Law / United States / Illinois

Illinois

United States law applies in Illinois Illinois is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Illinois, described on this page below, applies here too.

15 of 16 named instruments researched to a stage, across five of the six areas of law we track: 13 in force and 2 enacted but not yet in force. As of 20 September 2026.

When they take effect15 of 15 carry a date. Earlier is before 2016.
Before 2016: 3 instruments (3 in force) earlier 2016: 1 instrument (1 in force) 2017: 1 instrument (1 in force) 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 2 instruments (2 in force) ’25 2026: 2 instruments (2 in force) 2027: 1 instrument (1 enacted but not yet in force) 2028: 1 instrument (1 enacted but not yet in force) ’28 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 7
  2. Privacy law 3
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law7 instruments, 6 in force, 1 enacted but not yet in force

Research summary (205 words)

Illinois has enacted a denser cluster of AI-specific statutes than the federal transparency-only baseline covers, reaching employment civil rights, hiring-technology disclosure, publicity and digital-replica rights, mental health practice, child sexual abuse material, nonconsensual intimate imagery, and, starting 2027, frontier AI model safety and audits.

The Illinois Human Rights Act now makes it a civil rights violation for an employer to use AI that has the effect of discriminating on a protected class or to use zip codes as a discrimination proxy, and requires notice whenever AI is used in a covered employment decision, effective January 1, 2026.

Separately, the Artificial Intelligence Video Interview Act (2020) requires disclosure and consent before AI analyzes a recorded job interview, the Right of Publicity Act bans distributing an unauthorized AI-generated voice or image replica of a person, the Wellness and Oversight for Psychological Resources Act (2025) bars AI from independently providing therapy, and the Criminal Code's child sexual abuse material and nonconsensual-image statutes both reach a computer-generated or digitally altered depiction regardless of how it was produced.

The Artificial Intelligence Safety Measures Act (P.A. 104-0538, 2026) will require large frontier AI developers to publish a risk-management framework, undergo independent audits, and report critical safety incidents beginning January 1, 2027.

AI governance

Artificial Intelligence Safety Measures Act

P.A. 104-0538 (SB 315, 104th Gen. Assembly), enacting a new Act and amending 5 ILCS 140/7.5 and 740 ILCS 174/15enacted text of Public Act 104-0538, Illinois General Assembly (ilga.gov)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

The Artificial Intelligence Safety Measures Act splits its duties across two classes of developer. A frontier developer is one that trains, or initiates the training of, a frontier model using more than 10^26 integer or floating-point operations of computing power. A large frontier developer is a frontier developer whose group had annual gross revenues over $500,000,000 in the preceding calendar year.

Every frontier developer must publish a transparency report on its website before or when it deploys a new or substantially modified frontier model. Every frontier developer must also report a critical safety incident to the Illinois Emergency Management Agency and Office of Homeland Security and to the Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that one has occurred.

Where it discovers that a critical safety incident poses an imminent risk of death or serious physical injury, it must separately disclose that incident within 24 hours to an appropriate law enforcement or public safety authority. No frontier developer may retaliate against a covered employee who discloses, with reasonable cause, a specific and substantial danger to public health or safety from a catastrophic risk, or a violation of the Act.

A large frontier developer carries four further duties. It must write, implement and publish a frontier AI framework from January 1, 2028. It must add summaries of its catastrophic-risk assessments to that transparency report. It must obtain an annual independent third-party audit and meet the Act's access, retention and publication requirements for the results.

And it must provide a reasonable internal process through which a covered employee can disclose that kind of information to it anonymously. The Act establishes civil penalties for violations and expressly creates no private right of action, and takes effect January 1, 2027. The bill (as Senate Floor Amendment No. 2, further narrowed by Amendments No. 3 and No. 4) was approved by the Governor on July 6, 2026.

What it requires

AI prohibited practices

Child sexual abuse material, computer-generated and digitally altered depictions

720 ILCS 5/11-20.1 (P.A. 104-245, eff. Jan. 1, 2026)official text, Illinois Compiled Statutes, Illinois General Assembly (ilga.gov)

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Section 11-20.1(a)(7) defines child sexual abuse material to include a film, photograph, or other visual medium or depiction by computer that is or appears to be a person under 18, regardless of the method by which it is created, adopted, or modified to appear as such, a technology-neutral test that reaches an artificial-intelligence-generated or AI-altered depiction on the same footing as a photograph of a real event.

Producing, disseminating, or possessing such material is a felony under subsection (c): a still-image violation is a Class 1 felony and a moving-image violation a Class X felony for most paragraphs of subsection (a), each carrying a mandatory minimum fine and a maximum fine of $100,000, with the mandatory minimum ranging from $1,000 to $2,000 depending on which paragraph of subsection (a) was violated; subsection (c-5) raises every tier to a Class X felony, and a repeat offender to a mandatory 9-year minimum term, where the child depicted is under 13.

The section was renamed from Child Pornography to Child Sexual Abuse Material by Public Act 104-245, effective January 1, 2026, without changing the underlying prohibition.

What it requires

Civil Remedies for Nonconsensual Dissemination of Private Sexual Images Act, digitally altered images

740 ILCS 190/5, 10, 25 (P.A. 103-294, eff. Jan. 1, 2024)official text, Illinois Compiled Statutes, Illinois General Assembly (ilga.gov)

In force since 1 January 2024. Binds public and private bodies.

What this law does

A 2024 amendment added a digitally altered sexual image, defined in Section 5(3.5) as visual media created or substantially altered so that it would falsely appear to a reasonable person to be an authentic depiction of a person, to the images a depicted individual can sue over.

Section 10 gives an identifiable, depicted individual a cause of action against a person over 18 who intentionally disseminates or threatens to disseminate such an image, real or digitally altered (including an AI-generated fake), without consent and knowing or recklessly disregarding that the person did not consent; Section 10(c) specifically bars disclosing that an image was digitally altered as a defense to liability.

A prevailing plaintiff may recover the greater of actual damages or statutory damages of up to $10,000 per defendant under Section 25, plus the defendant's monetary gain, punitive damages, attorney's fees, and injunctive relief.

What it requires

Right of Publicity Act, unauthorized AI digital replica prohibition

765 ILCS 1075/5, 20, 30, 35 (P.A. 103-0836, eff. Jan. 1, 2025)official text, Public Act 103-0836, Illinois General Assembly (ilga.gov)

In force since 1 January 2025. Binds public and private bodies.

What this law does

Section 5 defines a digital replica as a newly created electronic representation of an actual individual's voice, image, or likeness, made using a computer, algorithm, software, tool, artificial intelligence, or other technology, fixed in a sound recording or audiovisual work the individual did not actually perform in, that a reasonable person would believe is that individual.

Section 30(b) makes it unlawful to knowingly distribute, transmit, or make available to the public a sound recording or audiovisual work with actual knowledge that it contains an unauthorized digital replica, enforceable by the individual depicted or their authorized representative under Section 20; Section 35 exempts news, documentary, biographical, comment, criticism, and parody uses unless the replica falsely creates the impression that the individual actually participated.

A service provider that only transmits, stores, or provides access to the material carries a Digital Millennium Copyright Act (DMCA)-style safe harbor under Section 30(e) and (f) if it acts expeditiously once it has actual knowledge of the infringing replica.

What it requires

AI sector rules

Illinois Human Rights Act, use of artificial intelligence in employment decisions

775 ILCS 5/2-102(L) (P.A. 103-0804, eff. January 1, 2026)official text, Illinois General Assembly (ilga.gov), Public Act 103-0804

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Section 2-102(L)(1) makes it a civil rights violation for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of a protected class, or to use zip codes as a proxy for a protected class, with respect to recruitment, hiring, promotion, discharge, discipline, or the terms and conditions of employment.

Section 2-102(L)(2) separately makes it a civil rights violation for an employer to fail to provide notice to an employee that the employer is using artificial intelligence for those purposes; the Illinois Department of Human Rights is directed to adopt rules on the timing, circumstances, and means of that notice.

The Human Rights Act's own employer definition reaches the State and every political subdivision as well as private employers, so this duty binds government and private employers alike.

What it requires

Wellness and Oversight for Psychological Resources Act

Wellness and Oversight for Psychological Resources Act, Public Act 104-0054 (HB 1806, eff. Aug. 1, 2025)official text, Public Act 104-0054, Illinois General Assembly (ilga.gov)

In force since 1 August 2025. Binds private bodies.

What this law does

Section 20(a) bars any individual, corporation, or entity from providing, advertising, or offering therapy or psychotherapy services to the public in Illinois, including through internet-based artificial intelligence, unless the services are conducted by a licensed professional.

A licensed professional may only use AI for administrative or supplementary support, and may never let AI make an independent therapeutic decision, interact directly with a client in therapeutic communication, generate a treatment plan without the professional's review and approval, or detect a client's emotions or mental state; using AI to record or transcribe a session requires prior written notice and the patient's consent.

The Department of Financial and Professional Regulation may assess a civil penalty of up to $10,000 per violation after a hearing, with religious counseling, peer support, and public self-help material exempted.

What it requires

AI transparency

Artificial Intelligence Video Interview Act

820 ILCS 42/1 et seq. (P.A. 101-260, eff. Jan. 1, 2020)official text, Illinois Compiled Statutes, Illinois General Assembly (ilga.gov)

In force since 1 January 2020. Binds private bodies.

What this law does

An employer that asks applicants for Illinois-based positions to record video interviews and uses artificial intelligence to analyze those videos must, before the interview, notify the applicant that AI may be used, explain how the AI works and what general characteristics it evaluates, and obtain the applicant's consent; sharing of the video is limited to persons whose expertise or technology is necessary to evaluate fitness for the position, and an applicant may request deletion of their video within 30 days.

An employer that relies solely on AI analysis of a video interview to decide who receives an in-person interview must collect and annually report race and ethnicity data on applicants and hires to the Department of Commerce and Economic Opportunity, which reports to the Governor and General Assembly whether the data disclose racial bias.

What it requires

Privacy law3 instruments, 3 in force

Research summary (202 words)

Illinois has no comprehensive consumer privacy statute; its dedicated personal-data law is the Biometric Information Privacy Act (740 ILCS 14), the first and most litigated biometric-privacy statute in the United States.

Biometric Information Privacy Act (BIPA) requires a written release before a private entity collects a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, bars profiting from the data, and mandates a public retention and destruction schedule, enforced solely through a private right of action carrying $1,000 to $5,000 statutory damages.

Between 2023 and 2026 the Illinois Supreme Court held claims accrue per scan or disclosure under a uniform five-year limitations period, the legislature capped recovery at one award per person per collection method and recognized electronic signatures as written release, and the Seventh Circuit held that cap applies retroactively to cases already pending; BIPA carries no publicly available data exemption anywhere in its Section 25 construction clause.

Separately, the general Personal Information Protection Act (815 ILCS 530), whose personal information definition expressly reaches biometric data, requires notice to affected residents without unreasonable delay after a breach and to the Illinois Attorney General once a single breach reaches 500 residents for a private data collector or 250 for a State agency.

Biometric privacy

Biometric Information Privacy Act (BIPA)

740 ILCS 14/1, 14/5, 14/10, 14/15, 14/25 (P.A. 95-994, eff. 2008-10-03, as amended by P.A. 103-0769, eff. 2024-08-02)Illinois Compiled Statutes, official code site (current codified text with per-section source notes)

In force since 3 October 2008. Binds private bodies.

What this law does

Requires a private entity to give written notice of the purpose and length of collection, storage and use, and to obtain a written release, before capturing a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry; a 2024 amendment recognizes an electronic signature as a valid release.

Bars selling, leasing, trading, or profiting from biometric data, limits disclosure to consent, a subject-requested transaction, or legal process, and requires a public written retention schedule that destroys the data within 3 years of the individual's last interaction or when the collection purpose is satisfied, whichever is first.

The Act excludes photographs, writing samples, and similar raw items from the definition of biometric identifier, but not an identifier such as a face-geometry scan that is itself enumerated, even when computed from an otherwise excluded item; no controlling appellate holding on that specific application was found.

What it requires

Breach notification

Personal Information Protection Act, data breach notification

815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01)Illinois Compiled Statutes, official code site (current codified text)

In force since 1 January 2006. Binds public and private bodies.

What this law does

Requires a data collector, government agency or private entity, holding computerized personal information of Illinois residents to notify affected residents of a security breach in the most expedient time possible and without unreasonable delay.

Personal information expressly includes unique biometric data used to authenticate an individual, such as a fingerprint, retina or iris image, or other physical or digital biometric representation, alongside a name paired with a Social Security number, account number, or medical information.

A data collector must notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, and a State agency must do so above 250 residents; a violation is an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.

What it requires

Enforcement supervision

BIPA Private Right of Action and 2024 Damages Amendment (SB 2979 / P.A. 103-0769)

740 ILCS 14/20, as amended by P.A. 103-0769 (SB 2979), eff. 2024-08-02Illinois Compiled Statutes official code site and Illinois General Assembly, Public Act 103-0769 (enrolled act)

In force since 2 February 2023, effective 2 August 2024. Binds private bodies.

What this law does

Arms any person aggrieved by a Biometric Information Privacy Act (BIPA) violation with a private right of action in state circuit court or as a supplemental federal claim, recovering the greater of $1,000 or actual damages for a negligent violation and the greater of $5,000 or actual damages for an intentional or reckless violation, plus attorneys' fees, costs, and injunctive relief.

The Illinois Supreme Court held a claim accrues with each scan or disclosure (Cothron v. White Castle, 2023) under one uniform five-year limitations period for every Section 15 claim (Tims v. Black Horse Carriers, 2023); a 2024 amendment then capped recovery at one award per person per collection or disclosure method, responding directly to Cothron's invitation to the legislature to revisit the resulting damages exposure.

The Seventh Circuit held in 2026 that the cap is a remedial change to available damages, not a substantive change to BIPA's liability standard, so it applies retroactively to cases already pending when the amendment took effect (Clay v. Union Pacific Railroad Co., 2026).

What it requires

Scraping law2 instruments, 2 in force

Research summary (247 words)

Illinois is the most consequential jurisdiction in this batch, not because of a scraping statute but because of the Biometric Information Privacy Act (Biometric Information Privacy Act (BIPA)), a private-right-of-action statute that has produced more scraping-adjacent litigation than any other law surveyed in this topic, because scraping photographs from the open web to build facial scans of face geometry is squarely how the leading BIPA scraping defendant, Clearview AI, built its database.

Illinois also has its own computer tampering statute with an authorization test that, unusually, expressly ties authorization for guest or public network access to compliance with an owner's posted terms and conditions, giving a ToS violation potential criminal significance beyond an ordinary breach-of-contract claim.

Illinois notably has no comprehensive consumer data privacy act of the kind several peer states carry; BIPA is a narrower, biometric-only statute, and general scraped personal data (name, address, purchase history) that is not a biometric identifier has no Illinois-specific statutory reach beyond general consumer-protection and common-law doctrines, which is a genuine finding for this dimension rather than a gap.

Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability beyond the computer tampering statute's own text, and the Illinois Consumer Fraud and Deceptive Business Practices Act, rest on general law not independently confirmed against primary text, so neither earns its own instrument. robots.txt carries no independent legal weight in Illinois, and BIPA is training-data-source-neutral: it regulates collection of biometric identifiers regardless of whether the collector goes on to train a model.

Computer misuse

Illinois Computer Tampering, authorization tied to posted network terms

720 ILCS 5/17-51official text, Illinois General Assembly (ilga.gov)

In force since 12 August 2016. Binds public and private bodies.

What this law does

Section 17-51(a) provides that a person commits computer tampering when he or she knowingly and without the authorization of a computer's owner or in excess of the authority granted to him or her accesses a computer, network, program, or data, naming both the without authorization and in excess of authority granted prongs the Computer Fraud and Abuse Act (CFAA) is built on, unaffected in its Illinois application by Van Buren v. United States, which narrowed only the federal statute.

Distinctively, subsection (a-10) provides that accessing a computer network is deemed to be with the authorization of a computer's owner if the owner authorizes patrons, customers, or guests to access the computer network and the person accessing it is an authorized patron, customer, or guest and complies with all terms or conditions for use of the computer network that are imposed by the owner.

This textually ties authorization for guest or public access to compliance with the site owner's own posted terms and conditions, a more explicit authorization-follows-ToS link than a bare computer-misuse statute carries elsewhere, and means a scraper that violates a site's terms of use for public access may be reading itself out of the (a-10) safe harbor even absent any technical circumvention. No Illinois appellate decision applies this provision to scraping specifically.

What it requires

Personal data

Biometric Information Privacy Act (BIPA), consent duty for scraped-photo facial geometry

740 ILCS 14/1 et seq. (P.A. 95-994, 2008; amended by P.A. 103-769, eff. Aug. 2, 2024)official text, Illinois General Assembly (ilga.gov)

In force since 2 August 2024. Binds private bodies.

What this law does

Section 15(b) requires a private entity, before it may collect, capture, purchase, receive through trade, or otherwise obtain a person's biometric identifier or biometric information, to inform the subject in writing that the data is being collected or stored, inform the subject in writing of the specific purpose and retention period, and obtain a written release.

Section 10 defines biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, expressly excluding photographs and physical descriptions on their own; a scan of face geometry derived from a photograph, rather than the photograph itself, is what the statute reaches.

This is precisely the scraping fact pattern behind Biometric Information Privacy Act (BIPA)'s most consequential litigation: Clearview AI scraped several billion photographs from the open web to construct facial-geometry faceprints without notice or consent, settled a state-court suit in May 2022 (ACLU v. Clearview AI) under a nationwide permanent injunction, and reached a roughly $51.75 million equity-stake class settlement in a parallel federal multidistrict litigation in March 2025.

BIPA carries a private right of action (section 20(a)) for each violation, liquidated damages of $1,000 or actual damages for a negligent violation and $5,000 or actual damages for an intentional or reckless one, plus attorney's fees, a materially more exposed damages structure than any general privacy act researched, none of which carries a private right of action at all.

The 2024 amendment, P.A. 103-769, effective August 2, 2024, added section 20(b)-(c) limiting a private entity to at most one recovery per person per method of collection or disclosure, responding to Cothron v. White Castle System, Inc., 2023 IL 128004 (Ill. 2023), which had held a separate claim accrues each time biometric data is scanned or transmitted.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (467 words)

Illinois has no enacted product-security law: no statute sets security requirements a connected device or software product must meet before or after it reaches the market, and no bill modeled on California's or Oregon's connected-device statutes has been introduced here, so this is a researched absence rather than a gap in coverage.

Illinois has no general private-sector duty to report an exploited vulnerability or a security incident to an authority, and no cybersecurity safe-harbor statute conditioning an affirmative defense on a framework-conforming security program, of the kind Utah, Ohio and Iowa enacted; both are researched absences. The Insurance Data Security Law (215 ILCS 215, P.A. 103-142, eff.

1 January 2024), modeled on the NAIC Insurance Data Security Model Law, requires each insurance licensee to develop, implement, and maintain a comprehensive written information security program and to notify the Director of Insurance of a cybersecurity event within 3 business days of determining one occurred, enforced through the Illinois Insurance Code's own penalty provisions and expressly creating no private cause of action; because its bound party, an insurance licensee, is a role the LexLint activity vocabulary cannot yet express (#6740), it is deferred rather than flagged on a guess, and no instrument for it is filed here.

Illinois's baseline security duty is split out of the state's breach-notification statute in the same pattern as New York's SHIELD Act: the Personal Information Protection Act (815 ILCS 530) Section 45 requires a data collector to implement and maintain reasonable security measures over records containing an Illinois resident's personal information, and Section 40 separately requires that materials containing personal information be safely disposed of, each a standalone duty whose trigger is holding personal information rather than a section of a comprehensive privacy regime, so both are researched here rather than folded into the already-researched breach-notification row.

Section 45 states no penalty of its own; Section 20 deems a violation of the Act an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, exposing a violator to the Attorney General's injunctive and civil-penalty authority, up to $50,000 or up to $50,000 per violation on a finding of intent to defraud, and to a private action for actual damages and attorneys' fees.

Section 40 carries its own Attorney-General-enforced civil penalty of up to $100 per individual, capped at $50,000 per instance of improper disposal.

Illinois's breach-notification duty, Personal Information Protection Act Sections 10 and 12, and the Biometric Information Privacy Act's own storage and protection clause (740 ILCS 14/15(e), requiring a private entity to protect biometric data using the reasonable standard of care within its industry) are already this jurisdiction's privacy rows rather than repeated here: the first is a notice-to-the-person duty, and the second is the biometric regime's own security-of-processing clause inside a data-specific statute already fully researched under that topic.

Security baseline statutes

Personal Information Protection Act, data security duty

815 ILCS 530/45 (P.A. 99-503, eff. 2017-01-01)Illinois Compiled Statutes, official code site

In force since 1 January 2017. Binds public and private bodies.

What this law does

A data collector, defined to include a government agency, a public or private university, and a privately or publicly held corporation, that owns or licenses, or maintains or stores without owning or licensing, records containing personal information about an Illinois resident must implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

It must require by contract that any party to whom it discloses that information do the same. A data collector already subject to and compliant with Gramm-Leach-Bliley Act Title V standards, or with a state or federal law requiring greater protection, is deemed to comply.

The duty carries no penalty of its own; Section 20 deems a violation of the Act an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, exposing a violator to the Attorney General's injunctive and civil-penalty authority and to a private action for actual damages.

What it requires

Personal Information Protection Act, safe disposal of personal information

815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01)Illinois Compiled Statutes, official code site

In force since 1 January 2012. Binds public and private bodies.

What this law does

Any person, defined to include a natural person, a corporation or other legal entity, a unit of local government, or the State of Illinois or one of its agencies, that disposes of materials containing personal information about an Illinois resident must do so in a manner that renders the personal information unreadable, unusable, and undecipherable, such as by redacting, burning, pulverizing, or shredding paper records, or destroying or erasing electronic media.

A third party contracted to dispose of such materials must implement and monitor policies and procedures against unauthorized access, acquisition, or use of personal information during collection, transport, and disposal. A financial institution regulated under Gramm-Leach-Bliley Act Title V, or a person subject to the disposal rule at 15 U.S.C. section 1681w, is exempt.

The Attorney General may impose a civil penalty of up to $100 per individual whose information was improperly disposed of, capped at $50,000 per instance of improper disposal, after notice and an opportunity to be heard, and may separately bring a circuit court action for any appropriate relief; Section 20 also deems a violation of this Section an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.

What it requires

Age gating law1 instrument, 1 enacted but not yet in force

Research summary (115 words)

Illinois has no age verification or age gating law currently in effect. HB 5511, a device level age signal and default minor protections bill for social media and connected devices, passed both chambers unanimously (final passage June 1, 2026) and was signed by the Governor on July 31, 2026 as Public Act 104-0664; its provisions do not take effect until January 1, 2028. The Act's short title is the Children's Online Social Media Safety Act; it was introduced as the Digital Age Assurance Act.

A separate adult content age verification bill (SB 3945) remains in committee and has not passed either chamber. Illinois has not enacted an app store age verification or design code law.

App store age verification (AV)

HB 5511 (2026), Children's Online Social Media Safety Act

Illinois Public Act 104-0664 (2026), enrolled as HB 5511, 104th General Assemblyofficial Public Act text, Illinois General Assembly

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

Requires internet enabled device operating systems to offer an age signal at device setup and pass an age category to apps and social media platforms on request, which must then apply default protections such as restricting algorithmic recommendations and notification hours for minors. Passed the House April 16, 2026, passed the Senate 57 to 0 with a 113 to 0 House concurrence on June 1, 2026, was sent to the Governor on June 26, 2026, and was signed July 31, 2026 as Public Act 104-0664. It was introduced as the Digital Age Assurance Act.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.