cd /news/artificial-intelligence/congress-moves-to-make-ai-model-dist… · home topics artificial-intelligence article
[ARTICLE · art-69812] src=startupfortune.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Congress moves to make AI model distillation a sanctionable offense as Chinese labs face theft accusations

Representative Bill Huizenga introduced the Deterring American AI Model Theft Act of 2026, H.R. 8283, on April 15, which would make AI model distillation a sanctionable offense, and the House Foreign Affairs Committee reported the bill 43-0 after an April 22 markup. Treasury Secretary Scott Bessent said on Fox Business on July 21 that the U.S. has the ability to sanction overseas models that steal from American companies, citing distillation. The bill targets model extraction attacks by foreign entities of concern, following allegations by Anthropic and OpenAI that Chinese labs DeepSeek, Moonshot AI, and MiniMax conducted industrial-scale distillation campaigns.

read5 min views1 publishedJul 23, 2026
Congress moves to make AI model distillation a sanctionable offense as Chinese labs face theft accusations
Image: Startupfortune (auto-discovered)

Washington is moving toward treating some AI distillation as sanctions territory, and Chinese model labs are no longer dealing only with angry blog posts from OpenAI and Anthropic.

The machinery is moving fast. Representative Bill Huizenga introduced the Deterring American AI Model Theft Act of 2026, H.R. 8283, on April 15, with Representative John Moolenaar, chair of the House Select Committee on China, as an original co-sponsor. The House Foreign Affairs Committee reported the bill 43-0 after an April 22 markup, according to congressional records and a policy analysis from the Institute for AI Policy and Strategy.

Then came Bessent. Treasury Secretary Scott Bessent appeared on Fox Business on July 21 and made the administration's position explicit: "If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft." He named the technique directly. Distillation. Investing.com reported that Bessent also said U.S. watermarks had been found on many Chinese models and that the administration would look at the issue in the coming days or week.

That's not routine Washington noise. A unanimous committee vote, followed three months later by a cabinet secretary publicly floating sanctions, tells you where the pressure is moving. The legal status of adversarial distillation is being pulled out of the private terms-of-service world and pushed into national security policy.

The bill is not vague about timing. As amended in committee, it would direct the Secretary of Commerce to assess which foreign entities of concern have conducted what it calls model extraction attacks, or helped users route around geographic access limits through fraudulent account networks. A first assessment would be due within 180 days of enactment, and export blacklist or sanctions decisions would follow within 210 days. The sanctions authority would run through the International Emergency Economic Powers Act, the 1977 law already used in parts of the U.S. technology control regime.

The targets already exist in public allegations, even if Washington has yet to publish its own list. Anthropic published an account in February accusing DeepSeek, Moonshot AI, and MiniMax of running industrial-scale distillation campaigns against Claude through about 24,000 fraudulent accounts and more than 16 million exchanges. Anthropic said the campaigns used proxy services, coordinated account patterns, and prompts aimed at Claude's agentic reasoning, coding, tool use, and other differentiated capabilities. The company also said it was sharing technical indicators with other AI labs, cloud providers, and relevant authorities.

OpenAI made a similar complaint about DeepSeek. Bloomberg reported in February that OpenAI sent a memo to the House Select Committee on China saying DeepSeek had used distillation techniques as part of "ongoing efforts to free-ride on the capabilities developed by OpenAI and other US frontier labs," including new obfuscated methods designed to evade defenses.

The Kimi K3 fight gave the bill new life #

Moonshot AI's Kimi K3 release on July 16 turned an already live policy fight into a market story. Reuters reported that the Beijing startup described Kimi K3 as a 2.8 trillion-parameter open-weight model with performance approaching Anthropic's Fable system. Nature reported that scientists were impressed by the model's size and capabilities, while also noting that Moonshot d new sign-ups three days after release because demand had pushed its systems close to processing limits.

For Washington, that timing is uncomfortable. Anthropic had named Moonshot in February. Then Moonshot shipped a model that looked close enough to the U.S. frontier to make investors and policymakers ask whether Chinese labs were narrowing the gap through better engineering, illicit copying, or some mix of both. You don't need to accept every accusation from a U.S. lab to see the policy consequence. The suspicion alone is now moving legislation.

If you're building on models, this matters #

For founders and investors, the issue is not abstract. If distillation attacks become sanctionable, the economics of building a Chinese AI competitor by extracting outputs from American frontier models changes overnight. This is the moat argument. Closed model providers such as OpenAI and Anthropic have always faced the threat that a well-funded rival could narrow the capability gap by querying rather than training from scratch. H.R. 8283 would turn that shortcut into a legal exposure. That's the open question: what counts as theft. Distillation is not automatically illicit. Anthropic itself says frontier labs legitimately distill their own models to make smaller versions for customers. The bill targets improper query-and-copy techniques used to extract key technical features from closed-source U.S.-owned models, and Commerce would do much of the definitional work after enactment. The Institute for AI Policy and Strategy has already warned that the bill could go further on industry cooperation, information sharing, and enforcement.

Frankly, Chinese AI labs should not wait for the final assessment to map their exposure. DeepSeek, Moonshot, MiniMax, Alibaba's Qwen team, and any proxy network selling access around U.S. restrictions are now operating in a different environment from the one they faced in February. A model launch can still win benchmarks. It can still go viral. But if Washington concludes the training path ran through illicit extraction, the next benchmark may be the Commerce Department's Entity List.

Also read: AMD bets $5 billion on Anthropic and gets tens of billions in chip orders backIBM's CEO says the mainframe isn't dying but the numbers are doing him no favorsServiceNow bets $40 million on an Indian AI banking startup to lock down enterprise agent governance

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @bill huizenga 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/congress-moves-to-ma…] indexed:0 read:5min 2026-07-23 ·