Don’t Turn Three AI Risks Into One Blunt Restriction: A Risk-Based U.S. Policy for Chinese Models, Distillation, and Open-Weight AI
By Daisy Thomas, Director of Advocacy and Policy Development at AI Salon
July 28, 2026
Position
Washington is merging three different artificial intelligence policy problems:
- American dependence on Chinese-developed models;
- alleged distillation and model-extraction attacks against U.S. companies; and
- the risks and benefits of open-weight AI.
These issues are connected. They are not interchangeable.
Provenance is a risk input. Distillation is a conduct question. Open weights are a distribution architecture.
Each raises different concerns, requires different evidence, and calls for a different policy response.
The United States should not impose a blanket prohibition on Americans accessing Chinese-developed open-weight models. Nor should allegations of unlawful model extraction become a general rationale for restricting open-weight AI.
National security concerns surrounding advanced AI are real. Intellectual property theft, export-control evasion, cyber misuse, espionage, military applications, insecure supply chains, and strategic dependence on foreign technology all warrant serious scrutiny.
But categorical restrictions based primarily on where a model was developed or whether its weights are publicly available are the wrong policy instruments.
A durable U.S. framework should ask:
- What can the model actually do?
- Where and how will it be deployed?
- What systems, data, and tools can it access?
- Has its developer engaged in legally actionable misconduct?
- Can the model and its distribution infrastructure be trusted?
- Does reliance on it create strategic dependency?
- What harms could follow from misuse, compromise, or failure?
Where the evidence supports restrictions, the United States should act decisively.
But broadly preventing American researchers, startups, cybersecurity defenders, and developers from accessing models that remain available elsewhere risks producing a double own goal: weakening American defensive capacity while increasing domestic dependence on a small number of proprietary AI providers.
The better strategy is neither technological naïveté nor indiscriminate openness.
It is to regulate provenance, conduct, capability, deployment, and dependency separately—and to apply comparable risk standards to open and closed systems.
Three Problems Are Being Collapsed Into One
The current debate is often described as a dispute over whether the United States should restrict Chinese open-weight AI.
That framing is too simple. Three policy questions are emerging at once.
1. Chinese Models: A Sovereignty and Dependency Question
Chinese developers are releasing increasingly capable models that American companies can download, modify, deploy locally, and use to build commercial products.
This raises legitimate questions about:
- supply-chain integrity;
- embedded vulnerabilities;
- foreign-government influence;
- data security;
- censorship and political control;
- dependence on foreign technical ecosystems;
- use of restricted advanced chips;
- and the possibility that Chinese models could become foundational infrastructure across global markets.
These are provenance and dependency concerns.
They are not resolved simply by determining that a model was developed in China. They require analysis of the specific model, developer, distribution mechanism, deployment, and relationship to sensitive American systems.
A Chinese-developed model running inside a classified federal network is not the same policy object as the same model being studied in an isolated university laboratory.
National origin may justify heightened scrutiny.
It should not end the analysis.
2. Distillation Attacks: A Conduct and Enforcement Question
U.S. officials and AI companies have accused some Chinese developers of using industrial-scale distillation or model-extraction techniques to reproduce capabilities from proprietary American models.
Distillation itself is a longstanding and widely used machine-learning technique. It can be authorized, legitimate, and socially useful. It can also be conducted through deception, access-control evasion, cyber intrusion, theft of protected assets, or other unlawful behavior.
The relevant policy question is therefore not:
Should distillation be prohibited?
It is:
When does model learning or distillation become unauthorized extraction, fraud, theft, circumvention, or another legally actionable form of misconduct?
That is a conduct question.
It should not automatically determine whether the resulting model may be released openly or whether unrelated open-weight developers should face new restrictions.
The legal boundary is not simple.
A company may possess valid user accounts while coordinating access at a scale designed to avoid detection. A laboratory may reverse-engineer model behavior without breaching an express contractual restriction. A provider may describe a competitor’s activity as theft even where the allegedly protected interest is unclear.
None of those facts alone should decide the case. Scale can be evidence of coordination. Intent can be evidence of purpose. Neither should, by itself, transform an otherwise lawful and authorized practice into a crime.
A legal standard that treats intent alone as sufficient would be dangerously expansive. Researchers, competitors, auditors, and developers often act with the express purpose of understanding how a model works. That purpose cannot itself become proof of theft.
Likewise, the use of thousands of accounts may indicate coordinated evasion, but scale alone does not establish which control was evaded, what protected interest was taken, or whether the conduct was unlawful.
Congress should define:
- the protected interest;
- the prohibited act;
- the required mental state;
- the role of deception or concealment;
- the significance of technical and contractual controls;
- the evidentiary threshold;
- and the defenses available to researchers, competitors, and authorized users.
Congress should also specify whether contractual terms alone can create the protected interest, or whether the underlying asset must satisfy additional criteria—for example, whether it constitutes a genuine trade secret protected through reasonable security measures.
Terms of service should not become a unilateral mechanism by which a provider defines unwanted competition as theft.
“Distillation” should not become a catch-all synonym for technical learning, benchmarking, interoperability, research, or competition that an incumbent provider dislikes.
3. Open-Weight Models: An Architecture and Access Question
Open-weight models allow users to download and operate model parameters rather than accessing the model only through a provider-controlled service.
That architecture changes the allocation of control.
It can enable:
- local deployment;
- independent evaluation;
- customization;
- lower-cost experimentation;
- privacy-preserving use;
- security research;
- scientific reproducibility;
- and reduced dependence on a single vendor.
It also creates a real and serious danger.
Once powerful model weights are available offline, no provider can reliably prevent a malicious actor from removing safeguards, modifying behavior, reproducing the model, or deploying it without supervision.
That is not a marginal concern. It is the central tradeoff. The policy question is not whether open weights create risk. They do.
The question is whether that risk is greater than the combined risks of concentrated vendor control, reduced independent scrutiny, limited defensive access, and dependence on a small number of systems whose permissions, availability, and behavior are controlled remotely.
Those risks cannot be resolved through slogans about openness or safety. They require comparative analysis.
The Governing Principle
The United States should begin with a simple distinction:
Provenance is a risk input. Distillation is a conduct question. Openness is a distribution architecture.
Confusing these categories creates bad policy.
An allegation that a Chinese company unlawfully extracted a U.S. model may justify enforcement against that company.
It does not establish that all Chinese models pose the same risk.
It does not establish that open-weight distribution caused the alleged violation.
And it does not establish that Americans should be prohibited from possessing model weights already circulating internationally.
Similarly, a concern that open-weight systems can be misused does not mean that closed systems are safe, controllable, or sufficient for every legitimate purpose.
The policy mechanism should follow the problem.
| Policy concern | Core question | Appropriate response |
| Chinese provenance | Does this model, developer, or dependency create a specific security risk? | Supply-chain review, sensitive-use controls, diversification, and domestic alternatives |
| Unlawful extraction | Did an actor obtain protected capabilities through deception, theft, circumvention, intrusion, or another prohibited method? | Evidence-based, actor-specific enforcement under clearly defined law |
| Dangerous capabilities | What harmful capabilities does the model possess, and what agency can it exercise? | Capability evaluation, deployment controls, security requirements, and incident reporting |
| Open-weight release | Does releasing the weights create an unacceptable marginal risk relative to the defensive, competitive, and public benefits? | Release-specific assessment and proportional safeguards |
| Market concentration | Would the restriction reduce technical diversity or entrench a small number of providers? | Security and competition analysis, interoperability, and support for credible alternatives |
This framework does not presume that every model should remain unrestricted.
It requires government to identify the risk it is addressing and demonstrate that its chosen intervention actually reduces it.
A Blanket Restriction Could Produce a Double Own Goal
Own Goal One: Weakening American Cyber Defense
The recent Hugging Face security incident offers a concrete example of why access policy and security policy cannot be treated as the same thing.
During its response to a major intrusion, Hugging Face reportedly needed AI assistance to examine more than 17,000 logs and related evidence. Its defenders encountered limitations when attempting to use guarded proprietary U.S. systems for parts of the investigation and instead used a Chinese-developed open-weight model on infrastructure they controlled.
The operational challenge was specific.
Cyber defenders may need models to:
- inspect malicious code and payloads;
- reconstruct attack chains;
- identify persistence mechanisms;
- reason about vulnerabilities;
- examine credential theft and lateral movement;
- test proof-of-concept exploits in controlled environments;
- analyze large volumes of forensic logs;
- and reproduce adversarial behavior to understand how to stop it.
Those activities can look similar, at the prompt level, to malicious hacking.
A proprietary safety system that sees a request for exploit analysis but cannot verify the user’s authority, environment, or defensive purpose may refuse exactly the assistance an incident responder requires.
That does not mean safety guardrails are misguided. It means effective cybersecurity requires contextual governance rather than indiscriminate capability denial.
The Hugging Face episode also does not prove that Chinese models are inherently safer. Nor does it establish that open-weight models should escape scrutiny.
Offline access means a malicious actor may be able to remove safeguards, alter the model, and operate without external oversight. That is the tradeoff.
The question is whether the danger created by irreversible offline access is greater or smaller than the danger created by centralized vendor control, limited technical visibility, restricted defensive use, and the possibility that one provider becomes a common point of refusal or failure.
The lesson is not that openness is always safer. It is:
A model can simultaneously create misuse risk and possess defensive value.
Policy must account for both. If an advanced model remains accessible to adversaries abroad while American researchers and defenders are prohibited from using it, the restriction does not eliminate the underlying capability. It changes who is allowed to study it.
That can produce an asymmetry in which adversaries retain access to globally circulating technology while American defenders lose tools needed to understand the threat environment.
Own Goal Two: Increasing Market Concentration—and Security Dependence—at Home
The second own goal may be even more consequential for U.S. economic and security policy.
Open-weight models lower barriers to entry by allowing companies to run systems on their own infrastructure, customize them, fine-tune them, evaluate their behavior, manage sensitive data locally, and avoid depending entirely on metered access to a proprietary provider.
For a well-capitalized company, losing access to a particular open model may be inconvenient.
For a startup built around low-cost inference, local deployment, specialized adaptation, or predictable compute economics, it can threaten the viability of the business.
Nearly 200 companies represented through the Little Tech Association have urged the administration not to impose broad restrictions on Chinese open-weight models. They warn that many smaller American companies rely on lower-cost open alternatives and could be pushed toward more expensive proprietary providers.
This creates a basic competition problem, but market concentration is not merely an economic side issue. It can become a security architecture.
When a small number of vendors control access to advanced models, those vendors also influence:
- which defensive tasks are permitted;
- what system behavior can be independently audited;
- when service may be limited or withdrawn;
- how incidents are disclosed;
- what logs and evidence customers can inspect;
- and whether users can move to an alternative during an outage, refusal, or security failure.
A concentrated market can create common points of refusal, correlated vulnerabilities, and operational dependence. Competition does not override national security.
It can strengthen security when it preserves independent evaluation, technical diversity, substitutability, and multiple defensive options. A defender responding to an incident needs options. If every available system depends on one vendor’s model, and that vendor’s API becomes unreachable, refuses the request, changes its policies, or suffers a compromise, the defender may have no effective alternative.
Technical diversity is defensive capacity. If a restriction removes a class of capable open models from lawful U.S. use while the remaining substitutes are controlled by a small number of large domestic firms, the effect is not merely geopolitical separation.
It is a change in domestic market structure and defensive resilience.
Smaller firms may face:
- higher inference costs;
- greater vendor dependence;
- less ability to customize systems;
- reduced control over deployment;
- exposure to unilateral changes in pricing or terms;
- fewer alternatives when a provider restricts a use case;
- less visibility into model behavior;
- and higher switching costs after products become deeply integrated with a proprietary platform.
The policy could strengthen incumbent AI companies while weakening the downstream startups policymakers say they want to encourage.
It could also reduce the number of independent systems available during a security incident.
American AI leadership is not synonymous with the market share of America’s largest laboratories.
National competitiveness and national resilience also depend on companies building applications, infrastructure, scientific tools, creative products, security systems, and specialized models on top of foundational technology.
A rule that benefits a few national champions while raising costs and reducing options for hundreds or thousands of downstream American firms may improve one measure of industrial advantage while damaging another.
That tradeoff must be treated as a central policy consequence, not as collateral damage.
Independent Access and Local Control Are Security Capabilities
The Hugging Face incident provides a concrete example of the defensive value of a model that an organization can operate and adapt under its own control.
The formation of the Open Secure AI Alliance reflects a broader industry hypothesis that shared models, tools, datasets, and techniques may help strengthen software and AI-agent security.
That announcement is relevant. It is not proof.
The alliance has not yet demonstrated at scale that open security tools consistently outperform vendor-controlled systems, nor has it established that open-weight models are necessary for every defensive task.
Its significance is narrower: major technology and infrastructure companies are treating shared and locally controlled AI capabilities as a serious component of future security strategy.
That proposition should now be tested. The alliance’s work should be evaluated against concrete outcomes, including:
- whether it produces usable defensive tools;
- whether those tools improve vulnerability discovery or incident response;
- whether independent researchers can reproduce results;
- whether the shared models introduce new misuse risks;
- whether participating organizations adopt the tools operationally;
- and whether open approaches outperform or complement controlled vendor access.
The policy argument should not depend on the success of one alliance. It rests on a broader principle:
Independent access, local control, technical visibility, and model diversity are security capabilities. Open-weight systems can provide those capabilities.
Organizations responding to sophisticated attacks may need to:
- process sensitive forensic evidence locally;
- reproduce technical findings;
- inspect or modify model behavior;
- adapt tools to an emerging threat;
- compare results across multiple systems;
- test whether a model is vulnerable to manipulation;
- and continue operating when an outside provider is unavailable or refuses a legitimate request.
Open weights are one way—not the only way—to provide that capacity.
Secure proprietary systems can also support advanced defense when they provide appropriate access, visibility, auditability, and trusted-research pathways.
The policy objective should not be to privilege one architecture categorically.
It should be to preserve the capabilities defenders need.
Some may argue that powerful access can simply be reserved for federal agencies and large defense contractors through private arrangements.
That approach may be appropriate for certain classified or exceptionally dangerous capabilities. It is not a complete solution.
Cyber defense is not performed only by the federal government or a handful of contractors. Universities, independent researchers, startups, hospitals, infrastructure operators, software companies, state and local governments, civil-society organizations, and public institutions all defend systems.
Restricting meaningful access to a narrow group of approved actors would reduce independent scrutiny, concentrate expertise, limit redundancy, and exclude many of the organizations that encounter attacks first.
It would also make the security ecosystem dependent on the willingness and capacity of a small number of providers and government-approved intermediaries.
Transparency, independent evaluation, and plural access are not substitutes for security controls. They are part of the security system.
Government cybersecurity guidance increasingly emphasizes continuous evaluation, threat modeling, lifecycle security, monitoring, trusted infrastructure, and the ability to assess AI systems against evolving threats.
Those functions require organizations to maintain meaningful technical visibility and evaluation capacity rather than depending exclusively on assurances from an outside vendor.
Open and locally controlled systems can support that capacity. They should not be restricted without accounting for the defensive capability being removed.
The relevant policy claim is therefore not:
Open models are always security infrastructure.
It is:
Open and locally controlled AI tools can form part of security infrastructure. Their defensive value and misuse risk should both be evaluated rather than presumed.
Policy Influence Should Trigger Scrutiny Across the Industry
Every company actively shaping AI regulation should be evaluated under the same standard.
That includes Anthropic, OpenAI, NVIDIA, other frontier laboratories, open-model developers, cloud providers, chip companies, cybersecurity firms, and industry coalitions.
Each may hold legitimate public-interest concerns.
Each also operates within a commercial and institutional context that can influence which risks it emphasizes and which remedies it prefers.
The appropriate response is not to presume bad faith.
It is to examine whether a proposed policy:
- addresses the stated risk;
- applies comparable standards to comparable capabilities;
- imposes proportionate compliance burdens;
- preserves legitimate research and competition;
- and disproportionately advantages the architecture or business model of the company proposing it.
Anthropic as a Case Study
Anthropic is a particularly relevant case study because it is a leading frontier-model developer actively shaping federal policy on distillation, export controls, dangerous capabilities, and open-weight release. It also declined to join a major industry coalition organized around open and shared security infrastructure.
Anthropic has described what it characterizes as industrial-scale distillation attacks and has supported stronger action at several technological chokepoints, including advanced chips, model extraction, and testing of highly capable systems.
Dario Amodei has also stated that Anthropic does not support a categorical ban on open-weight models and considers models without dangerous capabilities a public good. His stated concern is that sufficiently powerful open models may create risks that cannot be mitigated after release.
That position should be represented accurately.
At the same time, it should not be accepted uncritically.
Anthropic’s preferred policies could impose burdens that are easier for large closed-model firms to absorb than for startups, universities, researchers, or open-model developers.
This creates an unavoidable governance question. Anthropic may hold sincere security concerns. Sincerity does not eliminate commercial self-interest.
A proprietary provider can genuinely believe that open models create risk while also benefiting from regulations that restrict open competitors.
The same scrutiny should apply to NVIDIA when it argues for open infrastructure, to OpenAI when it advocates rules affecting frontier systems, and to open-model developers when they minimize release risks.
No actor should be permitted to define the public interest solely through its preferred architecture. The relevant tests are:
- Does the proposal regulate dangerous capabilities in open and closed systems comparably?
- Does it distinguish authorized distillation from fraud, theft, circumvention, or cyber intrusion?
- Is the compliance burden proportionate to demonstrated capability and risk?
- Could startups, universities, and open developers realistically comply?
- Would the rule reduce the identified danger or primarily remove substitutes for proprietary services?
- Are closed providers subject to equivalent incident reporting, evaluation, and accountability?
- Does the policy preserve legitimate security research and defensive access?
- Has the government considered effects on price, switching costs, technical diversity, and resilience?
Where a proposal produces asymmetric obligations without a risk-based justification, the concern is not merely hypocrisy.
It is the possibility that regulation is being shaped around the technical architecture and business model of the incumbent firms advocating it.
AI Salon need not adjudicate any company’s intent to identify that danger. The relevant institutional question is:
Are policymakers addressing the underlying risk—or converting the preferences of powerful market actors into rules for the entire ecosystem?
The Core Policy Framework
The United States does need to care where AI systems come from.
Foreign origin can reveal meaningful risks.
But provenance should trigger further analysis, not determine the outcome by itself.
A workable framework should assess at least seven dimensions.
1. Capability
What can the model actually do?
A small model used for document classification should not be governed as though it presents the same threat as a frontier system capable of autonomous vulnerability discovery, sophisticated persuasion, or advanced biological reasoning.
Risk should track demonstrated capability.
2. Deployment Context
Where is the model being used?
A locally isolated research environment is materially different from deployment inside:
- a defense network;
- the electric grid;
- a hospital;
- a financial clearing system;
- federal law-enforcement infrastructure;
- or another high-consequence environment.
The same model can present radically different risks depending on context.
3. Access and Agency
What can the model reach or control?
A model answering prompts offline presents a different risk profile from an agent with:
- persistent credentials;
- code execution;
- external network access;
- financial authority;
- physical-system control;
- autonomous tool use;
- or access to sensitive datasets.
Regulation should account not only for model intelligence, but for the system’s capacity to act.
4. Developer Conduct
Has the developer violated applicable law or engaged in conduct that creates a legitimate basis for targeted action?
Relevant conduct may include:
- intellectual property theft;
- unauthorized model extraction;
- material deception;
- fraudulent account creation;
- coordinated concealment;
- access-control evasion;
- sanctions violations;
- export-control circumvention;
- prohibited military collaboration;
- cyber intrusion;
- or concealment of material security vulnerabilities.
Conduct provides a stronger basis for enforcement than nationality alone.
But intent alone should not establish liability.
A researcher, competitor, or developer may intend to understand or reproduce model behavior without engaging in legally prohibited conduct.
Likewise, scale should be treated as evidence that may support an inference of coordination or evasion, not as an offense by itself.
The legal question should remain tied to a defined protected interest and a prohibited act.
5. Security and Integrity
Can the model and its surrounding infrastructure be trusted technically?
This includes:
- malicious code;
- compromised repositories;
- unsafe dependencies;
- tampered weights;
- insecure update channels;
- hidden network connections;
- undisclosed telemetry;
- vulnerability disclosure;
- and reproducibility or verification.
Open weights do not automatically resolve these concerns.
But neither does a domestic corporate logo.
Technical integrity must be evaluated directly.
6. Supply-Chain and Dependency Risk
Could reliance on the model create strategic leverage for a foreign actor?
A model may be technically safe in isolation while creating strategic exposure if American organizations become dependent on:
- a foreign licensing regime;
- foreign-controlled updates;
- proprietary tooling;
- remote inference infrastructure;
- specialized dependencies;
- or an ecosystem that can be withdrawn, manipulated, or politically conditioned.
This risk deserves separate treatment.
The appropriate response may involve:
- interoperability;
- diversification;
- local deployment;
- provenance disclosures;
- procurement rules;
- portability standards;
- contingency planning;
- and investment in competitive alternatives.
Dependency risk does not always require prohibition.
Often, it requires resilience.
7. Consequence
What happens if the system fails, is compromised, or is deliberately misused?
Regulation should become more stringent as potential consequences increase.
Ordinary commercial experimentation should not be governed in the same manner as systems whose failure could affect national security, critical infrastructure, physical safety, democratic institutions, or large populations.
Together, these dimensions provide a better question than:
Is this model Chinese?
They ask:
What risk does this model create, in this deployment, with this access, under this operator, through this supply chain—and what intervention actually reduces that risk?
That is the question regulation should answer.
What Better Policy Looks Like
A risk-based approach does not mean doing less.
It means matching each intervention to the risk it is designed to reduce.
1. When the Problem Is Unlawful Conduct, Define the Offense and Target the Actor
If a foreign developer steals intellectual property, conducts unauthorized model extraction, violates sanctions, circumvents export controls, or participates in prohibited activity, the United States should respond directly.
Potential tools include:
- entity-specific sanctions;
- export restrictions;
- restrictions on commercial transactions;
- civil or criminal enforcement where jurisdiction permits;
- procurement exclusions;
- financial restrictions;
- coordinated allied action;
- and formal mechanisms for companies to share evidence of model extraction or cyber-enabled theft with government.
But government should define prohibited model extraction precisely rather than treating “distillation” as a synonym for theft.
A workable standard should examine whether an actor:
- obtained access through material deception or concealed coordinated activity;
- circumvented technical or contractual controls designed to prevent extraction;
- knowingly and systematically exceeded the scope of authorization;
- acquired protected weights, confidential information, or nonpublic technical assets;
- used cyber intrusion or another independently unlawful method;
- or conducted extraction through a pattern of behavior that, together with other evidence, demonstrates deliberate evasion of legally protected controls.
Scale and intent should matter as evidence.
They should not, standing alone, make an otherwise authorized technical practice unlawful.
A company’s desire to understand, imitate, or compete with another model cannot itself establish criminal intent.
Nor should the use of a large number of accounts automatically establish theft unless the government can identify the protected interest, the control allegedly evaded, and the legally prohibited act.
The legal framework must distinguish between protected intellectual property and the more general fact that one model can learn from outputs made available to users.
Without that distinction, “model theft” could become an expansive label for ordinary competition, benchmarking, interoperability, research, and authorized distillation.
Congress should specify:
- the protected interest;
- the prohibited conduct;
- the required mental state;
- the role of deception or concealment;
- the significance of technical and contractual controls;
- whether contractual terms alone are sufficient;
- whether the underlying asset must qualify for independent legal protection;
- the evidentiary threshold;
- and the defenses available to researchers, competitors, and authorized users.
Enforcement should not depend solely on a provider retroactively characterizing unwanted competition as unauthorized extraction.
This approach punishes misconduct without converting a dispute over how one model was trained into a general restriction on how unrelated models may be distributed.
2. When the Problem Is Sensitive Deployment, Control the Deployment
Some environments should face stricter rules for foreign AI.
Government systems, defense networks, critical infrastructure, and other high-consequence settings may reasonably require:
- approved-model lists;
- security testing;
- local deployment;
- network isolation;
- data-residency requirements;
- supply-chain review;
- telemetry restrictions;
- provenance documentation;
- software bills of materials;
- and continuous monitoring.
A restriction on a model inside a classified network is analytically different from a prohibition on an American university evaluating the same model in an isolated laboratory.
One governs a sensitive deployment.
The other governs general possession and research.
Those categories should remain distinct.
3. When the Problem Is Dangerous Capability, Regulate Capability and Agency
Models with advanced cyber, biological, autonomous, or other high-consequence capabilities may warrant additional oversight regardless of where they were developed.
Possible measures include:
- standardized capability evaluations;
- pre-deployment testing for high-risk uses;
- incident reporting;
- controlled or staged release;
- security requirements for high-risk model weights;
- limits on autonomous access to critical systems;
- and narrowly defined emergency intervention authorities.
A Chinese model capable of autonomous cyber exploitation should face scrutiny.
So should an American one.
Risk crosses borders and technical architectures more easily than regulatory categories do.
4. When the Problem Is Defensive Access, Create Governed but Distributed Pathways
Dual-use capability creates one of the hardest AI governance problems.
Cybersecurity researchers may need to ask models to perform tasks that resemble malicious behavior because understanding an exploit often requires reproducing or analyzing it.
Policymakers should support mechanisms that distinguish legitimate defensive access from ordinary unrestricted access.
Possible approaches include:
- vetted researcher programs;
- controlled cyber ranges;
- auditable high-capability access;
- trusted incident-response channels;
- organizational verification;
- logging and accountability;
- legal safe harbors for authorized research;
- and specialized model configurations for defensive work.
The goal should not be a blanket exemption from safety.
It should be a governance structure that recognizes:
Defenders cannot defend effectively against capabilities they are institutionally prevented from studying.
Access should not be limited automatically to the largest contractors or incumbent providers.
Large institutions can play an important role, especially in classified environments. But a resilient defense ecosystem also requires universities, startups, independent researchers, public institutions, and infrastructure operators to maintain meaningful evaluation and response capacity.
The Open Secure AI Alliance may provide one venue for developing such mechanisms, but its value should be judged by operational results rather than by the announcement itself.
5. When the Problem Is Foreign Dependency, Build Alternatives and Require Resilience
The strongest answer to dependence on Chinese open-weight AI is not simply to make the technology unavailable to Americans.
It is to ensure that the United States can offer credible alternatives.
U.S. policy should support a competitive domestic open-weight ecosystem through:
- research and development;
- compute access;
- evaluation infrastructure;
- open technical standards;
- secure model-distribution systems;
- public-private research partnerships;
- procurement pathways;
- and markets that allow startups and researchers to build without depending on a handful of proprietary providers.
Organizations operating critical systems should also avoid single-model, single-provider, and single-country dependencies where continuity matters.
That may require:
- interoperability;
- portability;
- redundant model options;
- locally controlled copies;
- continuity planning;
- and migration testing.
Resilience is stronger than prohibition because it reduces dependency without reducing the country’s ability to understand competing technology.
6. When the Problem Is Market Concentration, Apply a Security-and-Competition Test
Every major restriction on open-weight AI should include an assessment of its market and resilience effects.
Policymakers should ask:
- Which firms gain customers if open models are restricted?
- Which startups face higher operating costs?
- Does the rule increase dependence on proprietary APIs?
- Can smaller developers satisfy the proposed compliance burden?
- Does the policy reduce switching options?
- Will users retain the ability to deploy locally?
- Does the rule reduce technical diversity?
- Does it create a common point of refusal or failure?
- Does it make independent security evaluation more difficult?
- Does it create a practical advantage for firms already operating at frontier scale?
National security should not become an exemption from this analysis.
The answer is not that competition matters more than security.
It is that concentrated markets can reduce defensive options.
If one vendor controls deployment, that vendor also controls what security researchers can access, what customers can inspect, and which defensive tasks its systems will perform.
A national-security proposal should therefore be evaluated for both its direct protective effect and its effect on systemic resilience.
A restriction that removes a compromised system may improve security.
A restriction that unnecessarily eliminates independent alternatives may reduce it.
The fact that a rule benefits an American company does not by itself mean it benefits American competitiveness or American security.
Why Timing Matters
This debate is no longer hypothetical.
The administration is considering how to respond to increasingly capable Chinese models, allegations of illicit distillation, and pressure from different parts of the American AI industry.
Congress is also pursuing several approaches, including:
- restrictions on Chinese AI in government environments;
- penalties or sanctions related to model extraction;
- inquiries into Chinese AI and data security;
- export-control enforcement;
- and broader oversight of frontier-model capabilities.
At the same time, major technology companies are publicly organizing in support of open models and shared security infrastructure.
The formation of the Open Secure AI Alliance and the subsequent debate over which frontier developers did or did not join it have made the dispute over open weights more visible.
The policy architecture is being shaped in real time.
The immediate question is not simply whether Washington will ban Chinese models.
It is whether the emerging framework will distinguish among:
- foreign provenance;
- unlawful conduct;
- dangerous capability;
- sensitive deployment;
- open-weight release;
- supply-chain dependency;
- defensive access;
- and domestic market concentration.
Getting those distinctions right now matters because categorical rules tend to become institutional defaults.
A response to one high-profile Chinese model or one alleged distillation campaign could become the template for governing an entire technical architecture.
The distinction between conduct-based enforcement and categorical prohibition may also become politically irreversible.
Once a rule banning Chinese models takes effect, dismantling it—even in light of new evidence—may be framed as weakening national security or being soft on China.
That political asymmetry matters.
It means a temporary response adopted under uncertainty may persist long after the assumptions behind it have changed.
Once companies, procurement systems, compliance structures, and enforcement agencies adapt around such a rule, it may become even more difficult to unwind.
The United States should establish the governing principle before the emergency creates the precedent:
Restrict demonstrated risk with the narrowest mechanism capable of materially reducing it.
The AI Salon Policy Lens
This position is not simply an argument about open-source economics.
It reflects a broader view of how emerging technologies should be governed under uncertainty.
PLAY FIRST: Learn Before Locking In
PLAY FIRST does not mean ignoring risk. It means preserving the institutional capacity to learn before uncertainty is converted into rigid policy.
Open-weight AI presents real unknowns:
- cybersecurity risks;
- defensive applications;
- competitive effects;
- supply-chain dependencies;
- research value;
- and geopolitical consequences.
Those uncertainties make structured experimentation more important, not less. Government should use:
- evaluations;
- pilots;
- sandboxed environments;
- controlled access;
- comparative testing;
- and adaptive thresholds
to determine which risks are real, which interventions work, and where restrictions create unintended consequences.
The Hugging Face incident and the formation of the Open Secure AI Alliance are the kinds of developments adaptive governance must be able to absorb.
A rule designed around the assumption that restricted access always increases security should be reconsidered when evidence shows that legitimate defenders may need flexible, inspectable, and locally controlled access to dual-use capabilities.
Policy should be capable of learning.
CREATE EXCELLENCE: Regulate the Actual Problem
CREATE EXCELLENCE requires fidelity between problem definition and policy mechanism.
- If the problem is intellectual property theft, define and enforce against theft.
- If the problem is access-control evasion, identify and punish the evasion.
- If the problem is export-control circumvention, strengthen export enforcement.
- If the problem is foreign surveillance risk, impose data and network protections.
- If the problem is dangerous autonomous capability, regulate capability and agency.
- If the problem is critical-infrastructure exposure, govern deployment.
- If the problem is strategic dependence, build resilience and alternatives.
- If the problem is market concentration, preserve competition, substitutability, and interoperability.
A nationality-based or architecture-based prohibition may be politically legible. But legibility is not the same as effectiveness.
Excellent policy asks:
Does this intervention reduce the identified risk better than available alternatives—and what new risks does it create?
That standard should apply with particular force to technologies already circulating globally.
GENEROUSLY LEAD: Expand American Capacity
AI leadership should not be measured solely by which country’s largest companies possess the most powerful proprietary models.
Leadership also depends on whether:
- startups can compete;
- researchers can investigate;
- defenders can defend;
- public institutions can build technical capacity;
- developers can choose among interoperable systems;
- and communities can participate without permission from a small number of gatekeepers.
The AI Salon policy framework emphasizes experimentation by independent innovators, knowledge-sharing, open standards, participatory governance, and systems worthy of public trust.
Those commitments matter most when openness becomes difficult.
Generous leadership does not require unconditional access to every technology.
It requires designing governance so legitimate security goals do not unnecessarily concentrate power or reduce the agency of everyone else.
The objective should be a U.S. AI ecosystem capable of examining, evaluating, competing with, securing, and improving upon technologies developed anywhere in the world.
That is a stronger form of leadership than isolation.
Our Position
The United States should reject a blanket prohibition on Chinese-developed open-weight AI models.
It should also reject efforts to turn allegations of model extraction into a general indictment of open-weight AI.
This is not an argument that provenance is irrelevant. It is not an argument that every model should be openly released. It is not an argument that all open systems should be deployable in government, critical infrastructure, or other high-consequence environments. And it is not an argument for leniency toward intellectual property theft, export-control evasion, cyber intrusion, espionage, fraud, or deliberate circumvention.
It is an argument for policy precision.
- Chinese provenance should trigger scrutiny where it creates relevant risk.
- Unlawful extraction should produce targeted consequences supported by evidence and clearly defined law.
- Intent and scale may support an enforcement case, but neither should substitute for identifying a protected interest and prohibited act.
- High-consequence deployments should face rigorous controls.
- Dangerous capabilities should be evaluated and governed regardless of national origin or distribution architecture.
- Strategic dependencies should be reduced through resilience and credible alternatives.
- Cybersecurity defenders and legitimate researchers should have governed pathways to study technologies they may need to defend against.
Those pathways should not be reserved solely for the largest contractors or incumbent model providers.
Open and closed providers should be held to comparable standards when they create comparable risks.
Market plurality, independent evaluation, local control, and substitutability should be recognized as components of security resilience.
A defender responding to an incident needs options.
If every available system runs through one vendor and that vendor’s API is unreachable, compromised, or unwilling to support the requested analysis, the defender has no meaningful alternative.
Technical diversity is defensive capacity.
And the United States should invest aggressively in world-leading American open-weight models and security infrastructure.
What the government should not do is confuse:
- restricting American access with reducing global risk;
- protecting proprietary business models with protecting national security;
- alleged misconduct by particular actors with the risks of an entire technical architecture;
- or national origin with a complete risk assessment.
For models whose weights already circulate internationally, a prohibition may prevent an American startup from building with a model.
- It may prevent an American researcher from evaluating it.
- It may prevent an American defender from using it during an incident.
- It may increase dependence on incumbent proprietary providers.
- It may reduce technical diversity and independent scrutiny.
None of those outcomes necessarily prevents an adversary abroad from possessing the same weights.
That is the central strategic test:
Does the policy make the threat less capable—or merely make Americans less capable of responding to it?
The United States should choose a different path:
Target conduct. Define prohibited extraction precisely. Evaluate capability. Govern dangerous deployment. Secure supply chains. Preserve legitimate research. Protect technical diversity. Build American alternatives. Retain the capacity to learn.
Openness is not the absence of security policy. Openness is a strategic resource that requires better security policy.
The question is not whether Chinese AI deserves special protection. It does not.
The question is whether American AI policy makes Americans more capable—or merely more restricted. We should choose capability.
The AI Salon
We are a community of AI optimists committed to mindfully exploring the power of AI to unlock opportunities for all.