Home IssueArtificial IntelligenceHow to Fix the AI Model Theft Bill Before It Becomes Law

How to Fix the AI Model Theft Bill Before It Becomes Law

by Michelle Lopes Maldonado

Adversarial AI distillation—the systematic extraction of capabilities from a frontier AI model to train a competing model—poses a real threat to U.S. AI leadership and national security. Congress is right to respond, and the Deterring American AI Model Theft Act of 2026 (DAAMTA) provides a strong starting point. But the bill needs targeted changes to stop large-scale AI model theft without discouraging legitimate research or slowing U.S. innovation.

Adversarial AI distillation raises three distinct concerns. First, it allows foreign competitors to benefit from significant U.S. AI research without making comparable investments. Second, extracted capabilities can support an adversary’s military and intelligence applications. Third, distilled models may inherit a frontier system’s capabilities while shedding its safety guardrails.

Existing laws, including the Computer Fraud and Abuse Act and the Defend Trade Secrets Act, are likely not enough to withstand coordinated, state-affiliated, industrial-scale model extraction. Congress and the White House have moved to fill the gap: the House Foreign Affairs Committee unanimously advanced the Deterring American AI Model Theft Act of 2026 (DAAMTA, H.R. 8283), and the White House Office of Science and Technology Policy’s Memorandum NSTM-4 designated foreign distillation campaigns a national security threat.

DAAMTA is a good legislative vehicle, but Congress should address four shortcomings before moving forward with the bill.

First, the bill defines model extraction too broadly. The definition relies heavily on violations of terms of service. Those agreements are private contracts between companies and their users, not public law. They vary across providers, change frequently, and often prohibit conduct that poses little or no security risk. Congress should instead define prohibited conduct around intentional account fraud combined with systematic efforts to extract model capabilities. Federal sanctions should not hinge on violating a company’s terms of service.

Second, DAAMTA needs stronger evidentiary requirements for its proposed public AI Model Extraction Attackers List. Public designations would likely rely on disclosures from AI companies rather than independently verified evidence. The government may possess classified intelligence that supports those findings, but public designations built on opaque evidence create due process concerns, risk harming wrongly identified organizations, and invite international legal challenges. Congress should require a public summary of the evidentiary basis for each designation, even if classified sources and methods remain protected.

Third, the bill should explicitly protect open-source AI development and security research. The legislation as drafted applies to “closed-source AI models,” which appropriately targets the primary concern. But political pressure can push legislative frameworks beyond their original targets. Congress should add clear, statutory safe harbors for open-source development, academic research, and legitimate security testing.

Fourth, the federal government should explain how its own AI development practices fit within the legal framework it seeks to establish. The Department of Defense’s 2026 AI strategy directs procurement of AI models “free from usage policy constraints that may limit lawful military applications.” Recent research found that commercial models refuse up to 98 percent of operationally relevant military queries, which creates institutional pressure to train around those restrictions. To be clear, the distillation the government conducts on models it has lawfully procured or licensed is categorically different from the fraudulent, access-control-evading extraction DAAMTA targets. But Congress should make that distinction explicit, and the executive branch should publicly explain how government AI development complies with the standards DAAMTA would establish.

Congress should pair any legislative action with broader efforts to strengthen AI security.

An initial priority is advancing DAAMTA with the amendments above. The bill’s reporting requirements, sanctions authorities, and export control mechanisms provide a solid framework. Narrowing the definition of prohibited conduct, strengthening evidentiary standards, and protecting legitimate research would make the law more effective.

Additionally, the federal government should invest in stronger technical defenses. The National Institute of Standards and Technology (NIST), working with the Commerce Department’s Center for AI Standards and Innovation (CAISI), should develop standards for detecting model extraction, limiting abusive API activity, and supporting forensic attribution. Those measures would strengthen the security of U.S. AI systems regardless of whether sanctions succeed.

Next, the United States should work with allies to establish common norms against state-backed AI model theft. Adversarial distillation occurs through Internet-connected AI services and can route through almost any jurisdiction. Coordinated action by countries with leading AI industries, including the United Kingdom, Japan, Canada, and France, would extend the reach of U.S. policy and increase the costs of state-sponsored model theft beyond U.S. sanctions alone.

Finally, policymakers should regulate harmful conduct, not the underlying technique. Knowledge distillation is a standard tool used throughout AI research and development. The problem is not distillation itself. It is fraudulent account creation, deliberate evasion of access controls, and systematic efforts to extract model capabilities at industrial scale on behalf of strategic competitors. Keeping that distinction clear will protect both U.S. security and U.S. innovation.

Congress should pass DAAMTA, but only after narrowing its scope and strengthening its safeguards. The goal is not to regulate AI distillation as a technique. The goal is to stop fraudulent, industrial-scale model theft by strategic competitors without undermining the research and innovation that keep the United States ahead.

Image credit: ttarasiuk/FlickrMichelle

You may also like

Show Buttons
Hide Buttons