Timeline

White House memo addresses distillation of US AI models

Citing a February disclosure that Chinese labs had run large-scale extraction campaigns against Claude, the memo directed agencies to share threat intelligence with AI companies rather than impose new restrictions.

  • Government & policy
  • Notable

The White House Office of Science and Technology Policy issued National Security Technology Memorandum 4, “Adversarial Distillation of American AI Models,” accusing foreign actors — the text focused on China — of running “deliberate, industrial-scale campaigns” to copy US frontier AI systems. Signed by OSTP director Michael Kratsios, the memo described “adversarial distillation” as feeding a target model thousands or millions of carefully constructed queries, collecting its responses, and using them to train a cheaper rival model that mimics its behaviour without access to its weights or training data.

The memo acknowledged distillation had legitimate uses — open-weight model releases and authorised customer fine-tuning services both depend on it — and drew a line at unauthorised extraction from systems whose developers had not consented. It said models produced this way “do not replicate the full performance of the original,” even as it warned that adversarial distillation let foreign competitors “release products that appear to perform comparably on select benchmarks at a fraction of the cost” of building a frontier model from scratch, allowing them to sidestep the compute and chip-export barriers the US had built against rival programmes.

Rather than announcing new restrictions, the memo directed federal agencies to share threat intelligence about distillation campaigns with US AI companies, work with them to develop shared defensive best practices, and explore ways to hold foreign actors accountable. It built directly on a disclosure Anthropic had made in February 2026, when the company reported that three Chinese labs — DeepSeek, Moonshot AI and MiniMax — had run extraction campaigns against Claude using roughly 24,000 fraudulent accounts across more than 16 million exchanges. The memo formalised a government response to a problem industry had already been raising, treating model-weight extraction through ordinary API access as a national-security concern alongside more conventional chip and export controls.