material adverse finding becomes evidence of noncompliance that the California or New York attorneys general could invoke.
Redrafting the AI Services Agreement: Both Sides of the Table
Most companies do not contract with frontier developers. They contract with vendors that build products on frontier models, and the act does impose obligations on this class of vendors.
However, both vendors and customers will benefit because the safety frameworks, reports and audit summaries that the act requires are the statutory counterparts to responsible AI. Each side will generally benefit from incorporating foundation developers' published safe AI practices.
Until California's statute took effect on Jan. 1, a responsible AI commitment would anchor only to material that the vendor itself authored — including its internal policies, voluntary framework commitments and AI model documentation — that generally was not externally verified. California replaced that self-authored material with documents whose content is prescribed by statute, filed publicly and backed by attorney general enforcement.
The Illinois act completes the structure by having adherence to those documents tested annually by an independent auditor. A representation keyed to the absence of a material adverse finding in the most recent audit is objectively testable in a way that a promise to develop AI responsibly never was. The statute does verification work that no customer could do. A contract embodying the standards provides the framework for creating AI certainty.
Key Statute Provisions
In my work on these agreements, I see five provisions that the statute now makes both possible and necessary for customers.
Disclosure of the Underlying Model, With Change Control
Contracts should identify the foundation models used by AI providers to deliver their own services, as well as any material change in models that affect deliverables. Customers should receive a notice and an assessment period if the vendor switches models or there is a substantial modification to the foundation model.
A Private Incident-Reporting Clock
The act's 72- and 24-hour reporting duties run from the developer to the state; no one is obliged to tell the customer. The agreements should create that duty privately.
Pass-Through of the Audit Record
Customers should require copies of the foundation model developer's published audit summaries, with prompt notice of any material adverse finding. This substitutes for audit rights.
Warranties Confined to the Vendor's Layer
The vendor stands behind what it controls: fine-tuning data, guardrails and configuration. It commits to build only on developers' current in their statutory frameworks and audits.
Exit Tied to the Statute's Machinery
Attorney general action against the developer, or the developer's failure to publish a required framework, transparency report or audit summary, triggers substitution or termination rights without proof of breach.
Vendors should respond with equal precision. Identifying the foundation model, committing to change notice, and passing through the developer's published framework and audit summary cost little — the act makes those documents public.
But a vendor should never represent that its foundation model complies with the act, nor should it commit to disclosing running changes made to the foundation model, because it will not know of them. A representation about another company's audit outcome is a liability the vendor cannot control and therefore cannot price.
A vendor can hold both lines with a standard AI addendum, which yields one governance model for all customers. One advantage to vendors of using objective standards in place of intrusive audit is that it avoids discovery of internal AI operations that a vendor wants to keep secret.
One caution as these standards move into negotiations. Fellow healthcare lawyers will recognize the pattern from the Health Insurance Portability and Accountability Act practice. HIPAA business associate agreements require specific terms. Sometimes a party incorporates terms that belong in the negotiated master services agreement, thus becoming a de facto amendment to the agreement.
The risk of that practice is greater here, because no implementing regulations yet exist, and the statute — unlike HIPPA application — does not even apply to the parties at the table. The law covers foundation model developers — not the AI services providers or their customers. The risk to avoid is treating the standards that function as benchmarks as having a statutory basis when they do not.
The M&A Dimension: AI Due Diligence Acquires an Audit Trail
The same standards will be applied to deal practice. AI due diligence has depended on management questionnaires and vendor self-descriptions. There was no independent document against which to test a target's AI dependencies as a common practice. Now there is.
An acquirer can match the foundation models behind a target's products and vendors supporting IT technology to the developers' published frameworks and audit summaries, and treat a material adverse finding upstream as a priced risk rather than an unknown.
Acquisition agreements will follow this with representations that the target's AI vendor agreements contain the protections described above, and that no deployed model is subject to a known material adverse audit finding. Representation and warranty insurers will ask the same questions. The absence of these protections becomes a quantifiable gap and unallocated AI risk that surfaces in the indemnity package or transaction pricing.
The Overreach Risk: How New Statutes Get Misused at the Negotiating Table
The healthcare practice supplies a familiar precedent for the overreach risk. HIPAA specifies the limited terms required in business associate agreements.
Fellow healthcare lawyers know the pattern: A party tries to include a provision in the business associate agreements that should be a negotiated commercial provision in the contract itself, while falsely asserting that the terms are required by HIPAA.
A cautionary note: the same posture is even more problematic here because, although the act authorizes Illinois agencies to issue implementing rules, none yet exist. There are only standards borrowed from a statute, and the statute does not apply to the parties to the AI contract; it governs the foundation model developer, not the AI services provider or its customer.
A negotiation that treats the standards as reference points reduces points of controversy.
EU Compliance Practices
The mechanism may not stop at the U.S. border. The EU AI Act built its general-purpose model regime on documentation, transparency and a code of practice, but not on mandatory independent audits of adherence.
Illinois has now supplied that verification layer for the same dozen developers the EU regime covers. Because the Illinois audit outputs are public, independent and address the identical models, they are natural reference points for European procurement diligence under the AI Act. The result is that U.S. state statutes can quietly become part of the EU compliance tool kit.
Conclusion
The private adoption of the audit standards drawn from the three state statutes follows a road that securities law paved. Securities regulation mandated disclosure, tested by an independent audit and filed publicly, and this became the infrastructure that private parties rely upon. Audited financial statements govern lending covenants, acquisition agreements and vendor relationships among companies.
The Illinois act imports a parallel architecture into AI. Illinois filings are narrower, its audits operate test processes rather than financial position, and the state certifies no model as safe. But the framework is similar. AI safety disclosure standards are becoming to AI transactions what audited financial reports are to commercial transactions generally.
As noted, disclosure obligations under the Illinois act begin on Jan. 1, 2027, and Illinois audits begin in 2028. Most AI services agreements will be negotiated or renegotiated in advance of these dates. The relevant provisions in California law have been in effect since Jan. 1. The statutory objective standards are in published form.
Accordingly, the objective standards for responsible audit exist and can now be incorporated in agreements between AI providers and customers. Put another way, these private parties do not need to wait for a statutory requirement that does not apply to them in the first place.
The unexpected advantage of the Illinois Act — in combination with the California and New York statutes — is that it provides objective standards that can be incorporated into private contracts, and it addresses the problem of defining responsible AI that does not use external objective standards. The standards can be imported into contracts before Illinois' effective dates of statutory obligations applicable to foundation developers.
Similarly, merger and acquisition agreements and due diligence can use the standards now, and for the same reason. This AI safety provision works in the same way that the standards for cybersecurity in the New York Department of Financial Services law work.[10] While that law applies to financial institutions, it provides a model that companies not subject to that law can use to structure their own cybersecurity operations.
The objective benchmarks exist now and provide more effective responsible AI contractual provisions that are also easier to negotiate. The Illinois audit requirements will strengthen the external standards because audits will test the effectiveness of foundation developers' safe AI practices.
—
William A. Tanenbaum is a partner and the chair of the AI and data law practice at Moses & Singer LLP.
This article was reprinted with permission from Law 360. The opinions expressed are those of the author(s) and do not necessarily reflect the views of their employer, its clients, or Portfolio Media Inc., or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.
[1] S.B. 315, 104th Gen. Assem. (Ill. 2026) (signed July 6, 2026; Public Act number pending as of this writing). Section references are to the act as enrolled.
[2] Id. § 10 (frontier AI framework requirements); see id. § 5 (definitions). The act adopts the coverage test used in the California and New York statutes: a frontier model is a foundation model trained using computing power greater than 1026 integer or floating-point operations, and a large frontier developer is a frontier developer whose annual revenues exceed $500 million. The shared thresholds are what allow a single safety framework to satisfy all three statutes; see Section 3.
[3] Id. § 15 (critical safety incident reporting).
[4] Id. § 10 (annual independent third-party audit, commencing in 2028). The act also requires the developer, within 30 days of receiving the audit report, to publish a summary and appropriately redacted copy on its website and to transmit copies to the attorney general and the Illinois Emergency Management Agency; the published summary is what the contract provisions described in Section 4 anchor to. See also Office of Gov. JB Pritzker, Gov. Pritzker Signs Nation-Leading Artificial Intelligence Safety Law (July 6, 2026) (press release).
[5] S.B. 315, supra note 1; Jenna Schweikert, Illinois Lawmakers Pass Landmark AI Accountability Bill, Capitol News Illinois (May 27, 2026).
[6] S.B. 315, supra note 1 (providing for attorney general enforcement and creating no private right of action).
[7] S.B. 53, 2025-2026 Reg. Sess. (Cal. 2025), codified at Cal. Bus. & Prof. Code § 22757.10 et seq. (signed Sept. 29, 2025) (Transparency in Frontier Artificial Intelligence Act).
[8] Responsible AI Safety and Education (RAISE) Act (S.B. 6953-B/A.B. 6453-B) (signed Dec. 19, 2025), as amended by chapter amendment S.B. 8828/A.B. 9449 (signed Mar. 27, 2026), codified at N.Y. Gen. Bus. Law art. 44-B (effective Jan. 1, 2027).
[9] Pritzker Signs Landmark AI Regulation Bill That Aims to Mitigate Risks, Capitol News Illinois (July 6, 2026) (three-state 40% market estimate).
[10] N.Y. Comp. Codes R. & Regs. tit. 23, pt. 500 (Cybersecurity Requirements for Financial Services Companies) (effective Mar. 1, 2017; second amendment effective Nov. 1, 2023).

