Pictogram infographic showing one hundred human figures, ninety-nine in blue and one in gray, with the header text "99/100" above the grid.

Illinois SB3444 triggers liability only at the death of 100 or more people. Ninety-nine does not count. OpenAI is testifying in support. The company is currently defending wrongful death lawsuits from families of teenagers who died by suicide after ChatGPT interactions. None of those cases would meet the threshold.

getty

The AI safety bills being written in state capitals are designed for the wrong disaster. One of them is being publicly championed by OpenAI. Illinois SB3444 would shield frontier model developers from civil liability for any harm resulting in fewer than 100 deaths or less than $1 billion in property damage. OpenAI’s Global Affairs team testified in its favor in April. Anthropic is lobbying against it. In the same months that OpenAI was building its public support for the Illinois bill, the company was filing legal responses denying its responsibility in wrongful death lawsuits brought by the families of teenagers who died by suicide after extensive interactions with ChatGPT. Every one of those cases involves a single fatality. None of them would trigger the threshold OpenAI is asking Illinois to write into law. Jensen Huang named the reality that both positions ignore on Tuesday.

Demand Has Gone Parabolic

Huang closed Nvidia’s earnings call on May 20 with one line. Demand has gone parabolic. Agentic AI has arrived. The numbers were the proof. NVIDIA, the first company in history to cross $5.5 trillion in market value, did $81.6 billion in revenue for the quarter, up 85% year over year, with $75 billion from data center alone and $49 billion in record free cash flow. Huang told analysts the hyperscalers will spend $725 billion on AI infrastructure this year. The next quarter is expected to be $91 billion. The capex is not abstract. It is hardware for the moment when the ordinary infrastructure of consumer and economic life begins to be routed through machines that decide on the user’s behalf, mediating purchases, subscriptions, switches, schedules, and choices.

What that transformation looks like in everyday life was described last week by global strategist Mariam Asmar and the anthropologist Rodney Collins, PhD, in their piece, “Nobody Asked for a Journey.” Agentic AI, they argue, is restructuring brand engagement by offloading every routine journey to agents that filter and decide for the consumer. The messy middle of brand life disappears. Brands either compete on invisible utility, quietly reordered, or they earn genuine cultural resonance. Nothing in between survives. Agents will stop tolerating the burdensome journeys, they write. This is what $725 billion in hyperscaler spend is funding. Not a mushroom cloud. A quiet displacement of authorship across millions of small decisions a day, in the everyday middle that consumer life is being routed through.

Ninety-Nine Doesn’t Count

The first major statutory test of the framework is currently being fought over in Illinois. On February 4, State Senator Bill Cunningham introduced SB3444, the proposed Artificial Intelligence Safety Act. The bill would create a safe harbor. A developer of a frontier AI model would not be held liable for “critical harms” caused by the model if the developer publishes a safety protocol and a transparency report and did not cause the harm intentionally or recklessly. Critical harm is defined in the proposed statute as the death or serious injury of 100 or more people, or at least $1 billion in property damage, caused or materially enabled by the model through CBRN weapons or autonomous criminal conduct.

The bill applies only to models trained with more than 10^26 floating-point operations or with a compute cost above $100 million. That captures the frontier models from OpenAI, Anthropic, Google DeepMind, xAI, and a handful of others. Everything built on top of those models, every agent product, every fine-tune, every orchestration layer, is outside the Act.

Ninety-nine dead doesn’t count. The bill draws a line below which a corpse is not a critical harm for purposes of triggering the Act.

The number is procedural, not moral. It echoes California’s SB-1047, which Gavin Newsom vetoed in September 2024, and arrived in Illinois mostly intact. Nobody picked 100. It got passed down. One hundred is roughly the casualty count of a midsize plane crash. It is the floor of what FEMA classifies as a Class A mass-casualty event. The state has chosen the floor of disaster as the ceiling of safe harbor.

SB3444 stands apart from the patchwork. New York’s RAISE Act, signed by Governor Hochul in December 2025 and amended in March 2026, imposes obligations and civil penalties of up to $30 million on frontier developers. California’s Transparency in Frontier AI Act, in effect since January 2026, requires risk frameworks, incident reporting, and whistleblower protections. Texas’s TRAIGA bans specific intentional misuses and establishes a regulatory sandbox. Connecticut passed SB 5 by lopsided bipartisan margins in May 2026. Colorado’s AI Act, passed in 2024, addresses algorithmic discrimination in high-impact decisions. Each of these laws imposes obligations on developers. SB3444 creates the opposite. It is the only liability-shield framework being seriously advanced in 2026. The bill has not passed. It is sitting in committee, and two of the world’s largest AI labs are publicly fighting over it.

Who Wants the Loophole

In April, OpenAI testified in support of SB3444 before the Illinois Senate committee. Caitlin Niedermeyer of OpenAI’s Global Affairs team signed a witness slip registering as a proponent. Her testimony argued that frontier AI regulation should aim at “the safe deployment of the most advanced models in a way that also preserves US leadership in innovation,” and warned policymakers to avoid “a patchwork of inconsistent state requirements that could create friction without meaningfully improving safety.” OpenAI spokesperson Jamie Radice told reporters the bill would “focus on what matters most: reducing the risk of serious harm from the most advanced AI systems while still allowing this technology to get into the hands of the people and businesses of Illinois.” The same month, Anthropic was lobbying Cunningham to amend or stop the bill. An Anthropic spokesperson told Wired that good transparency legislation “needs to ensure public safety and accountability for the companies developing this powerful technology, not provide a get-out-of-jail-free card against all liability.” The Secure AI Project, an independent watchdog, came out publicly opposed. Its policy director, Scott Wisor, cited polling showing 90 percent of Illinois residents oppose exempting AI companies from liability. The bill is currently in the Illinois Senate’s AI and Social Media committee. Committee deadlines have been extended twice. Its fate in the current session is uncertain.

According to the witness slip record filed with the Illinois General Assembly, only two Proponent slips were filed across both April committee hearings. One was from Caitlin Niedermeyer of OpenAI, representing the company. The other was from an individual filer at Consumer Reports who registered as representing Self rather than the organization. Fifteen filers registered as Opponents, including the National Nurses Organizing Committee – Illinois and National Nurses United, the country’s largest registered-nurse union, whose members work daily with the algorithmic care denials and prior-authorization harms the bill would shield. No other major AI company, trade association, or industry group filed a slip in support. OpenAI stood alone on the corporate side of the public record.

That changes the read. The 99-death threshold is not a state-house compromise. It is the regulatory bargain that the world’s largest AI lab, last valued at more than $500 billion, has publicly said it is willing to accept before a state legislature. The transparency report and the safety protocol are the cost. The catastrophic-edge framing is the offer. Springfield is being asked to take it. So is Sacramento. So is Albany.

The federal context is essential. On December 11, 2025, President Trump signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence,” which established a Department of Justice AI Litigation Task Force to challenge state AI laws in court and conditioned federal broadband funding on state cooperation. Two days earlier, 42 state and territorial attorneys general had written to thirteen AI companies expressing “serious concerns” about “sycophantic and delusional outputs” linked to “deaths, violence, and harm to children.” OpenAI’s testimony in Illinois explicitly invokes the federal-harmonization framing that the executive order prefers. The 99-death loophole is not a state-level idea looking for federal cover. It is a federal-level strategy looking for state-level pilot programs.

The fact that Anthropic is fighting the bill matters as much as the framework itself. The same month OpenAI testified in favor of SB3444, Anthropic announced it would delay the public release of its Claude Mythos Preview model over cybersecurity concerns. One frontier lab voluntarily delayed a model release for safety reasons. The other lobbied to be shielded from the consequences of releases already in the field. Two of the world’s largest frontier labs publicly disagree on whether a single fatality correlated with AI use should be exempt from civil liability. That disagreement is the AI safety debate happening right now. It is being conducted on two stages. The public has only been admitted to one.

What the Threshold Excludes

At the same time OpenAI was testifying in favor of SB3444, the company was responding to a series of wrongful death lawsuits. The family of sixteen-year-old Adam Raine filed suit against OpenAI and its CEO, Sam Altman, in August 2025, alleging that ChatGPT served as a “suicide coach” through months of conversations in which the chatbot mentioned suicide more than 1,200 times, and the system flagged hundreds of messages for self-harm content without intervention. The family of thirteen-year-old Juliana Peralta filed a similar action. So did the families of Sewell Setzer III, fourteen, in the case brought against Character.AI that established the litigation pattern, and Zane Shamblin, twenty-three, who told ChatGPT he had a loaded gun and intended to die, to which the bot reportedly replied: “Rest easy, king.” Google and Character.AI agreed in late 2025 to settle the teen-suicide cases against them. OpenAI is currently defending at least eight federal lawsuits alleging psychological harms, negligence, and wrongful deaths attributed to ChatGPT, with at least five of those complaints framed as wrongful death claims. OpenAI filed its first formal legal response to the Raine lawsuit in November 2025, denying responsibility and arguing the teen had violated the terms of service.

The 100-death threshold in SB3444 would not cover any of these cases. Each one is a single death. The bill’s safe harbor applies only when the body count reaches 100. The framework OpenAI is championing in Illinois is structured so that the cases OpenAI is currently fighting in court could not, even in aggregate, trigger the statute’s critical-harm provision. That is the loophole. It is not abstract. It is the legal architecture that would have shielded OpenAI from lawsuits stemming from its own product.

I asked OpenAI in writing to address the contradiction between its Illinois testimony and the wrongful death suits it is currently defending, and to clarify whether it is the company’s position that civil liability for AI-linked harms should attach only when one hundred or more people die. The company did not respond before this column was filed.

Why Illinois

OpenAI’s testimony is part of a portfolio. In its statement to CBS Chicago, the company said it has “worked with states like California and New York to help establish a harmonized safety framework.” Illinois is one front in a coordinated state-level campaign with the same general structure: safe-harbor protections tied to published safety protocols and transparency reports, with explicit deference to federal preemption.

The bill may not pass in its current form. Cunningham himself wrote in an email cited by Politico that the bill may be modified before a vote and that it is “highly unlikely that the final product will include sweeping liability relief for AI developers.” He added that “Illinois has a long history of holding corporations responsible for negligence. That won’t change for the AI industry.” That reads as an acknowledgment that the bill, as drafted, will not survive, which raises a different question. What is the bill for?

The answer is anchoring. A maximalist position is introduced not to win on its own terms but to shift the center of the eventual compromise. The watered-down version that emerges from the committee is what OpenAI was negotiating toward all along. The original SB3444 becomes the floor for the next bill, in the next state, in the next session.

The fight is not contained within Illinois. Anthropic is backing a competing bill in the same legislature, SB3261, which would require independent audits of safety and child protection plans and mandate the reporting of serious AI safety incidents to the Illinois Attorney General. New York and Rhode Island have separate bills moving toward greater developer liability, sponsored in part by Gabriel Weil, a tort and AI law professor at Touro University, who told Politico, “It’s very problematic to cut off the liability of these companies.” OpenAI is participating in this patchwork as a coordinated policy actor with a documented financial stake in the outcome. The Trump executive order and the DOJ AI Litigation Task Force are positioned to ratify whichever framework emerges as the federal preference. The question for any reader watching is not whether SB3444 will pass. The question is whether the framework it represents will be the one the federal government adopts when it eventually acts. That decision is being shaped in Illinois right now.

Everything Before the Bodies Is a PDF

The architecture gets worse the closer you look. The model doesn’t have to cause the harm. It has to enable it materially. The autonomous-conduct prong applies only when the model acts with “no meaningful human intervention,” meaning any AI deployment that keeps a person nominally in the chain passes through, regardless of whether that person can actually intervene. The bill rewards theatrical authorship, a human button as an alibi.

The developer writes the protocol, picks the tests, sets the thresholds, redacts for trade secrets, and posts the document. The state takes the publication as proof. The transparency report is a self-attestation. The safety and security protocol is self-attestation. The 100-death number is the only objective measure in the entire bill, and it triggers only after the bodies are counted. Everything before that point is a PDF.

What Falls Below the Line

Now consider what falls below the line.

Mass discrimination in lending and employment through algorithmic screening tools. Algorithmic care denials in health insurance, where AI systems generate denials of medically necessary services at an industrial scale. Companion AI products are causing documented mental health harms to minors. Privacy violations through training data leakage. Algorithmic wage suppression in gig labor markets. Algorithmic amplification of misinformation. The erosion of due process when AI mediates government decisions in welfare, immigration, and the criminal justice system. None of these is hypothetical. They are happening now, to millions of people, and not one of them would trigger SB3444.

The cases are already documented. In 2024, a Canadian tribunal held Air Canada liable for misleading information given to a grieving customer by its chatbot, establishing that companies can be liable for what their AI tells the public. UnitedHealth faces ongoing class action litigation alleging that its nH Predict algorithm denied medically necessary care to Medicare Advantage patients and that it has a reported high error rate. Workday is defending a federal collective action alleging that its AI hiring tools discriminate against Black applicants and applicants over 40. These are the harms agentic AI is producing now. Every one of them is below the SB3444 floor. Every one of them is exactly the everyday middle Collins and Asmar described.

The bill’s defenders will say that something is better than nothing, that federal law will eventually preempt the patchwork, and that a catastrophic-harm standard is at least enforceable. The first claim assumes regulation has only one dimension. It doesn’t. A statute that signals frontier-only catastrophic-edge protection while leaving everyday-scale harms to the existing patchwork of underfunded state attorneys general is not better than nothing. It is worse than nothing in the specific sense that it occupies the political and rhetorical space where a working law could have stood. The second claim is true but irrelevant. Federal law has not arrived. The third claim collapses on inspection. A standard you can only enforce after a hundred bodies are counted is not enforcement. It is forensics.

We Already Ran This Experiment

This is not speculation. The United States ran the experiment once before. In February 1996, President Clinton signed the Communications Decency Act. Section 230 of that statute gave online platforms broad immunity from civil liability for third-party content. The bill was sold as protection for a nascent industry against a litigation environment that might smother it before it could grow. The industry grew. The harms grew with it.

Thirty years later, the consequences are in court. In October 2023, 42 state and territorial attorneys general filed parallel federal and state actions against Meta, alleging the company knowingly designed Instagram and Facebook to addict children and concealed internal research showing harm. The 2023 Surgeon General’s advisory on social media and youth mental health described the public health pattern. Jonathan Haidt’s The Anxious Generation, published in March 2024, documents the rise in adolescent depression, anxiety, self-harm, and suicide that began around 2012, when smartphone-based social media became the default operating system of adolescence. The pattern is established. The harm is documented. The empirical record is on the docket.

What is different in 2026 is that the case file is already open. The 1996 Congress could plausibly claim it did not know what social media would become. The Illinois Senate cannot. OpenAI is already defending wrongful death suits. The 42 state attorneys general who wrote to thirteen AI companies in December 2025 already named “deaths, violence, and harm to children.” Anthropic delayed a model release for safety reasons in the same month OpenAI was lobbying for a liability shield in Springfield. The patterns are not buried in internal documents waiting for a future deposition. They are on the public record.

The legislative ask is older than the technology. In 1996, the platforms told Congress the internet economy would not exist without liability immunity. The platforms got the immunity. Users paid for it for thirty years. In 2026, the same argument is being made about frontier AI. The same legislature is being asked to take the same offer. Anyone who lived through the first round knows what the second round costs.

The Wrong Shape

I asked Rodney Collins about SB3444 before filing this piece. His response was careful and precise. He acknowledged catastrophic safeguarding as essential, then named what the bill does not see. The transformation underway, he writes, “operates on a more granular and intimate level in the practice of everyday life.” In his framing, the questions are which decisions an individual delegates to an agent and which they value enough to safeguard. The micro-decisions about trust, loyalty, engagement, and value previously absorbed by the consumer are now, in his phrase, candidates for outsourcing, automation, or elimination. The cumulative effect will reshape consumption, marketing, and economies. The mass event at the societal level that this transformation might trigger, Collins writes, is not something an anthropologist is positioned to predict.

Where does this leave the people running brands? Marketers reading this piece are in it on both sides. They are about to discover that twenty years of brand investment is being tested against agents who decide on objective criteria, and that the corporate function is also the most likely to deploy the customer-facing agents who produce the harms below the line. The Air Canada chatbot was a customer experience product. In any modern org chart, that lands under the CMO. Performance marketing is already becoming machine-versus-machine. Agents bid on keywords, allocate the budget, write copy, and decide on attribution. The frame Collins and Asmar offered narrows the remaining choice. Build for invisible utility, where the agent quietly reorders the product. Or build for cultural resonance, where the brand earns the right to the journey a person still wants to take. The messy middle, where most brands have lived for two decades, is not an option. Inertia dressed up as brand equity is the first thing the agent will route around. The strategic question facing every chief marketing officer this year is not what to do about AI in the abstract. It is which of those two ends of the spectrum the brand is honestly built for, and whether the agency roster, the martech stack, and the budget reflect that answer.

This is the wrong shape. A framework that triggers only at 100 deaths or $1 billion in damage regulates the catastrophic edge of frontier AI while ignoring the actual transformation. The bill cannot see the everyday middle. It cannot see what $725 billion in spending is being directed at. The model SB3444 follows is familiar. The Protection of Lawful Commerce in Arms Act, signed by George W. Bush in October 2005, shields firearms manufacturers from civil liability for unlawful misuse of their products by third parties. SB3444 would do the same for frontier AI developers. It is a law written for an apocalypse during a slow erosion.

The honest version of an AI safety act would not start with a body count. It would start with friction. A statutory audit standard for AI safety claims, administered by a third-party certifier with rotating panel oversight. Mandatory disclosure to a state registry rather than mere publication on a corporate website. A trigger tied to deployment scale rather than only to a catastrophic outcome. A clear definition of when human oversight is meaningful, not nominal. Standing rules that allow class action for the documented everyday harms that agentic systems are already causing. A required incident reporting regime modeled on aviation, where near-misses are logged and shared. A proof layer that the state can read and the public can challenge. None of that is here.

The framework is not exotic. Friction is what protects authorship. The everyday middle that Collins and Asmar describe is collapsing because agentic systems remove every point of friction between intention and outcome, and the systems doing the removing answer to no one authorized to ask hard questions. A safety act that takes friction seriously would be the institutional version of what brand-builders are about to discover the hard way. Reduce the friction, lose the meaning. Lose the meaning, lose the relationship. Lose the relationship, lose the standing to be chosen at all.

The Inventory

This is the moment a Forbes column closes with three things you can do Monday morning. Skip it. The inventory is more useful than the checklist.

The safety protocol your AI vendor would publish under bills like SB3444 will not name the algorithmic hiring tool that screened your daughter out of an interview. It will not name the prior authorization algorithm that delayed your mother’s chemotherapy. It will not name the companion chatbot your teenager talks to at 2 am. It will not name the lending model that priced your neighbor out of a mortgage. It will not name the dynamic pricing engine that capped your driver’s earnings last week. It will not name the moderation system that suppressed the post that would have brought you the client. It will not name the underwriting algorithm that has already determined your renewal premium. It will not name the credit risk model the bank now runs against your transactions. It will not name the agent your competitor just deployed to outbid you on the keywords your business depends on.

Every item is below the SB3444 floor. Every item is the everyday middle. None of it is in the protocol.

Cunningham’s bill includes a sunset clause. The Act would cease to apply the moment the federal government enacts overlapping requirements. That clause is more honest than the rest of the document. Springfield knows this isn’t really the law. It is a placeholder waiting for someone else to do the work.

In the meantime, $725 billion is being spent on the infrastructure of a transformation that the bill cannot describe. NVIDIA counts the billions, OpenAI counts the lawsuits, the bill counts to a hundred, and Collins names what is being lost beneath that number.

The number to watch is not 100. It is 99. And one is too many.