ARTIFICIAL INTELLIGENCE SAFETY
HB3506 creates the Artificial Intelligence Safety and Security Protocol Act, a new Illinois law focused on the largest developers of foundation models and other advanced artificial intelligence systems. The bill requires covered developers to create, implement, follow, and publicly post a detailed safety and security protocol describing how they manage critical risks, test models, decide whether to deploy them, protect against unauthorized access, respond to incidents, and update their safeguards. It also requires developers to publish a risk assessment report at least every 90 days, retain testing records for five years, and disclose material changes to their protocol within 30 days.
The bill further requires an annual independent audit by a reputable third-party auditor, with the audit report also made public. It includes redaction rules to protect trade secrets, public safety, and national security, while preserving unredacted versions for Attorney General inspection. The measure also adds whistleblower protections for employees who report unreasonable or substantial critical risks to the Attorney General and requires internal anonymous reporting channels within covered companies. Enforcement authority is given to the Attorney General, including civil actions, injunctive relief, declaratory relief, and civil penalties of up to $1,000,000 for violations.
HB3506 would add a new regulatory framework in Illinois for developers of large foundation models, especially those trained with very high computational resources. It would impose affirmative duties on covered AI developers to document and publish safety practices, conduct recurring risk assessments, preserve records, submit to third-party audits, and maintain internal whistleblower processes. The bill also creates potential civil liability and authorizes Attorney General enforcement, while leaving existing legal duties and remedies in place and not displacing other state or federal requirements.
Based on the bill text, the overall sentiment is precautionary and pro-regulation, with the General Assembly expressing support for transparency, human control, and reasonable care in advanced AI development. The findings section frames AI as economically beneficial but potentially capable of catastrophic misuse if not properly governed, suggesting the bill is intended as a safety measure rather than a restriction on ordinary AI use. No committee transcript or vote history was provided, so there is no recorded public debate or roll-call evidence of support or opposition in the materials supplied.
The main points of contention likely center on the scope and burden of compliance for major AI developers, including the requirement to publish detailed safety protocols, undergo annual third-party audits, and disclose risk assessments on a recurring basis. Another likely issue is the balance between transparency and protection of trade secrets or national security information, since the bill allows redactions but also requires Attorney General access to unredacted materials. The bill’s definition of critical risk, the threshold for covered developers, and the Attorney General’s enforcement authority could also be disputed by industry stakeholders, while supporters would likely emphasize public safety, accountability, and whistleblower protections.