Getting your Trinity Audio player ready...

People ask me the same question all the time: Why can’t Illinois keep its best technology talent? 

It’s a fair question, because talent is the one thing we’re not short on. I’ve spent my career watching it. I was the head of product for artificial intelligence, machine learning and cities at Uber, and some of the best engineers I hired came out of the University of Illinois, Northwestern University and the University of Chicago. Now, I teach at Northwestern’s Kellogg School of Management while building an AI-era identity company, and I watch the same movie on repeat: We grow exceptional technical minds here, and then we watch these talented people get on a plane and head for the coasts. 

That loss shows up on the scoreboard. The 2026 Global Startup Ecosystem Report just ranked Chicago 20th in markets around the world for startups, falling behind Austin, Texas; San Diego and Washington, D.C. Those cities aren’t outsmarting us. They have one thing we don’t: rules for fast-moving technology that are clear enough for a startup to build against. 

This brings me to Senate Bill 315. 

Signed into law recently by Gov. JB Pritzker, SB315 makes Illinois the first state to force large AI developers to hire a third party every year to audit their safety practices “consistent with generally accepted auditing standards and best practices.” The intent is right. Most people, me included, want checks and balances in place for the world’s biggest AI labs.

I’ve built these systems; I know exactly how much can go wrong. 

But SB315 gets the sequence backward. It mandates audits before anyone has defined the standard being audited. 

Every safety regime that actually works follows the same order: standards first, audits second and mandates last. Accounting didn’t start with mandatory audits; it started with generally accepted principles, and audits followed. Pharma didn’t start with Food and Drug Administration enforcement; it started with clinical research protocols that defined what “safe” and “effective” even meant. Then came the trials, then the mandates. 

Here’s the problem with reversing that order: There are no generally accepted AI safety practices in the United States today. No licensing body for AI auditors. No uniform standard. No agreement on what gets measured or by whom. So, when Illinois requires an audit without defining the standard, it hands the power to define “adequate AI safety” to the consulting firms hired to conduct the audits. Their invoices become our de facto law, and the General Assembly never votes on any of it.  

I don’t believe that’s what lawmakers intended. But it’s what pass-first, fix-later lawmaking produces. For a frontier lab, that ambiguity is an expensive nuisance. For a startup, it’s fatal.  

Most Illinois AI startups build on open-source models released by larger labs. If this law pressures those labs to pass through costs or stop releasing models altogether, our startups lose the foundation for the innovations they’re building. A bill aimed at accountability ends up entrenching the incumbents and pushing the builders to California, New York and Texas. 

And it doesn’t stop there. Audit costs and compliance uncertainty flow downstream to the hospitals, banks, manufacturers and schools that run on these tools. 

A practical AI safety framework must follow this path: Lawmakers define the specific harms and outcomes that matter for each of those layers; technical bodies build the evaluations that test for them; the state certifies who is qualified to run those evaluations; and only then do mandates kick in, tiered by actual risk. A chatbot recommending pizza and a model screening job applicants should not face the same audit. 

Lawmakers have the next session to define the outcomes, build the evaluation methods and establish who’s qualified to assess them. I hope they do just that, because this policy could determine whether members of the next generation of AI builders we educate here actually stay here. 

Illinois doesn’t have to choose between safety and growth. We can have both, but only if we regulate in the right order. 

Birju Shah is an associate professor at Northwestern University’s Kellogg School of Management. He also is an entrepreneur and a former Uber AI executive.

Submit a letter, of no more than 400 words, to the editor here or email [email protected].