Hot Seat
In this new section of the CFT newsletter, we ask experts and industry leaders at the frontlines of US and Chinese AI development for their quick takes to the hot button issues of the day.
This week's guest is Joe Khawam, managing director of legal and AI policy at the Law Reform Institute in Washington, and a former attorney at the US Department of State. His current research focuses include model distillation and the legal ramifications of the controversial practice.
1. Anthropic has accused multiple Chinese AI companies of “industrial scale” distillation campaigns to “steal” the outputs of its Claude models, a couple days after three US agencies including the FBI and the NSA released an advisory about Chinese companies’ alleged distillation campaigns. As a legal expert, what jumps out at you from these latest reports?
Both the three-agency report and the Anthropic report have added a lot of details that weren't previously public. I think there are lots of questions that are going to keep lawyers busy here. There are details here that are potentially legally relevant, but whether they change the analysis under various US statutes, I'm not so sure yet, because it's going to take some time to do that analysis.
On the US side, there were further details on efforts to extract Claude’s reasoning traces (the “chain of thought” reasoning tokens that AI models today use to “think” before generating their final answer). I think that strengthens the argument that [the US] can look at this from a trade secret theft perspective.
That said, most of the literature based on the information up until now had assumed that the strongest criminal theory would be under the Computer Fraud and Abuse Act (a US cybersecurity bill enacted in 1986 that criminalises IT-related fraud involving false identities and unauthorised access). I suspect that's still the case.
2. What is the significance of the timing of these reports, just weeks before a highly anticipated meeting between Chinese president Xi Jinping and US president Donald Trump, as well as AI-related talks between the two countries?
I think the issue is certainly developing quite a bit ahead of the US-China talks coming up this month.
The argument I’ve made before was that strengthening their defences is something that the companies need to be doing. And the US government needs to be working with them to do that.
But that likely is going to be insufficient to deter continued adversarial distillation attacks because of the fact that, for every defence that's erected, a new technique can be developed to get around it.
So in order to actually create deterrence here, there needs to be some sort of measure taken by the US government to create costs for those engaged in these types of distillation campaigns. That's where tools like entity listings and sanctions come in.
But in an ideal world, the US government would engage in quiet diplomacy with the Chinese government to attempt to achieve the result they're seeking without having to resort to these types of measures.
3. What might the US government do to restrict its own companies, such as US cloud providers, from working with these Chinese companies, which are being accused of stealing from leading US AI companies?
Generally, these types of cloud services are not considered an export under US export control law: they're considered to be a service. That's why in the past, the US Bureau of Industry and Security, or BIS, has issued advisory opinions essentially saying that these are services, not exports.
However, there have been recent reports that BIS is drafting a new AI diffusion rule for AI chips. As part of that rule, it may contain a provision regarding cloud services, so it's certainly possible that BIS may take a different position on that issue than they've taken in the past.
How precisely they would do that, I'm not sure. However, it certainly seems like an area that is very ripe for some sort of US government action because it’s a pretty big legal gap in US efforts to constrain the compute (computing power provided by semiconductor chips) provided to Chinese AI model developers.
|