America's AI Provenance Rules

By Dr. Gleb Tsipursky

The Trump administration has drawn a new line in its China strategy: legitimate model distillation can support open innovation, while covert industrial distillation designed to copy proprietary American technology may justify sanctions or export restrictions. That distinction is more sophisticated than treating every open model as a threat. Yet it will still fail unless the government translates it into operational rules that companies can actually use.

The core problem is provenance. Businesses adopting artificial intelligence need to know where a model came from, what data and teacher systems shaped it, which licenses or terms govern it, and whether the supplier can document those claims. A nationality test cannot answer those questions. An American model can carry unclear training rights or weak controls, while a foreign model can disclose its lineage, limitations, and security practices more clearly.

The technology alone does not determine legitimacy. Conduct, authorization, disclosure, and traceability do.

The administration already recognizes the value of open-source and open-weight AI. Its AI Action Plan encourages those models because they expand competition, customization, privacy, and access for smaller organizations. A national security memorandum also directs federal agencies to adapt commercial and open-source systems while building partnerships against malicious distillation attacks. Those goals can coexist, but only through standards that separate lawful learning and adaptation from theft, deception, and evasive access.

That separation requires evidence. Distillation is a normal technical method for transferring behavior from a larger model to a smaller one. Organizations use it to reduce computing costs, improve speed, and create tools for specialized tasks. The same method can become abusive when a company creates fraudulent accounts, circumvents access controls, violates contractual limits, or conceals the source of the capabilities it copied. The technology alone does not determine legitimacy. Conduct, authorization, disclosure, and traceability do.

Washington should therefore build an AI provenance framework rather than rely mainly on company nationality or political suspicion. The framework should require suppliers seeking federal contracts, access to sensitive markets, or favorable export treatment to disclose five things: model ownership, material training and distillation sources, authorization for those sources, security controls used during development, and known limitations established through independent evaluation.

The government should also require a named executive to certify those disclosures. That creates accountability when a supplier misrepresents its model lineage. Today, responsibility often dissolves across developers, cloud providers, distributors, and corporate customers. A signed certification would give regulators and buyers a clear starting point for investigation without forcing every organization to become an AI forensics laboratory.

Independent evaluation matters because political claims about a model can outrun the evidence. Axios reported that U.S. and British evaluators found China’s Kimi K3 performed well below leading frontier models on cybersecurity tasks, even as the model generated policy concern. Capability, security, and provenance are separate questions. A weaker model can still involve stolen intellectual property, while a powerful model can be lawfully developed yet unsafe for a particular use.

The National Institute of Standards and Technology already offers a workable organizational foundation. Its AI Risk Management Framework asks organizations to govern, map, measure, and manage AI risks. Applied to model provenance, that means assigning ownership, documenting the intended use and supply chain, testing relevant capabilities and vulnerabilities, and deciding whether the residual risk fits the deployment context.

Federal procurement can make these practices real. Agencies should require provenance documentation and risk evidence before buying or deploying models. They should also allow suppliers to provide confidential technical details through protected review channels rather than forcing public disclosure of trade secrets. Smaller vendors need standardized forms and shared testing resources so compliance does not become a barrier that only dominant firms can afford.

Private companies should adopt the same discipline now. Before integrating an external model into customer service, hiring, health care, finance, cybersecurity, or product development, leaders should ask who owns the model, what evidence supports that claim, what contractual rights govern its use, how outputs were evaluated, and who can suspend deployment when new information appears.

Employees need a simple escalation route when a model behaves unexpectedly or when a supplier’s claims change. Procurement, legal, security, and business teams should review high-impact models together. This cross-functional process takes more effort than checking a country-of-origin box, but it prevents organizations from confusing geopolitical confidence with operational safety.

Washington should therefore build an AI provenance framework rather than rely mainly on company nationality or political suspicion.

Congress should pair this framework with a safe-harbor mechanism. A company that documents authorized distillation, follows access terms, reports security incidents, and cooperates with independent evaluation should receive a predictable path to market. A supplier that hides its methods, uses deceptive access, or refuses traceability should face escalating scrutiny. This approach would reward responsible behavior across borders while preserving stronger remedies for actual theft. It would also reduce pressure on agencies to make technical judgments through headlines, lobbying campaigns, or political affiliation alone.

The administration is right to defend open innovation while confronting covert appropriation. It should now finish the job by defining the evidence that distinguishes them. America will protect its AI advantage more effectively through traceable model lineage, enforceable disclosures, independent testing, and named accountability than through broad suspicion of every foreign model.

A provenance standard would also improve domestic adoption. Companies move faster when they understand what they are buying, which risks they own, and what evidence they must preserve. Clear rules can support both competition and security. That is the durable line Washington needs to draw.

About the Author

Dr. Gleb TsipurskyDr. Gleb Tsipursky was named “Office Whisperer” by The New York Times for helping leaders overcome frustrations with Generative AI. He serves as the CEO of the future-of-work consultancy Disaster Avoidance Experts. Dr. Gleb wrote seven best-selling books, and his two most recent ones are Returning to the Office and Leading Hybrid and Remote Teams and ChatGPT for Leaders and Content Creators: Unlocking the Potential of Generative AI. His cutting-edge thought leadership was featured in over 650 articles and 550 interviews in Harvard Business Review, Inc. Magazine, USA Today, CBS News, Fox News, Time, Business Insider, Fortune, The New York Times, and elsewhere. His writing was translated into Chinese, Spanish, Russian, Polish, Korean, French, Vietnamese, German, and other languages. His expertise comes from over 20 years of consulting, coaching, and speaking and training for Fortune 500 companies from Aflac to Xerox. It also comes from over 15 years in academia as a behavioral scientist, with 8 years as a lecturer at UNC-Chapel Hill and 7 years as a professor at Ohio State. A proud Ukrainian American, Dr. Gleb lives in Columbus, Ohio.