Illinois did not regulate a chatbot. It regulated the file that is the model. In early July 2026, Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act. It takes effect January 1, 2027. The heavier duties, including a published frontier AI framework and an annual independent audit, phase in January 1, 2028. Covered developers have to secure unreleased model weights against unauthorized modification or transfer. A critical safety incident under the law includes unauthorized access to, modification of, or exfiltration of those weights when the result is death or injury.
That is a cybersecurity obligation written into an AI statute. The two teams that usually own those problems separately now own the same asset.
What a weight actually is
A model weight is a number inside the network. Training starts with rough values and adjusts them, pass after pass, until the errors shrink. The finished set of numbers is what the model “knows.” It is not the training set, and it is not the source code that ran the training job. It is the compressed result of both.
Two consequences follow. A high weight is the model treating that connection as important, so a small unauthorized edit can change behavior without crashing the service. And a full copy of the weights is a full copy of the capability. The attacker does not need the original data or the training pipeline. Open-weight releases, such as Meta’s Llama line, hand that file to the public on purpose. Closed systems, such as OpenAI’s GPT models and Anthropic’s Claude, keep it inside the lab and sell access through an API. Illinois is aimed at the second case: unreleased weights, in the hands of a large frontier developer.
The Act uses the same frontier threshold California and New York use. A frontier model is one trained with more than 1026 floating-point operations. A large frontier developer is one with more than $500 million in annual gross revenue. Enforcement sits with the Illinois Attorney General, with civil penalties up to $1 million for a first violation and $3 million for later ones.
What theft looks like
Losing the file is not a conventional breach. Three failure modes matter more than a leaked database.
- Fine-tune without the guardrails. Whoever holds the weights can retrain the refusals out, clone the behavior, or point the model at a task the developer blocked.
- Training data that never left as a row. Weights can memorize. A stolen file can surface personal information that was never stored as a record the privacy team inventoried.
- A quiet edit. Changing a slice of the numbers can plant a trigger. The service stays up. Logs look normal. Outputs shift only on the prompt the attacker chose.
The last one is why a standard data-loss playbook misses it. Exfiltration of a weight file can leave the system fully operational. Integrity attacks can be smaller than the change threshold a security operations center is tuned to page on.
Why the usual stack stops short
Encryption at rest and TLS in transit still matter. They do not cover the moment the law is worried about. During training and inference the weights are decrypted and loaded into GPU memory, across servers, cloud tenants, and inference endpoints. That is data in use. AES-256 does not help while the accelerator is doing the math. A compromised host, a malicious admin, or a hypervisor-level view can read the plaintext the chip is computing on.
The attack surface is also wider than a code repository. Weights move from the training cluster to a checkpoint store, to an evaluation environment, to a deployment bundle, to a vendor. Each hop is a copy. Traditional software security assumes you can put the crown jewels in one vault. A frontier training run assumes the opposite.
Controls that match the asset
No single tool satisfies a duty to prevent theft, tampering, and unauthorized access. A program that would survive the Act’s framework, and the audit that starts in 2028, has four layers.
Runtime. The dangerous hour is when the weights are loaded. A trusted execution environment isolates that memory from the rest of the host, so a compromise outside the enclave does not read the file. Remote attestation asks the hardware for a signed report of what is actually running before the weights are released. Fully homomorphic encryption, which computes on ciphertext, is still too expensive for most frontier inference, but it is the direction for the subset of workloads where the weights cannot be exposed even to the operator.
Infrastructure. Store checkpoints in one monitored repository. Least privilege on who can read them. Segment the training network, and for unreleased weights cut egress so a job cannot ship the file to a personal bucket. Harden the agent boundary: a coding agent does not get production credentials, and an inference service does not get a path back to the checkpoint store.
File format and provenance. Distribution format is a security choice. Pickle-style serialization can execute code on load. Data-only formats such as Safetensors cannot. Sign the artifact, check the signature before deploy, and treat an unsigned checkpoint as untrusted. Meta’s move away from pickle for Llama was a supply-chain fix, not a research preference.
Governance. Insiders already have a reason to touch the file. Weight access belongs in the insider-threat program, with alerts on bulk export. Log retrieval and API patterns that look like model extraction. Red-team the deployment, not just the model. Illinois requires that kind of testing as part of the safety program, and the annual third-party audit arriving in 2028 will ask for the evidence.
What to do before the dates
- Name an owner for unreleased weights. If security thinks it is an AI asset and the lab thinks it is a research artifact, nobody has the log.
- Map every copy: training checkpoints, eval snapshots, vendor shares, employee laptops, disaster-recovery replicas.
- Write the frontier framework so the weight controls are specific. “Industry-standard encryption” will not answer an auditor asking about data in use.
- Put weight exfiltration and weight tampering on the incident-response tree. The Act treats unauthorized access and modification as safety incidents, not only as IP events.
- If you buy a frontier model rather than train one, ask the provider where the weights live, who can read them, and what attestation you get. Their duty becomes your vendor question.
Frontier lab transparency
Illinois joined California and New York on frontier transparency, then went further: an annual independent audit, and an explicit duty to secure unreleased model weights. The file is the product. It is also the control surface. A program built for source code and customer databases does not see it, and a program built only for model behavior does not lock it. The statute is in force January 1, 2027. The audit trail has to exist before January 1, 2028.