S 5252
A bill to prevent foreign adversaries from threatening the national security of the United States by extracting key technical features of closed-source, United States-owned artificial intelligence models, and for other purposes.
TL;DR
Senator Bill Hagerty (R-TN) introduced this bill to block foreign adversaries (think China, Russia, Iran, North Korea) from extracting the underlying technical features of proprietary, closed-source AI models built by US companies. It targets model theft techniques like model distillation and would give the federal government new export-control-style powers over how US AI firms protect their models.
How This Might Impact Your Business
US-owned AI developers with closed-source, frontier models (OpenAI, Anthropic, Google, Meta, xAI, and similar) are the primary targets and would face new obligations to prevent foreign extraction of model weights, architectures, and training methods.
Cloud providers hosting AI APIs (AWS, Azure, Google Cloud) could face new customer screening and access controls to block users in adversary nations from querying models in ways that enable distillation or reverse engineering.
Enterprises using US AI APIs may see tighter Know Your Customer requirements, geographic restrictions, and rate limits designed to detect extraction attempts.
Companies with international operations or foreign subsidiaries in China, Russia, Iran, or North Korea may lose access to advanced US AI models or need to prove downstream users are not adversary-linked.
Penalties are not yet detailed in the referred version, but similar national security bills carry export control-style fines and criminal liability for executives who knowingly violate.
Open-source AI developers are largely exempt since the bill targets closed-source, US-owned models specifically.
Timeline is early stage: sits in Senate Banking Committee with no markup scheduled, so compliance requirements are months to years away if it advances.
What Should You Do
If you build or deploy proprietary AI models, ask your security team to inventory how your model weights and APIs are protected against distillation attacks and unauthorized access from restricted jurisdictions.
Cloud and SaaS companies should review customer onboarding to confirm you can identify and restrict users based in adversary nations, since that capability will likely become mandatory.
Have legal counsel track S 5252 through the Senate Banking Committee and flag any markup or amended text, since specific compliance obligations are not yet defined.
Multinationals should map which business units in China, Russia, Iran, or North Korea currently use US-built AI services and prepare contingency plans for restricted access.
Coordinate with your government affairs team if your business model depends on serving international AI customers, as this bill could reshape export rules for AI services.
Who It Affects
Sponsors
Status Timeline
committee
Read twice and referred to the Committee on Banking, Housing, and Urban Affairs.
August 5, 2026