Don’t Turn Three AI Risks Into One Blunt Restriction
A Risk-Based U.S. Policy for Chinese Models, Distillation, and Open-Weight AI
By Daisy Thomas, Director of Advocacy and Policy Development
July 28, 2026
The Core Problem: Three Distinct Issues Are Being Merged
1. Chinese Provenance
Issue: Dependence on foreign models
Response: Supply-chain review, diversification, sensitive-use controls
2. Distillation/Extraction
Issue: Alleged unlawful model theft
Response: Conduct-based enforcement under clearly defined law
3. Open-Weight Release
Issue: Risk vs. defensive value tradeoff
Response: Release-specific assessment, proportional safeguards
Core Principle: Provenance is a risk input. Distillation is a conduct question. Openness is a distribution architecture. Confusing these categories creates bad policy.
Why Blanket Restrictions Backfire: The Double Own Goal
- Own Goal 1—Weakening Defense: Hugging Face incident shows defenders need locally controlled access to study exploits and analyze forensic evidence. Prohibition removes capability from legitimate defenders while adversaries retain it abroad.
- Own Goal 2—Market Concentration: Restricting open models pushes startups toward expensive proprietary providers, reduces technical diversity, and creates single-vendor dependency for incident response.
The Seven-Dimension Risk Framework
Assess models on: (1) Capability | (2) Deployment context | (3) Access & agency | (4) Developer conduct | (5) Technical integrity | (6) Supply-chain risk | (7) Consequence
Ask: What risk does this model create, in this deployment, with this access, under this operator, through this supply chain—and what intervention actually reduces it?
Six Policy Responses (Not One Blanket Ban)
1. Unlawful Conduct
Define prohibited extraction precisely. Target actors with entity-specific sanctions, not entire architectures.
2. Sensitive Deployment
Restrict models in classified networks, defense, critical infrastructure—not in universities or startups.
3. Dangerous Capability
Regulate autonomous cyber, biological, high-consequence capabilities regardless of origin.
4. Defensive Access
Create governed pathways for cybersecurity researchers and incident responders—distributed, not contractor-only.
5. Foreign Dependency
Build resilient American alternatives. Require redundancy, interoperability, local copies—not prohibition.
6. Market Concentration
Assess security effects of restrictions. Technical diversity is defensive capacity; evaluate both.
The Three AI Salon Principles
PLAY FIRST:
Learn before locking in. Use evaluations, pilots, controlled access, and adaptive thresholds. Don’t convert uncertainty into permanent rules.
CREATE EXCELLENCE:
Match policy mechanism to actual problem. If the issue is IP theft, enforce theft—don’t ban the entire architecture.
GENEROUSLY LEAD:
Expand independent capacity—startups, researchers, defenders, public institutions—don’t concentrate power in incumbent firms.
Does the policy make the threat less capable—or merely make Americans less capable of responding to it?
The Bottom Line
Don’t: Impose blanket bans on Chinese models, turn distillation allegations into restrictions on all open-weight AI, confuse national origin with complete risk assessment.
Do: Target conduct. Evaluate capability. Govern deployment. Reduce dependency through resilience. Preserve research and competitive options. Build American alternatives.
Central Test: Restrict demonstrated risk with the narrowest mechanism capable of materially reducing it.
About the AI Salon
We are AI optimists committed to mindfully exploring the power of AI to unlock opportunities for all.
www.thesalon.ai