The bill strengthens U.S. defenses and legal tools to protect closed-source AI models and IP—providing federal assistance, definitions, guidance, and export controls—while imposing new compliance burdens and authorities that could chill legitimate research, disrupt international partnerships, and create diplomatic or oversight risks.
Owners and operators of U.S. closed-source AI models (tech workers, model-hosting firms) receive coordinated federal assistance and an interagency process to detect, deter, and respond to model-extraction attacks.
U.S. export controls and an entity-listing/blocking mechanism can prevent identified malicious actors from obtaining U.S. software and components, protecting American AI IP and reducing risk of capability proliferation.
Clearer legal definitions of 'closed-source' models, 'model extraction attacks,' and owner rights reduce legal uncertainty for companies and help enforce intellectual property protections.
U.S. companies—especially small businesses—face increased compliance, reporting, consultation, and potential surveillance burdens, raising costs and diverting resources toward legal and administrative work.
Broad definitions, criminal/civil penalties, and strong blocking authorities risk chilling legitimate research, defensive interoperability testing, and international collaborations by U.S. researchers and engineers.
Naming alleged attackers, imposing export controls, and taking punitive measures could increase diplomatic friction or provoke retaliation, complicating foreign relations and potentially harming U.S. interests abroad.
Based on analysis of 5 sections of legislative text.
Directs State and Commerce to identify and publish foreign actors who steal closed‑source AI models, issue guidance, enable confidential reporting, and permit Entity List additions and IEEPA sanctions.
Creates a federal program for identifying, naming, and responding to foreign actors who carry out “model extraction” attacks that steal capabilities from U.S. closed‑source AI models. It directs the State and Commerce Departments to assess attackers and fraudulent account networks, publish an attackers list and best‑practice guidance, set up confidential information sharing with model owners, and empowers Commerce to add offending entities to the Entity List and the President to impose IEEPA sanctions.
Official title: To prevent foreign adversaries from threatening the national security of the United States by extracting key technical features of closed-source, American-owned artificial intelligence models, and for other purposes.
Introduced April 15, 2026 by Bill Huizenga · Last progress April 15, 2026