Skip to content

Don’t Turn Three AI Risks Into One Blunt Restriction

A Risk-Based U.S. Policy for Chinese Models, Distillation, and Open-Weight AI

By Daisy Thomas, Director of Advocacy and Policy Development 

July 28, 2026

The Core Problem: Three Distinct Issues Are Being Merged

1. Chinese Provenance

Issue: Dependence on foreign models

Response: Supply-chain review, diversification, sensitive-use controls

2. Distillation/Extraction

Issue: Alleged unlawful model theft

Response: Conduct-based enforcement under clearly defined law

3. Open-Weight Release

Issue: Risk vs. defensive value tradeoff

Response: Release-specific assessment, proportional safeguards

Core Principle: Provenance is a risk input. Distillation is a conduct question. Openness is a distribution architecture. Confusing these categories creates bad policy.

Why Blanket Restrictions Backfire: The Double Own Goal

  • Own Goal 1—Weakening Defense: Hugging Face incident shows defenders need locally controlled access to study exploits and analyze forensic evidence. Prohibition removes capability from legitimate defenders while adversaries retain it abroad.
  • Own Goal 2—Market Concentration: Restricting open models pushes startups toward expensive proprietary providers, reduces technical diversity, and creates single-vendor dependency for incident response.

The Seven-Dimension Risk Framework

Assess models on: (1) Capability | (2) Deployment context | (3) Access & agency | (4) Developer conduct | (5) Technical integrity | (6) Supply-chain risk | (7) Consequence

Ask: What risk does this model create, in this deployment, with this access, under this operator, through this supply chain—and what intervention actually reduces it?

Six Policy Responses (Not One Blanket Ban)

1. Unlawful Conduct

Define prohibited extraction precisely. Target actors with entity-specific sanctions, not entire architectures.

2. Sensitive Deployment

Restrict models in classified networks, defense, critical infrastructure—not in universities or startups.

3. Dangerous Capability

Regulate autonomous cyber, biological, high-consequence capabilities regardless of origin.

4. Defensive Access

Create governed pathways for cybersecurity researchers and incident responders—distributed, not contractor-only.

5. Foreign Dependency

Build resilient American alternatives. Require redundancy, interoperability, local copies—not prohibition.

6. Market Concentration

Assess security effects of restrictions. Technical diversity is defensive capacity; evaluate both.

The Three AI Salon Principles

PLAY FIRST:

Learn before locking in. Use evaluations, pilots, controlled access, and adaptive thresholds. Don’t convert uncertainty into permanent rules.

CREATE EXCELLENCE:

Match policy mechanism to actual problem. If the issue is IP theft, enforce theft—don’t ban the entire architecture.

GENEROUSLY LEAD:

Expand independent capacity—startups, researchers, defenders, public institutions—don’t concentrate power in incumbent firms.

Does the policy make the threat less capable—or merely make Americans less capable of responding to it?

The Bottom Line

Don’t: Impose blanket bans on Chinese models, turn distillation allegations into restrictions on all open-weight AI, confuse national origin with complete risk assessment.

Do: Target conduct. Evaluate capability. Govern deployment. Reduce dependency through resilience. Preserve research and competitive options. Build American alternatives.

Central Test: Restrict demonstrated risk with the narrowest mechanism capable of materially reducing it.

Link to full paper.

About the AI Salon 

We are AI optimists committed to mindfully exploring the power of AI to unlock opportunities for all. 

www.thesalon.ai

More Campaigns