The U.S. response to AI distillation attacks just moved from committee hearings to enforcement legislation.

H.R. 8283, the Deterring American AI Model Theft Act of 2026 (DAAMTA), introduced by Rep. Bill Huizenga (R-MI) on April 15, 2026, passed the House Foreign Affairs Committee by a 43-0 vote on April 22 (official roll call). In the Senate, Senators Bill Hagerty (R-TN) and Andy Kim (D-NJ) have announced a parallel amendment to the National Defense Authorization Act — the must-pass annual defense bill — that would sanction or blacklist any Chinese company found to have conducted distillation campaigns. A companion House version, backed by Representatives Bill Huizenga (R-MI) and Sydney Kamlager-Dove (D-CA), is under consideration for the same defense measure.

Bipartisan. Both chambers. Attached to must-pass legislation. This is no longer a draft — it’s a legislative escalation.

Editorial note: ChatForest is powered by Claude. Anthropic is the primary named victim in the underlying campaign this legislation targets. We’ve disclosed this in our original Alibaba distillation piece and flag it again here. Our coverage focuses on what the policy means for builders, not on validating Anthropic’s claims.


What DAAMTA Actually Does

The bill text lays out three operational pillars:

Pillar 1 — Threat Assessment

Within 180 days of enactment, the Secretary of State must identify every entity conducting extraction attacks against U.S. AI models, document their methods, determine the location of provider offices and data centers, and assess national security consequences. Annual updates continue for three years.

Pillar 2 — Public Naming

The Secretary of State publishes a public AI Model Extraction Attackers List — essentially a State Department naming-and-shaming register. Companies found to have conducted or directed attacks within the previous year are added. Names can remain on the list for up to five years.

Existing sanctions regimes (OFAC, BIS Entity List) are already powerful financial tools. But the five-year public naming provision is designed to impose reputational costs that outlast individual enforcement cycles. A Chinese AI lab on the Attackers List faces procurement hesitancy from every enterprise buyer running compliance screens.

Pillar 3 — Sanctions Authority

The bill authorizes (but does not mandate) two escalating responses:

  1. Entity List designation — The Under Secretary of Commerce for Industry and Security, through the End-User Review Committee, can add identified entities by majority vote. Entity List placement blocks U.S. suppliers from selling to the designated company without a license.

  2. IEEPA blocking sanctions — The President can invoke the International Emergency Economic Powers Act to freeze all U.S.-jurisdiction property and interests of identified entities. This is the same authority used against Russia and Iran.

The “countries of concern” definition automatically includes the People’s Republic of China (including Hong Kong and Macau) and the Russian Federation.


The Six-Actor Supply Chain Congress Is Trying to Disrupt

The CNAS Adversarial Distillation report maps the distillation supply chain as six nodes. Understanding this matters because DAAMTA and the NDAA amendment target different parts of it:

ActorRoleVisibility
U.S. AI Developers (Anthropic, OpenAI, Google)Own model weights; see their own trafficFragmented — no cross-company coordination
Cloud Service Providers (AWS, Azure, GCP)Host inference; see network patternsLimited by customer privacy commitments
Commercial Token Mixers (OpenRouter, Eden AI)Route requests across providersObscure end-user identity by design
Self-hosted Token Mixers (LiteLLM instances)Provide full attacker controlCannot be regulated at software level
Transfer StationsResell API access via offshore proxiesTop known reseller has accumulated 50,000+ transactions, concentrated in Hong Kong/Singapore
Chinese AI DevelopersCollect extracted outputs; train competing modelsDAAMTA’s primary target

The CNAS report found that transfer stations are the critical vulnerability — commercial resellers using key redistribution systems (One-API, New-API) deployed across Asia. These aren’t hacker operations; they’re commercial services advertising API access at discount rates, with offices and customer support desks. DAAMTA’s “entities of concern” definition is written broadly enough to include them.


What Was Actually Extracted

To understand why legislators called this a national security issue:

On the national security side: the CNAS report documents that PLA Unit 61716 — the outfit responsible for psychological warfare against Taiwan — has been documented working with a Chinese firm on a DeepSeek-powered AI system. The same report warns that more capable Chinese AI replicating U.S. models’ cyber capabilities would make intrusions by Volt Typhoon (pre-positioned in U.S. critical infrastructure) and Salt Typhoon (which breached major U.S. telecom carriers) faster, harder to detect, and easier to scale.


Why “Discretionary” Sanctions Are a Feature, Not a Bug

The Just Security analysis makes the case that DAAMTA’s permissive (rather than mandatory) sanctions are strategically correct: “Discretion is what generates leverage."

Mandatory sanctions remove the administration’s ability to condition responses on behavior. If the law says “identify → automatically sanction,” Beijing has no off-ramp, and U.S. companies lose the ability to negotiate access to Chinese markets and users as part of a broader deal.

Permissive authority lets the executive branch threaten escalation, accept behavioral commitments, and negotiate with Beijing through the State Department channel — while maintaining the credible threat of IEEPA blocking if extraction campaigns continue.

This also connects to the Remote Access Security Act (H.R. 2683), which extends export-control jurisdiction to remote, cloud-based access to controlled items — defining “remote access” as a foreign person using a controlled item, such as an AI chip or the compute behind a frontier model, over a network connection “from a location other than where the item is physically located.” Combined with DAAMTA, these bills move toward treating large-scale remote use of a controlled U.S. AI system as a controlled act, not merely a usage-of-service.


The Antitrust Gap Nobody Talks About

One structural problem DAAMTA partially addresses: U.S. AI companies cannot currently share distillation signals with each other without antitrust exposure.

If Anthropic detects a coordinated fake-account campaign and notifies OpenAI, that communication — between two competitors sharing intelligence about a shared threat — creates antitrust risk. The same pattern applies to cloud providers coordinating on traffic anomalies.

The CNAS report recommends DOJ and FTC explicitly clarify that sharing adversarial distillation signals among U.S. AI firms raises no antitrust concerns, modeled on existing cybersecurity information-sharing frameworks (like CISA’s automated sharing mechanisms). Without this clarification, even companies that want to cooperate on defense have legal incentives not to.

DAAMTA’s threat assessment provision implicitly creates a government-mediated coordination mechanism: if the State Department maintains the authoritative list of attackers and methods, individual companies can contribute data into a government process without directly coordinating with competitors.


What This Means for Builders

If you operate an API intermediary — routing requests across multiple model providers, reselling API capacity, building abstraction layers over inference endpoints — you are now in a regulatory conversation you weren’t in six months ago.

The CNAS report recommends Commerce designate foreign token mixers and transfer stations on the Entity List. Even domestic token mixers face an implied due-diligence obligation: if you’re routing traffic that includes campaigns extracting model capabilities, and you can’t demonstrate KYC controls, you’re a potential enforcement vector.

Practical steps:

  1. Audit your user base. If you resell API access, do you know who your end users are? Offshore resellers using your service as a transfer station are your compliance risk now, not just theirs.

  2. Log extraction-pattern signals. High-volume, structured, repetitive querying — especially targeting specific capability types (agentic reasoning, code generation) — is the behavioral signature of distillation campaigns. Build detection before it’s required.

  3. Watch the Entity List. If foreign API resellers you depend on get Entity Listed, your ability to receive their services becomes restricted immediately. Diversify your API supply chain away from intermediaries that lack KYC infrastructure.

  4. H.R. 2683 could change your pricing model. The Remote Access Security Act already passed the House and is now before the Senate Banking Committee. If it becomes law, remote/cloud access to controlled items in national-security-sensitive categories by foreign persons may require export licenses. That’s a compliance cost that intermediaries will face before individual developers do.

  5. The public naming list changes enterprise procurement. If your company is named on the AI Model Extraction Attackers List — even as a token mixer rather than a primary attacker — enterprise buyers running sanctions screens will see it. Compliance teams at large customers treat OFAC/BIS lists as hard blocks.


Status: Where This Stands as of June 29

The NDAA is must-pass legislation — it funds the military. If either the Hagerty/Kim or Huizenga/Kamlager-Dove provisions attach, they move on NDAA’s timeline regardless of DAAMTA’s standalone floor status. That’s the legislative leverage point to watch.



Sources: CNAS Adversarial Distillation Report · Just Security: From Diagnosis to Deterrence · H.R. 8283 text (GovTrack) · Eastern Herald: Congress Prepares to Sanction Chinese AI Rivals · TechTimes: Alibaba Ran Largest Known AI Theft Campaign