AI Policy Wiki
Dashboard

Illinois SB 3444 — Artificial Intelligence Safety Act

medium confidence · updated 2026-06-06

Illinois Senate bill creating a conditional liability shield for frontier AI developers against 'critical harms' (100+ deaths/injuries, $1B+ property damage, CBRN enablement, autonomous criminal conduct) in exchange for publishing a safety protocol and transparency report. $100M / 10^26 FLOPs frontier threshold. OpenAI-backed.

Illinois SB 3444, the Artificial Intelligence Safety Act, is a bill in the 104th Illinois General Assembly that establishes a conditional safe harbor from liability for developers of frontier AI models when those models cause catastrophic ("critical") harms. Developers qualify for immunity if they did not act intentionally or recklessly and published a safety-and-security protocol and a transparency report before or at release. The bill offers two alternative compliance paths (EU AI Act Article 56 adherence or a federal-agency evaluation agreement) and self-sunsets if overlapping federal law is enacted. It has been described in reporting as the first state-level AI bill publicly championed by OpenAI.

Bill: SB 3444, 104th Illinois General Assembly Primary sponsor: Sen. Bill Cunningham (D) Filed: February 4, 2026

Status and timeline

The bill was filed on February 4, 2026 and referred to the Senate AI and Social Media Committee on February 18, 2026, with a committee deadline of April 24, 2026. OpenAI was represented in committee by Global Affairs lead Caitlin Niedermeyer (Source: Illinois SB 3444 — Artificial Intelligence Safety Act reporting compilation).

Scope and definitions

A frontier model is defined disjunctively: a model trained using greater than 10^26 computational operations, or trained with compute costs exceeding $100,000,000. Either threshold triggers coverage. The reported practical scope is OpenAI, Google DeepMind, Anthropic, xAI, and Meta, with open-source fine-tuners, startups, and deployers excluded.

A developer is anyone who has trained or initiated the training of at least one frontier model.

"Critical harm" requires both a covered outcome and a covered causal pathway. The covered outcomes are either the death or serious injury of 100 or more people, or at least $1,000,000,000 in property damage. The covered pathways are either the creation or use of a CBRN weapon (chemical, biological, radiological, nuclear), or other criminal conduct by the AI model without meaningful human intervention (autonomous agentic crime). Ordinary torts, discrimination claims, consumer harms, privacy violations, workforce displacement, and defamation fall outside the definition and are unaffected by the shield.

Key provisions

Safe harbor mechanism

A developer avoids liability for a critical harm if all three conditions are met: the developer did not intentionally or recklessly cause the harm; the developer published a safety and security protocol (Section 15) on its public website before release; and the developer published a transparency report (Section 20) on its public website at the time of release.

The bill conditions immunity on disclosure rather than on a substantive duty to prevent critical harms, and does not tie immunity to testing outcomes, red-team results, or third-party certification. Reporting characterizes it as a shield rather than a standard: a developer who publishes a protocol describing limited testing appears to retain the shield provided the conduct was not reckless (Source: Illinois SB 3444 — Artificial Intelligence Safety Act reporting compilation).

Compliance alternatives

A developer is deemed compliant if it agrees to be bound by EU AI Act Article 56 safety and security requirements (the GPAI Code of Practice adherence regime — see EU General-Purpose AI Code of Practice (Final Version, 2025)), or enters an agreement with a federal government agency providing model access, evaluation, and public disclosure of findings.

Reporting and transparency obligations

The safety and security protocol (Section 15) must document testing procedures; thresholds for assessing risk of critical harm; mitigation measures; use of third-party assessments; cybersecurity practices for model weights and training infrastructure; post-deployment monitoring; and processes for identifying material new post-release risks.

The transparency report (Section 20) must, at minimum, identify the frontier model and version, summarize assessment results, and describe risk-mitigation steps taken pre-release. Both documents permit redactions for trade-secret and cybersecurity reasons.

Enforcement

The bill is structured as an affirmative defense and liability shield rather than an administrative regulatory regime. The reported text creates no new state enforcement body, no pre-market approval, no mandatory reporting to an agency, and no fine schedule. A developer who fails to publish the protocol or report loses the shield and is exposed to ordinary common-law tort liability, which is generally attenuated by causation, foreseeability, and proximate-cause doctrines.

Reactions

OpenAI supported the bill publicly, a contrast with the industry's opposition to SB 1047 in California in 2024 and an instance of the company endorsing state legislation that reduces rather than expands liability exposure. Caitlin Niedermeyer (OpenAI, Global Affairs) testified in committee framing the bill as consistent with OpenAI's policy posture: "At OpenAI, we believe the North Star for frontier regulation should be the safe deployment of the most advanced models in a way that also preserves US leadership in innovation." (Source: Quartz/Futurism reporting, April 2026.) Jamie Radice (OpenAI spokesperson) described the bill as avoiding a "patchwork of state-by-state rules."

Scott Wisor, policy director of the Secure AI Project, opposed the bill: "90 percent of people oppose it. There's no reason existing AI companies should be facing reduced liability." Critics have framed the bill as an immunity grant disguised as a safety act, arguing that disclosure obligations are redactable, that the substantive safety floor is self-defined, and that the shield applies to the catastrophic-harm class where plaintiffs would otherwise have the strongest claims.

Reporting has identified several recurring points of contention. The bill does not require that published protocols be effective, only that they be published, so a developer whose protocol acknowledges an inability to mitigate a risk apparently retains the shield. The trade-secret and cybersecurity redactions are unconstrained, which critics argue could reduce transparency reports to marketing documents. Recklessness is described as a high plaintiff burden, such that plaintiffs in CBRN or autonomous-crime cases would face severe causation problems in addition to the recklessness bar. Because OpenAI, Anthropic, Google, and others are already GPAI Code of Practice signatories, the EU Article 56 alternative is reported to provide automatic compliance with no new US-specific action required (see EU General-Purpose AI Code of Practice (Final Version, 2025)). The Act extinguishes itself upon overlapping federal law, which reporting describes as aligning OpenAI's incentive toward federal legislation while creating an interim placeholder shield.

AI LEAD Act

SB 3444 and the federal AI LEAD Act (S. 2937) (Durbin-Hawley) take opposing postures on AI developer liability: SB 3444 reduces developer exposure while the AI LEAD Act expands it. Both involve Illinois lawmakers — Sen. Durbin (D-IL) co-sponsors AI LEAD at the federal level, while Sen. Cunningham (D-IL) sponsors SB 3444 at the state level. Reporting notes that two Illinois senators are simultaneously advancing directly opposing liability frameworks at different levels of government.

DimensionSB 3444 (IL)AI LEAD Act (federal)
Baseline postureImmunity by default (conditional)Strict liability available
Theories of liabilityShielded for unintentional/non-recklessNegligence, failure-to-warn, warranty, strict liability
Scope of harmsOnly "critical harms" (100+ deaths, $1B, CBRN, autonomous crime)All harms including mental/emotional/behavioral
Scope of developersOnly frontier developers ($100M / 10^26 FLOPs)All AI developers
Emergent capabilitiesShielded if disclosure madeIncluded in "design" — developer responsible
PreemptionSelf-sunsets on overlapping federal lawFederal floor, states can go stronger
Theory of changeDisclosure unlocks immunityTort liability forces safety investment
Industry postureOpenAI publicly supportsIndustry generally opposes

See AI LEAD Act (S. 2937) for the contrast.

California SB 53

California SB 53 — Transparency in Frontier AI Act (Transparency in Frontier AI Act, 2025) shares SB 3444's transparency-first structure — both require publication of safety protocols and pre-release reports by frontier developers — but SB 53 does not include a liability shield. SB 53 creates disclosure obligations without immunity; SB 3444 ties disclosure to immunity. Reporting notes that for a developer already complying with SB 53 in California, complying with SB 3444 is nearly costless.

New York RAISE Act

The New York RAISE Act (S. 8828) also follows a transparency-first model for frontier developers and, like SB 53, does not grant immunity. SB 3444 is described as the first bill in the frontier-transparency family to explicitly trade transparency for a legal shield.

Colorado AI Act

The Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) targets high-risk AI deployers and imposes duties around consequential decisions (employment, housing, lending). It has a different target (deployer-side), a different harm class (discrimination), and a different mechanism (duty-based). SB 3444 does not touch this territory.

Relationships

Confidence

Medium. Bill text was retrieved from the Illinois General Assembly's full-text endpoint but in structured-summary form rather than verbatim. Key provisions (compute threshold, critical harms definition, safe-harbor structure, EU/federal compliance alternatives, sunset) are corroborated across five independent reporting sources. Exact statutory citation numbering (e.g., "Section 10(b)") is as reported and should be re-verified against the ILGA PDF before being used in legal citation.