The Biggest Questions About AI
The map · 4 Power · 4.3 Geopolitics and military power · 4.3.5

Espionage and proliferation

Can model weights, algorithms, chip designs, and research knowledge be secured once they become central strategic assets?

RAND's weights-security analysis defines five attacker tiers and concludes that defending against top-tier state operations may be beyond any private company — which makes security a public problem, not a corporate one.

View on the map → · Open in Browse →

What changed
March–August 2026 · swept August 3, 2026 · editorial review pending
01

The threat model widened beyond weights: RAND's sequel framework covers algorithmic insights — know-how living in code, documents, and people, which conventional cybersecurity cannot protect — and the distillation literature argues capability can be extracted through model outputs without touching the weights at all, making both export controls and secure-the-weights framings insufficient on their own. Capability theft became official policy terrain, with a White House memorandum and congressional hearings.

Recent thinking
3 featured from 5 tracked · March–August 2026 · all 5 chronologically →
Brass-Gershovich, Steratore, Hurd, Bradley, Friedman & Nevo · RAND · 20 Jul 2026 report
Securing AI Algorithmic Insights
The authors identify 44 attack vectors across nine categories and propose five cumulative insight security levels (ISLs).

The sequel to RAND's canonical weights-security work: extends the tiered-security framework from weights to algorithmic know-how, which lives in code, documents, and people and so cannot be protected by conventional cybersecurity alone.

Theo Bearman · Institute for AI Policy and Strategy · 18 Mar 2026 report
AI Distillation Attacks: The Case for Targeted Government Intervention
Detection without credible enforcement is unlikely to alter adversary incentive.

Frames systematic distillation of US frontier models by Chinese companies as a theft problem labs cannot solve alone, proposing Entity List designations, sanctions, and defensive standards — capability extraction without touching the weights.

Sebastian Elbaum · War on the Rocks · 5 Jun 2026 essay
The Pentagon's AI Edge Is Being Distilled Away
Adversaries do not need to breach the Pentagon's systems: They only need to harvest the logic of the publicly released frontier AI models that underpin them.

Argues strategic AI capability leaks through model outputs via distillation, making both export controls and secure-the-weights framings insufficient; proposes classified fine-tuning ahead of public release.

Additional relevant discussion (2)
AI Distillation Attacks: Executive and Congressional Action Can Go Further — Theo Bearman · Institute for AI Policy and Strategy · 12 May 2026
China's Illicit Campaign to Steal and Subvert American AI Technology — Yusuf Mahmood · US House Select Committee on the CCP (testimony) · 16 Apr 2026
Foundational reading (2)Securing AI Model WeightsNevo et al., RAND · 2024A Playbook for Securing AI Model WeightsRAND · 2024
Previous4.3.4 Military integration