Topics / topic

Export Controls

5 items across 4 editions · appeared in the last 3 editions in a row. First seen Fri 11 Sep, last seen Tue 15 Sep. Traced across 1 weekly review.

How this story has evolved

From the week in review: the connections, developments and open questions filed under Export Controls, newest week first.

Week of 7–13 September 2026

Connection
Two government agencies, two frontier labs and Beijing all spoke about model extraction within three days

The joint advisory came on 8 September from CISA, NSA and FBI; Google's threat group published the same day; Anthropic's report followed on 10 September; Beijing responded on 9 September; and Amodei's essay of 12 September asks governments to "Crack down on unauthorized distillation by companies in authoritarian countries" and to "Do not sell powerful AI chips or semiconductor manufacturing equipment to China".

Development · Tue 8 Sep, Wed 9 Sep, Thu 10 Sep
Anthropic names seven Chinese labs over illicit distillation and Google reports campaigns exceeding 100 million prompts, two days after a joint US advisory named six firms

On 8 September CISA, NSA and FBI issued joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The advisory says the firms "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024", and says DeepSeek's publicly stated $5.6 million training cost excludes data "acquired through extensive malicious distillation".

Open question
Why does the US agencies' list of Chinese labs not match Anthropic's, and why does Google name none?

Advisory AA26-251A names StepFun; Anthropic's report does not. Anthropic names Xiaomi and SenseTime; the advisory does not. Google reports campaigns "some exceeding 100 million prompts" without naming any company. Neither document states what evidence it drew on or whether the lists were compiled together. Every exchange count, including the 151 million attributed to Alibaba, rests on the reporting company's own telemetry.

Tuesday, 15 September 2026

China's new exit rules take effect, allowing travel bans on citizens who endanger "technological security" harmful

  • China's new Exit and Entry Administration Provisions took effect on Tuesday 15 September 2026. Free Malaysia Today reports the rules target violations of export controls or technology import and export rules that may endanger "industrial or technological security", and were unveiled in July.
  • The News International reports the regulations were formulated by the State Council alongside multiple ministries and empower border and security authorities to impose exit bans, and says individuals who breach technology import and export rules — "particularly engineers and corporate officials operating in sensitive sectors like artificial intelligence (AI) and advanced manufacturing" — face immediate travel restrictions.
  • Free Malaysia Today reports the rules provide for exit bans of six months to three years on citizens who return to China after committing illegal or criminal acts abroad that harm national security or interests, and that foreign nationals may be denied entry for one to five years for false statements in visa applications.
  • Free Malaysia Today reports Taiwan's Mainland Affairs Council deputy head raised concerns about the new "export control" and "technology import-export management" grounds, particularly for Taiwanese tech workers. Neither report cites a case in which the AI-related grounds have been used.

Monday, 14 September 2026

Beijing's foreign and commerce ministries and Global Times reject Amodei's call to keep curbing China's AI Update

  • At a regular briefing in Beijing on Monday 14 September, foreign ministry spokesperson Guo Jiakun said: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one's interest." The AP reports the commerce ministry separately dismissed US allegations as groundless, said distillation is commonly used by many AI companies, and accused the US of pursuing a "monopoly of the AI industry".
  • The AP reports the response follows Amodei's essay, which warned that a "Chinese lead in AI would pose grave danger for the United States and the world" and called for continuing restrictions on sales of cutting-edge AI chips and chipmaking equipment to China.
  • Reuters reports the state-backed Global Times said the essay's true objective was "to attempt to curb China's AI development through technological barriers and regulatory monopolies", and that "this 'silent AI Cold War' is hypocritical and short-sighted", warning that excluding China would "significantly increase the trial-and-error costs and risks of loss of control in global AI development".
  • This is an update: the essay and its chip and distillation proposals were covered in earlier editions, and the Chinese government reaction is the new element. Neither wire reports any change in Chinese policy, and the AP places the exchange ahead of the Trump-Xi meeting on 24 September.

Sunday, 13 September 2026

Amodei ties his pacing plan to blocking China chip sales, a distillation crackdown and model weight security Company claimSingle source

  • Amodei lists three steps to defend the US lead: "Do not sell powerful AI chips or semiconductor manufacturing equipment to China, and crack down on chip smuggling operations and remote access to data centers outside China"; "Crack down on unauthorized distillation by companies in authoritarian countries"; and "Strengthen security at the AI companies and prevent model weight theft."
  • He writes: "If we execute these measures well, I believe they would slow China's progress enough to widen America's lead significantly over the next 3-5 years — the window when AI becomes geopolitically most important."
  • On international agreements he ranks four levels, calling a "speed limit" on recursive self-improvement "analogous to the SALT treaties" and "difficult but just on the edge of being possible", while a full pacing agreement or pause is "unlikely to actually happen any time soon".
  • This is one company chief executive's policy proposal, published on his personal site. No government has endorsed it, and the 3-5 year estimate is his own with no analysis published alongside it.

South Korea's expanded espionage law takes effect, covering leaks of AI and chip technology to any foreign country Single source

  • The revised Criminal Act took effect on Sunday 13 September, broadening espionage offences beyond acts involving North Korea to include all foreign countries. The National Assembly passed the revision on 26 February; it was promulgated on 12 March and took effect after a six-month grace period.
  • The amendment creates a new offence covering espionage for a foreign country or equivalent organisation, carrying a minimum sentence of three years in prison. Existing "enemy state" provisions remain in place.
  • Reuters reports the National Intelligence Service said the amendment would strengthen South Korea's ability to prevent leaks of strategic technologies such as semiconductors, displays, batteries and AI. The report cites the 2025 indictment of five former Samsung Electronics employees accused of transferring DRAM technology to Chinese memory maker CXMT.
  • Asked whether the law targets Beijing, Chinese foreign ministry spokesperson Mao Ning said all countries should safeguard normal investment and business activities of enterprises and provide a fair and non-discriminatory business environment. The report does not say how many cases are expected or how AI technology will be defined in practice.

Friday, 11 September 2026

Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts as US agencies name six Chinese firms over industrial-scale distillation harmful

  • TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
  • The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
  • The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
  • The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.