On July 21, 2026, the Treasury Secretary described a machine learning technique in the language of the criminal code.
"There's a very technical AI word for it called distillation," Scott Bessent said on Fox Business, "but you and I would call it theft." He went on to explain the scale of the concern: foreign labs generate "hundreds of millions of hits" against American models, then "try to reconstruct their code and their thought process." His conclusion was blunt. If the administration finds that overseas models were built on stolen material, "we have the ability to sanction them because of this theft."
That is a serious statement from a serious office. It is also a statement that skips over an unresolved question at the center of American intellectual property law, which is whether distillation is theft of anything a court currently recognizes as property.
For lawyers, the interesting part is not the geopolitics. It is that a cabinet secretary just signaled the government intends to resolve an open IP question using a tool that does not require an IP ruling at all. And that shift has practical consequences for any firm whose technology stack now includes a model it did not choose and cannot name.
What distillation actually does
Start with the mechanics, because the legal analysis depends entirely on them.
A large language model does not simply produce the next word. At every position it computes a probability distribution across its entire vocabulary, then samples one token from that distribution. The visible output is the last inch of a very long calculation.
Distillation trains a smaller "student" model on the teacher's full probability judgments rather than on the finished text alone. Knowing that "kitten" was nearly selected while "carburetor" was never in contention tells the student something the finished sentence never reveals. It tells the student how the teacher relates ideas to one another. Geoffrey Hinton, who pioneered the method, called this hidden layer "dark knowledge."
Two API features make this practical against a competitor. The first is the logprobs parameter, which returns the log probabilities of the most likely tokens at each position. The second is logit bias, which lets a caller nudge specific tokens up or down before sampling. Used together, a determined party can promote buried tokens until they surface into the visible ranking, then read off far more of the distribution than the provider intended to expose. Several providers have restricted or removed these features over the past two years for exactly this reason.
This is not a fringe allegation. In February 2026, Anthropic published findings that three Chinese laboratories generated more than sixteen million exchanges with Claude through roughly twenty four thousand fraudulent accounts, in violation of its terms of service and its regional access restrictions. In June 2026, Anthropic wrote to the Senate Banking Committee alleging a larger campaign involving approximately 28.8 million exchanges. OpenAI has described comparable activity, and Google's threat intelligence group reported disrupting extraction attempts against Gemini's reasoning traces.
Note what those allegations are actually made of: fraudulent accounts, evasion of regional restrictions, and volume. Hold that thought.
"Theft" is a word with a legal meaning
Run the conduct through the four doctrines a plaintiff would actually plead.
Copyright is the weakest claim available
Copyright protects original works of human authorship. It does not protect ideas, procedures, processes, systems, or methods of operation. 17 U.S.C. § 102(b) (2018).
Both halves of that sentence cut against a distillation claim. The training material at issue is the teacher's own generated output, and the D.C. Circuit has held that the Copyright Act "requires all work to be authored in the first instance by a human." Thaler v. Perlmutter, 130 F.4th 1039, 1041 (D.C. Cir. 2025), cert. denied, No. 25-449 (U.S. Mar. 2, 2026). Model output produced without meaningful human expressive contribution is unlikely to clear that bar. And several major providers assign output rights to the user by contract anyway, which leaves the provider without the ownership interest a claim would require.
The second half is worse for the claim. What a student model acquires is not expression. It is a behavioral pattern, a way of relating concepts. Courts have long declined to extend copyright to functional structure of that kind. See Lotus Dev. Corp. v. Borland Int'l, Inc., 49 F.3d 807, 815 (1st Cir. 1995), aff'd by an equally divided Court, 516 U.S. 233 (1996). And in Google LLC v. Oracle America, Inc., 593 U.S. 1 (2021), the Supreme Court found fair use where a competitor copied declaring code to build an interoperable platform.
There is contrary authority worth watching. In Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., 765 F. Supp. 3d 382 (D. Del. 2025), the court rejected a fair use defense where a startup trained a competing legal research tool on Westlaw headnotes. But that case turned on human authored headnotes, and the court expressly noted the defendant's system was not generative. The Third Circuit heard the interlocutory appeal in June 2026. Until it rules, the doctrine sits unsettled.
Trade secret is stronger and considerably harder
The better theory is misappropriation. A model's weights, architecture, and training methodology are classic trade secrets, and the Defend Trade Secrets Act reaches conduct abroad where "an act in furtherance of the offense was committed in the United States." 18 U.S.C. § 1837 (2018). The Seventh Circuit read that provision broadly in Motorola Solutions, Inc. v. Hytera Communications Corp., 108 F.4th 458 (7th Cir. 2024), holding that domestic marketing of a product built on misappropriated secrets was itself an act in furtherance.
Verification note: The first page of the Motorola reporter citation rests on a single secondary source. Verify against the slip opinion before use in any filing.
Ohio practitioners have a parallel state vehicle in the Ohio Uniform Trade Secrets Act, Ohio Rev. Code Ann. § 1333.61 to .69 (West 2026).
The obstacle is proof. Trade secret law protects against acquisition by improper means. It does not protect against reverse engineering or independent derivation. A provider that voluntarily publishes token probabilities through a documented API parameter, to paying customers, has a genuine problem establishing that reading those probabilities was improper. The provider's stronger facts are the fraudulent accounts and the deliberate evasion of geographic controls, not the distillation itself.
Contract is the claim that actually fits
Every frontier provider prohibits using outputs to train competing models. That is a clean contractual prohibition, breached by conduct the providers say they have documented.
The difficulties are practical rather than doctrinal. Contract binds parties. Where access runs through fraudulent accounts, proxy networks, intermediaries, and offshore entities, establishing privity and attribution becomes an evidentiary project. Damages for a breach of terms of service are difficult to quantify against the value of a competing model. And a favorable American judgment against a Chinese laboratory with no meaningful domestic assets is a piece of paper.
The claim nobody is discussing
The most doctrinally comfortable federal theory on these facts may be the Computer Fraud and Abuse Act, 18 U.S.C. § 1030. After Van Buren v. United States, 593 U.S. 374 (2021), the statute turns on whether the defendant accessed areas of a system placed off limits, a gates up or gates down inquiry. Scraping data one is authorized to see does not qualify. See hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022).
But fraudulent account creation to defeat a regional access block is not a scraping case. It is an access case. That is the same fact pattern the providers have already described in public.
Why Treasury reached past the courts
Now the reason the Secretary's framing matters.
Sanctions do not require any court to decide whether distillation is infringement. The Protecting American Intellectual Property Act of 2022, 50 U.S.C. § 1709, authorizes designation of foreign persons who knowingly engage in significant trade secret theft that poses a significant threat to United States national security, foreign policy, or economic health. Executive Order 13,694, 3 C.F.R. 297 (2016), issued under the International Emergency Economic Powers Act, 50 U.S.C. §§ 1701 to 1706, separately authorizes sanctions for malicious cyber enabled activity that includes the theft or use of misappropriated trade secrets for commercial advantage.
Those authorities are no longer theoretical. In February 2026, the State Department and the Office of Foreign Assets Control used PAIPA together with Executive Order 13,694 for the first time, designating a Russia based zero day exploit broker and affiliated entities for trade secret theft.
The doctrinal significance is easy to miss. A designation is an executive determination, not an adjudication. The evidentiary standard is not the standard a plaintiff carries at summary judgment. There is no fair use defense, no privity requirement, and no need to prove damages. The government can act on the same record that would leave a private plaintiff struggling for a viable count.
That is why the Secretary's language matters more than it might appear. He did not say infringement. He said theft. Under PAIPA, that word is the operative one.
The asymmetry in the room
There is an obvious tension, and any honest treatment has to name it.
The American laboratories asserting that their intellectual property was taken without permission are simultaneously defending a wave of litigation alleging that they took intellectual property without permission. The count depends on whose tracker you read. One widely circulated figure puts it at 117 cases.
Verification note: The 117 figure originates with a single commentator and is not independently corroborated.
The Copyright Alliance reported more than seventy copyright specific suits as of early 2026, while litigation trackers monitoring the broader AI docket, including privacy, defamation, and right of publicity claims, count between 125 and 189 matters. Whatever the number, the direction is unambiguous.
The defense in those cases is that training on protected works is transformative, that models learn statistical patterns rather than reproduce expression, and that the resulting system is a new thing. That defense, if it prevails, is close to the argument a distiller would make.
There is a real distinction available, and it is worth stating fairly. The frontier labs are not merely alleging that someone learned from their output. They are alleging fraudulent account creation, deliberate circumvention of geographic access controls, and breach of an express contractual prohibition. Reading a public web page is not the same act as manufacturing twenty four thousand fake identities to defeat a country level block.
That distinction may well be correct. It is also a distinction grounded in contract, fraud, and computer access law, not in copyright. Which returns us to the point: the strongest legal theory here is not the one the word "theft" implies.
What this means for your firm
Here is where the abstraction ends and the practice management question begins.
Most lawyers assume this debate happens somewhere above them, among laboratories and cabinet secretaries. It does not. It has already reached the tooling on your desk.
Chinese open weight models now carry a substantial and growing share of American enterprise inference. CNBC reported in July 2026 that Chinese origin models had held at least thirty percent of United States enterprise token volume on OpenRouter every week since February, peaking near forty six percent, against roughly four and a half percent in the first half of 2025. Later reporting placed the figure higher still.
Verification note: Reports of a fifty eight to sixty three percent share trace to a single dataset republished by multiple outlets. Treat the precise number as unsettled.
The driver is cost. Open source Chinese models run sixty to ninety percent cheaper than comparable American offerings, and firms under budget pressure route accordingly.
Legal technology vendors face the same economics you do. Many route inference across multiple providers and reserve the right to change models without notice. Unless your agreement says otherwise, the model behind your document summarizer may have changed last quarter and you would not know.
Five consequences follow.
Model provenance is now a diligence item, not a technical footnote.
Ask your vendors which foundation models process your matter data, whether that list can change without notice, and whether you get advance notice when it does. Get the answer in the contract, not the sales call.
Sanctions compliance is a live risk, not a policy preference.
An OFAC designation blocks property interests and generally prohibits United States persons from transacting with the designated party. If a Chinese laboratory is designated and your vendor routes to its hosted API, you have a compliance exposure that does not care whether you knew. Contractual notice rights are the control that makes this manageable.
Deployment mode governs the confidentiality analysis.
Self hosted open weights running inside infrastructure you control send nothing back to the developer. Calling a China hosted API is a different act entirely, and may place client data within reach of the PRC National Intelligence Law. Those are not the same decision, and lumping them together produces bad policy in both directions.
Ohio's ethics rules already cover this.
Rule 1.1 requires competence, which Comment 8 extends to the benefits and risks of relevant technology. Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. Rules 5.1 and 5.3 impose supervisory duties over lawyers and nonlawyer assistance alike, and ABA Formal Opinion 512 (2024) reads that obligation to cover generative AI tools. None of these rules require you to know how distillation works. All of them require you to know where client data goes.
Disclosure is coming.
Secretary Bessent raised the question of whether American companies should have to disclose their use of Chinese models. Congressional committees have already sent inquiry letters to specific companies. If a disclosure regime arrives, the firms that can answer will be the ones that built an inventory before they were asked.
The competence question underneath
There is a version of this story that is about great power competition, and a version that is about intellectual property doctrine. Both are real, and both are being argued by people well above our pay grade.
The version that belongs to practicing lawyers is smaller and more immediate. It is that a governance question we have been treating as optional is about to become mandatory, and the firms that will handle it well are the ones that already know what is in their stack.
That is not a technology problem. It is a supervision problem, and supervision has always been our job. The tools changed. Rule 5.3 did not.
If you cannot presently name the foundation models that touch your client files, that is the assignment. Start there.
The COUNSEL framework, which operationalizes ABA Formal Opinion 512, exists to make that inventory a repeatable process rather than a fire drill. If you want the model provenance checklist we use at Mishak Law, reach out through LegalTek.ai and we will send it.
Appendix A: Authorities Cited
Statutes and regulations
- Computer Fraud and Abuse Act, 18 U.S.C. § 1030 (2018).
- Copyright Act, 17 U.S.C. §§ 102(b), 107 (2018).
- Defend Trade Secrets Act, 18 U.S.C. §§ 1836, 1837, 1839 (2018).
- Exec. Order No. 13,694, 3 C.F.R. 297 (2016), as amended by Exec. Order No. 13,757, 3 C.F.R. 659 (2017).
- International Emergency Economic Powers Act, 50 U.S.C. §§ 1701 to 1706 (2018).
- Ohio Rev. Code Ann. §§ 1333.61 to .69 (West 2026) (Ohio Uniform Trade Secrets Act).
- Ohio R. Prof. Cond. 1.1 cmt. 8, 1.4, 1.6(c), 5.1, 5.3.
- Protecting American Intellectual Property Act of 2022, 50 U.S.C. § 1709 (Supp. 2024).
Cases
- Google LLC v. Oracle America, Inc., 593 U.S. 1 (2021).
- hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022).
- Lotus Development Corp. v. Borland International, Inc., 49 F.3d 807 (1st Cir. 1995), aff'd by an equally divided Court, 516 U.S. 233 (1996).
- Motorola Solutions, Inc. v. Hytera Communications Corp., 108 F.4th 458 (7th Cir. 2024).
- Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. 2025), cert. denied, No. 25-449 (U.S. Mar. 2, 2026).
- Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., 765 F. Supp. 3d 382 (D. Del. 2025), interlocutory appeal docketed, No. 25-8018 (3d Cir. June 17, 2025).
- Van Buren v. United States, 593 U.S. 374 (2021).
Ethics authority
- ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 512 (2024).
Appendix B: Sources and Links
Bessent remarks and coverage
Distillation allegations
Sanctions authority and first use
Enterprise adoption and congressional inquiry
IP doctrine analysis
Matthew A. Mishak, Esq. is the Managing Attorney of Mishak Law LLC and the Founder and CEO of LegalTek.ai (SilverTung), an AI powered legal practice management and governance platform. He serves as Law Director for the Village of South Amherst, Ohio. A summa cum laude graduate of Cleveland-Marshall College of Law with executive AI credentials from MIT Sloan and Harvard Business School Online, he brings twenty years of Ohio legal practice across domestic relations, criminal defense, and municipal law. He is the architect of the COUNSEL framework operationalizing ABA Formal Opinion 512.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Attorney review required before reliance. LegalTek.ai is a technology company, not a law firm.









