AI Policy Wiki
Dashboard

OSTP NSTM-4: Adversarial Distillation of American AI Models

high confidence · updated 2026-06-06

White House Office of Science and Technology Policy memorandum (NSTM-4), signed April 23, 2026 by Director Michael Kratsios. Directs the federal government to share information with US AI companies on foreign attempts at unauthorized industrial-scale distillation of American AI models, support private-sector coordination, develop best-practices with industry, and explore measures to hold foreign actors accountable.

NSTM-4 is a two-page memorandum issued on April 23, 2026 by the White House Office of Science and Technology Policy (OSTP), signed by Michael J. Kratsios, Assistant to the President for Science and Technology and OSTP Director, and addressed to the heads of executive departments and agencies. It directs the federal government to coordinate with US AI companies against what OSTP characterizes as deliberate, industrial-scale foreign campaigns to distill US frontier AI models. The memo frames itself as consistent with America's AI Action Plan.

Issuer: Executive Office of the President, Office of Science and Technology Policy From: Michael J. Kratsios, Assistant to the President for Science and Technology, Director, OSTP To: Heads of Executive Departments and Agencies Issued: April 23, 2026

Assertions

OSTP states that the US government has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill US frontier AI systems. According to the memo, these campaigns use tens of thousands of proxy accounts to evade detection and jailbreaking techniques to expose proprietary information, and they "systematically extract capabilities" from American AI models.

The memo highlights two consequences. The first is capability replication: derivative models that "appear to perform comparably on select benchmarks at a fraction of the cost" of training original frontier systems. The second is that the same campaigns "deliberately strip security protocols from the resulting models and undo mechanisms that ensure that AI models are ideologically neutral and truth-seeking." This second point connects adversarial distillation to broader US concerns about non-US AI deployment, not only intellectual-property theft.

Directed actions

The memo commits the administration to four actions:

  1. Share information with US AI companies concerning foreign attempts at unauthorized, industrial-scale distillation, including tactics employed and actors involved.
  2. Enable the private sector to better coordinate against such attacks.
  3. Develop best practices with industry to identify, mitigate, and remediate industrial-scale distillation activities and build defenses.
  4. Explore a range of measures to hold foreign actors accountable for industrial-scale distillation campaigns.

Definitional distinction

OSTP distinguishes legitimate distillation from industrial distillation activities. It describes legitimate distillation — producing smaller, lighter-weight models from more advanced systems — as "a vital part of [the US AI] ecosystem," underlying the open-source frameworks and open-weight models the US explicitly supports. It contrasts this with industrial distillation activities that "aim to systematically undermine American research and development and access proprietary information," which it labels "unacceptable." The line is drawn at purpose and method, and the memo reaffirms support for open-source and open-weight ecosystems.

On openness, the memo states: "There is nothing innovative about systematically extracting and copying the innovations of American industry, and there is nothing open about supposedly open models that are derived from acts of malicious exploitation." It positions the US as a champion of AI openness while reframing adversarially-distilled non-US open models as not-actually-open derivatives; the unstated but implicit referents include DeepSeek and Qwen-derived systems.

On forward posture, the memo states: "Consistent with America's AI Action Plan, the United States will continue to foster a vibrant open-source ecosystem built on firm foundations, support American industry in making frontier AI broadly accessible to users worldwide, and safeguard the free and fair market competition that enables the broad and beneficial diffusion of these technologies."

Context and reception

NSTM-4 is the first formal federal characterization of adversarial distillation as a national-security concern requiring a coordinated federal-private response. It extends CISA-style threat-intelligence sharing into the AI domain, with the federal government committing to share tactics and actor identification with US AI companies, and it provides policy footing for US AI labs to deploy more aggressive API rate-limiting, know-your-customer requirements, and coordinated counter-distillation defenses without regulatory friction.

The memo does not name a specific case, but its capability-replication language tracks the DeepSeek case: DeepSeek's January 2025 release performed comparably to US frontier models at a fraction of reported training cost and was widely reported to involve distillation. NSTM-4 is plausibly the formal federal response to that and subsequent cases. It coincided with a same-week State Department cable directing global posts to spotlight alleged Chinese IP theft via DeepSeek, and with the April 24, 2026 launch of DeepSeek V4, which some commentators framed as evidence supporting NSTM-4's allegations.

No supporting evidence is declassified or made public with the memo; the assertion of "tens of thousands of proxy accounts" and the attribution to "principally China" are not accompanied by published evidence. The memo commits to no specific accountability measures, stating instead that the administration will "explore a range of measures." It creates no new legal authority, operating within existing executive-branch authority for information-sharing, industry coordination, and best-practice development.

Relationships