Political · compiled 4 September 2026 · 100 sources

Political and geopolitical view of AI distillation

Between January 2025 and September 2026, model distillation went from an obscure machine-learning technique to a named object of US national security policy. It began when OpenAI and Microsoft said they had evidence a DeepSeek-linked group had pulled data through OpenAI's API, and White House AI czar David Sacks said there was 'substantial evidence' DeepSeek had distilled OpenAI models. It escalated through OpenAI's March 2025 OSTP filing calling DeepSeek 'state-subsidized' and 'state-controlled,' Anthropic's September 2025 ban on entities majority-controlled from China, and a February 2026 wave of disclosures in which OpenAI, Google and Anthropic each published evidence of large-scale extraction campaigns. It became formal policy in April 2026 with OSTP memorandum NSTM-4 on 'adversarial distillation,' a State Department demarche cable, and H.R. 8283, which would create a public 'AI Model Extraction Attackers List' — followed by NSPM-11 in June, Anthropic's letter alleging a 28.8-million-exchange Alibaba campaign, and Treasury Secretary Bessent's July 2026 sanctions threat. Underneath the geopolitics sits an unresolved legal question: the strongest theory against distillation is breach of contract, not copyright or trade secret, and critics from ITIF to the Institute for Law & AI warn that building export controls and sanctions on top of private terms of service is a shaky foundation.

Key figures · 8 figures

Claude exchanges in largest disclosed campaign

28,800,000 exchanges

vs 16M disclosed in Feb 2026

Anthropic's June 10, 2026 letter to Senate Banking alleges Alibaba/Qwen-affiliated operators ran 28.8M+ exchanges between Apr 22 and Jun 5, 2026

d1e00ek4ebabms.cloudfront.net

Fraudulent accounts alleged (Alibaba campaign)

25,000 accounts

24,000 in the Feb 2026 DeepSeek/Moonshot/MiniMax disclosure

Anthropic's June 10, 2026 letter to the Senate Banking Committee alleges almost 25,000 fraudulent accounts violating its terms of service and regional access restrictions

d1e00ek4ebabms.cloudfront.net

House Foreign Affairs vote on H.R. 8283

43 yeas (43-0)

unanimous

Deterring American AI Model Theft Act of 2026 ordered reported April 22, 2026; not yet passed the full House as of Sept 2026

congress.gov

US states restricting DeepSeek on state devices

14 states

0 before Jan 31, 2025

Texas, New York, Virginia, Iowa, South Dakota, North Carolina, Nebraska, Tennessee, Arkansas, North Dakota, Oklahoma, Alabama, Kansas and Georgia, as of April 2025; likely higher by Sept 2026

statetechmagazine.com

Nvidia/AMD China revenue share to US government

15 % of China chip revenue

new condition, Aug 2025

Reported arrangement tied to resumed H20 / MI308 export licences

fortune.com

Section 232 tariff on advanced AI chips imported into the US (incl. those routed to China)

25 %

new; paired with BIS case-by-case review replacing presumption of denial

Proclamation signed Jan 14, 2026, effective Jan 15, 2026; separately BIS moved H200 / MI325X to case-by-case review for China and Macau

whitecase.com

Entities on Pentagon 1260H list after June 2026 update

188 entities

+65 added June 2026

Alibaba, Baidu, BYD and Unitree added; DeepSeek notably not listed

cnbc.com

Maximum EU AI Act fine for GPAI providers

15,000,000 EUR or 3% of global turnover

enforceable from Aug 2, 2026

Whichever is higher; AI Office gained investigation and model-access powers on that date

ec.europa.eu

Key findings · 10 findings

  1. Distillation is now a named category in US national security policy — but naming has not produced sanctions

    OSTP memorandum NSTM-4, 'Adversarial Distillation of American AI Models,' issued by OSTP under Director Michael Kratsios on April 23, 2026, is the first US policy instrument to formally classify systematic capability extraction from frontier models as a national security threat. It found that foreign entities, principally in China, are running 'deliberate, industrial-scale campaigns' using tens of thousands of proxy accounts, and committed the executive branch to threat-intelligence sharing with industry, joint defensive best practices, and exploration of accountability measures. NSPM-11, signed June 5, 2026, then directed the national security enterprise to help secure US models against distillation attacks. Naming has not yet become enforcement: no Chinese AI lab has been sanctioned or Entity Listed specifically for distillation as of early September 2026. In June 2026 the administration held off publishing an expanded blacklist covering DeepSeek and 100+ other flagged firms, reportedly to avoid escalating with Beijing, and DeepSeek was absent from the Pentagon's June 2026 1260H expansion that added Alibaba and Baidu. Treasury Secretary Bessent's July 21, 2026 warning that Washington could sanction overseas models found to have stolen from US firms remained a threat.

    Sources nextgov.com · whitehouse.gov · justsecurity.org · cnbc.com · cnbc.com · cnbc.com

  2. The legal core of the accusation is breach of contract, not IP theft — and that is a weaker peg than the rhetoric implies

    US copyright law does not protect purely machine-generated outputs, and OpenAI's own terms assign output rights to the user, so a copyright claim against a distiller is difficult. Trade secret theory is available but unsettled: it depends on whether querying an API counts as acquisition by 'improper means.' The theory that actually fits is contract — OpenAI's terms bar using Output 'to develop models that compete with OpenAI' — plus, where fraudulent accounts and evaded geo-restrictions are involved, the Computer Fraud and Abuse Act. H.R. 8283 mirrors this: its definition of a 'model extraction attack' turns on circumventing access controls, using fraudulent credentials, or violating terms of service. The symmetry argument has never gone away either: because copyright does not protect bare machine outputs and terms of service are private contracts, critics — including a Cornell tip sheet published within days of OpenAI's January 2025 statement — note that training on publishers' content also violated those publishers' terms. The asymmetry the labs rely on is jurisdictional and contractual rather than moral, which is why the fight migrated to export controls, sanctions and procurement bans rather than the courts.

    Sources govinfo.gov · law.asia · justsecurity.org · copyright.gov · news.cornell.edu · futurism.com

  3. Building federal sanctions on top of private terms of service is the central critique of the 2026 bills

    ITIF's July 28, 2026 analysis of H.R. 8283 argues the bill leans too heavily on terms-of-service violations — private contracts that vary provider to provider — as the trigger for federal designation, and that an 'AI Model Extraction Attackers List' built on unverified corporate disclosures raises due-process concerns. It recommends narrowing the definition to intentional account fraud, requiring public evidentiary summaries, and adding safe harbours for open-source development, academic research and security testing. The Institute for Law & AI makes a parallel argument: policymakers should first ask how much distillation actually contributes to the capability gap before locking in restrictions.

    Sources itif.org · law-ai.org · lawfaremedia.org

  4. Disclosure moved from anecdote to numbers — and the numbers keep growing

    January 2025 accusations were qualitative: Microsoft security researchers observed suspected DeepSeek-linked individuals exfiltrating data via the OpenAI API, and David Sacks cited 'substantial evidence' without detailing it. By February 2026 the labs published counts: Anthropic attributed 150,000+ exchanges to DeepSeek, 3.4 million to Moonshot AI and 13 million to MiniMax across ~24,000 fraudulent accounts; Google's Threat Intelligence Group disrupted a cluster of 100,000+ prompts aimed at coercing Gemini reasoning traces. By June 2026 Anthropic put a single Alibaba-linked campaign at 28.8 million exchanges. The trend line of disclosed volume is the single most concrete input to the policy debate.

    Sources anthropic.com · techinformed.com · d1e00ek4ebabms.cloudfront.net · cloud.google.com

  5. Export controls and distillation policy are the same argument in two registers

    Anthropic's public position is that distillation 'reinforces the rationale for export controls,' because harvested exchanges are only useful if the distiller has compute to train on them. Dario Amodei made the compute-asymmetry argument in January 2025. The counter-current is commercial: the Biden AI Diffusion Rule (Jan 15, 2025) was rescinded before its May 15, 2025 enforcement date; the GAIN AI Act, which would have required US customers be served first, passed the Senate as an NDAA amendment in October 2025 but was dropped from the final FY2026 NDAA; and in January 2026 H200 and MI325X exports moved from presumption of denial to case-by-case review with a 25% tariff.

    Sources anthropic.com · darioamodei.com · wiley.law · nextgov.com

  6. Private corporate policy has become de facto foreign policy

    OpenAI blocked API traffic from unsupported regions including mainland China on July 9, 2024, then introduced Verified Organization ID checks for frontier API access in April 2025. Anthropic went furthest: on September 5, 2025 it barred service to companies more than 50% owned by entities in China, Russia, Iran and North Korea regardless of where those subsidiaries operate, accepting a revenue hit it described as in the low hundreds of millions of dollars. These access rules, not statutes, are what H.R. 8283 would convert into a designation trigger — which is precisely why critics call the mechanism circular.

    Sources semafor.com · rte.ie · help.openai.com · restofworld.org

  7. Evidence quality is contested, and at least one White House accusation drew expert pushback

    On July 22, 2026 OSTP Director Kratsios accused Moonshot AI of distilling Anthropic's Fable to build Kimi K3 and of obtaining export-controlled Nvidia servers. Researchers including Nathan Lambert (Allen Institute for AI) and Braden Hancock (Laude Institute) publicly doubted that distillation alone could explain K3's capabilities on that timeline — Fable had been publicly available only since July 1 — and no supporting evidence was published. Earlier, US officials alleged DeepSeek trained V4 on smuggled Blackwell GPUs; Nvidia called the claim farfetched and DeepSeek's V4 preview shipped optimised for Huawei Ascend silicon. Accusation-without-published-evidence is a recurring pattern.

    Sources cyberscoop.com · techcrunch.com · technologyreview.com

  8. China's response has moved from denial to mirror-imaging

    The Chinese Embassy in Washington called US allegations groundless and framed them as attacks on China's AI development. On July 27, 2026 the Ministry of Commerce went further, accusing 'many American AI enterprises' of distilling Chinese models — naming none and supplying no evidence — calling US actions 'double standards' and 'AI hegemony,' and promising 'all necessary measures' if Chinese firms were sanctioned. Separately, FT reported that MOFCOM was consulting Alibaba, ByteDance and Zhipu on adding model weights, key training data and chip designs to China's technology export catalogue, which would make Chinese open weights themselves a licensed export.

    Sources implicator.ai · techrepublic.com · cnbc.com

  9. The EU regulates capability, not provenance — which leaves distillation largely untouched

    EU AI Act GPAI obligations began applying August 2, 2025, backed by a Code of Practice published July 10, 2025 with Transparency, Copyright, and Safety & Security chapters; Commission enforcement powers, including fines up to EUR 15 million or 3% of global turnover, went live August 2, 2026. None of this creates a distillation-specific offence. Europe's actual friction with Chinese models has run through GDPR instead — Italy's Garante ordered DeepSeek's chatbot blocked in early 2025, and Berlin's commissioner found its transfer practices unlawful — while self-hosted open weights on EU servers sidestep the transfer question entirely.

    Sources artificialintelligenceact.eu · ec.europa.eu · privacylaws.com · pinsentmasons.com

  10. A grey market for API access is the practical enforcement problem

    Extraction at the scale the labs describe requires access the labs have formally denied. Reporting on China's 'transfer station' economy describes tens of thousands of internet-facing servers running reseller billing panels that proxy OpenAI, Anthropic, Google and other Western models into China, sometimes at roughly a tenth of list price. Anthropic says a single proxy network managed more than 20,000 fraudulent accounts. H.R. 8283 responds by defining a 'fraudulent account network provider' as a designation target in its own right — with a carve-out for services that enable internet access for freedom of expression.

    Sources chinatalk.media · deeplearning.ai · govinfo.gov

Charts · 5 charts

Distillation-adjacent policy and enforcement actions per quarter, 2022-2026

actions
The values plotted in “Distillation-adjacent policy and enforcement actions per quarter, 2022-2026”, in actions.
QuarterActions catalogued actions
2022 Q41
2023 Q41
2024 Q31
2024 Q41
2025 Q19
2025 Q24
2025 Q36
2025 Q42
2026 Q15
2026 Q211
2026 Q36

Counts are computed strictly from the entries in this dashboard's own timeline[] — one point per event, no other inclusion rule — so every bar can be reproduced by filtering the timeline by quarter. Not an exhaustive census of AI policy activity. Quarters with zero catalogued events are omitted. 2026 Q3 runs only to September 4, 2026.

Sources: justsecurity.org · congress.gov

Jurisdiction stance comparison: which policy tools are actually in place

binary indicator
The values plotted in “Jurisdiction stance comparison: which policy tools are actually in place”, in binary indicator.
JurisdictionDistillation-specific policy instrument binary indicatorBinding law on general-purpose / frontier AI binary indicatorRestricts Chinese AI apps on government devices binary indicatorUnilateral controls on advanced AI chip / tech exports binary indicator
United States1011
European Union0100
United Kingdom0000
China0101
South Korea0110
Japan0001
Australia0010
Taiwan0011

US row scores 0 on binding GPAI law at the federal level; California SB 53 and the New York RAISE Act are state instruments. EU scores 0 on export controls because those are member-state and Wassenaar instruments (e.g. the Netherlands), not bloc-level AI chip controls. China's binding-law score reflects its generative AI and labelling measures; its export-control score reflects existing materials controls plus the 2026 consultation on model weights.

Sources: ec.europa.eu · cooley.com · techrepublic.com · statetechmagazine.com

Exchanges with Claude attributed to each accused lab, as disclosed by Anthropic

exchanges
The values plotted in “Exchanges with Claude attributed to each accused lab, as disclosed by Anthropic”, in exchanges.
Accused labFebruary 23, 2026 disclosure exchangesJune 10, 2026 letter to Senate Banking exchanges
DeepSeek150,000
Moonshot AI3,400,000
MiniMax13,000,000
Alibaba / Qwen-affiliated operators28,800,000

Figures are Anthropic's own attributions and have not been independently verified or adjudicated. The February set totals over 16 million exchanges across approximately 24,000 fraudulent accounts; the Alibaba campaign is dated April 22 to June 5, 2026 and used nearly 25,000 accounts. Alibaba denies using proprietary model outputs to train its models.

Sources: anthropic.com · d1e00ek4ebabms.cloudfront.net · cnbc.com

How far each US bill has actually travelled

stage
The values plotted in “How far each US bill has actually travelled”, in stage.
BillFurthest stage (1 introduced, 2 reported by committee, 3 passed a chamber, 4 enacted) stage
H.R. 8283 Model Theft2
H.R. 3447 Chip Security2
S. 1705 Chip Security1
S. 3150 GAIN AI3
S. 321 Decoupling1
S. 2177 No Adversarial AI1
H.R. 4142 No Adversarial AI1
H.R. 1121 No DeepSeek on Gov Devices1

S. 3150 scores 3 because the GAIN AI Act passed the Senate as an amendment to the FY2026 NDAA on October 9, 2025 — but it was stripped in conference and the enacted NDAA excludes it, so no bill in this set has reached stage 4.

Sources: congress.gov · congress.gov · nextgov.com

Cumulative restrictions on DeepSeek among the jurisdictions this dashboard tracks, first quarter after R1

jurisdictions
The values plotted in “Cumulative restrictions on DeepSeek among the jurisdictions this dashboard tracks, first quarter after R1”, in jurisdictions.
MonthJurisdictions with a public restriction jurisdictions
2025-012
2025-029
2025-0312
2025-0412

Counts only the restrictions listed in the 'Government restrictions on DeepSeek' table: Italy and Texas in January; Taiwan, Australia, New York, Virginia, South Korea, Iowa and the US Commerce Department in February; South Dakota, Oklahoma and North Carolina in March; no further additions in April within this table. This is deliberately narrower than the full picture — StateTech lists 14 US states restricting DeepSeek by April 2025, including Nebraska, Tennessee, Arkansas, North Dakota, Alabama, Georgia and Kansas, which this table does not enumerate individually.

Sources: statetechmagazine.com · privacylaws.com

Tables · 6 tables

Policy matrix: how each jurisdiction treats distillation and Chinese models

12 rows
Policy matrix: how each jurisdiction treats distillation and Chinese models — Binding instruments, government-device restrictions and the specific stance on model extraction, as of September 2026.
JurisdictionPrimary instrumentStatusKey dateDistillation stanceChinese-model stance
United States (executive)OSTP NSTM-4; NSPM-11; AI Action PlanIn force2026-04-23Named national security threat; intel sharing with labs; accountability measures 'explored'Federal device bans proposed; export controls; no model sanctions yet nextgov.com
United States (Congress)H.R. 8283 Deterring American AI Model Theft ActReported by committee 43-0; not enacted2026-04-22Would create public 'AI Model Extraction Attackers List' + IEEPA/Entity List authoritiesPRC, Hong Kong, Macau and Russia are 'countries of concern' by statute congress.gov
United States (states)Executive directives; CA SB 53; NY RAISE ActIn force2026-01-01No state distillation offence; frontier-model transparency only7+ states bar DeepSeek on state devices and networks statetechmagazine.com
European UnionAI Act GPAI obligations + Code of PracticeApplying; enforcement powers live2026-08-02No distillation-specific rule; downstream fine-tuners can become providersCapability-based, provenance-neutral; friction runs through GDPR ec.europa.eu
ItalyGarante order under GDPRIn force2025-01-30Not addressedDeepSeek chatbot blocked for the general public, not just government privacylaws.com
United KingdomSovereign AI Unit (DSIT); AI Security InstituteNon-statutory2025No dedicated instrument; treated as a security-research questionNo ban; AISI evaluations flag DeepSeek jailbreak and censorship behaviour oecd.ai
ChinaGlobal AI Governance Action Plan; WAICO; export catalogue reviewAnnounced / under consultation2025-07-26Defends distillation as an industry-wide technique; counter-accuses US firmsPromotes open-weight release; weighing export controls on weights and training data techrepublic.com
South KoreaAI Basic Act (Framework Act)In force2026-01-22Not addressedPIPC suspended DeepSeek app downloads Feb 2025 pending compliance cooley.com
JapanAI Promotion Act (May 2025)In force; promotional, light-touch2025-05Not addressedNo ban; policy focus on domestic R&D capacity and competitiveness whitecase.com
AustraliaGovernment device directiveIn force2025-02-04Not addressedDeepSeek prohibited on government devices privacylaws.com
TaiwanGovernment agency guidanceIn force2025-02Not addressedDeepSeek restricted in public sector over cross-border data transfer risk tech.co
Gulf states (UAE, Saudi Arabia)Bilateral compute and security agreementsNegotiated, deal-by-deal2026Not addressed directly; governed via US access conditionsUAE aligned G42 away from Chinese tech; Saudi retains Huawei links iiss.org

Coding reflects publicly reported instruments only. 'Not addressed' means no distillation-specific rule, not that generic IP or computer-misuse law is unavailable.

Sources: congress.gov · ec.europa.eu · statetechmagazine.com · congress.gov

US federal bills touching distillation, Chinese AI and chip flows (119th Congress)

8 rows
US federal bills touching distillation, Chinese AI and chip flows (119th Congress) — Every bill tracked here is from the 119th Congress (2025-2026). Status as of September 2026.
BillNumberLead sponsorIntroducedFurthest stageDistillation relevance
Deterring American AI Model Theft Act of 2026H.R. 8283Rep. Huizenga (R-MI)2026-04-15Reported by House Foreign Affairs 43-0Direct: defines 'model extraction attack', creates public attackers list, authorises IEEPA sanctions and Entity Listing congress.gov
Decoupling America's AI Capabilities from China ActS. 321Sen. Hawley (R-MO)2025-01-29Referred to JudiciaryIndirect: would bar import/export of AI tech and IP to/from China; penalties up to 20 years congress.gov
No DeepSeek on Government Devices ActH.R. 1121Rep. Gottheimer (D-NJ)2025-02-07Referred to committeeIndirect: federal device ban aimed at the model most associated with distillation claims congress.gov
No Adversarial AI ActS. 2177 / H.R. 4142Sen. Scott (R-FL) [S. 2177]; Rep. Moolenaar (R-MI) [H.R. 4142]2025-06-25Referred to committeeIndirect: FASC list of foreign-adversary AI; bans agency use with narrow research carve-outs congress.gov
Chip Security Act (Senate)S. 1705Sen. Cotton (R-AR)2025-05-08Referred to BankingUpstream: location verification on exported AI chips limits compute available for distillation training congress.gov
Chip Security Act (House)H.R. 3447Rep. Huizenga (R-MI)2025-05-15Reported by House Foreign Affairs 42-0 (2026-03-26)Upstream: same location-verification mandate; not enacted congress.gov
GAIN AI Act of 2025S. 3150 (also H.R. 5885)Sen. Banks (R-IN)2025-11-06Passed Senate as NDAA amendment; dropped from final FY26 NDAAUpstream: would require US customers be prioritised before advanced chip sales abroad congress.gov
AI Security and Innovation ActH.R. 9363Rep. Obernolte (R-CA)2026-06-18Reported by House Science, Space and Technology 29-0 (2026-06-25)Peripheral: establishes an AI evaluation/security center under the National AI Initiative Act; no distillation provisions science.house.gov

GAIN AI Act status confirmed by reporting that the final FY2026 NDAA, signed 2025-12-18, excluded it.

Sources: congress.gov · nextgov.com · congress.gov · science.house.gov · govinfo.gov

Terms-of-service and licence clauses across labs: can you train on the outputs?

9 rows
Terms-of-service and licence clauses across labs: can you train on the outputs? — The contractual layer that US policy now treats as a designation trigger. Wording summarised, not quoted in full.
Provider / model familyAccess modelClause on training competing modelsWho owns outputsJurisdictional restriction
OpenAIClosed API + appsProhibits using Output to develop models that compete with OpenAIAssigned to the userAPI traffic blocked from unsupported regions incl. mainland China since 2024-07-09; Verified Organization ID checks for frontier models since 2025-04 openai.com
Anthropic (Claude)Closed API + appsProhibits using the Services to develop competing products, including to train any AI/ML modelsAnthropic assigns its rights, if any, in Outputs to the userSince 2025-09-05 no service to entities >50% owned from China, Russia, Iran, North Korea, worldwide anthropic.com
Google (Gemini)Closed API + appsProhibits using outputs to develop competing modelsUser-facing rights per service termsRegional availability limits; GTIG disrupted extraction clusters in Feb 2026 techinformed.com
Meta Llama 2 / Llama 3Open weights, community licenceProhibited using Llama materials or outputs to improve any other LLMLicenseeAcceptable use policy only llama.com
Meta Llama 3.1 and laterOpen weights, community licencePermitted: outputs may be used for synthetic data generation and distillation with attributionLicenseeAcceptable use policy only huggingface.co
xAIClosed API + appsRestricts competitive training; distillation risk addressed in its Risk Management Framework (2025-08-20)Per service termsRegional availability limits docs.house.gov
DeepSeekOpen weights + hosted APIPermissive open-weight licensing; V3/R1 weights on Hugging FaceLicenseeHosted service blocked or restricted in Italy, South Korea, Australia, Taiwan and 7+ US states statetechmagazine.com
Alibaba (Qwen)Open weights + hosted APIPermissive open-weight licensingLicenseeAlibaba added to Pentagon 1260H list 2026-06; barred from Anthropic services under the 2025 China policy cnbc.com
Moonshot AI (Kimi)Open weights + hosted APIPermissive open-weight licensingLicenseeNamed in Anthropic Feb 2026 disclosure and State Department April 2026 cable cnbc.com

The asymmetry is structural: closed US labs restrict output-based training by contract, while the leading Chinese labs release weights under permissive licences. That is why an extraction-attack statute keyed to terms of service applies in one direction only.

Sources: openai.com · anthropic.com · llama.com · anthropic.com · anthropic.com

US export-control milestones that frame the distillation debate

12 rows
US export-control milestones that frame the distillation debate — Compute access is the other half of the argument: distilled data is only useful with chips to train on.
DateActionScopeEffect / response
2022-10-07BIS advanced computing and semiconductor ruleA100/H100-class GPUs to ChinaNvidia introduced China-specific A800/H800 with reduced interconnect congress.gov
2023-10-17BIS October 2023 updateCaptures A800/H800 and similar workaroundsNvidia announced H20, L20, L2 for China cset.georgetown.edu
2025-01-15AI Diffusion Rule publishedWorldwide tiered licensing for advanced computingEnforcement set for 2025-05-15; triggered allied and industry objections wiley.law
2025-04H20 licence requirement imposedNvidia H20 to ChinaNvidia forecast a $5.5bn charge in April 2025 and recorded $4.5bn in Q1 FY2026 techcrunch.com
2025-05-13BIS announces rescission of the AI Diffusion RuleGlobal framework withdrawn before enforcementNon-enforcement instruction pending formal rescission; replacement rule promised wiley.law
2025-08H20 / MI308 licences resume with revenue-share arrangementNvidia and AMD China salesReported 15% of China chip revenue to the US government fortune.com
2025-10-09Senate passes NDAA including GAIN AI ActUS-customer-first allocation of advanced chipsOpposed by Nvidia, SIA and the White House AI adviser nextgov.com
2025-12-18FY2026 NDAA signed without the GAIN AI ActChip allocation mandate droppedRemoved the main statutory brake on advanced chip exports nextgov.com
2026-01-15BIS moves H200 / MI325X to case-by-case reviewChina and Macau destinationsPresumption of denial replaced; 25% tariff proclamation signed 2026-01-14 cnbc.com
2026-03-26Chip Security Act reported out of House Foreign Affairs 42-0Location verification for exported AI chipsBipartisan support; not enacted as of Sept 2026 congress.gov
2026-06-17Expanded Entity List publication held backDeepSeek, CXMT and 100+ flagged firmsReported delay to avoid escalation ahead of talks; DeepSeek remained unlisted cnbc.com
2026-07-21China consults industry on AI export controlsModel weights, key training data, chip designsWould make Chinese open weights a licensed export; still under review techrepublic.com

Nvidia flagged an anticipated $5.5bn H20 charge in its April 15, 2025 8-K; the charge actually recorded in its Q1 FY2026 results (May 28, 2026 reporting) was $4.5bn. The 15% revenue-share figure is press-reported and has not been published as a formal rule.

Sources: congress.gov · wiley.law · cnbc.com · techcrunch.com · hpcwire.com

Government restrictions on DeepSeek, by jurisdiction

13 rows
Government restrictions on DeepSeek, by jurisdiction — The first Chinese model to be treated as a national security object rather than a product.
JurisdictionDateScopeStated rationale
Italy2025-01-30Public block of the chatbot nationwideGarante found privacy-policy and data-transfer disclosures inadequate privacylaws.com
Texas2025-01-31All state-owned devicesFirst US state ban; data harvesting and CCP-linkage concerns statetechmagazine.com
Taiwan2025-02-02Public sector agenciesCross-border data transmission and leakage risk taipeitimes.com
Australia2025-02-04Government devicesSecurity concerns thecable.ng
New York State2025-02-10Government networks and devicesForeign surveillance and censorship risk nbcnews.com
Virginia2025-02-11State devices and networksThird US state to act natlawreview.com
South Korea2025-02-17App-store downloads suspendedPIPC found non-compliance with Korean data protection law privacylaws.com
Iowa2025-02-19State devices, alongside other Chinese appsGovernor's directive statetechmagazine.com
South Dakota2025-03Government-issued devices and contractorsBundled with RedNote restriction statetechmagazine.com
Oklahoma2025-03-21All state-owned devicesGovernor Stitt executive action citing data security oklahoma.gov
North Carolina2025-03State devicesFollowed peer states statetechmagazine.com
US Commerce Department2025-02Department devicesReported internal prohibition ahead of any statute pymnts.com
Germany (Berlin DPA)2025-06-27Finding of unlawful processing under GDPRCould not demonstrate EU-equivalent protection for data transferred to China datenschutz-berlin.de

Dates for South Dakota and North Carolina are month-level in the underlying reporting. This is a floor count of publicly reported restrictions, not an exhaustive census; StateTech lists 14 US states restricting DeepSeek as of April 2025.

Sources: statetechmagazine.com · privacylaws.com · tech.co · datenschutz-berlin.de · taipeitimes.com

Timeline · 47 events

  1. policy

    BIS imposes advanced computing export controls on China

    Cuts off A100/H100-class GPUs. Nvidia responds with China-specific A800 and H800 parts with reduced interconnect bandwidth. This is the compute-asymmetry baseline that later distillation arguments rest on.

    Source: congress.gov
  2. policy

    BIS closes the A800/H800 workaround

    The October 2023 update captures the China-tailored parts. Nvidia then announces H20, L20 and L2 for the Chinese market.

    Source: cset.georgetown.edu
  3. product

    OpenAI blocks API traffic from unsupported regions including mainland China

    Developers in China had been reaching the API through VPNs; OpenAI began blocking that traffic. Microsoft's Azure China joint venture continued serving eligible customers, an early illustration of how corporate access policy fragments.

    Source: restofworld.org
  4. research

    DeepSeek V3 is reported to self-identify as ChatGPT

    Widely reported behaviour in which V3 described itself as a version of ChatGPT. Later cited by the House Select Committee and by AFPI testimony as circumstantial evidence of OpenAI-derived training data.

    Source: techcrunch.com
  5. policy

    AI Diffusion Rule published

    Biden-era framework imposing worldwide tiered licensing on advanced computing, with enforcement scheduled for May 15, 2025. OpenAI's March filing would later propose banning PRC-produced models within its Tier 1 country group.

    Source: wiley.law
  6. policy

    David Sacks says there is 'substantial evidence' DeepSeek distilled OpenAI models

    The White House AI and crypto czar told Fox News that DeepSeek 'distilled knowledge out of OpenAI models,' without detailing the evidence, and predicted US labs would move to block copycat models.

    Source: bloomberg.com
  7. policy

    Dario Amodei publishes 'On DeepSeek and Export Controls'

    Argues DeepSeek's efficiency does not undermine export controls but makes them more important, and that a substantial share of DeepSeek's fleet was pre-ban, unbanned or likely smuggled. Sets the compute-asymmetry frame the labs still use.

    Source: darioamodei.com
  8. policy

    Senator Hawley introduces S. 321, the Decoupling America's AI Capabilities from China Act

    Would prohibit US persons from exporting AI technology or IP to China or importing Chinese-developed AI, bar joint research, and impose penalties of up to 20 years. Referred to Judiciary and not advanced.

    Source: congress.gov
  9. policy

    Texas becomes the first US state to ban DeepSeek on state devices

    Opens a wave of state-level restrictions that reached at least seven states by April 2025, plus agency-level bans elsewhere.

    Source: statetechmagazine.com
  10. policy

    Australia bans DeepSeek on government devices

    Followed within weeks by South Korea suspending app-store downloads and Taiwan restricting public-sector use.

    Source: thecable.ng
  11. policy

    OpenAI's OSTP filing calls DeepSeek 'state-subsidized' and 'state-controlled'

    In its response to the AI Action Plan RFI, OpenAI recommended considering bans on PRC-produced models in Tier 1 countries, citing security risk and risk of IP theft, and pointed to distillation against its terms of service. OpenAI later softened the framing, saying it was proposing export-rule changes rather than usage restrictions.

    Source: techcrunch.com
  12. product

    OpenAI introduces Verified Organization ID checks for frontier API access

    Government-ID verification gates access to the most capable models, with one ID per organisation per 90 days. An access-control response to extraction rather than a legal one.

    Source: help.openai.com
  13. policy

    House Select Committee on the CCP publishes 'DeepSeek Unmasked'

    Bipartisan report calling DeepSeek a 'profound threat,' alleging data routing through China Mobile-linked infrastructure, likely unlawful distillation of US models, and export-control circumvention. Recommends expanding and better enforcing export controls.

    Source: chinaselectcommittee.house.gov
  14. policy

    BIS announces rescission of the AI Diffusion Rule

    Two days before it would have taken effect, with an instruction not to enforce pending formal rescission. The administration argued it would stifle US innovation and undermine diplomacy; a replacement rule was promised.

    Source: wiley.law
  15. policy

    No Adversarial AI Act introduced

    Sens. Rick Scott and Gary Peters, with House Select Committee members, propose a Federal Acquisition Security Council list of foreign-adversary AI and a ban on executive-agency use with narrow research carve-outs.

    Source: congress.gov
  16. policy

    European Commission publishes the final GPAI Code of Practice

    Three chapters — Transparency, Copyright, Safety and Security — as a voluntary route to compliance with obligations applying from August 2, 2025. Formally approved on August 1.

    Source: artificialintelligenceact.eu
  17. policy

    White House releases 'Winning the Race: America's AI Action Plan'

    Over 90 federal actions across innovation, infrastructure and international pillars. Notably promotes open-source and open-weight models and calls for exporting the full American AI stack — a posture in tension with the case for restricting model access.

    Source: whitehouse.gov
  18. policy

    China unveils a Global AI Governance Action Plan and proposes a world AI cooperation body

    Announced at the World AI Conference in Shanghai: a thirteen-point roadmap, an International Open Source AI Cooperation Initiative, and a proposed organisation headquartered in Shanghai. The counter-offer to US-led restriction.

    Source: technode.com
  19. policy

    EU AI Act obligations for general-purpose AI providers begin to apply

    Applies to models placed on the market on or after this date. Commission enforcement, including model access and recalls, deferred one year to August 2, 2026.

    Source: ec.europa.eu
  20. policy

    Nvidia and AMD reported to agree a 15% China revenue share for export licences

    Commerce began issuing H20 licences days after Jensen Huang met President Trump. A novel instrument: export policy priced rather than prohibited.

    Source: fortune.com
  21. product

    Anthropic bars entities majority-controlled from China, Russia, Iran and North Korea

    Applies worldwide to subsidiaries and joint ventures regardless of where they operate. Anthropic cited legal compulsion to share data with authoritarian states and estimated a revenue impact in the low hundreds of millions of dollars.

    Source: semafor.com
  22. policy

    Senate passes its NDAA including the GAIN AI Act

    Would require US chipmakers to prioritise American customers before selling advanced AI chips abroad. Opposed by Nvidia, the Semiconductor Industry Association and the White House AI adviser; supported by Microsoft and Americans for Responsible Innovation.

    Source: nextgov.com
  23. policy

    FY2026 NDAA signed without the GAIN AI Act

    The chip-allocation mandate was stripped in conference. Ten days earlier the President had directed that H200-class exports to approved customers be permitted in exchange for a federal surcharge.

    Source: nextgov.com
  24. policy

    BIS moves H200 and MI325X exports to case-by-case review; 25% tariff applies

    Replaces the presumption of denial for China and Macau destinations, with third-party lab testing and a cap on the China share relative to US customers. The proclamation imposing a 25% duty was signed the previous day.

    Source: cnbc.com
  25. policy

    South Korea's AI Basic Act takes effect

    The first comprehensive national AI framework outside the EU, with generative-AI and high-impact obligations, a National AI Committee, an AI Policy Center and an AI Safety Research Institute. It does not address distillation.

    Source: cooley.com
  26. policy

    Chip Security Act reported out of House Foreign Affairs 42-0

    Would require location-verification mechanisms on covered chips before export, with reporting to Commerce if a chip's location changes. Bipartisan but not enacted.

    Source: congress.gov
  27. market

    OpenAI, Anthropic and Google agree to share distillation threat intelligence

    Coordination routed through the Frontier Model Forum, responding to the AI Action Plan's call for an industry information-sharing centre. The companies sought antitrust comfort before trading notes.

    Source: techbrew.com
  28. policy

    H.R. 8283, the Deterring American AI Model Theft Act of 2026, is introduced

    Reps. Huizenga and Moolenaar. Defines a 'model extraction attack' as unauthorized extraction of a closed-source model's capabilities where the querying circumvents access controls, uses fraudulent credentials, or violates terms prohibiting output-based training. Explicitly exempts training that complies with terms of service.

    Source: govinfo.gov
  29. policy

    House Select Committee hearing: 'China's Illicit Campaign to Steal and Subvert American AI Technology'

    Testimony from AFPI's Yusuf Mahmood collating the OpenAI, Google, Anthropic and xAI disclosures and arguing that consistent lag behind the American frontier is itself evidence of a distillation-driven development model.

    Source: docs.house.gov
  30. policy

    H.R. 8283 ordered reported 43-0

    Unanimous House Foreign Affairs vote, alongside a package of export-control measures. The bill has not received a floor vote as of September 2026.

    Source: congress.gov
  31. policy

    OSTP issues NSTM-4, 'Adversarial Distillation of American AI Models'

    Signed by Director Michael Kratsios. Finds foreign entities principally in China running deliberate, industrial-scale campaigns using tens of thousands of proxy accounts and jailbreaking to expose proprietary information, and that the resulting models strip safety protocols. Commits to intelligence sharing with industry, joint best practices and exploration of accountability measures.

    Source: nextgov.com
  32. policy

    State Department cables posts worldwide to raise distillation with foreign counterparts

    Instructs diplomats to discuss concerns over adversaries' extraction and distillation of US AI models, naming DeepSeek, Moonshot AI and MiniMax. The Chinese Embassy called the allegations groundless.

    Source: cnbc.com
  33. product

    DeepSeek releases a preview of V4

    A trillion-parameter-class open model, notable as DeepSeek's first optimised for domestic Chinese accelerators such as Huawei Ascend. US officials alleged it was trained on smuggled Blackwell GPUs; Nvidia called that farfetched.

    Source: technologyreview.com
  34. policy

    President signs NSPM-11 on AI in the national security enterprise

    Four pillars — adoption, adaptation, assurance, accountability — with Section 4(c) directing protection of advanced AI systems against malicious distillation attacks. Rescinds and replaces the prior administration's NSM-25.

    Source: whitehouse.gov
  35. policy

    Pentagon adds Alibaba, Baidu, BYD and Unitree to the 1260H list

    Sixty-five entities added, bringing the list to 188. Procurement prohibitions take effect June 30, 2026. DeepSeek was not added.

    Source: cnbc.com
  36. policy

    US holds off blacklisting DeepSeek and 100-plus other flagged firms

    An inter-agency committee had approved DeepSeek for Entity List addition, but publication was delayed, reportedly to avoid escalating tensions with Beijing. A State Department official said DeepSeek has supported Chinese military and intelligence operations.

    Source: cnbc.com
  37. market

    Alibaba bars employees from using Anthropic products

    Announced 6 July 2026, effective 10 July 2026: staff were told to uninstall Anthropic models and agent products and use Alibaba's own assistant. Alibaba denied using proprietary model outputs to train its models and denied Chinese government involvement.

    Source: cnbc.com
  38. policy

    Treasury Secretary Bessent threatens sanctions over AI model theft

    Said the US is finding watermarks of American large language models inside Chinese systems and has the ability to sanction overseas models that steal from US companies. The same day, FT reported MOFCOM consulting Alibaba, ByteDance and Zhipu on export controls covering model weights, key training data and chip designs.

    Source: cnbc.com
  39. policy

    Open-weights letter launches with ~25 signatories, later exceeding 270

    Nvidia, Meta, Microsoft and Amazon were among roughly 25 companies signing at launch on July 24, 2026; OpenAI and Google were absent on the day and appeared on the signatory list around July 26. The count passed 150 by July 28 and later exceeded 270. Signatories argue open weights are essential to American AI leadership and that closed-model concentration is a systemic risk. Dario Amodei published a rebuttal on July 27 accepting open weights in general but arguing the most powerful frontier weights carry irreversible national security risk.

    Source: images.nvidia.com
  40. policy

    China's Ministry of Commerce counter-accuses American AI firms of distilling Chinese models

    Called US allegations factually and legally unsupported and an act of 'AI hegemony,' promised 'all necessary measures' if Chinese firms are sanctioned, and defended distillation as a widely used industry technique. No companies were named and no evidence was supplied.

    Source: implicator.ai
  41. policy

    EU AI Act enforcement powers go live

    The AI Office can now request information and documentation, obtain model access for evaluation, require corrective measures, and fine GPAI providers up to EUR 15 million or 3% of global turnover. Its stated preferred first tool remains technical compliance dialogues.

    Source: ec.europa.eu

Glossary · 16 terms

Distillation
Training a smaller or cheaper student model on the outputs of a larger teacher model. Legitimate and standard when the teacher's licence permits it; the policy fight is about doing it to a closed model in breach of its terms.
Adversarial distillation
The term adopted by OSTP memorandum NSTM-4 (April 23, 2026) for systematic extraction of a frontier model's capabilities via large volumes of constructed queries, typically through proxy accounts that evade access controls.
Model extraction attack
The statutory term in H.R. 8283: unauthorized extracting of a closed-source model's capabilities to replicate, develop, train or improve another model, where the querying circumvents access controls, uses fraudulent credentials, or violates output-training terms.
AI Model Extraction Attackers List
The public list H.R. 8283 would have the Secretary of State maintain, naming individuals and entities assessed to have conducted model extraction attacks, as a predicate for sanctions or Entity Listing.
Fraudulent account network provider
A category defined in H.R. 8283 covering foreign entities that create, sell or broker accounts allowing entities of concern to reach models they are barred from, with a carve-out for services enabling internet access for freedom of expression.
Entity List
The Commerce/BIS list imposing licence requirements, usually with a presumption of denial, on exports to named foreign parties. Repeatedly floated for Chinese AI labs; not applied to DeepSeek as of September 2026.
Section 1260H list
The Pentagon's annual list of Chinese military companies. Listing bars Department procurement contracts. Alibaba, Baidu, BYD and Unitree were added in June 2026.
IEEPA
The International Emergency Economic Powers Act, the authority under which a president can declare a national emergency and impose blocking sanctions. The main vehicle proposed for sanctioning distillation actors.
AI Diffusion Rule
The January 15, 2025 BIS framework creating worldwide tiered licensing for advanced computing. BIS announced its rescission on May 13, 2025, before its May 15 enforcement date.
GPAI obligations
The EU AI Act duties on providers of general-purpose AI models — technical documentation, copyright policy, training-data summary, and systemic-risk duties above a compute threshold — applying from August 2, 2025 and enforceable from August 2, 2026.
Code of Practice (GPAI)
The voluntary EU compliance instrument published July 10, 2025, with Transparency, Copyright, and Safety and Security chapters. Signing it is a presumption-of-conformity route, not a legal obligation.
Open weights
Model parameters published for download and self-hosting. Central to the policy paradox: the US AI Action Plan promotes open weights while distillation policy tries to restrict capability diffusion.
Sovereign AI
A state's pursuit of domestically controlled compute, models and data. In 2026 the practical question is whether a country's sovereign stack sits on US closed models, US open weights, or Chinese open weights.
Transfer station economy
The grey market of proxy servers and reseller billing panels that resell access to Western frontier models inside China, sometimes at a fraction of list price. The practical delivery mechanism behind alleged extraction campaigns.
Military-civil fusion
China's policy of integrating civilian technology development with military modernisation, invoked by US officials to argue that capabilities distilled by commercial Chinese labs reach the PLA.
Frontier Model Forum
The industry body founded in 2023 by Anthropic, Google, Microsoft and OpenAI, used from April 2026 as the channel for sharing distillation threat intelligence between labs.

Sources · 100 sources

Every figure on this page comes from one of these primary sources. Compiled 4 September 2026.

  1. Detecting and preventing distillation attacksAnthropic · 23 February 2026 · blog
  2. Letter to Senate Banking Committee on illicit access to American AI models by Alibaba-affiliated operatorsAnthropic · 10 June 2026 · filing
  3. H.R. 8283, Deterring American AI Model Theft Act of 2026 (introduced text)US Government Publishing Office · 15 April 2026 · law
  4. H.R. 8283 bill page and statusCongress.gov · 22 April 2026 · law
  5. National Security Presidential Memorandum NSPM-11The White House · 5 June 2026 · law
  6. Winning the Race: America's AI Action PlanThe White House · 23 July 2025 · law
  7. China's Illicit Campaign to Steal and Subvert American AI Technology (testimony of Yusuf Mahmood)US House Select Committee on the CCP · 16 April 2026 · filing
  8. OpenAI response to the OSTP/NSF RFI on the AI Action PlanOpenAI · 13 March 2025 · filing
  9. OpenAI calls DeepSeek 'state-controlled,' calls for bans on 'PRC-produced' modelsTechCrunch · 13 March 2025 · news
  10. AI Czar Sacks Says 'Evidence' DeepSeek Leaned On OpenAI's ModelsBloomberg · 28 January 2025 · news
  11. Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI DataBloomberg · 29 January 2025 · news
  12. OpenAI says DeepSeek may have 'inappropriately' used its models' outputAxios · 29 January 2025 · news
  13. On DeepSeek and Export ControlsDario Amodei · 29 January 2025 · blog
  14. Moolenaar, Krishnamoorthi unveil report on DeepSeekUS House Select Committee on the CCP · 16 April 2025 · filing
  15. S. 321 Decoupling America's Artificial Intelligence Capabilities from China ActCongress.gov · 29 January 2025 · law
  16. H.R. 3447 Chip Security ActCongress.gov · 15 May 2025 · law
  17. S. 1705 Chip Security ActCongress.gov · 8 May 2025 · law
  18. S. 3150 GAIN AI Act of 2025Congress.gov · 6 November 2025 · law
  19. S. 2177 No Adversarial AI Act (text)Congress.gov · 25 June 2025 · law
  20. H.R. 1121 No DeepSeek on Government Devices ActCongress.gov · 7 February 2025 · law
  21. US Export Controls and China: Advanced Semiconductors (CRS R48642)Congressional Research Service · August 2025 · filing
  22. Explainer: The Commerce Department's October 2023 Export Controls UpdateCSET, Georgetown · October 2023 · blog
  23. BIS Rescinds AI Diffusion Rule and Issues GuidanceWiley Rein · 14 May 2025 · blog
  24. Nvidia says it will record $5.5 billion charge tied to H20 processorsCNBC · 15 April 2025 · news
  25. Nvidia, AMD to pay 15% of China chip revenue to US governmentFortune · 10 August 2025 · news
  26. Trump administration clears way for Nvidia H200 chip sales to ChinaCNBC · 14 January 2026 · news
  27. AI export control bill passes Senate as NDAA amendmentNextgov/FCW · 9 October 2025 · news
  28. Bill prioritizing American customers for AI chips not expected to make it into final NDAANextgov/FCW · December 2025 · news
  29. White House accuses China of deliberate, industrial-scale campaigns to steal US AI modelsNextgov/FCW · 23 April 2026 · news
  30. US State Department orders global warning about alleged China AI theftCNBC · 25 April 2026 · news
  31. Anthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract Claude capabilitiesCNBC · 24 June 2026 · news
  32. China's Alibaba bans Anthropic AI for employees after distillation accusationCNBC · 6 July 2026 · news
  33. Bessent says U.S. could sanction China over AI model 'theft'CNBC · 21 July 2026 · news
  34. US holds off blacklisting China's DeepSeek and 100+ firmsCNBC · 17 June 2026 · news
  35. Pentagon expands list of China military-linked firms to include Alibaba, Baidu, BYDCNBC · 9 June 2026 · news
  36. Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcementCNBC · 3 August 2026 · news
  37. Commission starts enforcing AI Act rules and new transparency obligationsEuropean Commission · 2 August 2026 · law
  38. Overview of the General-Purpose AI Code of PracticeEU AI Act explorer · 10 July 2025 · docs
  39. EU AI Act rules on GPAI models under DeepSeek reviewPinsent Masons · 2025 · blog
  40. White House accuses Moonshot AI of distilling Anthropic's modelCyberScoop · 22 July 2026 · news
  41. Experts say exploiting Anthropic's Fable isn't how Kimi K3 got so goodTechCrunch · 23 July 2026 · news
  42. Three reasons why DeepSeek's new model mattersMIT Technology Review · 24 April 2026 · news
  43. The Case for Imposing Costs on China's AI Distillation CampaignsJust Security · 2026 · blog
  44. From Diagnosis to Deterrence: The Emerging U.S. Response to DistillationJust Security · 2026 · blog
  45. Responding to AI Distillation Without PanicInstitute for Law & AI · 2026 · blog
  46. How to Fix the AI Model Theft Bill Before It Becomes LawITIF · 28 July 2026 · blog
  47. Adversarial Distillation: China's Campaign to Extract American AI CapabilitiesCenter for a New American Security · 2 June 2026 · paper
  48. AI Distillation Attacks: Executive and Congressional Action Can Go FurtherInstitute for AI Policy and Strategy · 2026 · paper
  49. Trade Secrecy Meets Generative AICamilla Alexandra Hrdy, SSRN · 2025 · paper
  50. Dispute over AI model distillation tech in OpenAI-DeepSeek caseLaw.asia · 2025 · blog
  51. Copyright Office report on copyrightability of AI-generated materialUS Copyright Office · January 2025 · law
  52. 'Ironic, hypocritical' of big tech to call out DeepSeekCornell University · January 2025 · news
  53. OpenAI hit with mockery over DeepSeek complaintFuturism · January 2025 · news
  54. Why DeepSeek's new AI model thinks it's ChatGPTTechCrunch · 27 December 2024 · news
  55. Anthropic blocks sales of AI to Chinese firmsSemafor · 5 September 2025 · news
  56. US AI giant Anthropic bars Chinese-owned entitiesRTE · 5 September 2025 · news
  57. OpenAI Terms of UseOpenAI · 2025 · docs
  58. Anthropic Consumer Terms of ServiceAnthropic · 2025 · docs
  59. Meta Llama 3 Community LicenseMeta · 2024 · docs
  60. Llama 3.3 70B Instruct model cardMeta / Hugging Face · December 2024 · docs
  61. API Organization VerificationOpenAI · April 2025 · docs
  62. OpenAI to cut off API access in China on July 9Rest of World · June 2024 · news
  63. OpenAI accuses DeepSeek of malpractice ahead of AI launchRest of World · 2026 · news
  64. These States Have Banned DeepSeekStateTech Magazine · April 2025 · news
  65. New York state bans DeepSeek from government devicesNBC News · 10 February 2025 · news
  66. Italy and South Korea ban DeepSeek and start investigationPrivacy Laws & Business · February 2025 · news
  67. Governor Stitt bans DeepSeek on all state-owned devicesState of Oklahoma · March 2025 · law
  68. South Korea's AI Basic Act: Overview and Key TakeawaysCooley · 27 January 2026 · blog
  69. AI Watch: Global regulatory tracker - JapanWhite & Case · 2025 · blog
  70. UK Sovereign AI UnitOECD.AI · 2025 · docs
  71. China proposes new global AI cooperation organization, headquarters planned in ShanghaiTechNode · 29 July 2025 · news
  72. China launches Shanghai-based AI governance body with 29 founding nationsCaixin Global · 17 July 2026 · news
  73. China Accuses US AI Firms of Distilling Chinese ModelsImplicator.ai · 27 July 2026 · news
  74. China Considers Export Controls on AI Models, Training Data and Chip TechnologyTechRepublic · July 2026 · news
  75. Google disrupts Gemini model extraction attemptsTechInformed · 16 February 2026 · news
  76. OpenAI, Anthropic, Google join forces against ChinaTech Brew · 7 April 2026 · news
  77. How to Buy Cheap Claude Tokens in ChinaChinaTalk · 2026 · news
  78. Inside the Gray Market for LLM AccessDeepLearning.AI, The Batch · 2026 · news
  79. Open Weights and American AI Leadership (open letter)Multi-company coalition · 24 July 2026 · filing
  80. Gulf AI infrastructure and the limits of technological sovereigntyIISS · June 2026 · paper
  81. Which Countries Have Banned DeepSeek Already?Tech.co · 2025 · news
  82. DeepSeek and Chinese AI Models: GDPR Data Transfer ComplianceAI Policy Desk · June 2026 · blog
  83. Report: Commerce Department bans use of DeepSeek on government devicesPYMNTS · February 2025 · news
  84. Three States Ban DeepSeek Use on State Devices and NetworksNational Law Review · February 2025 · news
  85. South Korea joins Italy, Australia in banning DeepSeekThe Cable · February 2025 · news
  86. Nvidia expects to lose billions in revenue due to H20 chip licensing requirementsTechCrunch · 28 May 2025 · news
  87. Nvidia announces financial results for 1st quarter fiscal 2026HPCwire · 28 May 2025 · filing
  88. H.R. 9363, AI Security and Innovation ActHouse Science, Space and Technology Committee · 25 June 2026 · law
  89. CBO cost estimate, H.R. 9363Congressional Budget Office · 2026 · law
  90. President Trump orders narrowly targeted 25% Section 232 tariff on certain advanced semiconductorsWhite & Case · January 2026 · law
  91. BlnBDI press release: DeepSeek apps reported to Apple and GoogleBerlin Commissioner for Data Protection and Freedom of Information · 27 June 2025 · law
  92. Nvidia and 24 other companies sign open-weights letterTom's Hardware · 24 July 2026 · news
  93. Open weights, American AI leadership letter: OpenAI absentThe Next Web · 25 July 2026 · news
  94. Taiwan bans DeepSeek in the public sectorTaipei Times · 2 February 2025 · news
  95. H.R. 4142 No Adversarial AI Act (introduced)GovInfo · 25 June 2025 · law
  96. House Foreign Affairs markup documents, H.R. 8283 (April 22, 2026)Congress.gov · 22 April 2026 · law
  97. Distillation, experimentation and integration: adversarial use of AIGoogle Threat Intelligence Group · 12 February 2026 · blog
  98. Updated Stakes for American-Led, Democratic AI (memo to House Select Committee)OpenAI · 12 February 2026 · filing
  99. Anthropic Commercial Terms of ServiceAnthropic · 2025 · docs
  100. Anthropic Usage PolicyAnthropic · 2025 · docs