Floor SpeechNeutral2026-07-13

Text of Senate Amendment 6610

Bill Hagerty
Bill Hagerty
RTN · Senator
Share:
TaxesEnvironmentForeign PolicyDefenseChinaTradeHousingTechnology

Context

On 2026-07-13, Senator Bill Hagerty (R-TN) delivered a floor speech titled "Text Of Senate Amendment 6610" in the Senate.

Full Text

Text of Senate Amendment 6610

Congressional Record, Volume 172 Issue 113 (Monday, July 13, 2026) [Congressional Record Volume 172, Number 113 (Monday, July 13, 2026)] [Senate] [Pages S3803-S3805] From the Congressional Record Online through the Government Publishing Office [ www.gpo.gov ] SA 6610. Mr. HAGERTY (for himself and Mr. Kim) submitted an amendment intended to be proposed by him to the bill S. 4784, to authorize appropriations for fiscal year 2027 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes; which was ordered to lie on the table; as follows: At the end of division A, add the following: TITLE XVII--BLOCKING LARGE-SCALE ADVERSARIAL DISTILLATION EFFORTS ACT OF 2026 SEC. 1701. SHORT TITLE. This title may be cited as ``Blocking Large-scale Adversarial Distillation Efforts Act of 2026'' or ``BLADE Act''. SEC. 1702. SENSE OF CONGRESS. It is the sense of Congress that-- (1) artificial intelligence models owned by United States private sector entities are essential for advancing economic and national security interests of the United States; (2) many of the most advanced artificial intelligence models owned by United States entities are ``closed-source models'' whose unique technical characteristics are not openly shared or published; (3) the unauthorized acquisition of model capabilities, such as model weights, model architectures, and other technical characteristics of closed-source artificial intelligence models, by persons of concern through model extraction attacks represents a threat to the national security and foreign policy interests of the United States, as well as the intellectual property rights and economic competitiveness of United States entities; (4) the United States Government, in cooperation with private owners of closed-source artificial intelligence models, should take steps to identify, punish, and deter model extraction attacks on the protected capabilities of closed-source artificial intelligence models by persons of concern; (5) model extraction attacks against United States closed- source artificial intelligence models allow foreign adversaries a short cut to acquiring advanced artificial intelligence capabilities; and (6) authorized model training practices that adhere to the terms of service or are otherwise consistent with contractual terms set by the owners of closed-source artificial intelligence models are a legitimate research method that play an important role in artificial intelligence research and are fundamentally distinct from model extraction attacks addressed by this title. SEC. 1703. DEFINITIONS. In this title: (1) Appropriate congressional committees.--The term ``appropriate congressional committees'' means-- (A) the Committee on Banking, Housing, and Urban Affairs and the Select Committee on Intelligence of the Senate; and (B) the Committee on Foreign Affairs of the House of Representatives. (2) Closed-source artificial intelligence model.--The term ``closed-source artificial intelligence model'' means any artificial intelligence model with the following characteristics: (A) Proprietary key technical information, such as underlying model weights, that are necessary to reproduce and independently recreate the model and that are not willingly shared with third parties or otherwise made publicly available by the owner of the model. (B) Access and use governed by terms of service or contractual agreements that are established by the owner of the model. (C) Access that is provided via an application program interface or another consumer-facing, owner-controlled interface without enabling third parties to obtain, modify, or host the closed-source artificial intelligence model on their own data servers or other technology unless specifically authorized by the owner of the model. (3) Country of concern.--The term ``country of concern'' means-- (A) the People's Republic of China, including the Hong Kong and Macau Special Administrative Regions; (B) the Russian Federation; and (C) any other foreign country-- (i) listed in Country Group D:5 in Supplement No. 1 to part 740 of title 15, Code of Federal Regulations, as published on January 1, 2026, that is designated by the Secretary of Commerce, in consultation with the Secretary of State, as a country of concern for purposes of this section and for which notice of such designation has been published in the Federal Register; and (ii) identified by the Secretary of Commerce, in coordination with the head of each agency that is a member of the Operating Committee for Export Policy, the Director of National Intelligence, and the heads of such other departments or agencies of the Federal Government as the President determines appropriate, pursuant to an assessment required by subsection (a) or (e) of section 1704. (4) Person of concern.--The term ``person of concern'' means any foreign person that-- (A) is located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; (B) is operating under the direction or control of any entity located or headquartered in, or the ultimate parent company of which is headquartered in, a country of concern; or (C) is conducting or attempting to conduct a model extraction attack against closed-source artificial intelligence models owned by United States persons and outside of authorized model training practices. (5) Foreign person.--The term ``foreign person'' means a person that is not a United States person. (6) Fraudulent account network provider.-- [[Page S3804]] (A) In general.--The term ``fraudulent account network provider'' means any foreign person that knowingly and intentionally creates, obtains, maintains, sells, brokers, or otherwise provides access to an account that allows a person of concern to access a closed-source artificial intelligence model that the entity would otherwise be prohibited from accessing as a result of location restrictions in the terms of service or a contractual agreement created by the owner of the model. (B) Exception.--For purposes of subparagraph (A), an entity that creates or transmits location information to enable persons within countries of concern to access the internet for purposes of freedom of expression is not, on the basis of that activity alone, a fraudulent account network provider. (7) Model extraction attack.-- (A) In general.--The term ``model extraction attack'' means the unauthorized extracting of the capabilities of a closed- source artificial intelligence model to replicate, develop, train, or improve another artificial intelligence model, if such extraction-- (i) circumvents technical, contractual, or other access controls, identity verification requirements, or geographic access restrictions implemented by the owner of the model; (ii) is conducted through fraudulent, misrepresented, or unauthorized credentials; or (iii) violates the terms, conditions, or restrictions governing access to or use of the model, as established by the owner, that specifically prohibit the use of model outputs or interactions to replicate, develop, train, or improve another artificial intelligence model. (B) Inference of purpose.--For purposes of subparagraph (A), the purpose of extraction may be inferred from the totality of circumstances, including-- (i) the volume, structure, pattern, coordination, or timing of the extraction activity; (ii) the concentration of extractions on specific model capabilities; (iii) the use of multiple accounts in a coordinated manner; or (iv) the correlation of extraction activity within the development timeline of another artificial intelligence model. (C) Exclusion.--For purposes of subparagraph (A), model training activities conducted in compliance with the terms, conditions, and restrictions governing access to and use of a closed-source artificial intelligence model, or otherwise conducted within a permitted exception or the express authorization of the owner of the model, are not model extraction attacks. (8) Operating committee for export policy.--The term ``Operating Committee for Export Policy'' means the Operating Committee for Export Policy referred to in section 1763(c) of the Export Control Reform Act of 2018 (50 U.S.C. 4822(c)). (9) Owner.--The term ``owner'' means, with respect to a closed-source artificial intelligence model, the person that-- (A) holds intellectual property rights (including trade secret, copyright, patent, or other proprietary rights), contractual rights, or a combination thereof, sufficient to authorize or restrict third-party access to, use of, extraction from, or reproduction of the model, or any version, instance, or deployment the model, whether such rights were obtained through development, acquisition, assignment, license, or otherwise; and (B) is a United States person. (10) Person.--The term ``person'' means individual or entity. (11) United states person.--The term ``United States person'' means-- (A) a United States citizen or an alien lawfully admitted for permanent residence to the United States; (B) an entity organized under the laws of the United States or any jurisdiction within the United States, including a foreign branch of such an entity; or (C) any person located in the United States. SEC. 1704. ASSESSMENT OF MODEL EXTRACTION ATTACKS AND FRAUDULENT ACCOUNT NETWORK PROVIDERS. (a) In General.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Commerce, in coordination with the head of each agency that is a member of the Operating Committee for Export Policy, the Director of National Intelligence, and the heads of such other departments or agencies of the Federal Government as the President determines appropriate, shall complete an assessment to determine-- (1) which, if any, persons of concern have conducted or are currently conducting model extraction 
View original source →