ARTIFICIAL INTELLIGENCE SAFETY
Illinois HB3506, introduced by Rep. Daniel Didech in the 104th General Assembly, creates the Artificial Intelligence Safety and Security Protocol Act (Section 1). The bill targets large-scale AI 'developers'—defined in Section 10 as entities that have trained at least one foundation model using at least $100 million in computing costs. Under Section 15, every covered developer must produce, implement, follow, and publicly publish a safety and security protocol detailing how it manages 'critical risks'—defined in Section 10 as foreseeable risks of death or serious injury to more than 100 people, or more than $1 billion in property damage, stemming from AI-enabled weapons of mass destruction, cyberattacks, autonomous criminal conduct, or loss of developer control. Developers must also publish a risk assessment report at least every 90 days and retain test records for at least five years. Section 25 requires an annual independent third-party audit assessing compliance with the safety and security protocol, with the audit report published within 90 days of completion. Section 20 permits redactions for trade secrets, public safety, or national security, but unredacted documents must be retained for five years and made available to the Attorney General upon request. Section 30 extends Whistleblower Act protections to employees who report unreasonable critical risks to the Attorney General, and requires developers to maintain an internal anonymous disclosure process with quarterly reporting to conflict-free officers and directors. Section 35 authorizes the Attorney General to seek civil penalties up to $1,000,000 per violation of Sections 15 or 25, as well as injunctive or declaratory relief. Section 40 clarifies that the Act's duties are cumulative with all other legal obligations.
Status history
Current status as of 2025-02-07
In committee
2025-02-07
observed 2026-09-23
Impact areas
- Enterprise Adoption
- Quality Assurance
- AI Policy