No CRS summary available for this bill.
This section expresses the sense of Congress that (1) artificial intelligence (AI) models owned by U.S. private sector companies are essential to U.S. economic and national security interests; (2) many advanced U.S.-owned AI models are closed-source (i.e., not openly shared); (3) unauthorized model extraction attacks (i.e., acquisition of model weights, architectures, and other characteristics) by entities of concern threaten U.S. national security, foreign policy, intellectual property, and economic competitiveness; (4) the U.S. government should work with private owners to identify, punish, and deter such attacks; (5) these attacks provide foreign adversaries a shortcut to advanced AI capabilities; and (6) authorized model training consistent with owners' terms of service is legitimate research distinct from extraction attacks.
This section defines key terms used in the Act, including (1) appropriate congressional committees (i.e., House Foreign Affairs Committee and Senate Banking, Housing, and Urban Affairs Committee); (2) closed-source AI model (i.e., proprietary AI model with restricted access via APIs or terms of service); (3) country of concern (i.e., China including Hong Kong and Macau, Russia, and certain others designated by the Secretary of State); (4) entity of concern (i.e., foreign persons or entities tied to countries of concern or conducting model extraction attacks); (7) fraudulent account network provider (i.e., foreign entities enabling unauthorized access to closed-source AI models, with exceptions for freedom of expression tools); and (11) model extraction attack (i.e., unauthorized querying to replicate or improve another AI model, inferred from querying patterns and excluding compliant training).
This section directs the Secretary of State, in coordination with members of the Operating Committee for Export Policy, to complete within 180 days of enactment an assessment of (1) entities of concern conducting or having conducted model extraction attacks (i.e., illicit attempts to replicate closed-source AI models owned by U.S. entities via repeated queries) against such U.S. models and (2) entities of concern acting as fraudulent account network providers (i.e., providers of fake accounts facilitating such attacks). The assessment must determine involved entities and countries, government assistance provided, attack methods and scale (including fraudulent account roles, office/data center locations, and attempted attacks over the prior two calendar years), detection approaches, economic and national security consequences of prior successful attacks, U.S. government assistance to model owners, and a diplomatic strategy with allies. This section further requires the Secretary of Commerce, in coordination with Operating Committee members, to (1) consult voluntarily with closed-source AI model owners, companies, experts, and others to identify attack patterns and develop best practices; (2) submit to congressional committees within 210 days of enactment an unclassified report (with classified annex option) on the assessment, with annual updates for three years identifying additional entities; (3) conduct routine post-assessment monitoring of attacks, providers, and related changes; and (4) establish a voluntary, confidential information-sharing mechanism with closed-source AI model owners. Finally, this section requires the Secretary of State to maintain and publish on a public State Department website, for up to five years, the "AI Model Extraction Attackers List" of individuals and entities identified in the assessment or routine monitoring as having conducted or directed such attacks in the past year (protecting confidential information).
This section directs the Under Secretary of Commerce for Industry and Security, in coordination with the End-User Review Committee, to determine by majority vote within 210 days of enactment whether to add to the Entity List (i.e., a Bureau of Industry and Security-maintained roster of foreign end users subject to presumptive export license denials) entities identified under section 4(e) as having conducted model extraction attacks or facilitated them via fraudulent account networks after the section 4 assessment (or affiliates with 50% or more aggregate ownership). The section further authorizes the President, acting through the Secretary of State under the International Emergency Economic Powers Act, to block all transactions in property and interests in property of entities of concern identified under sections 4(b)(1) and 4(e) that are in the United States, come within the United States, or are in the possession or control of a U.S. person—subject to exceptions for compliance with the U.N. Headquarters Agreement or other international obligations, humanitarian assistance (including agricultural commodities, food, medicine, medical devices, and related financial transactions or transportation), and U.S. intelligence, law enforcement, or national security activities—with violations subject to civil and criminal penalties under IEEPA section 206(b) and (c).