How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
This Act may be cited as ''Deterring American AI Model Theft Act of 2026''.
Establishes the short title of the Act as the Deterring American AI Model Theft Act of 2026. No compliance obligations arise from this section.
(1)–(6) It is the sense of Congress that— (1) artificial intelligence (AI) models owned by United States private sector companies are essential for advancing United States economic and national security interests; (2) many of the most advanced AI models owned by United States companies are ''closed-source models'' whose unique technical characteristics are not openly shared or published; (3) the unauthorized acquisition of model capabilities, such as model weights, model architectures, and other technical characteristics of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) by entities of concern through model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) represents a threat to the national security and foreign policy interests of the United States, as well as the intellectual property rights and economic competitiveness of United States companies; (4) the United States Government, in cooperation with private ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2), should take steps to identify, punish, and deter model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) on the protected capabilities of closed-source models by entities of concern; (5) model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) against American closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) allow foreign adversaries a short cut to acquiring advanced AI capabilities; and (6) authorized model training practices that adhere to the terms of service or are otherwise consistent with contractual terms set by the ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) are a legitimate research method that play an important role in AI research and are fundamentally distinct from model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) defined in this Act.
Expresses six Congressional findings establishing the importance of protecting closed-source AI models from model extraction attacks by entities of concern, recognizing the national security and economic threat posed by unauthorized extraction and distinguishing authorized model training practices from model extraction attacks. These are legislative findings with no operative compliance obligations.
(1)–(14) In this Act: (1) APPROPRIATE CONGRESSIONAL COMMITTEESAppropriate congressional committees"Appropriate congressional committees" means— (A) the Committee on Foreign Affairs of the House of Representatives; and (B) the Committee on Banking, Housing, and Urban Affairs in the Senate.Sec. 3(1).—The term ''appropriate congressional committeesAppropriate congressional committees"Appropriate congressional committees" means— (A) the Committee on Foreign Affairs of the House of Representatives; and (B) the Committee on Banking, Housing, and Urban Affairs in the Senate.Sec. 3(1)'' means— (A) the Committee on Foreign Affairs of the House of Representatives; and (B) the Committee on Banking, Housing, and Urban Affairs in the Senate. (2) CLOSED-SOURCE AI MODELClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2).—The term ''closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2)'' means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13)-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2). (3) COUNTRY OF CONCERNCountry of concern"Country of concern" means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the Export Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act.Sec. 3(3).—The term ''country of concernCountry of concern"Country of concern" means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the Export Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act.Sec. 3(3)'' means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concernCountry of concern"Country of concern" means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the Export Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act.Sec. 3(3) for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act. (4) ENTITY OF CONCERNEntity of concern"Entity of concern" means any foreign person or entity that— (A) is located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; (B) is operating under the direction or control of any entity located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; or (C) is conducting or attempting to conduct a model extraction attack against closed-source AI models owned by United States persons and outside of authorized model training practices.Sec. 3(4).—The term ''entity of concernEntity of concern"Entity of concern" means any foreign person or entity that— (A) is located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; (B) is operating under the direction or control of any entity located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; or (C) is conducting or attempting to conduct a model extraction attack against closed-source AI models owned by United States persons and outside of authorized model training practices.Sec. 3(4)'' means any foreign personForeign person"Foreign person" means a person that is not a United States person.Sec. 3(6) or entity that— (A) is located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concernCountry of concern"Country of concern" means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the Export Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act.Sec. 3(3); (B) is operating under the direction or control of any entity located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concernCountry of concern"Country of concern" means— (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country— (i) listed in Country Group D:5 under Supplement No. 1 to part 740 of the Export Administration Regulations, as published on January 1, 2026, that is designated by the Secretary of State as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) designated by the Secretary of State pursuant to the assessment described in subsection (b) or (e) of section 4 of this Act.Sec. 3(3); or (C) is conducting or attempting to conduct a model extraction attackModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) against closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) owned by United States persons and outside of authorized model training practices. (5) EXPORTExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5).—The term ''exportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5)'' has the meaning given that term in section 1742(3) of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Control Reform Act of 2018 (50 U.S.C. 4801(3)). (6) FOREIGN PERSONForeign person"Foreign person" means a person that is not a United States person.Sec. 3(6).—The term ''foreign personForeign person"Foreign person" means a person that is not a United States person.Sec. 3(6)'' means a person that is not a United States person. (7) FRAUDULENT ACCOUNT NETWORK PROVIDERFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7).—(A) IN GENERAL.—The term ''fraudulent account network providerFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7)'' means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2). (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network providerFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7). (8) GOODGood"Good" has the meaning given that term in section 16 of the Export Administration Act of 1979 (50 U.S.C. App. 2415)(as continued in effect pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.)).Sec. 3(8).—The term ''goodGood"Good" has the meaning given that term in section 16 of the Export Administration Act of 1979 (50 U.S.C. App. 2415)(as continued in effect pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.)).Sec. 3(8)'' has the meaning given that term in section 16 of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Administration Act of 1979 (50 U.S.C. App. 2415)(as continued in effect pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.)). (9) IN-COUNTRY TRANSFERIn-country transfer"In-country transfer" has the meaning given that term in section 1742(6) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(6)).Sec. 3(9).—The term ''in-country transferIn-country transfer"In-country transfer" has the meaning given that term in section 1742(6) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(6)).Sec. 3(9)'' has the meaning given that term in section 1742(6) of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Control Reform Act of 2018 (50 U.S.C. 4801(6)). (10) ITEMItem"Item" has the meaning given that term in section 1742(7) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(7)).Sec. 3(10).—The term ''itemItem"Item" has the meaning given that term in section 1742(7) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(7)).Sec. 3(10)'' has the meaning given that term in section 1742(7) of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Control Reform Act of 2018 (50 U.S.C. 4801(7)). (11) MODEL EXTRACTION ATTACKModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11).—(A) IN GENERAL.—The term ''model extraction attackModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11)'' means the unauthorized extracting of a closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2)'s capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13); (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2), or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2), are not model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11). (12) OPERATING COMMITTEE FOR EXPORT POLICYOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12).—The term ''Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12)'' means the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12) referred to in section 1763(c) of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Control Reform Act of 2018 (50 U.S.C. 4822(c)). (13) OWNEROwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13).—The term ''ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13)'' means, with respect to a closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2), the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI modelClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2), or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person. (14) REEXPORTReexport"Reexport" has the meaning given that term in section 1742(9) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(9)).Sec. 3(14).—The term ''reexportReexport"Reexport" has the meaning given that term in section 1742(9) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(9)).Sec. 3(14)'' has the meaning given that term in section 1742(9) of the ExportExport"Export" has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (50 U.S.C. 4801(3)).Sec. 3(5) Control Reform Act of 2018 (50 U.S.C. 4801(9)).
Defines fourteen terms used throughout the Act, including closed-source AI model, entity of concern, model extraction attack, fraudulent account network provider, and owner. The model extraction attack definition includes an inference-of-purpose test and an exclusion for authorized training activities. No operative obligations are created by this section; all definitions are captured in the top-level definitions dictionary.
(a) 1 IN GENERAL.—Not later than 180 days after the date of the enactment of this Act, the Secretary of State, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall complete an assessment to determine— (1) which, if any, entities of concern have conducted or are currently conducting model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) against closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) owned by United States entities; and (2) which, if any, entities of concern are fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7).
(b) 1 MATTERS TO BE INCLUDED.—The assessment required by subsection (a) shall include the following: (1) A determination of which entities of concern— (A) have either previously or are currently engaging in model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11); or (B) are fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7). (2) A determination of which, if any, countries model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) have originated from and where fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) exist. (3) An identification of which, if any, agencies or instrumentalities of governments of countries of concern have provided or are providing material assistance to entities identified pursuant to paragraph (1). (4) An analysis of the methods employed by entities of concern identified pursuant to paragraph (1), including— (A) the role of fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) in model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11), including, to the extent possible, the physical location of fraudulent account network providerFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) offices and data centers; and (B) a determination, to the extent possible, of the number of attempted model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) that occurred in the previous two calendar years from the date on which the Secretary of State begins the assessment pursuant to subsection (a)(1). (5) An examination of the strengths and weaknesses of various detection approaches that can be used to determine whether a model extraction attackModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) has occurred or is occurring. (6) An assessment of the economic and national security consequences of successful model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) by entities of concern that occurred in the previous two calendar years from the date on which the Secretary of State begins the assessment pursuant to subsection (a)(1). (7) Steps detailing how the United States Government is assisting ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) that have been the target or victim of model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) in detecting model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11), deterring future model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11), and punishing entities of concern that engage in model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) or are fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7). (8) A diplomatic strategy to leverage United States allies and partners in detecting and preventing model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) by entities of concern.
(c) 1 PUBLIC CONSULTATION.—In conducting the assessment required by subsection (a), the Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall consult with ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) that have been the targets or victims of model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11), whose participation in this consultation shall be voluntary, other companies, academic experts, industry fora, and other appropriate entities to— (1) identify patterns of attacker behavior and methods to better inform United States Government and private sector efforts to detect model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11); (2) develop best practices for defending against model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11); and (3) develop best practices for identifying fraudulent account network providerFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) activities that facilitate model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11).
(d) 2 REPORT.— (1) IN GENERAL.—Not later than 210 days after the date of the enactment of this Act, the Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall submit to the appropriate congressional committeesAppropriate congressional committees"Appropriate congressional committees" means— (A) the Committee on Foreign Affairs of the House of Representatives; and (B) the Committee on Banking, Housing, and Urban Affairs in the Senate.Sec. 3(1) a report that contains the findings of the assessment. The Secretary of Commerce shall, annually for 3 years, submit to the appropriate congressional committeesAppropriate congressional committees"Appropriate congressional committees" means— (A) the Committee on Foreign Affairs of the House of Representatives; and (B) the Committee on Banking, Housing, and Urban Affairs in the Senate.Sec. 3(1) an updated report with any additional entities of concern identified pursuant to subsection (b)(1). (2) FORM.—The report required by this subsection shall be submitted in unclassified form, but may contain a classified annex.
(e) 3 ROUTINE ASSESSMENT.—The Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall routinely assess for— (1) model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) directed against ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) that occur after the date of completion of the assessment required by this section; (2) fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) that facilitate model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) after the date of completion of the assessment required by this section; and (3) any material changes related to other matters specified in subsection (b).
(f) 4 INDUSTRY COORDINATION.—The Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall establish an information sharing mechanism that allows ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) to voluntarily, quickly, and confidentially share information about model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) and fraudulent account network providersFraudulent account network provider"Fraudulent account network provider" means any foreign entity that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to accounts that allow entities of concern to access closed-source AI models that they would otherwise be prohibited from accessing due to location restrictions in the terms of service or contractual agreements created by the owner of the closed-source AI model. (B) EXCEPTION.—An entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not considered, on the basis of this activity alone, a fraudulent account network provider.Sec. 3(7) with the Department of Commerce.
(g) 5 AI MODEL EXTRACTION ATTACKERS LIST.— (1) IN GENERAL.—The Secretary of State, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall— (A) maintain a list, to be known as the ''AI Model Extraction Attackers List'', that displays information about specific individuals and entities of concern, that the assessment required by subsection (a) and routine assessment described in subsection (e) identify as having conducted or directed model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) in the past year; and (B) publish such list on a publicly available website of the Department of State for up to 5 years. (2) PROTECTION OF CONFIDENTIAL INFORMATION.—The Secretary of State may not, in publishing the list required by paragraph (1) on a publicly available website of the Department of State, disclose confidential information provided by ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) without the express permission of said ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13).
(h) 6 PUBLIC GUIDANCE.—Not later than 210 days after the date of the enactment of this Act, the Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall publish a report comprising of best practices to detect, prevent, and respond to model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11). (1) PUBLIC ACCESS.—The report required by this subsection shall be publicly available. (2) PROTECTION OF CONFIDENTIAL INFORMATION.—In making the report required by this subsection publicly available, the Secretary of Commerce, in coordination with each agency that is a member of the Operating Committee for Export PolicyOperating Committee for Export Policy"Operating Committee for Export Policy" means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)).Sec. 3(12), shall not disclose confidential information provided by ownersOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13) of closed-source AI modelsClosed-source AI model"Closed-source AI model" means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information such as underlying model weights that are necessary to reproduce and independently recreate the model that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an Application Program Interface (API) or other consumer-facing, owner-controlled interfaces without enabling third parties to obtain, modify, or host the closed-source AI model on their own data servers or other technology unless specifically authorized by the owner of the closed-source AI model.Sec. 3(2) without the express permission of said ownerOwner"Owner" means, with respect to a closed-source AI model, the person or entity that— (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of such closed-source AI model, or any version, instance, or deployment thereof, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person.Sec. 3(13).
This section imposes the bill's core government-facing obligations. It requires the Secretary of State, coordinating with Operating Committee for Export Policy agencies, to complete within 180 days a comprehensive assessment identifying entities of concern that have conducted or are conducting model extraction attacks or operating as fraudulent account network providers. The assessment must cover originating countries, government complicity, attack methods, detection approaches, economic and national security consequences, U.S. government assistance steps, and a diplomatic strategy.
The section further mandates public consultation with affected model owners, academic experts, and industry; a congressional report within 210 days (with three annual updates); ongoing routine assessments; an information-sharing mechanism for confidential industry reporting; publication and maintenance of an AI Model Extraction Attackers List on the State Department's website; and issuance of publicly available best-practice guidance for detecting, preventing, and responding to model extraction attacks.
(a) 7 ADDITION CONSIDERATION FOR ENTITY LIST.—Not later than 210 days after the date of the enactment of this Act, the Under Secretary of Commerce for Industry and Security, in coordination with each agency that is a member of the End-User Review Committee, shall make a determination by majority vote of the Committee on whether entities identified as having conducted model extraction attacksModel extraction attack"Model extraction attack" means the unauthorized extracting of a closed-source AI model's capabilities to replicate, develop, train, or improve another AI model, where such querying— (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the model's owner; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner or authorized provider, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another AI model. (B) INFERENCE OF PURPOSE.—For purposes of subparagraph (A), the purpose of querying may be inferred from the totality of circumstances, including— (i) the volume, structure, pattern, coordination, or timing of the querying activity; (ii) the concentration of queries on specific model capabilities; (iii) the use of multiple accounts in a coordinated matter; or (iv) the correlation of querying activity within the development timeline of another AI model. (C) EXCLUSION.—Model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of the closed-source AI model, or otherwise conducted within a permitted exception or the express authorization of the owner of the closed-source AI model, are not model extraction attacks.Sec. 3(11) or having facilitated them via fraudulent account networks after the date of the completion of the assessment required under section 4 of this Act (identified pursuant to subsection (e) of such section), or any affiliate of such entity (to be determined by ownership of 50 percent or more in the aggregate, directly or indirectly), should be added to the Entity List maintained by the Bureau of Industry and Security of the Department of Commerce under Supplement No. 4 to part 744 of title 15, Code of Federal Regulations, or any successor regulations.
(b)(1) 8 SANCTIONS DESCRIBED.— (1) IN GENERAL.—The President, acting through the Secretary of State, may, pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.), block and prohibit all transactions in all property and interests in property of entities of concern identified pursuant to subsections (b)(1) and (e) of section 4 if such property and interests in property are in the United States, come within the United States, or are or come within the possession or control of a United States person.
(b)(2) EXCEPTIONS.— (A) EXCEPTION TO COMPLY WITH INTERNATIONAL OBLIGATIONS.—Sanctions under this subsection shall not apply with respect to the admission of an alien if admitting or paroling the alien into the United States is necessary to permit the United States to comply with the Agreement regarding the Headquarters of the United Nations, signed at Lake Success June 26, 1947, and entered into force November 21, 1947, between the United Nations and the United States, or other applicable international obligations. (B) EXCEPTION RELATING TO THE PROVISION OF HUMANITARIAN ASSISTANCE.—Sanctions under this subsection may not be imposed with respect to transactions or the facilitation of transactions for— (i) the sale of agricultural commodities, food, medicine, or medical devices; (ii) the provision of humanitarian assistance; (iii) financial transactions relating to humanitarian assistance; or (iv) transporting goodsGood"Good" has the meaning given that term in section 16 of the Export Administration Act of 1979 (50 U.S.C. App. 2415)(as continued in effect pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.)).Sec. 3(8) or services that are necessary to carry out operations relating to humanitarian assistance. (C) EXCEPTION FOR INTELLIGENCE, LAW ENFORCEMENT, AND NATIONAL SECURITY ACTIVITIES.—Sanctions under this subsection shall not apply to any authorized intelligence, law enforcement, or national security activities of the United States.
(b)(3) PENALTIES.—A person that violates, attempts to violate, conspires to violate, or causes a violation of this subsection or any regulation, license, or order issued to carry out that subsection shall be subject to the penalties set forth in subsections (b) and (c) of section 206 of the International Emergency Economic Powers Act (50 U.S.C. 1705) to the same extent as a person that commits an unlawful act described in subsection (a) of that section.
This section establishes the bill's enforcement tools. First, it requires the Under Secretary of Commerce for Industry and Security, within 210 days and by majority vote of the End-User Review Committee, to determine whether entities identified under Section 4 should be added to the Entity List (Supplement No. 4 to 15 C.F.R. Part 744), extending to affiliates with 50% or greater ownership.
Second, it authorizes the President, acting through the Secretary of State, to impose IEEPA property-blocking sanctions against identified entities of concern. Exceptions are carved out for international obligations (UN Headquarters Agreement), humanitarian assistance, and intelligence/law enforcement/national security activities. Violators face IEEPA penalties under 50 U.S.C. § 1705.