Espionage and proliferation
Can model weights, algorithms, chip designs, and research knowledge be secured once they become central strategic assets?
RAND's weights-security analysis defines five attacker tiers and concludes that defending against top-tier state operations may be beyond any private company — which makes security a public problem, not a corporate one.
View on the map → · Open in Browse →
What changed
01
The threat model widened beyond weights: RAND's sequel framework covers algorithmic insights — know-how living in code, documents, and people, which conventional cybersecurity cannot protect — and the distillation literature argues capability can be extracted through model outputs without touching the weights at all, making both export controls and secure-the-weights framings insufficient on their own. Capability theft became official policy terrain, with a White House memorandum and congressional hearings.
Recent thinking
Brass-Gershovich, Steratore, Hurd, Bradley, Friedman & Nevo · RAND · 20 Jul 2026 report
Securing AI Algorithmic InsightsThe authors identify 44 attack vectors across nine categories and propose five cumulative insight security levels (ISLs).
The sequel to RAND's canonical weights-security work: extends the tiered-security framework from weights to algorithmic know-how, which lives in code, documents, and people and so cannot be protected by conventional cybersecurity alone.
Theo Bearman · Institute for AI Policy and Strategy · 18 Mar 2026 report
AI Distillation Attacks: The Case for Targeted Government InterventionDetection without credible enforcement is unlikely to alter adversary incentive.
Frames systematic distillation of US frontier models by Chinese companies as a theft problem labs cannot solve alone, proposing Entity List designations, sanctions, and defensive standards — capability extraction without touching the weights.
Sebastian Elbaum · War on the Rocks · 5 Jun 2026 essay
The Pentagon's AI Edge Is Being Distilled AwayAdversaries do not need to breach the Pentagon's systems: They only need to harvest the logic of the publicly released frontier AI models that underpin them.
Argues strategic AI capability leaks through model outputs via distillation, making both export controls and secure-the-weights framings insufficient; proposes classified fine-tuning ahead of public release.
Additional relevant discussion (2)
Foundational reading (2)
Securing AI Model WeightsNevo et al., RAND · 2024A Playbook for Securing AI Model WeightsRAND · 2024