What happened? Governor Pritzker established the Illinois AI Cabinet on September 22, 2026. The Cabinet’s mandate includes AI liability, cybersecurity, privacy, contracts, data centers, and whether existing legal remedies are sufficient when AI causes harm.
Who should pay attention? Any Illinois business that uses AI tools in its operations, including hiring software, customer service automation, marketing platforms, contract review tools, data analytics, and scheduling systems.
What should you do right now? You do not need to wait for the Cabinet to issue recommendations to start protecting yourself. The legal risks around AI use are already real under existing Illinois and federal law. Now is the time to audit how your business uses AI and make sure the foundation is solid before new rules arrive.
Illinois just made a significant move on artificial intelligence. On September 22, 2026, Governor Pritzker established the Illinois AI Cabinet, a formal state body charged with developing policy recommendations across a remarkably broad set of AI-related issues — including who is legally responsible when AI causes harm, how AI intersects with privacy and cybersecurity obligations, what AI means for existing contracts, and whether Illinois needs new data center infrastructure to support the technology.
For most Illinois business owners, the instinct will be to wait and see. That instinct is understandable. But it is probably the wrong call.
Here is why, and what, to do in the meantime.
WHAT THE ILLINOIS AI CABINET IS AND WHAT IT IS CHARGED WITH DOING
The Illinois AI Cabinet is a formal executive body created by Governor Pritzker to develop a coordinated state approach to artificial intelligence policy. Its mandate is notably specific and notably broad at the same time.
The Cabinet has been charged with developing recommendations covering:
AI liability: who bears legal responsibility when an AI system causes harm, makes a discriminatory decision, produces a false output, or fails in ways that injure individuals or businesses.
Cybersecurity: how AI systems introduce new vulnerabilities, and what obligations businesses have to secure AI tools and the data they process.
Privacy: how AI intersects with Illinois’s existing privacy framework, including the Biometric Information Privacy Act (BIPA) and broader consumer data protections, and what new protections may be needed.
Contracts: how existing contract law applies to AI-generated outputs, AI-assisted decisions, and agreements made with or through AI systems, and where the law may be insufficient.
Data centers: what infrastructure Illinois needs to support AI development and deployment, and what obligations or opportunities that creates for businesses.
Whether existing legal remedies are adequate, a direct signal that the Cabinet is being asked to identify gaps in current Illinois law where AI-related harms cannot be effectively remedied under existing frameworks.
That last point is the one businesses should pay particular attention to. When a government body is asked to assess whether existing remedies are sufficient, new legislation typically follows.
WHY THIS MATTERS FOR ILLINOIS BUSINESSES RIGHT NOW
The AI Cabinet has not yet issued recommendations. No new Illinois AI law has been passed as a result of its creation. So why does this matter today?
Because the legal risks around AI use in Illinois already exist under current law, and the Cabinet’s mandate signals that those risks are about to get more formal attention, more regulatory structure, and very likely new legal requirements.
Illinois businesses that use AI tools are already operating in a legal environment that includes:
The Illinois Human Rights Act’s existing AI provisions, which prohibit using AI in employment decisions in ways that result in unlawful discrimination and require notice when AI is used for covered employment decisions. These provisions are already in effect.
BIPA, which applies whenever biometric data, including facial recognition and voiceprints, is collected, processed, or stored, including by AI systems. Illinois businesses that use AI tools touching biometric data are already subject to BIPA’s notice, consent, and retention requirements.
The Illinois Consumer Fraud and Deceptive Business Practices Act, which can apply when AI-generated outputs are used in ways that mislead consumers or business partners.
Federal frameworks including the FTC’s existing authority over deceptive AI practices and emerging federal AI guidance that applies regardless of what Illinois does.
The AI Cabinet’s work will layer new requirements on top of this existing framework. Businesses that have not addressed their current exposure will face a compounding problem when new rules arrive.
THE SIX AREAS OF THE CABINET’S MANDATE: WHAT EACH MEANS FOR YOUR BUSINESS
AI Liability
The question of who is legally responsible when AI causes harm is one of the most unsettled areas in law right now. If your business uses an AI tool that produces a discriminatory hiring recommendation, a false output that injures a customer, or a flawed analysis that leads to a bad business decision, the liability picture is genuinely unclear under current law.
What is clear is that “the AI did it” is not a legal defense. Courts and regulators have consistently treated AI outputs as the responsibility of the business that deployed the tool. The AI Cabinet is being asked to develop a clearer framework for that responsibility, which means the framework is coming. Illinois businesses should be thinking now about how they document AI use, what human review processes they have in place, and what their vendor contracts say about liability for AI errors.
Cybersecurity
AI systems introduce cybersecurity risks that many businesses have not fully assessed. AI tools process large volumes of sensitive data, often through third-party platforms with their own security postures. They can be manipulated through adversarial inputs. They may retain data in ways that are not fully transparent. And a breach of an AI system can expose not just the data it holds but the proprietary processes and models it runs.
Illinois already has breach notification obligations under the Personal Information Protection Act (PIIPA). The AI Cabinet’s cybersecurity mandate signals that AI-specific security requirements are likely coming. Businesses should be reviewing their AI vendors’ security practices, their own data handling protocols, and their breach response plans now.
Privacy
Illinois has some of the strongest privacy protections in the country, anchored by BIPA and supplemented by other state consumer protection frameworks. AI tools that collect, analyze, or process personal data, including behavioral data, location data, purchasing patterns, and communications, are already subject to these protections.
The Cabinet’s privacy mandate suggests Illinois is evaluating whether its existing framework is sufficient for AI-specific privacy risks, including the use of AI to infer sensitive characteristics from non-sensitive data. Businesses should audit what personal data their AI tools collect and process, and whether current disclosures and consent practices are adequate.
Contracts
AI is already changing how contracts are drafted, reviewed, and negotiated. It is also raising questions that existing contract law was not designed to answer: Who owns an AI-generated work product? What happens when an AI system makes a representation that turns out to be false? Is a contract enforceable when one party used AI to generate material terms without disclosure? What does a vendor’s indemnification clause actually cover when an AI error causes harm?
The Cabinet’s focus on contracts is a signal that Illinois is taking these questions seriously. Businesses should be reviewing their vendor agreements for AI-specific provisions, particularly indemnification, liability caps, data ownership, and accuracy warranties, and making sure their own client agreements address AI use where relevant.
Data Centers
The data center component of the Cabinet’s mandate is primarily an infrastructure and economic development question, what Illinois needs to build to support AI growth. For most small and mid-sized businesses, this part of the mandate has less immediate practical impact. But it signals that Illinois is planning for AI to be a long-term, significant part of the state’s economic landscape, which means the regulatory framework around it is also going to be long-term and significant.
Whether Existing Legal Remedies Are Sufficient
This is the mandate item that most directly signals new legislation. The Cabinet has been explicitly charged with evaluating whether current Illinois law gives individuals and businesses adequate tools to seek remedies when AI causes harm. When the answer to that question is no — and it almost certainly will be for at least some categories of harm, the legislature will be asked to fill the gap.
Illinois businesses that want to influence that process, or at least understand what is coming, should be paying attention to the Cabinet’s work and engaging with counsel as recommendations develop.
WHAT ILLINOIS BUSINESSES SHOULD DO RIGHT NOW
You do not need to wait for the Cabinet’s recommendations to take action. The businesses that will be best positioned when new AI rules arrive are the ones that have already built a solid foundation under current law.
Audit your AI tools.
Make a complete list of every AI-enabled tool your business uses or that is embedded in platforms you use, hiring software, customer service automation, marketing analytics, contract review tools, scheduling systems, financial modeling, and any other platform that uses algorithmic or machine learning methods to make or influence decisions. Many businesses are using AI without realizing it.
Review your vendor contracts.
For every AI tool on your list, pull the contract and look for provisions covering data ownership, liability for errors, indemnification, security standards, breach notification, and accuracy warranties. Most standard vendor agreements were not written with AI-specific risks in mind. Gaps in these contracts are your exposure.
Assess your employment AI use.
If any of your AI tools are used to make or influence employment decisions, hiring, scheduling, performance evaluation, discipline, review your compliance with the Illinois Human Rights Act’s existing AI provisions. Required notices, bias safeguards, and documentation practices should already be in place.
Check your BIPA exposure.
If any AI tool your business uses touches biometric data, facial recognition, voiceprints, fingerprint data, your BIPA obligations are already triggered. Consent, notice, retention policies, and vendor contracts need to be reviewed.
Update your privacy disclosures.
If your business’s privacy policy or customer disclosures do not address AI use, they should. As the regulatory environment tightens, businesses that have been transparent with customers about how AI is used in their operations will be in a far better position than those that have not.
Document your AI decision-making processes.
For any significant business decision influenced by AI, a hiring recommendation, a credit decision, a customer classification, a pricing model, document the human review process. The ability to show that a person reviewed and took responsibility for an AI-assisted decision is going to become increasingly important as liability frameworks develop.
YOUR AI COMPLIANCE CHECKLIST FOR ILLINOIS BUSINESSES
- Complete a full audit of all AI tools used in your business operations.
- Identify which tools influence employment decisions and confirm compliance with Illinois Human Rights Act AI provisions.
- Pull all vendor contracts for AI tools and review data ownership, liability, and indemnification provisions.
- Assess whether any AI tools process biometric data and confirm BIPA compliance.
- Review privacy disclosures and customer communications for accuracy regarding AI use.
- Implement documented human review processes for significant AI-assisted decisions.
- Review cybersecurity practices for AI platforms and confirm vendor security standards.
- Confirm breach notification procedures cover AI system breaches under Illinois PIIPA.
- Monitor Illinois AI Cabinet recommendations as they are issued.
- Engage legal counsel to assess exposure under current law and prepare for new requirements.
FREQUENTLY ASKED QUESTIONS
What is the Illinois AI Cabinet?
The Illinois AI Cabinet is a formal executive body established by Governor Pritzker on September 22, 2026. It is charged with developing policy recommendations on artificial intelligence across a range of issues including liability, cybersecurity, privacy, contracts, data infrastructure, and whether existing legal remedies are adequate when AI causes harm.
Has the Illinois AI Cabinet passed any new laws yet?
No. The Cabinet has been established and charged with developing recommendations. It has not yet issued those recommendations, and no new Illinois AI legislation has been passed as a direct result of its creation. However, its mandate signals that new legal requirements are likely coming, and Illinois businesses should be preparing now rather than waiting.
Does my small business need to worry about AI regulation if I just use standard software tools?
Possibly. Many standard business software platforms, applicant tracking systems, scheduling tools, customer service platforms, marketing analytics, and performance management software, now include AI components, often without obvious labeling. If those tools influence employment decisions, collect biometric data, or process personal information, existing Illinois law may already apply. The AI Cabinet’s work is likely to expand those requirements.
What does the AI Cabinet’s focus on liability mean for businesses?
It means Illinois is working toward a clearer legal framework for who is responsible when AI causes harm. Under current law, that picture is unclear — but courts and regulators have consistently held that businesses are responsible for the AI tools they deploy, regardless of whether the AI vendor shares that responsibility. Businesses should be documenting their AI use and human review processes now.
What is the connection between the Illinois AI Cabinet and BIPA?
BIPA already applies to AI tools that collect or process biometric data, including facial recognition systems, voiceprint analysis, and fingerprint-based authentication. The AI Cabinet’s privacy mandate suggests Illinois is evaluating whether BIPA and related frameworks are sufficient for AI-specific privacy risks, which could mean expanded requirements for businesses using these tools.
How should I prepare for AI regulations that have not been written yet?
The most effective preparation is getting your current compliance in order. Businesses that have audited their AI tools, reviewed their vendor contracts, confirmed their employment AI compliance, and documented their decision-making processes will be able to adapt to new requirements far more efficiently than those starting from scratch. Engage legal counsel now rather than when the rules arrive.
CONSULT WITH EXPERIENCED ILLINOIS BUSINESS ATTORNEYS
The Illinois AI Cabinet is a clear signal that significant new legal requirements for AI use are coming. The businesses that will navigate that transition most successfully are the ones that have addressed their current exposure before new rules force the issue.
George Bellas, SuperLawyer at Bellas & Wachowski have been counseling Illinois business owners for over 50 years. As Illinois’s AI regulatory framework develops, we are here to help your business stay ahead of it.
Contact us for a consultation.
This article is provided for general informational purposes only and does not constitute legal advice. You should not act upon any information in this article without seeking the advice of a licensed attorney. Prior results do not guarantee a similar outcome.
Chicago Business Attorney Blog

