Illinois SB 3444, the Artificial Intelligence Safety Act, is a bill in the 104th Illinois General Assembly that establishes a conditional safe harbor from liability for developers of frontier AI models when those models cause catastrophic ("critical") harms. Developers qualify for immunity if they did not act intentionally or recklessly and published a safety-and-security protocol and a transparency report before or at release. The bill offers two alternative compliance paths (EU AI Act Article 56 adherence or a federal-agency evaluation agreement) and self-sunsets if overlapping federal law is enacted. It has been described in reporting as the first state-level AI bill publicly championed by OpenAI.
Bill: SB 3444, 104th Illinois General Assembly Primary sponsor: Sen. Bill Cunningham (D) Filed: February 4, 2026
Status and timeline
The bill was filed on February 4, 2026 and referred to the Senate AI and Social Media Committee on February 18, 2026, with a committee deadline of April 24, 2026. OpenAI was represented in committee by Global Affairs lead Caitlin Niedermeyer (Source: Illinois SB 3444 — Artificial Intelligence Safety Act reporting compilation).
Scope and definitions
A frontier model is defined disjunctively: a model trained using greater than 10^26 computational operations, or trained with compute costs exceeding $100,000,000. Either threshold triggers coverage. The reported practical scope is OpenAI, Google DeepMind, Anthropic, xAI, and Meta, with open-source fine-tuners, startups, and deployers excluded.
A developer is anyone who has trained or initiated the training of at least one frontier model.
"Critical harm" requires both a covered outcome and a covered causal pathway. The covered outcomes are either the death or serious injury of 100 or more people, or at least $1,000,000,000 in property damage. The covered pathways are either the creation or use of a CBRN weapon (chemical, biological, radiological, nuclear), or other criminal conduct by the AI model without meaningful human intervention (autonomous agentic crime). Ordinary torts, discrimination claims, consumer harms, privacy violations, workforce displacement, and defamation fall outside the definition and are unaffected by the shield.
Key provisions
Safe harbor mechanism
A developer avoids liability for a critical harm if all three conditions are met: the developer did not intentionally or recklessly cause the harm; the developer published a safety and security protocol (Section 15) on its public website before release; and the developer published a transparency report (Section 20) on its public website at the time of release.
The bill conditions immunity on disclosure rather than on a substantive duty to prevent critical harms, and does not tie immunity to testing outcomes, red-team results, or third-party certification. Reporting characterizes it as a shield rather than a standard: a developer who publishes a protocol describing limited testing appears to retain the shield provided the conduct was not reckless (Source: Illinois SB 3444 — Artificial Intelligence Safety Act reporting compilation).
Compliance alternatives
A developer is deemed compliant if it agrees to be bound by EU AI Act Article 56 safety and security requirements (the GPAI Code of Practice adherence regime — see EU General-Purpose AI Code of Practice (Final Version, 2025)), or enters an agreement with a federal government agency providing model access, evaluation, and public disclosure of findings.
Reporting and transparency obligations
The safety and security protocol (Section 15) must document testing procedures; thresholds for assessing risk of critical harm; mitigation measures; use of third-party assessments; cybersecurity practices for model weights and training infrastructure; post-deployment monitoring; and processes for identifying material new post-release risks.
The transparency report (Section 20) must, at minimum, identify the frontier model and version, summarize assessment results, and describe risk-mitigation steps taken pre-release. Both documents permit redactions for trade-secret and cybersecurity reasons.
Enforcement
The bill is structured as an affirmative defense and liability shield rather than an administrative regulatory regime. The reported text creates no new state enforcement body, no pre-market approval, no mandatory reporting to an agency, and no fine schedule. A developer who fails to publish the protocol or report loses the shield and is exposed to ordinary common-law tort liability, which is generally attenuated by causation, foreseeability, and proximate-cause doctrines.
Reactions
OpenAI supported the bill publicly, a contrast with the industry's opposition to SB 1047 in California in 2024 and an instance of the company endorsing state legislation that reduces rather than expands liability exposure. Caitlin Niedermeyer (OpenAI, Global Affairs) testified in committee framing the bill as consistent with OpenAI's policy posture: "At OpenAI, we believe the North Star for frontier regulation should be the safe deployment of the most advanced models in a way that also preserves US leadership in innovation." (Source: Quartz/Futurism reporting, April 2026.) Jamie Radice (OpenAI spokesperson) described the bill as avoiding a "patchwork of state-by-state rules."
Scott Wisor, policy director of the Secure AI Project, opposed the bill: "90 percent of people oppose it. There's no reason existing AI companies should be facing reduced liability." Critics have framed the bill as an immunity grant disguised as a safety act, arguing that disclosure obligations are redactable, that the substantive safety floor is self-defined, and that the shield applies to the catastrophic-harm class where plaintiffs would otherwise have the strongest claims.
Reporting has identified several recurring points of contention. The bill does not require that published protocols be effective, only that they be published, so a developer whose protocol acknowledges an inability to mitigate a risk apparently retains the shield. The trade-secret and cybersecurity redactions are unconstrained, which critics argue could reduce transparency reports to marketing documents. Recklessness is described as a high plaintiff burden, such that plaintiffs in CBRN or autonomous-crime cases would face severe causation problems in addition to the recklessness bar. Because OpenAI, Anthropic, Google, and others are already GPAI Code of Practice signatories, the EU Article 56 alternative is reported to provide automatic compliance with no new US-specific action required (see EU General-Purpose AI Code of Practice (Final Version, 2025)). The Act extinguishes itself upon overlapping federal law, which reporting describes as aligning OpenAI's incentive toward federal legislation while creating an interim placeholder shield.
Comparison with related bills
AI LEAD Act
SB 3444 and the federal AI LEAD Act (S. 2937) (Durbin-Hawley) take opposing postures on AI developer liability: SB 3444 reduces developer exposure while the AI LEAD Act expands it. Both involve Illinois lawmakers — Sen. Durbin (D-IL) co-sponsors AI LEAD at the federal level, while Sen. Cunningham (D-IL) sponsors SB 3444 at the state level. Reporting notes that two Illinois senators are simultaneously advancing directly opposing liability frameworks at different levels of government.
| Dimension | SB 3444 (IL) | AI LEAD Act (federal) |
|---|---|---|
| Baseline posture | Immunity by default (conditional) | Strict liability available |
| Theories of liability | Shielded for unintentional/non-reckless | Negligence, failure-to-warn, warranty, strict liability |
| Scope of harms | Only "critical harms" (100+ deaths, $1B, CBRN, autonomous crime) | All harms including mental/emotional/behavioral |
| Scope of developers | Only frontier developers ($100M / 10^26 FLOPs) | All AI developers |
| Emergent capabilities | Shielded if disclosure made | Included in "design" — developer responsible |
| Preemption | Self-sunsets on overlapping federal law | Federal floor, states can go stronger |
| Theory of change | Disclosure unlocks immunity | Tort liability forces safety investment |
| Industry posture | OpenAI publicly supports | Industry generally opposes |
See AI LEAD Act (S. 2937) for the contrast.
California SB 53
California SB 53 — Transparency in Frontier AI Act (Transparency in Frontier AI Act, 2025) shares SB 3444's transparency-first structure — both require publication of safety protocols and pre-release reports by frontier developers — but SB 53 does not include a liability shield. SB 53 creates disclosure obligations without immunity; SB 3444 ties disclosure to immunity. Reporting notes that for a developer already complying with SB 53 in California, complying with SB 3444 is nearly costless.
New York RAISE Act
The New York RAISE Act (S. 8828) also follows a transparency-first model for frontier developers and, like SB 53, does not grant immunity. SB 3444 is described as the first bill in the frontier-transparency family to explicitly trade transparency for a legal shield.
Colorado AI Act
The Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) targets high-risk AI deployers and imposes duties around consequential decisions (employment, housing, lending). It has a different target (deployer-side), a different harm class (discrimination), and a different mechanism (duty-based). SB 3444 does not touch this territory.
Relationships
- contradicts: AI LEAD Act (S. 2937) — on liability posture (immunity vs. strict liability)
- related: California SB 53 — Transparency in Frontier AI Act, New York RAISE Act (S. 8828) — same frontier-transparency family, no shield
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — different target population (deployers, not frontier developers)
- related: California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) — the Newsom-vetoed CA bill whose scope SB 3444 resembles but whose duty-side substance SB 3444 inverts
- depends-on: EU General-Purpose AI Code of Practice (Final Version, 2025) — one of the two statutory compliance alternatives
- instance-of: frontier-model regulation (state level)
Confidence
Medium. Bill text was retrieved from the Illinois General Assembly's full-text endpoint but in structured-summary form rather than verbatim. Key provisions (compute threshold, critical harms definition, safe-harbor structure, EU/federal compliance alternatives, sunset) are corroborated across five independent reporting sources. Exact statutory citation numbering (e.g., "Section 10(b)") is as reported and should be re-verified against the ILGA PDF before being used in legal citation.