Illinois Just Made “Trust Me” Obsolete

Illinois did not ask AI companies to promise they are safe. It made them prove it to someone with no stake in the answer.

On July 6, Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act. The headlines called it the strongest AI accountability law in the country. That is true, but it undersells the part that matters most. Illinois became the first state to require independent, third-party audits of covered AI systems. The public no longer has to take AI companies at their word.

That single shift, from disclosure to verification, is the story every business leader should be watching. Not because the law applies to most of us. It does not. But because of where it points.

What Illinois actually did

The law targets the largest AI developers, the frontier labs building the most powerful models. It requires them to disclose their safety practices, report serious incidents, and maintain real compliance processes. It protects the employees who raise concerns.

Then it goes one step further than California or New York. It requires regular audits by qualified outside experts who have no financial conflict of interest. As one advocate put it, the public does not have to take AI companies at their word anymore.

Read that again. The novel part is not the transparency. Companies have made safety claims for years. The novel part is the verification. Someone independent now checks the work.

Yes, this targets labs. Can the rest of us be far behind?

The obvious response is that none of this touches a growing business using AI for hiring, customer service, or forecasting. The law names frontier developers, not the 200-person professional services firm.

That comfort is temporary.

Regulation almost always starts at the top and works its way down. It begins with the biggest players and the highest-stakes systems, then the expectations settle into the rest of the market. Data privacy followed this path. So did financial reporting and workplace safety. It’s a pattern.

The expectation Illinois just set is simple to state and hard to escape. Show your work. If you claim your AI is fair, safe, or accurate, be ready to prove it to someone who does not work for you.

That expectation will not stay locked inside frontier labs. It will arrive through your enterprise clients, who will ask how your AI makes decisions before they sign. It will arrive through your insurers, your board, and eventually a regulator who does not care how large you are. It’s not a question of IF auditability reaches your business, but WHEN, and if you are ready when it does.

You cannot audit what you never documented

Here is the problem most organizations will discover too late. Auditability is not something you add at the end. It is a design choice you make at the beginning, or fail to make.

An auditor, a client, or a regulator asks a straightforward question. What context did this AI system use to make this decision? What rules governed it? Who was it built to serve? If your answer is a shrug, you do not have a governance gap. You have a governance void.

Most AI use inside companies today runs on ad-hoc prompts. One person writes a clever instruction, gets a good result, and moves on. Nothing is recorded. Nothing is repeatable. There is no trail to follow, because no trail was ever laid.

That works fine until someone asks you to prove it. Then the absence of a record becomes the whole story.

Structured context is an audit trail

This is where the discipline of good AI practice and the demand for governance turn out to be the same thing.

The Kendall Framework, the approach we teach at RBK Strategic Consultants, is built on defining and documenting the context that shapes every AI interaction. Who is involved. What problem you are solving. What the organization can do. How the work happens today. Add to that your documented rules, your guardrails, and your standards, assembled in structured, reusable blocks.

We have always framed this as the path to reliable output, and it is. Ad-hoc prompts produce a lottery. Managed context produces repeatable results.

But look at that same practice through the lens of SB 315. Documented roles, defined problems, embedded rules, and structured context are, functionally, an audit trail. When you can show what context went into a decision and why, you are not just getting better answers. You are building the proof that governance now demands.

The companies treating structured context as a quality practice today are, without trying, building the audit-readiness they will need tomorrow.

Governance stopped being optional

For years, AI governance sat on the someday list, worthy in principle, easy to defer. Illinois (where I was born.) just moved it. Governance is no longer a matter of good intentions. It is becoming a matter of verification, and verification requires a record.

The organizations that built auditability into how they use AI will be ready when the question comes. The ones treating it as future paperwork will be scrambling to reconstruct decisions they never documented.

You do not have to wait for a law with your name on it to start. If you want to understand what audit-ready AI looks like inside your business, and how to build the context and governance to support it, that is the work we do. Let us talk before the question arrives.