Treasury Secretary Scott Bessent put the legal question on a short fuse on July 21, 2026. Speaking about Chinese artificial-intelligence labs, he said, "You'll see watermarks of our US large language models on many of the Chinese models," and warned that Treasury could impose sanctions for AI-related intellectual-property theft in "the coming days or weeks."[1][2]
That is enough to make a board ask for a sanctions memo, but not enough to answer it. The relevant question is not whether the United States has a general objection to Chinese AI distillation. It is which legal hook can carry which piece of conduct: export-controlled access to a model, dealings with a sanctioned foreign lab, theft of trade secrets, contractual abuse of an API, or a proposed statute that would make model extraction itself a sanctionable act.

The factual pattern also should not be waved away as theater. Anthropic said in June 2026 that a campaign targeting Alibaba used 28.8 million fraudulent exchanges through 25,000 fake accounts over 45 days, and that earlier campaigns involving DeepSeek, Moonshot, and MiniMax involved 16 million exchanges.[3] Those allegations do not, by themselves, prove every element of a criminal trade-secret case or justify every possible sanctions designation. They do explain why agencies are stretching current tools while Congress considers a tool designed for this exact problem.
The Current Toolkit Is Layered, Not Seamless
For legal and compliance teams, the sanctions issue is really a map of overlapping authorities. Each authority reaches a different actor, requires a different factual showing, and creates a different control obligation. The danger is treating them as interchangeable because they all sit under the same national-security headline.
| Tool | What it can plausibly reach | Main weak point |
|---|---|---|
| ECRA/EAR export controls | Release of controlled AI model technology, including the disputed theory that API access can be a release | The BIS theory is new and is being litigated |
| IEEPA blocking sanctions | Foreign persons designated under an existing national emergency authority | Treasury still needs a designation theory tied to an existing executive order or emergency framework |
| Trade-secret criminal enforcement | Improper acquisition, copying, or use of trade secrets under 18 U.S.C. Section 1832 | Fraudulent model queries may not equal theft of secret training data or weights without more |
| Copyright | Potential claims involving protected expression or training materials | AI-generated outputs without meaningful human authorship are not the obvious protected asset |
| Contract and terms of service | API scraping, fake accounts, rate-limit evasion, and prohibited reverse engineering | Private-law claims do not automatically create sanctions or criminal exposure |
| DAAMTA, if enacted | Foreign AI model extraction attacks as an expressly sanctionable category | It is proposed law, not current law |
That map matters because the same engineering event can look different under each regime. A China-based entity using false identities to query a US model may be a contract problem immediately. It may be an export-control problem if the model or access is controlled and the user is unauthorized. It may become a sanctions problem if the counterparty is designated, or if new legislation gives Treasury a tailored designation basis. It becomes a criminal trade-secret matter only if prosecutors can prove the statutory elements, not merely because the conduct feels like taking.
BIS Has Already Moved First
The most consequential existing-authority move is not Treasury's July warning. It is Commerce's June 2026 Is-Informed Letter to Anthropic. According to analysis of the letter, BIS treated certain advanced AI models as controlled technology under the Export Administration Regulations and authorized release only to specified trusted partners. The letter also advanced the theory that API access can constitute a "release" of controlled technology.[4]
That is a large jurisdictional claim. Export controls usually give compliance teams a familiar sequence: classify the item, determine destination, identify end user and end use, screen for restricted parties, and decide whether a license or license exception is available. API-based model access complicates that sequence because the "item" is not a box, the user may be hidden behind account farms, and the technical value may be transferred through repeated outputs rather than a single download.
If BIS's view holds, a model provider cannot treat API access as merely a customer-service or cybersecurity issue. It becomes an export-control access issue. The compliance questions become more concrete: which models are subject to the letter or a future control; which affiliates, contractors, and customers can access them; whether China-based personnel can test, tune, or support them; what logs show about location and identity; and who approves exceptions.
But the word "if" is doing real work. The BIS theory is already being litigated in Legion LegalTech v. United States, No. 1:26-cv-02225 in the District Court for the District of Columbia.[4][5] Until that theory survives judicial review or is codified more directly, counsel should treat it as a serious enforcement signal rather than a settled universal rule that every model query is an export.
Why API Access Is the Hard Part
Traditional export-control analysis is more comfortable when a controlled design file, chip, source code repository, or technical manual moves across a border or is released to a foreign person. Distillation sits awkwardly beside that model. The foreign actor may never receive weights or source code. It may receive a long series of answers that allow it to approximate capability.
That is why the Anthropic allegations are operationally important even where they are not legally dispositive. A few improper prompts are easy to characterize as platform abuse. Millions of exchanges across fake accounts look more like an organized extraction campaign. The volume does not automatically solve the statutory question, but it changes the enforcement posture: agencies and courts are less likely to see the issue as an ordinary consumer breach of terms.
What Treasury Can Do Now, and What DAAMTA Would Add
Treasury does not need DAAMTA to impose sanctions in every conceivable case. Under the International Emergency Economic Powers Act, the executive branch can block property and prohibit transactions when acting under a declared national emergency and an applicable executive order. The practical question is whether the facts fit an existing authority well enough for OFAC to designate a Chinese AI lab, its principals, or supporting entities.
A designation would matter immediately. US persons would generally have to stop dealing with the blocked person, freeze any property or interests in property within US jurisdiction, and avoid facilitation. Non-US companies would reassess secondary exposure, dollar clearing, US-origin services, and contractual covenants. The company that thought it had only an API-abuse problem could suddenly have a sanctions-counterparty problem.
DAAMTA would make that path more explicit. The proposed framework would define an "AI model extraction attack" and authorize, but not require, IEEPA sanctions against foreign persons that conduct such attacks. It also would create a public AI Model Extraction Attackers List.[6] That distinction matters: DAAMTA is not currently an obligation that compliance teams can plug into a policy as enacted law. It is evidence that Congress sees a gap in the current toolkit.
The proposed statute would also reduce the amount of doctrinal improvisation required. Instead of trying to characterize distillation as ordinary IP theft, cyber-enabled misconduct, export diversion, or some combination of those labels, Treasury would have a category built around extraction from AI models. That would not eliminate factual disputes. It would narrow the legal fight over whether the conduct belongs inside the sanctions architecture at all.

Copyright and Trade-Secret Claims Are Less Clean Than the Rhetoric
Calling distillation "AI IP theft" may be politically efficient. It is not a complete legal theory. Copyright, trade-secret law, and contract each have a role, but none automatically captures every extraction campaign.
Copyright is the least obvious fit when the asserted asset is model capability. The Copyright Office's January 2025 report confirmed that AI-generated outputs without meaningful human authorship are not copyrightable.[7] That does not mean copyright is irrelevant to AI disputes. It means the cleanest copyright asset may not be the output produced during a distillation campaign.
There is also an uncomfortable consistency problem. Major AI developers have invoked fair-use defenses in litigation brought by authors and publishers over training data, including disputes involving OpenAI and Anthropic.[7] If those same developers frame downstream distillation as infringement, they need a theory that distinguishes extraction of model capabilities from the ingestion and transformation arguments they use when defending their own training practices. That does not make their distillation concerns frivolous. It does make infringement rhetoric more complicated than some public statements suggest.
Trade-secret law is stronger in one respect and vulnerable in another. Section 1832 reaches theft or misappropriation of trade secrets in appropriate circumstances, and model weights, confidential training methods, system prompts, safety architectures, or proprietary evaluation data may be protectable if the owner takes reasonable secrecy measures. The hard element is improper acquisition. Outputs obtained through standard API calls, even through fraudulent accounts, may not prove that the defendant acquired the secret training data or weights themselves.[7]
The evidence would matter. If an extraction campaign exploited credentials, bypassed technical controls, accessed nonpublic model artifacts, or induced insiders to disclose restricted information, the trade-secret theory changes. If the conduct is only high-volume querying in violation of terms, the case may still be serious, but prosecutors would need more than indignation over copied performance.
Contract Claims Help, but They Do Not Substitute for Public Enforcement
Terms-of-service claims are the most immediate private-law response. They can prohibit fake accounts, credential sharing, scraping, automated querying, reverse engineering, benchmark evasion, model training on outputs, and use by sanctioned or restricted parties. They also create a record: the user accepted a rule, violated it, and continued after controls were deployed.
That record is useful beyond civil litigation. It can support account termination, injunctive relief, damages claims, referrals to law enforcement, and factual submissions to regulators. It also helps show that the company treated model access as controlled, monitored, and conditional rather than as a public faucet.
But contract law is not a sanctions program. A US company cannot block a foreign lab's property by winning a terms-of-service dispute. It cannot create an export license requirement by drafting a stricter acceptable-use policy. Contract is part of the evidentiary and remedial stack, not a replacement for Commerce, Treasury, or the Justice Department.
The Escalation Pressure Is Real, but It Is Not the Legal Test
The diplomatic backdrop explains the pace. Just Security has described the September 2026 US-China AI talks as a timeline that could push the administration either to use sanctions as leverage or to defer escalation.[5] The State Department also reportedly ordered a global warning to allies in April 2026 about alleged Chinese AI theft.[8] Those facts matter because agencies do not enforce in a vacuum.
They should not be mistaken for the legal test. A demarche does not designate a counterparty. A diplomatic deadline does not prove improper acquisition. A national-security speech does not classify a model under the EAR. Legal departments need to track the escalation because it affects timing and risk appetite, but the controls still have to be tied to actual authorities.
What Counsel Should Audit Before Treasury Moves
The practical response is not to wait for a single definitive AI IP theft statute. The current exposure map already crosses export controls, sanctions, cybersecurity, contracts, trade secrets, and legislative monitoring. A useful audit starts with access, not labels.
- Model classification and access: identify which models, tools, weights, APIs, evaluation systems, and technical documentation could fall within current or future export-control treatment.
- Foreign-person and affiliate access: determine whether China-based employees, contractors, customers, resellers, or support teams can reach restricted systems directly or indirectly.
- Counterparty screening: update sanctions, restricted-party, ownership, and beneficial-owner screening for AI labs, cloud intermediaries, research partners, and account clusters.
- API abuse controls: review account creation, identity verification, rate limits, anomaly detection, geolocation signals, payment patterns, credential sharing, and escalation procedures.
- Trade-secret hygiene: document secrecy measures for weights, system prompts, training methods, safety layers, evaluation data, and internal model-development workflows.
- Contract evidence: preserve assent records, acceptable-use terms, logs, notices, suspensions, and communications showing how the user violated access conditions.
- Legislative tracking: monitor DAAMTA's path, including whether it moves through a defense authorization vehicle and whether the final text changes the sanctions trigger.
The board-level message should be equally disciplined. There is a credible enforcement trend. There is alleged conduct at a scale that regulators will take seriously. There is a live BIS theory that could convert model access into an export-control problem. There is a Treasury sanctions threat. There is also no single enacted AI extraction statute that makes every distillation allegation automatically sanctionable, criminal, or infringing.
That is the uncomfortable but usable answer. The United States is building a layered response to Chinese AI distillation, and some layers already have legal force. The wall is not seamless. Until it is, compliance teams should treat unsettled theories as risk signals, current controls as real obligations where they apply, and proposed legislation as a warning about where the law is likely trying to go.
References
- Bessent says U.S. could sanction China over AI model 'theft' - CNBC, July 21, 2026.
- Scott Bessent warns US may sanction China over intellectual property theft tied to AI - The Hill, July 21, 2026.
- Anthropic accuses Alibaba of campaign to extract AI capabilities - CNBC, June 24, 2026.
- Commerce Department Extends Export Controls to Advanced AI Models - MayerBrown, June 2026.
- The Emerging U.S. Response to Adversarial Distillation - Just Security.
- U.S. Vows to Fight Distillation Attacks - Lawfare.
- Is AI distillation by DeepSeek IP theft? - Winston Taylor.
- State Dept orders global warning about alleged China AI theft - CNBC, April 25, 2026.
Comments
Join the discussion with an anonymous comment.