By Kim Xi Harris | Founder & Platform Architect, Lex Arca™ Legal Vault | Calculate your firm’s billing leakage | legalvault@lex-arca.com

According to Clio’s 2026 Legal Trends Report for Solo and Small Law Firms (May 2026, https://www.clio.com/about/press/2026-solo-small-firm-report/), 71% of solo practitioners and 75% of small firms are now using AI to complete legal work — yet fewer than 33% have seen any revenue increase from it, compared to nearly 60% of enterprise firms. The gap between AI adoption and AI results is not a training problem. It is an architecture problem.

Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on July 6, 2026 — establishing one of the most stringent AI developer audit mandates in the country. The Act requires annual independent third-party audits of AI developers operating in Illinois and mandates transparency disclosures that developers cannot satisfy through self-reporting. For law firms in Illinois using AI tools on client matters, the question is no longer whether the developer complied. It is whether you verified that before deploying the tool.

What Does Illinois SB 315 Actually Require?

Illinois Senate Bill 315 — the Artificial Intelligence Safety Measures Act — mandates that AI developers operating in Illinois submit to annual independent third-party audits assessing the accuracy, reliability, and safety of their systems. Developers must disclose the results of those audits to regulators and maintain records of AI-generated outputs used in high-stakes decisions.

SB 315 was enacted because Illinois legislators determined that AI developers could not self-certify compliance. The same marketing materials that law firms have been using to evaluate AI tools — accuracy claims, uptime percentages, enterprise security attestations — are not audits. They are sales collateral. SB 315 creates a mechanism for independent verification of what AI developers actually produce, rather than what they claim their tools produce.

For law firms, SB 315 shifts the baseline expectation. A firm that deployed an AI tool based on vendor representations, without any independent verification of the tool’s audit status, has operated on a standard that the State of Illinois has now formally declared insufficient for developers. The attorney’s obligation under ABA Formal Opinion 512 to understand the capabilities and limitations of any AI tool remains unchanged — and SB 315 provides the verification framework that makes that obligation practicable.

Does SB 315 Apply Directly to Law Firms, or Only to AI Developers?

SB 315’s direct obligations fall on AI developers, not on law firms as end users. Developers operating in Illinois must conduct and publish audits. Law firms using those developers’ tools are not independently regulated by SB 315.

But the implication for law firms is structural. ABA Formal Opinion 512 (July 29, 2024) requires attorneys to maintain “a reasonable understanding of any AI tool used in their practice, including its capabilities and limitations.” If a developer cannot produce an SB 315 audit when a law firm asks — or if the developer’s most recent audit raises concerns about output accuracy or reliability — that is information the attorney is now on notice to request. Deploying an unaudited or audit-failed AI tool on a client matter, after SB 315 establishes that independent auditing is the applicable standard, is a harder position to defend under Rule 1.1’s competence requirement.

The connection is direct: SB 315 creates an external, mandatory audit standard for AI developers. ABA 512 requires attorneys to understand their tools. Understanding your tool now includes knowing whether it meets the independent audit standard that Illinois has established. Understanding the ABA Opinion 512 compliance workflow is no longer a standalone compliance exercise — it now intersects with state AI developer regulation.

What Should Illinois Law Firms Do Before Deploying AI on Client Matters?

The practical obligation SB 315 creates for Illinois law firms is a due diligence step that most firms have not been taking: ask the developer for their audit results before deploying the tool on client matters.

The question to ask every AI vendor: Is your platform subject to independent third-party auditing under Illinois SB 315 or a comparable standard, and can you produce the most recent audit report? A vendor that cannot answer that question — or whose answer is a marketing document rather than an audit report — has not satisfied the transparency standard SB 315 was designed to enforce.

For matters already in progress using AI tools deployed before SB 315 took effect, the obligation is the same one ABA 512 has always imposed: the attorney must be able to demonstrate that AI output was verified before reliance. A documented activity trail showing the attorney’s verification steps — independent of the AI tool’s own audit status — is the record that protects the client and the practice. The tool’s compliance with SB 315 is the developer’s obligation. The attorney’s verification of the output is always the attorney’s.

From Kim’s Chair: The Questions I Would Have Asked

I did not build Lex Arca™ Legal Vault by taking AI developers at their word. I built it because I understand what it means to be the person downstream from a system that no one independently verified — to have relied on output assembled by tools whose accuracy claims existed only in sales decks. When I read about Illinois SB 315, I do not see a regulatory compliance exercise for developers. I see the law firms that deployed tools on client matters on the assumption that vendor representations were sufficient, and the clients whose matters were handled on that assumption.

If I were in the Illinois Governor’s signing event for SB 315 as a client whose attorney used AI tools on my matter, here is what I would ask:

1. SB 315 mandates annual independent third-party audits because Illinois determined that AI developers could not self-certify compliance — but law firms have been deploying those same unaudited tools on client matters since 2023. What standard should have applied to law firm AI deployment during the period before SB 315 created an external accountability mechanism?

2. The Act requires audit transparency to regulators — but the clients of the law firms using those tools are not regulators. Who has the obligation to tell a client that the AI tool used on their matter had never been independently audited?

3. SB 315 was enacted because self-certification was not enough for AI developers — but law firms have been self-certifying AI tool competence to their own clients under ABA 512’s “reasonable understanding” standard. What would make that self-certification adequate?

4. If an AI developer fails an SB 315 audit after a law firm has been using that tool for 18 months on active client matters, what does the client’s recourse look like — and does that audit result trigger any disclosure obligation for the attorney?

And if I were your client — whose matter you handled using an AI tool deployed in Illinois — here is what I would have asked you:

1. The AI tool you used on my matter — did you ask the developer for an independent audit report before deploying it on a client matter, and does one exist?

2. Illinois SB 315 establishes that AI developer self-certification is not sufficient — did you evaluate the tool I was billed for on a standard higher than the developer’s own marketing materials?

3. ABA Formal Opinion 512 requires you to understand your AI tool’s capabilities and limitations. What specifically did you learn about the limitations of the tool you used on my matter, and where is that documented?

4. If that tool’s accuracy or reliability is later called into question through an SB 315 audit finding, is there a verification record in my file showing that you checked its output independently before relying on it?

The attorneys who can produce that verification record — independent of whatever the developer’s audit shows — are the attorneys whose clients are protected regardless of what SB 315 subsequently reveals about the tool. The ones who cannot are relying on the audit to do a job the audit was never designed to do.

Key Takeaways

1. Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on July 6, 2026, requiring annual independent third-party audits of AI developers operating in Illinois — establishing that self-certification by AI vendors is not a sufficient compliance standard.

2. SB 315’s direct obligations fall on AI developers, not law firms, but its audit standard creates a due diligence baseline for Illinois attorneys: asking AI vendors for independent audit results before deploying their tools on client matters is now the applicable standard of care.

3. Attorneys whose AI tools cannot produce an SB 315 audit report should redouble their reliance on attorney-side verification documentation — the timestamped activity trail that shows the attorney checked AI output independently, regardless of the developer’s compliance status.

4. Lex Arca™ Legal Vault provides a documented, verifiable AI activity trail designed to support attorney compliance workflows — including the attorney-side verification record that protects clients and practitioners regardless of what any developer audit subsequently reveals.

5. Calculate your firm’s billing leakage and get early access at https://calculator.lex-arca.com.


About the Author: Kim Xi Harris is the Founder and Platform Architect of Lex Arca™, an AI-native litigation intelligence and compliance platform for solo and small-firm attorneys. She is a Cornell Women’s Entrepreneur Program graduate, SBA Women in Business Champion Award recipient, WOSB certified, and holds five Google AI certifications. Calculate your firm’s billing leakage at https://calculator.lex-arca.com — or reach us at legalvault@lex-arca.com.