A public compendium · updated daily
How frontier intelligence is compressed, priced, and contested.
Distillation moves capability from a large teacher model into a small, cheap student. It is the quiet engine behind most models people actually pay for, the subject of an open dispute between the largest labs, and a live regulatory question in three jurisdictions. This compendium tracks all of it.
Political · compiled 4 September 2026 · 100 sources
Political and geopolitical view of AI distillation
Between January 2025 and September 2026, model distillation went from an obscure machine-learning technique to a named object of US national security policy. It began when OpenAI and Microsoft said they had evidence a DeepSeek-linked group had pulled data through OpenAI's API, and White House AI czar David Sacks said there was 'substantial evidence' DeepSeek had distilled OpenAI models. It escalated through OpenAI's March 2025 OSTP filing calling DeepSeek 'state-subsidized' and 'state-controlled,' Anthropic's September 2025 ban on entities majority-controlled from China, and a February 2026 wave of disclosures in which OpenAI, Google and Anthropic each published evidence of large-scale extraction campaigns. It became formal policy in April 2026 with OSTP memorandum NSTM-4 on 'adversarial distillation,' a State Department demarche cable, and H.R. 8283, which would create a public 'AI Model Extraction Attackers List' — followed by NSPM-11 in June, Anthropic's letter alleging a 28.8-million-exchange Alibaba campaign, and Treasury Secretary Bessent's July 2026 sanctions threat. Underneath the geopolitics sits an unresolved legal question: the strongest theory against distillation is breach of contract, not copyright or trade secret, and critics from ITIF to the Institute for Law & AI warn that building export controls and sanctions on top of private terms of service is a shaky foundation.
Key figures · 8 figures
Claude exchanges in largest disclosed campaign
28,800,000 exchanges
vs 16M disclosed in Feb 2026
Anthropic's June 10, 2026 letter to Senate Banking alleges Alibaba/Qwen-affiliated operators ran 28.8M+ exchanges between Apr 22 and Jun 5, 2026
Fraudulent accounts alleged (Alibaba campaign)
25,000 accounts
24,000 in the Feb 2026 DeepSeek/Moonshot/MiniMax disclosure
Anthropic's June 10, 2026 letter to the Senate Banking Committee alleges almost 25,000 fraudulent accounts violating its terms of service and regional access restrictions
House Foreign Affairs vote on H.R. 8283
43 yeas (43-0)
unanimous
Deterring American AI Model Theft Act of 2026 ordered reported April 22, 2026; not yet passed the full House as of Sept 2026
US states restricting DeepSeek on state devices
14 states
0 before Jan 31, 2025
Texas, New York, Virginia, Iowa, South Dakota, North Carolina, Nebraska, Tennessee, Arkansas, North Dakota, Oklahoma, Alabama, Kansas and Georgia, as of April 2025; likely higher by Sept 2026
Nvidia/AMD China revenue share to US government
15 % of China chip revenue
new condition, Aug 2025
Reported arrangement tied to resumed H20 / MI308 export licences
Section 232 tariff on advanced AI chips imported into the US (incl. those routed to China)
25 %
new; paired with BIS case-by-case review replacing presumption of denial
Proclamation signed Jan 14, 2026, effective Jan 15, 2026; separately BIS moved H200 / MI325X to case-by-case review for China and Macau
Entities on Pentagon 1260H list after June 2026 update
188 entities
+65 added June 2026
Alibaba, Baidu, BYD and Unitree added; DeepSeek notably not listed
Maximum EU AI Act fine for GPAI providers
15,000,000 EUR or 3% of global turnover
enforceable from Aug 2, 2026
Whichever is higher; AI Office gained investigation and model-access powers on that date
Key findings · 10 findings
Distillation is now a named category in US national security policy — but naming has not produced sanctions
OSTP memorandum NSTM-4, 'Adversarial Distillation of American AI Models,' issued by OSTP under Director Michael Kratsios on April 23, 2026, is the first US policy instrument to formally classify systematic capability extraction from frontier models as a national security threat. It found that foreign entities, principally in China, are running 'deliberate, industrial-scale campaigns' using tens of thousands of proxy accounts, and committed the executive branch to threat-intelligence sharing with industry, joint defensive best practices, and exploration of accountability measures. NSPM-11, signed June 5, 2026, then directed the national security enterprise to help secure US models against distillation attacks. Naming has not yet become enforcement: no Chinese AI lab has been sanctioned or Entity Listed specifically for distillation as of early September 2026. In June 2026 the administration held off publishing an expanded blacklist covering DeepSeek and 100+ other flagged firms, reportedly to avoid escalating with Beijing, and DeepSeek was absent from the Pentagon's June 2026 1260H expansion that added Alibaba and Baidu. Treasury Secretary Bessent's July 21, 2026 warning that Washington could sanction overseas models found to have stolen from US firms remained a threat.
The legal core of the accusation is breach of contract, not IP theft — and that is a weaker peg than the rhetoric implies
US copyright law does not protect purely machine-generated outputs, and OpenAI's own terms assign output rights to the user, so a copyright claim against a distiller is difficult. Trade secret theory is available but unsettled: it depends on whether querying an API counts as acquisition by 'improper means.' The theory that actually fits is contract — OpenAI's terms bar using Output 'to develop models that compete with OpenAI' — plus, where fraudulent accounts and evaded geo-restrictions are involved, the Computer Fraud and Abuse Act. H.R. 8283 mirrors this: its definition of a 'model extraction attack' turns on circumventing access controls, using fraudulent credentials, or violating terms of service. The symmetry argument has never gone away either: because copyright does not protect bare machine outputs and terms of service are private contracts, critics — including a Cornell tip sheet published within days of OpenAI's January 2025 statement — note that training on publishers' content also violated those publishers' terms. The asymmetry the labs rely on is jurisdictional and contractual rather than moral, which is why the fight migrated to export controls, sanctions and procurement bans rather than the courts.
Building federal sanctions on top of private terms of service is the central critique of the 2026 bills
ITIF's July 28, 2026 analysis of H.R. 8283 argues the bill leans too heavily on terms-of-service violations — private contracts that vary provider to provider — as the trigger for federal designation, and that an 'AI Model Extraction Attackers List' built on unverified corporate disclosures raises due-process concerns. It recommends narrowing the definition to intentional account fraud, requiring public evidentiary summaries, and adding safe harbours for open-source development, academic research and security testing. The Institute for Law & AI makes a parallel argument: policymakers should first ask how much distillation actually contributes to the capability gap before locking in restrictions.
Disclosure moved from anecdote to numbers — and the numbers keep growing
January 2025 accusations were qualitative: Microsoft security researchers observed suspected DeepSeek-linked individuals exfiltrating data via the OpenAI API, and David Sacks cited 'substantial evidence' without detailing it. By February 2026 the labs published counts: Anthropic attributed 150,000+ exchanges to DeepSeek, 3.4 million to Moonshot AI and 13 million to MiniMax across ~24,000 fraudulent accounts; Google's Threat Intelligence Group disrupted a cluster of 100,000+ prompts aimed at coercing Gemini reasoning traces. By June 2026 Anthropic put a single Alibaba-linked campaign at 28.8 million exchanges. The trend line of disclosed volume is the single most concrete input to the policy debate.
Export controls and distillation policy are the same argument in two registers
Anthropic's public position is that distillation 'reinforces the rationale for export controls,' because harvested exchanges are only useful if the distiller has compute to train on them. Dario Amodei made the compute-asymmetry argument in January 2025. The counter-current is commercial: the Biden AI Diffusion Rule (Jan 15, 2025) was rescinded before its May 15, 2025 enforcement date; the GAIN AI Act, which would have required US customers be served first, passed the Senate as an NDAA amendment in October 2025 but was dropped from the final FY2026 NDAA; and in January 2026 H200 and MI325X exports moved from presumption of denial to case-by-case review with a 25% tariff.
Private corporate policy has become de facto foreign policy
OpenAI blocked API traffic from unsupported regions including mainland China on July 9, 2024, then introduced Verified Organization ID checks for frontier API access in April 2025. Anthropic went furthest: on September 5, 2025 it barred service to companies more than 50% owned by entities in China, Russia, Iran and North Korea regardless of where those subsidiaries operate, accepting a revenue hit it described as in the low hundreds of millions of dollars. These access rules, not statutes, are what H.R. 8283 would convert into a designation trigger — which is precisely why critics call the mechanism circular.
Evidence quality is contested, and at least one White House accusation drew expert pushback
On July 22, 2026 OSTP Director Kratsios accused Moonshot AI of distilling Anthropic's Fable to build Kimi K3 and of obtaining export-controlled Nvidia servers. Researchers including Nathan Lambert (Allen Institute for AI) and Braden Hancock (Laude Institute) publicly doubted that distillation alone could explain K3's capabilities on that timeline — Fable had been publicly available only since July 1 — and no supporting evidence was published. Earlier, US officials alleged DeepSeek trained V4 on smuggled Blackwell GPUs; Nvidia called the claim farfetched and DeepSeek's V4 preview shipped optimised for Huawei Ascend silicon. Accusation-without-published-evidence is a recurring pattern.
China's response has moved from denial to mirror-imaging
The Chinese Embassy in Washington called US allegations groundless and framed them as attacks on China's AI development. On July 27, 2026 the Ministry of Commerce went further, accusing 'many American AI enterprises' of distilling Chinese models — naming none and supplying no evidence — calling US actions 'double standards' and 'AI hegemony,' and promising 'all necessary measures' if Chinese firms were sanctioned. Separately, FT reported that MOFCOM was consulting Alibaba, ByteDance and Zhipu on adding model weights, key training data and chip designs to China's technology export catalogue, which would make Chinese open weights themselves a licensed export.
The EU regulates capability, not provenance — which leaves distillation largely untouched
EU AI Act GPAI obligations began applying August 2, 2025, backed by a Code of Practice published July 10, 2025 with Transparency, Copyright, and Safety & Security chapters; Commission enforcement powers, including fines up to EUR 15 million or 3% of global turnover, went live August 2, 2026. None of this creates a distillation-specific offence. Europe's actual friction with Chinese models has run through GDPR instead — Italy's Garante ordered DeepSeek's chatbot blocked in early 2025, and Berlin's commissioner found its transfer practices unlawful — while self-hosted open weights on EU servers sidestep the transfer question entirely.
A grey market for API access is the practical enforcement problem
Extraction at the scale the labs describe requires access the labs have formally denied. Reporting on China's 'transfer station' economy describes tens of thousands of internet-facing servers running reseller billing panels that proxy OpenAI, Anthropic, Google and other Western models into China, sometimes at roughly a tenth of list price. Anthropic says a single proxy network managed more than 20,000 fraudulent accounts. H.R. 8283 responds by defining a 'fraudulent account network provider' as a designation target in its own right — with a carve-out for services that enable internet access for freedom of expression.
Charts · 5 charts
Distillation-adjacent policy and enforcement actions per quarter, 2022-2026
actions| Quarter | Actions catalogued actions |
|---|---|
| 2022 Q4 | 1 |
| 2023 Q4 | 1 |
| 2024 Q3 | 1 |
| 2024 Q4 | 1 |
| 2025 Q1 | 9 |
| 2025 Q2 | 4 |
| 2025 Q3 | 6 |
| 2025 Q4 | 2 |
| 2026 Q1 | 5 |
| 2026 Q2 | 11 |
| 2026 Q3 | 6 |
Counts are computed strictly from the entries in this dashboard's own timeline[] — one point per event, no other inclusion rule — so every bar can be reproduced by filtering the timeline by quarter. Not an exhaustive census of AI policy activity. Quarters with zero catalogued events are omitted. 2026 Q3 runs only to September 4, 2026.
Sources: justsecurity.org · congress.gov
Jurisdiction stance comparison: which policy tools are actually in place
binary indicator| Jurisdiction | Distillation-specific policy instrument binary indicator | Binding law on general-purpose / frontier AI binary indicator | Restricts Chinese AI apps on government devices binary indicator | Unilateral controls on advanced AI chip / tech exports binary indicator |
|---|---|---|---|---|
| United States | 1 | 0 | 1 | 1 |
| European Union | 0 | 1 | 0 | 0 |
| United Kingdom | 0 | 0 | 0 | 0 |
| China | 0 | 1 | 0 | 1 |
| South Korea | 0 | 1 | 1 | 0 |
| Japan | 0 | 0 | 0 | 1 |
| Australia | 0 | 0 | 1 | 0 |
| Taiwan | 0 | 0 | 1 | 1 |
US row scores 0 on binding GPAI law at the federal level; California SB 53 and the New York RAISE Act are state instruments. EU scores 0 on export controls because those are member-state and Wassenaar instruments (e.g. the Netherlands), not bloc-level AI chip controls. China's binding-law score reflects its generative AI and labelling measures; its export-control score reflects existing materials controls plus the 2026 consultation on model weights.
Sources: ec.europa.eu · cooley.com · techrepublic.com · statetechmagazine.com
Exchanges with Claude attributed to each accused lab, as disclosed by Anthropic
exchanges| Accused lab | February 23, 2026 disclosure exchanges | June 10, 2026 letter to Senate Banking exchanges |
|---|---|---|
| DeepSeek | 150,000 | — |
| Moonshot AI | 3,400,000 | — |
| MiniMax | 13,000,000 | — |
| Alibaba / Qwen-affiliated operators | — | 28,800,000 |
Figures are Anthropic's own attributions and have not been independently verified or adjudicated. The February set totals over 16 million exchanges across approximately 24,000 fraudulent accounts; the Alibaba campaign is dated April 22 to June 5, 2026 and used nearly 25,000 accounts. Alibaba denies using proprietary model outputs to train its models.
Sources: anthropic.com · d1e00ek4ebabms.cloudfront.net · cnbc.com
How far each US bill has actually travelled
stage| Bill | Furthest stage (1 introduced, 2 reported by committee, 3 passed a chamber, 4 enacted) stage |
|---|---|
| H.R. 8283 Model Theft | 2 |
| H.R. 3447 Chip Security | 2 |
| S. 1705 Chip Security | 1 |
| S. 3150 GAIN AI | 3 |
| S. 321 Decoupling | 1 |
| S. 2177 No Adversarial AI | 1 |
| H.R. 4142 No Adversarial AI | 1 |
| H.R. 1121 No DeepSeek on Gov Devices | 1 |
S. 3150 scores 3 because the GAIN AI Act passed the Senate as an amendment to the FY2026 NDAA on October 9, 2025 — but it was stripped in conference and the enacted NDAA excludes it, so no bill in this set has reached stage 4.
Sources: congress.gov · congress.gov · nextgov.com
Cumulative restrictions on DeepSeek among the jurisdictions this dashboard tracks, first quarter after R1
jurisdictions| Month | Jurisdictions with a public restriction jurisdictions |
|---|---|
| 2025-01 | 2 |
| 2025-02 | 9 |
| 2025-03 | 12 |
| 2025-04 | 12 |
Counts only the restrictions listed in the 'Government restrictions on DeepSeek' table: Italy and Texas in January; Taiwan, Australia, New York, Virginia, South Korea, Iowa and the US Commerce Department in February; South Dakota, Oklahoma and North Carolina in March; no further additions in April within this table. This is deliberately narrower than the full picture — StateTech lists 14 US states restricting DeepSeek by April 2025, including Nebraska, Tennessee, Arkansas, North Dakota, Alabama, Georgia and Kansas, which this table does not enumerate individually.
Sources: statetechmagazine.com · privacylaws.com
Tables · 6 tables
Policy matrix: how each jurisdiction treats distillation and Chinese models
12 rows| Jurisdiction | Primary instrument | Status | Key date | Distillation stance | Chinese-model stance |
|---|---|---|---|---|---|
| United States (executive) | OSTP NSTM-4; NSPM-11; AI Action Plan | In force | 2026-04-23 | Named national security threat; intel sharing with labs; accountability measures 'explored' | Federal device bans proposed; export controls; no model sanctions yet nextgov.com |
| United States (Congress) | H.R. 8283 Deterring American AI Model Theft Act | Reported by committee 43-0; not enacted | 2026-04-22 | Would create public 'AI Model Extraction Attackers List' + IEEPA/Entity List authorities | PRC, Hong Kong, Macau and Russia are 'countries of concern' by statute congress.gov |
| United States (states) | Executive directives; CA SB 53; NY RAISE Act | In force | 2026-01-01 | No state distillation offence; frontier-model transparency only | 7+ states bar DeepSeek on state devices and networks statetechmagazine.com |
| European Union | AI Act GPAI obligations + Code of Practice | Applying; enforcement powers live | 2026-08-02 | No distillation-specific rule; downstream fine-tuners can become providers | Capability-based, provenance-neutral; friction runs through GDPR ec.europa.eu |
| Italy | Garante order under GDPR | In force | 2025-01-30 | Not addressed | DeepSeek chatbot blocked for the general public, not just government privacylaws.com |
| United Kingdom | Sovereign AI Unit (DSIT); AI Security Institute | Non-statutory | 2025 | No dedicated instrument; treated as a security-research question | No ban; AISI evaluations flag DeepSeek jailbreak and censorship behaviour oecd.ai |
| China | Global AI Governance Action Plan; WAICO; export catalogue review | Announced / under consultation | 2025-07-26 | Defends distillation as an industry-wide technique; counter-accuses US firms | Promotes open-weight release; weighing export controls on weights and training data techrepublic.com |
| South Korea | AI Basic Act (Framework Act) | In force | 2026-01-22 | Not addressed | PIPC suspended DeepSeek app downloads Feb 2025 pending compliance cooley.com |
| Japan | AI Promotion Act (May 2025) | In force; promotional, light-touch | 2025-05 | Not addressed | No ban; policy focus on domestic R&D capacity and competitiveness whitecase.com |
| Australia | Government device directive | In force | 2025-02-04 | Not addressed | DeepSeek prohibited on government devices privacylaws.com |
| Taiwan | Government agency guidance | In force | 2025-02 | Not addressed | DeepSeek restricted in public sector over cross-border data transfer risk tech.co |
| Gulf states (UAE, Saudi Arabia) | Bilateral compute and security agreements | Negotiated, deal-by-deal | 2026 | Not addressed directly; governed via US access conditions | UAE aligned G42 away from Chinese tech; Saudi retains Huawei links iiss.org |
Coding reflects publicly reported instruments only. 'Not addressed' means no distillation-specific rule, not that generic IP or computer-misuse law is unavailable.
Sources: congress.gov · ec.europa.eu · statetechmagazine.com · congress.gov
US federal bills touching distillation, Chinese AI and chip flows (119th Congress)
8 rows| Bill | Number | Lead sponsor | Introduced | Furthest stage | Distillation relevance |
|---|---|---|---|---|---|
| Deterring American AI Model Theft Act of 2026 | H.R. 8283 | Rep. Huizenga (R-MI) | 2026-04-15 | Reported by House Foreign Affairs 43-0 | Direct: defines 'model extraction attack', creates public attackers list, authorises IEEPA sanctions and Entity Listing congress.gov |
| Decoupling America's AI Capabilities from China Act | S. 321 | Sen. Hawley (R-MO) | 2025-01-29 | Referred to Judiciary | Indirect: would bar import/export of AI tech and IP to/from China; penalties up to 20 years congress.gov |
| No DeepSeek on Government Devices Act | H.R. 1121 | Rep. Gottheimer (D-NJ) | 2025-02-07 | Referred to committee | Indirect: federal device ban aimed at the model most associated with distillation claims congress.gov |
| No Adversarial AI Act | S. 2177 / H.R. 4142 | Sen. Scott (R-FL) [S. 2177]; Rep. Moolenaar (R-MI) [H.R. 4142] | 2025-06-25 | Referred to committee | Indirect: FASC list of foreign-adversary AI; bans agency use with narrow research carve-outs congress.gov |
| Chip Security Act (Senate) | S. 1705 | Sen. Cotton (R-AR) | 2025-05-08 | Referred to Banking | Upstream: location verification on exported AI chips limits compute available for distillation training congress.gov |
| Chip Security Act (House) | H.R. 3447 | Rep. Huizenga (R-MI) | 2025-05-15 | Reported by House Foreign Affairs 42-0 (2026-03-26) | Upstream: same location-verification mandate; not enacted congress.gov |
| GAIN AI Act of 2025 | S. 3150 (also H.R. 5885) | Sen. Banks (R-IN) | 2025-11-06 | Passed Senate as NDAA amendment; dropped from final FY26 NDAA | Upstream: would require US customers be prioritised before advanced chip sales abroad congress.gov |
| AI Security and Innovation Act | H.R. 9363 | Rep. Obernolte (R-CA) | 2026-06-18 | Reported by House Science, Space and Technology 29-0 (2026-06-25) | Peripheral: establishes an AI evaluation/security center under the National AI Initiative Act; no distillation provisions science.house.gov |
GAIN AI Act status confirmed by reporting that the final FY2026 NDAA, signed 2025-12-18, excluded it.
Sources: congress.gov · nextgov.com · congress.gov · science.house.gov · govinfo.gov
Terms-of-service and licence clauses across labs: can you train on the outputs?
9 rows| Provider / model family | Access model | Clause on training competing models | Who owns outputs | Jurisdictional restriction |
|---|---|---|---|---|
| OpenAI | Closed API + apps | Prohibits using Output to develop models that compete with OpenAI | Assigned to the user | API traffic blocked from unsupported regions incl. mainland China since 2024-07-09; Verified Organization ID checks for frontier models since 2025-04 openai.com |
| Anthropic (Claude) | Closed API + apps | Prohibits using the Services to develop competing products, including to train any AI/ML models | Anthropic assigns its rights, if any, in Outputs to the user | Since 2025-09-05 no service to entities >50% owned from China, Russia, Iran, North Korea, worldwide anthropic.com |
| Google (Gemini) | Closed API + apps | Prohibits using outputs to develop competing models | User-facing rights per service terms | Regional availability limits; GTIG disrupted extraction clusters in Feb 2026 techinformed.com |
| Meta Llama 2 / Llama 3 | Open weights, community licence | Prohibited using Llama materials or outputs to improve any other LLM | Licensee | Acceptable use policy only llama.com |
| Meta Llama 3.1 and later | Open weights, community licence | Permitted: outputs may be used for synthetic data generation and distillation with attribution | Licensee | Acceptable use policy only huggingface.co |
| xAI | Closed API + apps | Restricts competitive training; distillation risk addressed in its Risk Management Framework (2025-08-20) | Per service terms | Regional availability limits docs.house.gov |
| DeepSeek | Open weights + hosted API | Permissive open-weight licensing; V3/R1 weights on Hugging Face | Licensee | Hosted service blocked or restricted in Italy, South Korea, Australia, Taiwan and 7+ US states statetechmagazine.com |
| Alibaba (Qwen) | Open weights + hosted API | Permissive open-weight licensing | Licensee | Alibaba added to Pentagon 1260H list 2026-06; barred from Anthropic services under the 2025 China policy cnbc.com |
| Moonshot AI (Kimi) | Open weights + hosted API | Permissive open-weight licensing | Licensee | Named in Anthropic Feb 2026 disclosure and State Department April 2026 cable cnbc.com |
The asymmetry is structural: closed US labs restrict output-based training by contract, while the leading Chinese labs release weights under permissive licences. That is why an extraction-attack statute keyed to terms of service applies in one direction only.
Sources: openai.com · anthropic.com · llama.com · anthropic.com · anthropic.com
Legal theories for attacking distillation, and how strong each is
8 rows| Theory | Source of law | Who can bring it | Strength | Principal weakness |
|---|---|---|---|---|
| Breach of contract (terms of service) | State contract law | Model owner against the account holder | Strongest | Standard-form contract enforceability; jurisdiction and enforcement against foreign entities; privity if a proxy reseller holds the account law.asia |
| Computer Fraud and Abuse Act | 18 U.S.C. 1030 | DOJ; private civil action | Strong where fraudulent credentials used | Post-Van Buren narrowing of 'exceeds authorized access'; requires proving the credentials were fraudulent, not merely ToS-violating justsecurity.org |
| Trade secret misappropriation | Defend Trade Secrets Act; state UTSA | Model owner | Contested | Outputs served to any paying user are hard to characterise as secret; turns on whether API querying is 'improper means' papers.ssrn.com |
| Economic Espionage Act | 18 U.S.C. 1831-1839 | DOJ | Weak in practice | Same secrecy problem as DTSA, plus foreign-defendant enforcement; commentators call it unsettled footing justsecurity.org |
| Copyright infringement in outputs | 17 U.S.C. | Model owner | Weak | US Copyright Office and DC Circuit hold purely AI-generated outputs are not copyrightable; OpenAI assigns output rights to the user anyway copyright.gov |
| Unfair competition / unjust enrichment | State law; Lanham Act adjacent | Model owner | Weak to moderate | Hard to establish deception where data was obtained through a public paid API rather than intrusion law.asia |
| Export control / sanctions designation | ECRA, EAR Entity List, IEEPA | US government | Most likely operative route | Political, not judicial; requires attribution evidence agencies may not want to publish; escalation risk with Beijing justsecurity.org |
| Statutory model-extraction designation (proposed) | H.R. 8283 if enacted | State Dept / Commerce | Untested | Anchored to private terms of service; ITIF flags due-process concerns and lack of research safe harbours itif.org |
Commentators consulted include Joe Khawam (Law Reform Institute) on national security authorities, Camilla Hrdy on trade secrecy and generative AI, and Bahrad A. Sokhansanj (Institute for Law & AI) on proportionality.
Sources: justsecurity.org · papers.ssrn.com · law-ai.org · copyright.gov
US export-control milestones that frame the distillation debate
12 rows| Date | Action | Scope | Effect / response |
|---|---|---|---|
| 2022-10-07 | BIS advanced computing and semiconductor rule | A100/H100-class GPUs to China | Nvidia introduced China-specific A800/H800 with reduced interconnect congress.gov |
| 2023-10-17 | BIS October 2023 update | Captures A800/H800 and similar workarounds | Nvidia announced H20, L20, L2 for China cset.georgetown.edu |
| 2025-01-15 | AI Diffusion Rule published | Worldwide tiered licensing for advanced computing | Enforcement set for 2025-05-15; triggered allied and industry objections wiley.law |
| 2025-04 | H20 licence requirement imposed | Nvidia H20 to China | Nvidia forecast a $5.5bn charge in April 2025 and recorded $4.5bn in Q1 FY2026 techcrunch.com |
| 2025-05-13 | BIS announces rescission of the AI Diffusion Rule | Global framework withdrawn before enforcement | Non-enforcement instruction pending formal rescission; replacement rule promised wiley.law |
| 2025-08 | H20 / MI308 licences resume with revenue-share arrangement | Nvidia and AMD China sales | Reported 15% of China chip revenue to the US government fortune.com |
| 2025-10-09 | Senate passes NDAA including GAIN AI Act | US-customer-first allocation of advanced chips | Opposed by Nvidia, SIA and the White House AI adviser nextgov.com |
| 2025-12-18 | FY2026 NDAA signed without the GAIN AI Act | Chip allocation mandate dropped | Removed the main statutory brake on advanced chip exports nextgov.com |
| 2026-01-15 | BIS moves H200 / MI325X to case-by-case review | China and Macau destinations | Presumption of denial replaced; 25% tariff proclamation signed 2026-01-14 cnbc.com |
| 2026-03-26 | Chip Security Act reported out of House Foreign Affairs 42-0 | Location verification for exported AI chips | Bipartisan support; not enacted as of Sept 2026 congress.gov |
| 2026-06-17 | Expanded Entity List publication held back | DeepSeek, CXMT and 100+ flagged firms | Reported delay to avoid escalation ahead of talks; DeepSeek remained unlisted cnbc.com |
| 2026-07-21 | China consults industry on AI export controls | Model weights, key training data, chip designs | Would make Chinese open weights a licensed export; still under review techrepublic.com |
Nvidia flagged an anticipated $5.5bn H20 charge in its April 15, 2025 8-K; the charge actually recorded in its Q1 FY2026 results (May 28, 2026 reporting) was $4.5bn. The 15% revenue-share figure is press-reported and has not been published as a formal rule.
Sources: congress.gov · wiley.law · cnbc.com · techcrunch.com · hpcwire.com
Government restrictions on DeepSeek, by jurisdiction
13 rows| Jurisdiction | Date | Scope | Stated rationale |
|---|---|---|---|
| Italy | 2025-01-30 | Public block of the chatbot nationwide | Garante found privacy-policy and data-transfer disclosures inadequate privacylaws.com |
| Texas | 2025-01-31 | All state-owned devices | First US state ban; data harvesting and CCP-linkage concerns statetechmagazine.com |
| Taiwan | 2025-02-02 | Public sector agencies | Cross-border data transmission and leakage risk taipeitimes.com |
| Australia | 2025-02-04 | Government devices | Security concerns thecable.ng |
| New York State | 2025-02-10 | Government networks and devices | Foreign surveillance and censorship risk nbcnews.com |
| Virginia | 2025-02-11 | State devices and networks | Third US state to act natlawreview.com |
| South Korea | 2025-02-17 | App-store downloads suspended | PIPC found non-compliance with Korean data protection law privacylaws.com |
| Iowa | 2025-02-19 | State devices, alongside other Chinese apps | Governor's directive statetechmagazine.com |
| South Dakota | 2025-03 | Government-issued devices and contractors | Bundled with RedNote restriction statetechmagazine.com |
| Oklahoma | 2025-03-21 | All state-owned devices | Governor Stitt executive action citing data security oklahoma.gov |
| North Carolina | 2025-03 | State devices | Followed peer states statetechmagazine.com |
| US Commerce Department | 2025-02 | Department devices | Reported internal prohibition ahead of any statute pymnts.com |
| Germany (Berlin DPA) | 2025-06-27 | Finding of unlawful processing under GDPR | Could not demonstrate EU-equivalent protection for data transferred to China datenschutz-berlin.de |
Dates for South Dakota and North Carolina are month-level in the underlying reporting. This is a floor count of publicly reported restrictions, not an exhaustive census; StateTech lists 14 US states restricting DeepSeek as of April 2025.
Sources: statetechmagazine.com · privacylaws.com · tech.co · datenschutz-berlin.de · taipeitimes.com
Timeline · 47 events
BIS imposes advanced computing export controls on China
Cuts off A100/H100-class GPUs. Nvidia responds with China-specific A800 and H800 parts with reduced interconnect bandwidth. This is the compute-asymmetry baseline that later distillation arguments rest on.
Source: congress.govBIS closes the A800/H800 workaround
The October 2023 update captures the China-tailored parts. Nvidia then announces H20, L20 and L2 for the Chinese market.
Source: cset.georgetown.eduOpenAI blocks API traffic from unsupported regions including mainland China
Developers in China had been reaching the API through VPNs; OpenAI began blocking that traffic. Microsoft's Azure China joint venture continued serving eligible customers, an early illustration of how corporate access policy fragments.
Source: restofworld.orgDeepSeek V3 is reported to self-identify as ChatGPT
Widely reported behaviour in which V3 described itself as a version of ChatGPT. Later cited by the House Select Committee and by AFPI testimony as circumstantial evidence of OpenAI-derived training data.
Source: techcrunch.comAI Diffusion Rule published
Biden-era framework imposing worldwide tiered licensing on advanced computing, with enforcement scheduled for May 15, 2025. OpenAI's March filing would later propose banning PRC-produced models within its Tier 1 country group.
Source: wiley.lawDavid Sacks says there is 'substantial evidence' DeepSeek distilled OpenAI models
The White House AI and crypto czar told Fox News that DeepSeek 'distilled knowledge out of OpenAI models,' without detailing the evidence, and predicted US labs would move to block copycat models.
Source: bloomberg.comMicrosoft and OpenAI confirm they are investigating a DeepSeek-linked group
Microsoft security researchers had observed individuals believed linked to DeepSeek exfiltrating large volumes of data through the OpenAI API in autumn 2024. OpenAI said it takes 'aggressive, proactive countermeasures' and knows PRC-based companies are constantly trying to distill leading US models.
Source: bloomberg.comDario Amodei publishes 'On DeepSeek and Export Controls'
Argues DeepSeek's efficiency does not undermine export controls but makes them more important, and that a substantial share of DeepSeek's fleet was pre-ban, unbanned or likely smuggled. Sets the compute-asymmetry frame the labs still use.
Source: darioamodei.comSenator Hawley introduces S. 321, the Decoupling America's AI Capabilities from China Act
Would prohibit US persons from exporting AI technology or IP to China or importing Chinese-developed AI, bar joint research, and impose penalties of up to 20 years. Referred to Judiciary and not advanced.
Source: congress.govItaly's Garante orders DeepSeek's chatbot blocked
The first national-level public block, on data-protection rather than security grounds, after DeepSeek failed to address the regulator's questions about its privacy policy and transfers.
Source: privacylaws.comTexas becomes the first US state to ban DeepSeek on state devices
Opens a wave of state-level restrictions that reached at least seven states by April 2025, plus agency-level bans elsewhere.
Source: statetechmagazine.comAustralia bans DeepSeek on government devices
Followed within weeks by South Korea suspending app-store downloads and Taiwan restricting public-sector use.
Source: thecable.ngOpenAI's OSTP filing calls DeepSeek 'state-subsidized' and 'state-controlled'
In its response to the AI Action Plan RFI, OpenAI recommended considering bans on PRC-produced models in Tier 1 countries, citing security risk and risk of IP theft, and pointed to distillation against its terms of service. OpenAI later softened the framing, saying it was proposing export-rule changes rather than usage restrictions.
Source: techcrunch.comOpenAI introduces Verified Organization ID checks for frontier API access
Government-ID verification gates access to the most capable models, with one ID per organisation per 90 days. An access-control response to extraction rather than a legal one.
Source: help.openai.comHouse Select Committee on the CCP publishes 'DeepSeek Unmasked'
Bipartisan report calling DeepSeek a 'profound threat,' alleging data routing through China Mobile-linked infrastructure, likely unlawful distillation of US models, and export-control circumvention. Recommends expanding and better enforcing export controls.
Source: chinaselectcommittee.house.govBIS announces rescission of the AI Diffusion Rule
Two days before it would have taken effect, with an instruction not to enforce pending formal rescission. The administration argued it would stifle US innovation and undermine diplomacy; a replacement rule was promised.
Source: wiley.lawNo Adversarial AI Act introduced
Sens. Rick Scott and Gary Peters, with House Select Committee members, propose a Federal Acquisition Security Council list of foreign-adversary AI and a ban on executive-agency use with narrow research carve-outs.
Source: congress.govEuropean Commission publishes the final GPAI Code of Practice
Three chapters — Transparency, Copyright, Safety and Security — as a voluntary route to compliance with obligations applying from August 2, 2025. Formally approved on August 1.
Source: artificialintelligenceact.euWhite House releases 'Winning the Race: America's AI Action Plan'
Over 90 federal actions across innovation, infrastructure and international pillars. Notably promotes open-source and open-weight models and calls for exporting the full American AI stack — a posture in tension with the case for restricting model access.
Source: whitehouse.govChina unveils a Global AI Governance Action Plan and proposes a world AI cooperation body
Announced at the World AI Conference in Shanghai: a thirteen-point roadmap, an International Open Source AI Cooperation Initiative, and a proposed organisation headquartered in Shanghai. The counter-offer to US-led restriction.
Source: technode.comEU AI Act obligations for general-purpose AI providers begin to apply
Applies to models placed on the market on or after this date. Commission enforcement, including model access and recalls, deferred one year to August 2, 2026.
Source: ec.europa.euNvidia and AMD reported to agree a 15% China revenue share for export licences
Commerce began issuing H20 licences days after Jensen Huang met President Trump. A novel instrument: export policy priced rather than prohibited.
Source: fortune.comAnthropic bars entities majority-controlled from China, Russia, Iran and North Korea
Applies worldwide to subsidiaries and joint ventures regardless of where they operate. Anthropic cited legal compulsion to share data with authoritarian states and estimated a revenue impact in the low hundreds of millions of dollars.
Source: semafor.comSenate passes its NDAA including the GAIN AI Act
Would require US chipmakers to prioritise American customers before selling advanced AI chips abroad. Opposed by Nvidia, the Semiconductor Industry Association and the White House AI adviser; supported by Microsoft and Americans for Responsible Innovation.
Source: nextgov.comFY2026 NDAA signed without the GAIN AI Act
The chip-allocation mandate was stripped in conference. Ten days earlier the President had directed that H200-class exports to approved customers be permitted in exchange for a federal surcharge.
Source: nextgov.comBIS moves H200 and MI325X exports to case-by-case review; 25% tariff applies
Replaces the presumption of denial for China and Macau destinations, with third-party lab testing and a cap on the China share relative to US customers. The proclamation imposing a 25% duty was signed the previous day.
Source: cnbc.comSouth Korea's AI Basic Act takes effect
The first comprehensive national AI framework outside the EU, with generative-AI and high-impact obligations, a National AI Committee, an AI Policy Center and an AI Safety Research Institute. It does not address distillation.
Source: cooley.comOpenAI memo to the House Select Committee and Google GTIG report land the same day
OpenAI's 'Updated Stakes for American-Led, Democratic AI' accused Chinese companies including DeepSeek of using sophisticated, multi-stage pipelines. Google's Threat Intelligence Group reported disrupting Gemini extraction activity, including a cluster of more than 100,000 prompts aimed at coercing reasoning behaviour, and framed the threat as global rather than China-specific.
Source: cdn.openai.comAnthropic publicly discloses industrial-scale distillation attacks
Names DeepSeek, Moonshot AI and MiniMax: over 16 million exchanges through roughly 24,000 fraudulent accounts, with MiniMax accounting for over 13 million. Calls for coordinated industry, cloud-provider and policymaker response and argues the episode reinforces the case for chip export controls.
Source: anthropic.comChip Security Act reported out of House Foreign Affairs 42-0
Would require location-verification mechanisms on covered chips before export, with reporting to Commerce if a chip's location changes. Bipartisan but not enacted.
Source: congress.govOpenAI, Anthropic and Google agree to share distillation threat intelligence
Coordination routed through the Frontier Model Forum, responding to the AI Action Plan's call for an industry information-sharing centre. The companies sought antitrust comfort before trading notes.
Source: techbrew.comH.R. 8283, the Deterring American AI Model Theft Act of 2026, is introduced
Reps. Huizenga and Moolenaar. Defines a 'model extraction attack' as unauthorized extraction of a closed-source model's capabilities where the querying circumvents access controls, uses fraudulent credentials, or violates terms prohibiting output-based training. Explicitly exempts training that complies with terms of service.
Source: govinfo.govHouse Select Committee hearing: 'China's Illicit Campaign to Steal and Subvert American AI Technology'
Testimony from AFPI's Yusuf Mahmood collating the OpenAI, Google, Anthropic and xAI disclosures and arguing that consistent lag behind the American frontier is itself evidence of a distillation-driven development model.
Source: docs.house.govH.R. 8283 ordered reported 43-0
Unanimous House Foreign Affairs vote, alongside a package of export-control measures. The bill has not received a floor vote as of September 2026.
Source: congress.govOSTP issues NSTM-4, 'Adversarial Distillation of American AI Models'
Signed by Director Michael Kratsios. Finds foreign entities principally in China running deliberate, industrial-scale campaigns using tens of thousands of proxy accounts and jailbreaking to expose proprietary information, and that the resulting models strip safety protocols. Commits to intelligence sharing with industry, joint best practices and exploration of accountability measures.
Source: nextgov.comState Department cables posts worldwide to raise distillation with foreign counterparts
Instructs diplomats to discuss concerns over adversaries' extraction and distillation of US AI models, naming DeepSeek, Moonshot AI and MiniMax. The Chinese Embassy called the allegations groundless.
Source: cnbc.comDeepSeek releases a preview of V4
A trillion-parameter-class open model, notable as DeepSeek's first optimised for domestic Chinese accelerators such as Huawei Ascend. US officials alleged it was trained on smuggled Blackwell GPUs; Nvidia called that farfetched.
Source: technologyreview.comPresident signs NSPM-11 on AI in the national security enterprise
Four pillars — adoption, adaptation, assurance, accountability — with Section 4(c) directing protection of advanced AI systems against malicious distillation attacks. Rescinds and replaces the prior administration's NSM-25.
Source: whitehouse.govPentagon adds Alibaba, Baidu, BYD and Unitree to the 1260H list
Sixty-five entities added, bringing the list to 188. Procurement prohibitions take effect June 30, 2026. DeepSeek was not added.
Source: cnbc.comAnthropic tells Senate Banking that Alibaba ran the largest known distillation attack against it
Letter to Chairman Tim Scott and Ranking Member Elizabeth Warren alleging 28.8 million-plus exchanges through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026, targeting agentic reasoning, software engineering and long-horizon tasks. Asks Congress to enable threat-information sharing, close chip loopholes and penalise responsible PRC labs.
Source: d1e00ek4ebabms.cloudfront.netUS holds off blacklisting DeepSeek and 100-plus other flagged firms
An inter-agency committee had approved DeepSeek for Entity List addition, but publication was delayed, reportedly to avoid escalating tensions with Beijing. A State Department official said DeepSeek has supported Chinese military and intelligence operations.
Source: cnbc.comAlibaba bars employees from using Anthropic products
Announced 6 July 2026, effective 10 July 2026: staff were told to uninstall Anthropic models and agent products and use Alibaba's own assistant. Alibaba denied using proprietary model outputs to train its models and denied Chinese government involvement.
Source: cnbc.comTreasury Secretary Bessent threatens sanctions over AI model theft
Said the US is finding watermarks of American large language models inside Chinese systems and has the ability to sanction overseas models that steal from US companies. The same day, FT reported MOFCOM consulting Alibaba, ByteDance and Zhipu on export controls covering model weights, key training data and chip designs.
Source: cnbc.comKratsios accuses Moonshot AI of distilling Anthropic's Fable to build Kimi K3
The OSTP director also alleged Moonshot obtained export-controlled Nvidia servers. No supporting evidence was published; researchers including Nathan Lambert and Braden Hancock publicly doubted distillation alone could explain K3's capabilities on that timeline, noting Fable had been publicly available only since July 1 — about two weeks.
Source: cyberscoop.comOpen-weights letter launches with ~25 signatories, later exceeding 270
Nvidia, Meta, Microsoft and Amazon were among roughly 25 companies signing at launch on July 24, 2026; OpenAI and Google were absent on the day and appeared on the signatory list around July 26. The count passed 150 by July 28 and later exceeded 270. Signatories argue open weights are essential to American AI leadership and that closed-model concentration is a systemic risk. Dario Amodei published a rebuttal on July 27 accepting open weights in general but arguing the most powerful frontier weights carry irreversible national security risk.
Source: images.nvidia.comChina's Ministry of Commerce counter-accuses American AI firms of distilling Chinese models
Called US allegations factually and legally unsupported and an act of 'AI hegemony,' promised 'all necessary measures' if Chinese firms are sanctioned, and defended distillation as a widely used industry technique. No companies were named and no evidence was supplied.
Source: implicator.aiEU AI Act enforcement powers go live
The AI Office can now request information and documentation, obtain model access for evaluation, require corrective measures, and fine GPAI providers up to EUR 15 million or 3% of global turnover. Its stated preferred first tool remains technical compliance dialogues.
Source: ec.europa.eu
Glossary · 16 terms
- Distillation
- Training a smaller or cheaper student model on the outputs of a larger teacher model. Legitimate and standard when the teacher's licence permits it; the policy fight is about doing it to a closed model in breach of its terms.
- Adversarial distillation
- The term adopted by OSTP memorandum NSTM-4 (April 23, 2026) for systematic extraction of a frontier model's capabilities via large volumes of constructed queries, typically through proxy accounts that evade access controls.
- Model extraction attack
- The statutory term in H.R. 8283: unauthorized extracting of a closed-source model's capabilities to replicate, develop, train or improve another model, where the querying circumvents access controls, uses fraudulent credentials, or violates output-training terms.
- AI Model Extraction Attackers List
- The public list H.R. 8283 would have the Secretary of State maintain, naming individuals and entities assessed to have conducted model extraction attacks, as a predicate for sanctions or Entity Listing.
- Fraudulent account network provider
- A category defined in H.R. 8283 covering foreign entities that create, sell or broker accounts allowing entities of concern to reach models they are barred from, with a carve-out for services enabling internet access for freedom of expression.
- Entity List
- The Commerce/BIS list imposing licence requirements, usually with a presumption of denial, on exports to named foreign parties. Repeatedly floated for Chinese AI labs; not applied to DeepSeek as of September 2026.
- Section 1260H list
- The Pentagon's annual list of Chinese military companies. Listing bars Department procurement contracts. Alibaba, Baidu, BYD and Unitree were added in June 2026.
- IEEPA
- The International Emergency Economic Powers Act, the authority under which a president can declare a national emergency and impose blocking sanctions. The main vehicle proposed for sanctioning distillation actors.
- AI Diffusion Rule
- The January 15, 2025 BIS framework creating worldwide tiered licensing for advanced computing. BIS announced its rescission on May 13, 2025, before its May 15 enforcement date.
- GPAI obligations
- The EU AI Act duties on providers of general-purpose AI models — technical documentation, copyright policy, training-data summary, and systemic-risk duties above a compute threshold — applying from August 2, 2025 and enforceable from August 2, 2026.
- Code of Practice (GPAI)
- The voluntary EU compliance instrument published July 10, 2025, with Transparency, Copyright, and Safety and Security chapters. Signing it is a presumption-of-conformity route, not a legal obligation.
- Open weights
- Model parameters published for download and self-hosting. Central to the policy paradox: the US AI Action Plan promotes open weights while distillation policy tries to restrict capability diffusion.
- Sovereign AI
- A state's pursuit of domestically controlled compute, models and data. In 2026 the practical question is whether a country's sovereign stack sits on US closed models, US open weights, or Chinese open weights.
- Transfer station economy
- The grey market of proxy servers and reseller billing panels that resell access to Western frontier models inside China, sometimes at a fraction of list price. The practical delivery mechanism behind alleged extraction campaigns.
- Military-civil fusion
- China's policy of integrating civilian technology development with military modernisation, invoked by US officials to argue that capabilities distilled by commercial Chinese labs reach the PLA.
- Frontier Model Forum
- The industry body founded in 2023 by Anthropic, Google, Microsoft and OpenAI, used from April 2026 as the channel for sharing distillation threat intelligence between labs.
Sources · 100 sources
Every figure on this page comes from one of these primary sources. Compiled 4 September 2026.
- Detecting and preventing distillation attacks
- Letter to Senate Banking Committee on illicit access to American AI models by Alibaba-affiliated operators
- H.R. 8283, Deterring American AI Model Theft Act of 2026 (introduced text)
- H.R. 8283 bill page and status
- National Security Presidential Memorandum NSPM-11
- Winning the Race: America's AI Action Plan
- China's Illicit Campaign to Steal and Subvert American AI Technology (testimony of Yusuf Mahmood)
- OpenAI response to the OSTP/NSF RFI on the AI Action Plan
- OpenAI calls DeepSeek 'state-controlled,' calls for bans on 'PRC-produced' models
- AI Czar Sacks Says 'Evidence' DeepSeek Leaned On OpenAI's Models
- Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI Data
- OpenAI says DeepSeek may have 'inappropriately' used its models' output
- On DeepSeek and Export Controls
- Moolenaar, Krishnamoorthi unveil report on DeepSeek
- S. 321 Decoupling America's Artificial Intelligence Capabilities from China Act
- H.R. 3447 Chip Security Act
- S. 1705 Chip Security Act
- S. 3150 GAIN AI Act of 2025
- S. 2177 No Adversarial AI Act (text)
- H.R. 1121 No DeepSeek on Government Devices Act
- US Export Controls and China: Advanced Semiconductors (CRS R48642)
- Explainer: The Commerce Department's October 2023 Export Controls Update
- BIS Rescinds AI Diffusion Rule and Issues Guidance
- Nvidia says it will record $5.5 billion charge tied to H20 processors
- Nvidia, AMD to pay 15% of China chip revenue to US government
- Trump administration clears way for Nvidia H200 chip sales to China
- AI export control bill passes Senate as NDAA amendment
- Bill prioritizing American customers for AI chips not expected to make it into final NDAA
- White House accuses China of deliberate, industrial-scale campaigns to steal US AI models
- US State Department orders global warning about alleged China AI theft
- Anthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract Claude capabilities
- China's Alibaba bans Anthropic AI for employees after distillation accusation
- Bessent says U.S. could sanction China over AI model 'theft'
- US holds off blacklisting China's DeepSeek and 100+ firms
- Pentagon expands list of China military-linked firms to include Alibaba, Baidu, BYD
- Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement
- Commission starts enforcing AI Act rules and new transparency obligations
- Overview of the General-Purpose AI Code of Practice
- EU AI Act rules on GPAI models under DeepSeek review
- White House accuses Moonshot AI of distilling Anthropic's model
- Experts say exploiting Anthropic's Fable isn't how Kimi K3 got so good
- Three reasons why DeepSeek's new model matters
- The Case for Imposing Costs on China's AI Distillation Campaigns
- From Diagnosis to Deterrence: The Emerging U.S. Response to Distillation
- Responding to AI Distillation Without Panic
- How to Fix the AI Model Theft Bill Before It Becomes Law
- Adversarial Distillation: China's Campaign to Extract American AI Capabilities
- AI Distillation Attacks: Executive and Congressional Action Can Go Further
- Trade Secrecy Meets Generative AI
- Dispute over AI model distillation tech in OpenAI-DeepSeek case
- Copyright Office report on copyrightability of AI-generated material
- 'Ironic, hypocritical' of big tech to call out DeepSeek
- OpenAI hit with mockery over DeepSeek complaint
- Why DeepSeek's new AI model thinks it's ChatGPT
- Anthropic blocks sales of AI to Chinese firms
- US AI giant Anthropic bars Chinese-owned entities
- OpenAI Terms of Use
- Anthropic Consumer Terms of Service
- Meta Llama 3 Community License
- Llama 3.3 70B Instruct model card
- API Organization Verification
- OpenAI to cut off API access in China on July 9
- OpenAI accuses DeepSeek of malpractice ahead of AI launch
- These States Have Banned DeepSeek
- New York state bans DeepSeek from government devices
- Italy and South Korea ban DeepSeek and start investigation
- Governor Stitt bans DeepSeek on all state-owned devices
- South Korea's AI Basic Act: Overview and Key Takeaways
- AI Watch: Global regulatory tracker - Japan
- UK Sovereign AI Unit
- China proposes new global AI cooperation organization, headquarters planned in Shanghai
- China launches Shanghai-based AI governance body with 29 founding nations
- China Accuses US AI Firms of Distilling Chinese Models
- China Considers Export Controls on AI Models, Training Data and Chip Technology
- Google disrupts Gemini model extraction attempts
- OpenAI, Anthropic, Google join forces against China
- How to Buy Cheap Claude Tokens in China
- Inside the Gray Market for LLM Access
- Open Weights and American AI Leadership (open letter)
- Gulf AI infrastructure and the limits of technological sovereignty
- Which Countries Have Banned DeepSeek Already?
- DeepSeek and Chinese AI Models: GDPR Data Transfer Compliance
- Report: Commerce Department bans use of DeepSeek on government devices
- Three States Ban DeepSeek Use on State Devices and Networks
- South Korea joins Italy, Australia in banning DeepSeek
- Nvidia expects to lose billions in revenue due to H20 chip licensing requirements
- Nvidia announces financial results for 1st quarter fiscal 2026
- H.R. 9363, AI Security and Innovation Act
- CBO cost estimate, H.R. 9363
- President Trump orders narrowly targeted 25% Section 232 tariff on certain advanced semiconductors
- BlnBDI press release: DeepSeek apps reported to Apple and Google
- Nvidia and 24 other companies sign open-weights letter
- Open weights, American AI leadership letter: OpenAI absent
- Taiwan bans DeepSeek in the public sector
- H.R. 4142 No Adversarial AI Act (introduced)
- House Foreign Affairs markup documents, H.R. 8283 (April 22, 2026)
- Distillation, experimentation and integration: adversarial use of AI
- Updated Stakes for American-Led, Democratic AI (memo to House Select Committee)
- Anthropic Commercial Terms of Service
- Anthropic Usage Policy