AI Policy Wiki
Dashboard

Illinois SB 3444 — Artificial Intelligence Safety Act

medium confidence · updated 2026-06-06

Illinois state bill establishing a conditional liability safe harbor for frontier AI developers against 'critical harms' (100+ deaths, $1B+ property damage, CBRN enablement, autonomous crime) in exchange for publishing safety protocols and transparency reports. Covered scope is $100M / 10^26 FLOPs developers. OpenAI publicly supports.

Illinois SB 3444, the Artificial Intelligence Safety Act, is a state bill that would establish a conditional liability safe harbor for developers of frontier AI models. A developer that publishes a safety-and-security protocol and a transparency report would not be liable for "critical harms" caused by its model, provided it did not intentionally or recklessly cause the harm. The bill applies only to frontier developers (defined by a $100 million / 10^26 FLOPs threshold) and self-sunsets if federal law establishes overlapping requirements. OpenAI publicly supports the bill.

The Act is structured as an affirmative defense rather than an administrative regulatory regime, which distinguishes it from duty-based and strict-liability approaches advanced elsewhere; critics describe it as an immunity grant.

FieldValue
Full titleArtificial Intelligence Safety Act
Bill numberSB 3444
Enacting bodyIllinois General Assembly (104th GA), Senate
Primary sponsorSen. Bill Cunningham (D)
Introduced / First ReadingFebruary 4, 2026
StatusReferred to Senate AI and Social Media Committee (2/18/2026); committee deadline 4/24/2026
SourceIllinois SB 3444 — Artificial Intelligence Safety Act (source summary); Raw Sources/Illinois SB 3444 - Artificial Intelligence Safety Act.md (full text)

Status and timeline

SB 3444 received its first reading on February 4, 2026 and was referred to the Senate AI and Social Media Committee on February 18, 2026, with a committee deadline of April 24, 2026. The primary sponsor is Sen. Bill Cunningham (D), and the bill is before the 104th Illinois General Assembly.

Scope and definitions

The Act applies to developers of frontier AI models. A frontier model is defined disjunctively as a model trained using either greater than 10^26 computational operations or compute costs exceeding $100,000,000. A "developer" is any person or organization that has trained, or initiated the training of, at least one frontier model. As described in the source reporting, the practical scope covers OpenAI, Google DeepMind, Anthropic, xAI, and Meta, and excludes open-source fine-tuners, startups, deployers, and non-frontier labs.

Section 5 sets out the governing definitions:

  • Artificial Intelligence Model. An engineered or machine-based component of a system, varying in autonomy, capable of generating outputs that influence physical or virtual environments.
  • Frontier Model. Greater than 10^26 FLOPs or greater than $100M compute cost.
  • Critical Harm. Either (a) death or serious injury of 100 or more people, or (b) at least $1B in property damage — and in either case caused through (i) CBRN weapon creation or use or (ii) autonomous criminal conduct by the AI model without meaningful human intervention.
  • Developer. A person or organization that has trained, or initiated training of, at least one frontier model.

Key provisions

Section 10 — liability protection (safe harbor)

A developer is not liable for critical harms caused by a frontier model if all of the following hold: the developer did not intentionally or recklessly cause the harm; before release, the developer published a safety-and-security protocol on its public website; and at the time of release, the developer published a transparency report on its public website.

A developer is alternatively deemed compliant if it either agrees to be bound by Article 56 of the EU AI Act safety-and-security requirements (the GPAI Code of Practice — see EU General-Purpose AI Code of Practice (Final Version, 2025)), or enters an agreement with a federal government agency providing model access, evaluation, and public disclosure of findings meeting specified requirements.

Section 15 — safety and security protocol

The protocol must document at minimum: testing procedures; thresholds for assessing risk of critical harm; mitigation measures; third-party assessments; cybersecurity practices for model weights and training infrastructure; post-deployment monitoring; and processes for identifying material new risks after release. Trade-secret and cybersecurity redactions are permitted.

Section 20 — transparency report

The report must at minimum identify the frontier model and version, summarize assessment results, and describe risk-mitigation steps taken pre-release. Redactions are permitted for security or proprietary reasons.

Section 25 — sunset / federal preemption trigger

The Act ceases to apply if federal law establishes overlapping safety requirements for frontier models.

Enforcement

The bill is structured as an affirmative defense and liability shield rather than an administrative regulatory regime. It creates no new state enforcement body, no pre-market approval, no mandatory agency reporting, and no fine schedule. A non-compliant developer loses the shield and faces ordinary common-law tort liability, which the source reporting describes as heavily attenuated by causation, foreseeability, and proximate-cause doctrines in catastrophic-harm cases.

Reactions

OpenAI publicly supports the bill, which the source reporting characterizes as a departure from its defensive-only posture during California SB 1047 (2024). Caitlin Niedermeyer of OpenAI Global Affairs testified in committee, and spokesperson Jamie Radice framed the bill as reducing harms while avoiding a "patchwork of state-by-state rules." Per the reporting, it is the first state AI bill OpenAI has publicly championed rather than opposed.

Scott Wisor of the Secure AI Project opposed the bill, stating: "There's no reason existing AI companies should be facing reduced liability." Critics characterize the bill as an immunity grant disguised as a safety act, and argue that its name (Artificial Intelligence Safety Act) misrepresents its function as a shield rather than a duty.

Several structural features have drawn commentary in the source reporting. The bill does not require that published protocols be effective, only that they be published; a developer whose protocol concedes inability to mitigate a risk would appear to retain the shield. The trade-secret and cybersecurity redactions are unconstrained, which critics argue could reduce transparency reports to marketing documents. Plaintiffs in CBRN or autonomous-crime cases would face causation problems and a recklessness bar, a difficult path even without the shield. OpenAI, Anthropic, Google, and others are already GPAI Code of Practice signatories, so the Article 56 alternative compliance path requires no US-specific action. By sunsetting on overlapping federal law, the Act functions as a placeholder, which the reporting notes is consistent with OpenAI's stated preference for federal over state regulation.

Comparison with the AI LEAD Act (federal)

SB 3444 and the AI LEAD Act take opposite positions on liability for the same frontier-developer population. The following table summarizes the contrast drawn in the source reporting.

DimensionIL SB 3444 (state)AI LEAD Act (federal)
Baseline postureConditional immunityStrict liability available
Theories of liabilityShielded for non-reckless conductNegligence, failure-to-warn, warranty, strict liability
Scope of harmOnly "critical harms" (100+ deaths, $1B, CBRN, autonomous crime)All harms, including mental/emotional/behavioral
Scope of developerOnly frontier ($100M / 10^26 FLOPs)All AI developers
Emergent capabilitiesShielded if disclosure was madeIncluded in "design" — developer responsible
PreemptionSelf-sunsets on overlapping federal lawFederal floor; states can go stronger
Theory of changeDisclosure unlocks immunityTort risk forces safety investment
Industry postureOpenAI publicly supportsIndustry broadly opposes

Both bills involve Illinois legislators: Sen. Durbin (D-IL) co-sponsors the federal AI LEAD Act, while Sen. Cunningham (D-IL) sponsors the state SB 3444. The two frameworks would operate on the same developer population in opposite directions, one expanding exposure and one shielding it, which the source reporting cites as an illustration of Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race dynamics in which two Illinois senators simultaneously advance directly opposing liability frameworks at different levels of government.

Comparison with transparency-first bills

SB 3444 and California SB 53 — Transparency in Frontier AI Act share a transparency-first core: both require frontier developers to publish safety-and-security protocols and pre-release reports. The difference is in what the disclosure does. SB 53 imposes disclosure as a regulatory duty without granting immunity, whereas SB 3444 conditions immunity on disclosure, turning the same set of disclosures into a legal shield. According to the source reporting, a developer already complying with SB 53 in California would incur near-zero marginal cost complying with SB 3444 while gaining a liability shield available nowhere else; the reporting describes this structural alignment as apparently intentional and as one reason industry advocates for transparency-first regimes over duty-based or strict-liability regimes.

New York RAISE Act (S. 8828) is also transparency-first for frontier developers and likewise grants no immunity. The source reporting characterizes SB 3444 as the first bill in the frontier-transparency family to explicitly trade disclosure for a legal shield.

Relationships

Confidence

Medium. The ILGA full-text endpoint returned a structured summary rather than clean verbatim text; substantive provisions are corroborated across five independent reporting sources. Exact statutory section numbering should be re-verified against the ILGA PDF before use in legal citation.