AI model extraction safeguards and sanctions

Full Title:
Deterring American AI Model Theft Act of 2026

Summary#

This bill is about stopping foreign adversaries from copying or stealing the technical details of closed-source AI models owned by U.S. companies. It requires federal agencies to assess and report on model extraction attacks, create a public list of offenders, share best practices with industry, and consider placing offenders on export-control and sanctions lists. The broad goal is to protect U.S. economic and national security interests and private-sector intellectual property.

  • Main changes: Requires an interagency assessment of model extraction attacks and “fraudulent account network providers” within 180 days, with a public report due within 210 days and annual updates for 3 years.
  • Public list: Creates an “AI Model Extraction Attackers List” for named individuals and entities identified as attackers; it may be published for up to 5 years.
  • Information sharing and guidance: Directs Commerce to set up voluntary, confidential information sharing with model owners and to publish best practices for detecting and stopping attacks.
  • Enforcement tools: Directs Commerce and other agencies to consider adding identified entities (and affiliates) to the Commerce Department’s Entity List (export restrictions) and allows the President, via the State Department and IEEPA, to block property and transactions of identified entities, with some humanitarian and national-security exceptions.
  • Protections for confidential information: The bill bars disclosing confidential model-owner information on public materials without the owner’s permission.

What it means for you#

  • Owners of closed‑source AI models (U.S. companies):
    • Must be able to voluntarily share confidential information with the government about attacks.
    • Could get federal help detecting, deterring, and responding to model extraction attacks.
    • May be asked to provide information for the government’s assessment and guidance development.
  • Foreign entities and persons in listed “countries of concern” (for example China and Russia):
    • Could be investigated and named if they are found to have run model extraction attacks or provided fraudulent accounts.
    • Could face export controls, transaction blocks, and sanctions if added to the Entity List or targeted under IEEPA.
  • Fraudulent account network providers (entities that sell or operate fake accounts to bypass location restrictions):
    • Are specifically identified as targets for the assessment and potential listing and sanctions.
    • The bill excludes providers whose only activity is aiding internet access for legitimate freedom-of-expression uses.
  • U.S. government agencies (Commerce, State, others on export-policy committees):
    • Must do an assessment, set up information sharing, publish reports and guidance, and coordinate possible listing and sanctions decisions.
    • Will have new investigative and reporting duties with set deadlines (180–210 days for the initial work).
  • Researchers and legitimate users:
    • The bill says authorized model training consistent with terms of service is not a model extraction attack. The bill does not change protections for lawful, permitted research that owners authorize.
  • Companies or persons doing business with identified entities:
    • Could face legal limits or penalties if they transact with entities that are added to the Entity List or are sanctioned under IEEPA.

Expenses#

No publicly available information.

  • The bill requires new assessments, routine monitoring, reports, a public list, and an information‑sharing mechanism. These duties would likely require staff time, technical analysis, and systems for secure information handling.
  • Adding entities to the Entity List and administering sanctions can increase agency workload for licensing, enforcement, and legal review.
  • The bill does not include a fiscal note or specific funding amounts.

Proponents' View#

  • The bill appears intended to protect U.S. national security and economic interests by stopping foreign actors from copying advanced, closed-source AI models.
  • It aims to help U.S. companies defend trade secrets and intellectual property by improving detection and response and by creating tools to punish offenders.
  • The bill could improve coordination between government and industry through voluntary, confidential information sharing.
  • Publishing best practices may help model owners better detect and respond to attacks.
  • Creating public and export-control lists could deter future attacks by raising the cost for attackers.

Opponents' View#

  • One concern is that the bill does not fully explain how the government will reliably determine when querying behavior counts as a model extraction attack versus legitimate use; this could raise risks of false positives.
  • The bill leaves some technical details unclear, such as the exact standards for identifying fraudulent account networks and how attribution will be proven.
  • There may be practical trade-offs between public naming of entities and protecting confidential company information, even though the bill seeks owner permission for disclosures.
  • The bill could increase agency workloads and require funding not specified in the text.
  • It is unclear how the measures would affect lawful research, third-party hosting services, or legitimate cross-border collaboration in AI beyond the stated exclusion for authorized training.