Illinois SB 3444, the Artificial Intelligence Safety Act, is a state bill that would establish a conditional liability safe harbor for developers of frontier AI models. A developer that publishes a safety-and-security protocol and a transparency report would not be liable for "critical harms" caused by its model, provided it did not intentionally or recklessly cause the harm. The bill applies only to frontier developers (defined by a $100 million / 10^26 FLOPs threshold) and self-sunsets if federal law establishes overlapping requirements. OpenAI publicly supports the bill.
The Act is structured as an affirmative defense rather than an administrative regulatory regime, which distinguishes it from duty-based and strict-liability approaches advanced elsewhere; critics describe it as an immunity grant.
| Field | Value |
|---|---|
| Full title | Artificial Intelligence Safety Act |
| Bill number | SB 3444 |
| Enacting body | Illinois General Assembly (104th GA), Senate |
| Primary sponsor | Sen. Bill Cunningham (D) |
| Introduced / First Reading | February 4, 2026 |
| Status | Referred to Senate AI and Social Media Committee (2/18/2026); committee deadline 4/24/2026 |
| Source | Illinois SB 3444 — Artificial Intelligence Safety Act (source summary); Raw Sources/Illinois SB 3444 - Artificial Intelligence Safety Act.md (full text) |
Status and timeline
SB 3444 received its first reading on February 4, 2026 and was referred to the Senate AI and Social Media Committee on February 18, 2026, with a committee deadline of April 24, 2026. The primary sponsor is Sen. Bill Cunningham (D), and the bill is before the 104th Illinois General Assembly.
Scope and definitions
The Act applies to developers of frontier AI models. A frontier model is defined disjunctively as a model trained using either greater than 10^26 computational operations or compute costs exceeding $100,000,000. A "developer" is any person or organization that has trained, or initiated the training of, at least one frontier model. As described in the source reporting, the practical scope covers OpenAI, Google DeepMind, Anthropic, xAI, and Meta, and excludes open-source fine-tuners, startups, deployers, and non-frontier labs.
Section 5 sets out the governing definitions:
- Artificial Intelligence Model. An engineered or machine-based component of a system, varying in autonomy, capable of generating outputs that influence physical or virtual environments.
- Frontier Model. Greater than 10^26 FLOPs or greater than $100M compute cost.
- Critical Harm. Either (a) death or serious injury of 100 or more people, or (b) at least $1B in property damage — and in either case caused through (i) CBRN weapon creation or use or (ii) autonomous criminal conduct by the AI model without meaningful human intervention.
- Developer. A person or organization that has trained, or initiated training of, at least one frontier model.
Key provisions
Section 10 — liability protection (safe harbor)
A developer is not liable for critical harms caused by a frontier model if all of the following hold: the developer did not intentionally or recklessly cause the harm; before release, the developer published a safety-and-security protocol on its public website; and at the time of release, the developer published a transparency report on its public website.
A developer is alternatively deemed compliant if it either agrees to be bound by Article 56 of the EU AI Act safety-and-security requirements (the GPAI Code of Practice — see EU General-Purpose AI Code of Practice (Final Version, 2025)), or enters an agreement with a federal government agency providing model access, evaluation, and public disclosure of findings meeting specified requirements.
Section 15 — safety and security protocol
The protocol must document at minimum: testing procedures; thresholds for assessing risk of critical harm; mitigation measures; third-party assessments; cybersecurity practices for model weights and training infrastructure; post-deployment monitoring; and processes for identifying material new risks after release. Trade-secret and cybersecurity redactions are permitted.
Section 20 — transparency report
The report must at minimum identify the frontier model and version, summarize assessment results, and describe risk-mitigation steps taken pre-release. Redactions are permitted for security or proprietary reasons.
Section 25 — sunset / federal preemption trigger
The Act ceases to apply if federal law establishes overlapping safety requirements for frontier models.
Enforcement
The bill is structured as an affirmative defense and liability shield rather than an administrative regulatory regime. It creates no new state enforcement body, no pre-market approval, no mandatory agency reporting, and no fine schedule. A non-compliant developer loses the shield and faces ordinary common-law tort liability, which the source reporting describes as heavily attenuated by causation, foreseeability, and proximate-cause doctrines in catastrophic-harm cases.
Reactions
OpenAI publicly supports the bill, which the source reporting characterizes as a departure from its defensive-only posture during California SB 1047 (2024). Caitlin Niedermeyer of OpenAI Global Affairs testified in committee, and spokesperson Jamie Radice framed the bill as reducing harms while avoiding a "patchwork of state-by-state rules." Per the reporting, it is the first state AI bill OpenAI has publicly championed rather than opposed.
Scott Wisor of the Secure AI Project opposed the bill, stating: "There's no reason existing AI companies should be facing reduced liability." Critics characterize the bill as an immunity grant disguised as a safety act, and argue that its name (Artificial Intelligence Safety Act) misrepresents its function as a shield rather than a duty.
Several structural features have drawn commentary in the source reporting. The bill does not require that published protocols be effective, only that they be published; a developer whose protocol concedes inability to mitigate a risk would appear to retain the shield. The trade-secret and cybersecurity redactions are unconstrained, which critics argue could reduce transparency reports to marketing documents. Plaintiffs in CBRN or autonomous-crime cases would face causation problems and a recklessness bar, a difficult path even without the shield. OpenAI, Anthropic, Google, and others are already GPAI Code of Practice signatories, so the Article 56 alternative compliance path requires no US-specific action. By sunsetting on overlapping federal law, the Act functions as a placeholder, which the reporting notes is consistent with OpenAI's stated preference for federal over state regulation.
Comparison with the AI LEAD Act (federal)
SB 3444 and the AI LEAD Act take opposite positions on liability for the same frontier-developer population. The following table summarizes the contrast drawn in the source reporting.
| Dimension | IL SB 3444 (state) | AI LEAD Act (federal) |
|---|---|---|
| Baseline posture | Conditional immunity | Strict liability available |
| Theories of liability | Shielded for non-reckless conduct | Negligence, failure-to-warn, warranty, strict liability |
| Scope of harm | Only "critical harms" (100+ deaths, $1B, CBRN, autonomous crime) | All harms, including mental/emotional/behavioral |
| Scope of developer | Only frontier ($100M / 10^26 FLOPs) | All AI developers |
| Emergent capabilities | Shielded if disclosure was made | Included in "design" — developer responsible |
| Preemption | Self-sunsets on overlapping federal law | Federal floor; states can go stronger |
| Theory of change | Disclosure unlocks immunity | Tort risk forces safety investment |
| Industry posture | OpenAI publicly supports | Industry broadly opposes |
Both bills involve Illinois legislators: Sen. Durbin (D-IL) co-sponsors the federal AI LEAD Act, while Sen. Cunningham (D-IL) sponsors the state SB 3444. The two frameworks would operate on the same developer population in opposite directions, one expanding exposure and one shielding it, which the source reporting cites as an illustration of Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race dynamics in which two Illinois senators simultaneously advance directly opposing liability frameworks at different levels of government.
Comparison with transparency-first bills
SB 3444 and California SB 53 — Transparency in Frontier AI Act share a transparency-first core: both require frontier developers to publish safety-and-security protocols and pre-release reports. The difference is in what the disclosure does. SB 53 imposes disclosure as a regulatory duty without granting immunity, whereas SB 3444 conditions immunity on disclosure, turning the same set of disclosures into a legal shield. According to the source reporting, a developer already complying with SB 53 in California would incur near-zero marginal cost complying with SB 3444 while gaining a liability shield available nowhere else; the reporting describes this structural alignment as apparently intentional and as one reason industry advocates for transparency-first regimes over duty-based or strict-liability regimes.
New York RAISE Act (S. 8828) is also transparency-first for frontier developers and likewise grants no immunity. The source reporting characterizes SB 3444 as the first bill in the frontier-transparency family to explicitly trade disclosure for a legal shield.
Relationships
- contradicts: AI LEAD Act (S. 2937) — opposite liability posture (immunity vs. strict liability) on the same developer population
- related: California SB 53 — Transparency in Frontier AI Act, New York RAISE Act (S. 8828) — shared transparency-first structure, without the immunity trade
- related: California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) — scope resembles the Newsom-vetoed CA bill; duty side inverted into a shield
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — different target (deployers, not frontier developers) and different harm class (discrimination)
- depends-on: EU General-Purpose AI Code of Practice (Final Version, 2025) — one of the two statutory compliance alternatives
- instance-of: frontier-model safe-harbor regulation (state level)
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — a clean example of opposing state/federal approaches on the same question
Confidence
Medium. The ILGA full-text endpoint returned a structured summary rather than clean verbatim text; substantive provisions are corroborated across five independent reporting sources. Exact statutory section numbering should be re-verified against the ILGA PDF before use in legal citation.