AI Distillation Is a Standard Tool. Washington Is Deciding When It Becomes Model Theft The U.S. government is weighing whether AI distillation — a standard technique for training one model using another's outputs — constitutes model theft when done without authorization, as a House bill and White House memorandum target foreign extraction operations. Anthropic alleges that Chinese AI developers DeepSeek, Moonshot AI and MiniMax generated over 16 million Claude exchanges through roughly 24,000 fraudulent accounts, while an industry coalition including Nvidia, Microsoft, Meta, Google and OpenAI warns that overly broad restrictions could harm research and competition. AI Distillation Is a Standard Tool. Washington Is Deciding When It Becomes Model Theft - Distillation trains a “student” model to imitate useful behavior from a “teacher,” generally without copying the teacher’s underlying weights. 1 https://research.google/pubs/distilling-the-knowledge-in-a-neural-network/ 7 https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation/ - The central regulatory question is authorization: proposed U.S. legislation distinguishes permitted distillation from extraction that evades access controls or violates contractual restrictions. 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm - Anthropic says DeepSeek, Moonshot AI and MiniMax generated more than 16 million Claude exchanges through roughly 24,000 fraudulent accounts. Those figures and attributions are Anthropic’s findings, not an independent government determination. 3 https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks - A July 24 industry letter now lists 50 signatories, including Nvidia, Microsoft, Meta, Google and OpenAI, and urges policymakers to protect legitimate distillation while targeting unlawful extraction. 4 https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ A long-established technique for transferring artificial-intelligence capabilities has become a test case for how Washington will regulate the technology. The contested word is “distillation”: training one model with information generated by another. The immediate fight concerns allegations that Chinese AI developers systematically queried American frontier models, collected millions of responses and used them as training material. An April 23 White House memorandum treated industrial-scale “adversarial distillation” as a national-security concern. A House bill would create mechanisms to identify foreign model-extraction operations and consider their operators for export restrictions or sanctions. 5 https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm The policy difficulty is that distillation is also routine engineering. OpenAI offers customers an authorized distillation workflow, while a broad industry coalition that includes OpenAI, Google, Nvidia, Microsoft and Meta is warning lawmakers that treating the technique itself as theft could restrict research, competition and open-weight AI development. 6 https://openai.com/index/api-model-distillation/ 4 https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ What distillation actually does In a conventional setup, a large “teacher” model generates predictions that contain more information than a simple correct-or-incorrect label. A smaller “student” model is trained to approximate those predictions. Geoffrey Hinton, Oriol Vinyals and Jeff Dean described the modern approach in a 2015 paper as a way to compress knowledge from an expensive model or ensemble into a system that is easier to deploy. 1 https://research.google/pubs/distilling-the-knowledge-in-a-neural-network/ With today’s language models, developers can ask a teacher to generate answers, code, critiques or worked examples, then use those outputs as synthetic training data. The student is a separate model with its own weights; it learns patterns from the teacher’s behavior rather than receiving a copy of the teacher’s model files. 7 https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation/ Access determines what information is available. A developer working with its own model may use internal probability distributions, hidden states and input-output pairs. An outside developer usually sees only the answers returned by an API or chatbot, requiring it to collect outputs at scale. Reasoning examples, critiques and grading signals can be particularly useful for training models on mathematics, coding and multistep tasks. 7 https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation/ The commercial appeal is straightforward. Distillation can produce models that are cheaper to run, faster to query or optimized for a defined workload. OpenAI’s authorized product, for example, lets customers store outputs from larger models and use them to fine-tune more cost-efficient models on its platform. 6 https://openai.com/index/api-model-distillation/ When model development becomes an extraction campaign The emerging U.S. policy definition focuses less on the algorithm than on how access was obtained and used. H.R. 8283, the Deterring American AI Model Theft Act, defines a model-extraction attack as unauthorized querying used to replicate or improve another model when the operator circumvents controls, uses fraudulent credentials or violates restrictions that specifically prohibit training on outputs. It excludes activity performed with permission or in compliance with the provider’s terms. 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm Anthropic supplied the most detailed public allegations. It said the three named labs generated more than 16 million Claude exchanges through approximately 24,000 fraudulent accounts. Anthropic attributed more than 3.4 million exchanges to Moonshot and more than 13 million to MiniMax, saying the operations targeted capabilities including coding, tool use, computer use and reasoning. 3 https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks Those numbers describe Anthropic’s detection and attribution, not an independently audited measurement of how much any resulting model learned from Claude. Anthropic said its evidence included request metadata, infrastructure indicators, account coordination and activity that corresponded with product-development timelines. 3 https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks That distinction matters because individual prompts can resemble ordinary customer activity. Providers instead look for patterns across accounts: repetitive prompt structures, unusually high volume, concentration on selected capabilities, coordinated credentials and timing that aligns with another developer’s model training. 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm 3 https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks The intellectual-property claim is less settled than the rhetoric Calling unauthorized distillation “IP theft” does not by itself establish which legal right has been violated. Contract-based claims are the most immediate route when users accept terms that prohibit model extraction or competitive training. OpenAI’s current business agreement defines reverse engineering to include model-extraction or stealing attacks, while its consumer terms prohibit automated output extraction and using output to develop competing models. 8 https://openai.com/policies/services-agreement/ Copyright is more complicated. The U.S. Copyright Office says protection does not extend to purely AI-generated material or material lacking sufficient human control over its expressive elements. 9 Distillation also need not reproduce the teacher’s code or weights. A 2026 law-journal analysis concluded that model distillation is unlikely, by itself, to constitute copyright infringement under existing U.S. doctrine, although particular outputs, access methods and contracts could produce different claims. 13 https://repository.uclawsf.edu/hastings science technology law journal/vol17/iss1/3/ Congress can create a national-security framework without declaring every model response to be copyrighted property. H.R. 8283 would require government assessments, confidential information sharing and a public list of identified extraction operators. It also would permit consideration of Commerce Department Entity List restrictions and sanctions. 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm The House Foreign Affairs Committee ordered the bill reported, as amended, by a 43-0 vote on April 22. As of July 26, its latest recorded action remained at the committee stage; the full House had not passed it. 10 https://www.cbo.gov/publication/62480 14 https://usdocket.org/bill/8378 Safety arguments cut in both directions Frontier labs argue that a distilled model can acquire useful capabilities without inheriting the teacher’s safety measures. Safety behavior may depend on separate post-training, access controls, monitoring and deployment policies. The Frontier Model Forum warns that selective extraction can therefore produce models with advanced coding or reasoning skills but little or none of the source model’s safety training. 7 https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation/ Open-model supporters answer that closed access is not automatically safer. The July 24 industry letter says downloadable weights allow more researchers to inspect model behavior, find vulnerabilities, conduct red-team tests and develop safeguards. It acknowledges that released weights cannot easily be recalled or controlled, but argues that unlawful extraction should be addressed through targeted legal and commercial tools rather than sweeping restrictions on distillation. 4 https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ The letter’s list displayed 50 signatories on July 26, spanning model developers, chipmakers, cloud providers and security companies. It includes Google and OpenAI, even though both companies separately say they detect and oppose unauthorized extraction from their models. Google has called such activity a form of IP theft that violates its terms, while OpenAI has asked the government and industry to strengthen defenses against adversarial distillation. 4 https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ 11 https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use 12 https://cdn.openai.com/pdf/045aa967-ee96-4a09-94ee-3098ddf6db2c/OpenAI-US-House-Select-Cmte-Update-%5B021226%5D.pdf The company positions are therefore not as binary as “open” versus “closed.” OpenAI and Google support open-weight development and legitimate distillation while opposing covert extraction. Anthropic, which was not listed among the letter’s signatories on July 26, has taken a more restrictive public position on uncontrolled frontier capabilities. 4 https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ 3 https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks The unresolved policy work lies in proving intent and drawing enforceable boundaries. Query volume and account coordination can signal extraction, but the same underlying methods—synthetic-data generation, model grading and learning from another system’s outputs—also support ordinary research and commercial development. Rules aimed at conduct, access and authorization are more likely to preserve that distinction than a prohibition on distillation itself. 2 https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm 7 https://www.frontiermodelforum.org/issue-briefs/issue-brief-adversarial-distillation/ Companies mentioned Further sources 1 Google Research, “Distilling the Knowledge in a Neural Network,” Geoffrey Hinto… ↗ https://research.google/pubs/distilling-the-knowledge-in-a-neural-network/ 2 U.S. Government Publishing Office, text of H.R. 8283, Deterring American AI Mod… ↗ https://www.govinfo.gov/content/pkg/BILLS-119hr8283ih/html/BILLS-119hr8283ih.htm 3 Anthropic, “Detecting and preventing distillation attacks,” February 23, 2026. ↗ https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks 4 Microsoft, “Open Weights and American AI Leadership,” July 24, 2026; signatory … ↗ https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/ 5 White House Office of Science and Technology Policy, NSTM-4, “Adversarial Disti… ↗ https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf 6 OpenAI, “Model Distillation in the API,” October 1, 2024. ↗ https://openai.com/index/api-model-distillation/ +8 more The stories that matter, in one email. Free — unsubscribe anytime.