This is your short answer. No federal law regulates your use of artificial intelligence technology; a few states have binding requirements, and some apply even to organizations convinced they are exempt. The state of Illinois has become the first state in the nation to require independent third-party audits of artificial intelligence safety measures, although not until 2028, and not of all organizations. Anyone who ever worked in IT assurance during cloud computing adoption knows this pattern all too well, but it did not stop there.
The Cloud Playbook, Replayed
Adoption of cloud computing was way ahead of any verification capabilities back in 2010. Companies shifted payroll systems, customer databases, and financials to vendors that were vetted using spreadsheet questionnaires and “Security” web pages. Due diligence was asking a vendor if its services were secure and documenting the answer. The important question that was not asked was “how do you know?”
There was no legislation, as there was never any law mandating a SOC 2 report. Buyers started asking for independent assurance, some large buyers demanded it, and in a few years nobody could close an enterprise-level deal without an independent attestation of the vendor. Assurance became a condition of doing business through procurement rather than through legislation. AI finds itself today roughly in a place where cloud found itself in 2010, but with faster adoption and a lack of a verification layer behind.

What Illinois Actually Did & What It Does Not Require of Organizations
July 6, 2026 saw the signature by Governor JB Pritzker of Senate Bill 315 – Artificial Intelligence Safety Measures Act. It becomes the first law in the US to mandate independent third-party audits of AI safety practices. Covered developers will be required to develop and annually review safety frameworks, provide transparency reports, report critical safety incidents, and hire a qualified independent auditor with no financial conflicts of interest. Violations will carry penalties from $1,000,000 on the first occasion to $3,000,000 thereafter.
Two facts are left out of the picture entirely. The Act becomes operative on January 1, 2027, and the requirements for audits do not become operative until January 1, 2028. It applies to large frontier developers, which are defined as developers with revenues in excess of $500,000,000 per year that train models of above 10^26 operations. Yours likely does not appear on that list.
SB 315 is not a deadline for most organizations; it is a leading indicator. The legislature has considered the most impactful existing AI systems, balanced against the insufficiency of self-attestation, and decided it was not enough.
The Patchwork That Does Apply
Whereas frontier legislation grabs the headlines, legislation placing obligations on ordinary organizations has grown state by state, often with conflicting definitions and deadlines. The trend is more important than the details: disclosure first, then transparency, and eventually independent verification.

Federal Friction & Why Waiting Is Not a Strategy
On December 11, 2025, President Trump signed Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, which views excessive regulation of AI as an impediment to competitiveness and instructs federal agencies to contest AI regulation by states. Colorado’s AI Act has been enjoined by a federal court prior to being repealed and rewritten.
The natural inclination is to hold off on any governance work until the situation clears up, and this is where the logic falters. Preemption actions strike regulations. They do not have anything to do with client expectations. Even if all state-level laws on AI are enjoined next quarter, that customer looking for information on how your models were validated will still be there.
Organizations Who Were Certain This Did Not Apply
There is a common theme in these examinations. First thing management mentions is that AI regulation is meaningless, because the company does not develop or train models. And then comes the scope walk-through revealing the systems in use.
In one mid-sized organization that did not have any machine learning in its own products at all, there were three different systems live. Human resources used a recruitment platform that evaluated resumes and analyzed video interviews. Customer service used an AI assistant, trained on a large language model, to deal with billing disputes. The sales team used a credit scoring tool.
None of those systems was developed internally. None was considered an AI implementation by anybody. Each of those systems had an influence on employment and credit decisions in states that required notice and the right of recourse for such decisions. In Colorado, the use of that recruiting tool makes an employer a deployer of automated decision-making technology requiring notice and access to human review for all rejected applicants.
The real trouble was evidence. That organization could not provide any information about systems that they had not built themselves. The only documents they had were a questionnaire and a contract from the vendor. That organization was bearing the risks of a technology it could neither evaluate nor understand.
What Independent Verification Actually Looks Like
ISO/IEC 42001:2023 is the first international standard for AI management systems. Certification takes place through an accredited organization: a documentation audit, testing of controls related to transparency, bias, human oversight, and data management, and annual surveillance. As opposed to assessing one model snapshot in time, it manages risk throughout the life cycle, the only method that stands up to model drift.
For those already doing SOC 2, AI controls could be incorporated into an existing exam rather than being conducted as a separate program. Model validation, handling of training data, version control of models, and monitoring for degradation fit within existing criteria and would be assessed anyway, driving down marginal costs below those presumed by teams.
The second half of the practice is the half organizations ignore. The same burden of evidence needs to apply further upstream. Procurement could require an ISO 42001 certification, or a SOC 2 report which has demonstrated inclusion of AI controls, rather than having an unchecked self-reported questionnaire from a supplier. Any vendor who does not produce one is requesting to be taken on trust; the practice cloud vendors moved away from fifteen years ago.

Considerations for Building an Auditable Program
First, take stock of everything that is actually deployed, including AI functions embedded within software already licensed, noting its inputs, purpose, and the human oversight applied to each decision. Design one control system rather than five, mapping overlapping requirements like pre-use notification, adverse decision explanation, and incident reporting to one set of processes that meet the most stringent applicable state. And enforce that standard further upstream, demanding independent assessment of AI and SaaS suppliers with defined scope rather than a seal on their website.
Will AI Replace Regulatory Compliance?
No, though the form of the work shifts. AI tools excel at monitoring, evidence collection, and detecting changes in regulatory text. The tools themselves lack the ability to regulate. The tool could tell me that my data store was encrypted; it could not determine the relevance of a policy exception, determine if an algorithmic decision was made fairly, or apply any healthy degree of skepticism to its own analysis. It is those very tools that are prone to drift and hallucination that require a second set of eyes.
Is My Company Covered if We Purchase AI But Do Not Develop it Ourselves?
Yes, typically. State frameworks usually carry deployment requirements, not just development requirements. Use of a vendor’s AI tool in making any material decision related to employment, housing, lending, insurance, or health care is often enough.
Moving Forward
There is one clear trend: A technology is adopted faster than it can be regulated, self-certification works for a bit, and then it doesn’t anymore. Illinois became the first state legislature to declare that much clearly. The customers will say it next as we continue to see the AI threat landscape expand.
Linford & Company is an independent audit firm experienced in SOC 1, SOC 2, HITRUST, ISO 27001, and ISO 42001 engagements. For more information on how an independent audit of your AI system and/or your vendor’s would look, visit linfordco.com or contact us.
