The Deterring American AI Model Theft Act of 2026 (DAAMTA, H.R. 8283) has advanced through the House Foreign Affairs Committee with unanimous support, but legal analysts say the bill needs key amendments to shut down large-scale AI model theft without entangling legitimate research. The legislation targets adversarial AI distillation-the systematic extraction of frontier model capabilities to train competing systems-which raises national security concerns including military exploitation and the stripping of safety guardrails. As drafted, however, the bill's broad definitions and reliance on private agreements create enforceability and due process risks that could weaken its impact.
Narrowing the definition of model extraction
DAAMTA defines prohibited conduct largely by referencing violations of a company's terms of service. Those agreements are private contracts, not public law, and they change frequently while routinely prohibiting activity that poses no real security threat. Congress should instead anchor the offense to intentional account fraud combined with systematic efforts to extract model capabilities. Federal sanctions should not hinge on the shifting text of a user agreement.
Strengthening evidentiary requirements for public designations
The bill proposes a public AI Model Extraction Attackers List, but designations would likely rely on disclosures from AI companies rather than independently verified evidence. Classified intelligence may support the findings, yet a public list built on opaque evidence creates due process problems, risks harming wrongly identified organizations, and invites international legal challenges. Lawmakers should require a public summary of the evidentiary basis for each designation, even while protecting classified sources and methods. Without such a requirement, the list could become a legal liability.
Protecting open-source development and security research
Although the current draft applies only to closed-source AI models, political pressure has a history of pushing legislative frameworks beyond their original targets. To prevent mission creep, Congress should add explicit statutory safe harbors for open-source development, academic research, and legitimate security testing. Clear carve-outs would keep the law from chilling the very research that hardens AI systems against theft.
Clarifying how government AI development fits within the framework
The Department of Defense's 2026 AI strategy directs procurement of models "free from usage policy constraints that may limit lawful military applications." Recent research found that commercial models refuse up to 98 percent of operationally relevant military queries, which creates institutional pressure to train around those restrictions. The distillation the government conducts on lawfully procured or licensed models differs categorically from the fraudulent extraction DAAMTA targets, and the bill should make that distinction explicit. The executive branch should also publicly explain how its own AI development complies with the standards the law would establish.
Beyond the bill: technical and international measures
The federal government should invest in stronger technical defenses. NIST, working with the Commerce Department's Center for AI Standards and Innovation, should develop standards for detecting model extraction, limiting abusive API activity, and supporting forensic attribution. The United States should also work with allies-the United Kingdom, Japan, Canada, and France-to establish common norms against state-backed AI model theft. Because adversarial distillation can route through almost any jurisdiction, coordinated action would extend U.S. policy's reach and raise the cost of state-sponsored theft beyond U.S. sanctions alone.
Most critically, policymakers must regulate harmful conduct, not the underlying technique. Knowledge distillation is a standard tool used throughout AI research and development. The problem is not distillation itself but fraudulent account creation, deliberate evasion of access controls, and industrial-scale extraction on behalf of strategic competitors. Keeping that distinction clear protects both security and innovation.
Why this matters for legal professionals
The proposed fixes highlight how seemingly technical AI legislation raises core legal issues: the limits of private contract-based enforcement, due process in public designations, and the need for clear statutory safe harbors. Attorneys advising AI developers, government agencies, or companies covered by the law will need to understand these nuances. AI for Legal Professionals Courses provide the grounding to navigate this shifting terrain. Government counsels and policymakers, meanwhile, may benefit from resources like AI for Government Courses to align agency practices with emerging legal standards.
Your membership also unlocks: