
Runtime Geopolitical Risk: The Export Problem and the Global Data Market

Washington Can Now Describe AI Extraction With Statutory Precision — and Cannot Yet Convert the Description Into an Enforceable Event, While the Market Moves One Layer Past Every Instrument Being Built
Commerce Department (BIS) · NSA · CISA · FBI · FTC · U.S. Congress (H.R. 8283) · Anthropic · OpenAI · Alibaba · DeepSeek · Moonshot · Zhipu AI · MiniMax · SenseTime · United States · China
Both papers extend Anthropic, Alibaba, and the Runtime Theft Problem (June 2026), which predicted that enforcement against AI distillation would migrate from private litigation to export control three months before the September record confirmed it.
Full publications: The Runtime Export Problem | The Runtime Global Data Market
On June 12, 2026 the Commerce Department restricted foreign access to two named Anthropic models, an extension of export control that practitioners called unprecedented. Between May and July, a single Alibaba distillation campaign ran more than 151 million exchanges against Claude — peaking near three million a day from over 3,500 fraudulent accounts — almost entirely through models the restriction never touched. Three federal agencies and one provider have since named the actors, and no named lab faces any sanction.
Central finding: the unit of AI export control is migrating twice — from the model to the extraction campaign, and from the campaign to the harvested corpus the campaign produces. Every enforcement instrument now forming, entity designation, intermediary categories and provider telemetry duties, watches the runtime interface, while capability transfer shifts toward the one channel no telemetry observes: commerce in harvested behavioral corpora.
Advisory AA26-251A compressed attribution without resolving it. On September 8 the NSA, CISA and FBI jointly named six Chinese AI firms for industrial-scale distillation, two days before Anthropic published the fuller evidentiary record, and five names overlap across the two lists. The stage holding the strongest evidence holds no sanction, and the stage holding sanctions has not moved.
Congress already drafted the behavioral test. H.R. 8283, the Deterring American AI Model Theft Act, defines a model extraction attack through the totality of querying circumstances — volume, capability concentration, coordinated multi-account use, correlation with a rival model's development timeline — and expressly names the fraudulent account-network provider. The bill names one role in a four-role supply chain: the logger who harvests sessions, the broker who packages corpora and the buyer who trains on them all operate outside every drafted category.
Deterrence in this domain is engineered rather than decreed. Zhipu abandoned an extraction attempt when Anthropic's Fable safeguards degraded the product, then rerouted toward models it assessed as weaker — safeguard strength decided the routing, export status never entered it. Behavioral economics explains the regulatory miss, since institutions anchor to the salient object, the named model; dynamic game theory explains the routing, since extraction flows to the lowest-cost interface.
SenseTime closed the loop the enforcement architecture cannot see. The lab purchased transcripts of user exchanges with Claude from third-party vendors, inheriting the capability without performing the conduct, while proxy services logged unwitting users' sessions for resale and MiniMax ran a shell storefront offering only American models. Pricing the account channel raises the relative value of the corpus channel, so enforcement success at the interface reads as progress while the decisive transaction moves past it.
The papers close with the administrable answer. A reachable rule assembles from three axes — harvested provenance, the H.R. 8283 conduct indicia read at dataset level, and recipient class — with provenance marking as the binding constraint, since no rule can administer what no party can detect.
What the full publications add. Together the two papers release fourteen MindCast Foresight Simulation Predictions — six in The Runtime Export Problem (three Primary, three Secondary) and eight in The Runtime Global Data Market (four Primary, four Secondary) — each carrying an event probability with a sensitivity band, a settlement window, an explicit falsifier and a named settlement source: the Federal Register (RIN 0694-AJ90), the BIS Entity List, the OFAC SDN list, DOJ dockets and MOFCOM, CAC and MIIT publications. The full papers also deliver the assessed June prediction ledger with two registers settled, the four-stage supply-chain map, the four-claim property analysis run through Coase and Becker, the five-architecture comparison for governing the corpus, the three-axis candidate rule, and per-register risk-mitigation entries specifying exposure, owner, deadline and the residual that survives full mitigation.
Read the full analyses: The Runtime Export Problem | The Runtime Global Data Market
Leading Simulation Predictions.
From The Runtime Export Problem, which releases six registers under the P/S convention:
P-1 (84%, band 78–89): Federal policy operationalizes runtime extraction through entity, intermediary and telemetry measures rather than licensing of ordinary foreign inference, through September 2027.
P-3 (83%, band 77–88): No Entity List addition or sanctions designation of the six advisory-named labs lands before the September 24, 2026 Trump-Xi summit opens.
From The Runtime Global Data Market, which releases eight registers under the RD convention and inherits the P/S set with frozen terms:
RD-P1 (74%, band 67–80): No federal export instrument names a transcript-broker or harvested-corpus category, by September 30, 2027.
RD-P2 (78%, band 72–84): Private provenance and source-tracing practice develops before any government corpus category, by September 30, 2027.
RD-P4 (80%, band 73–87): A further authoritative publication documents intermediated or harvested-corpus acquisition, by September 30, 2027.
RD-S1 (80%, band 73–86): Buyer-side origin diligence appears before any seller-side broker licensing, by September 30, 2027.
RD-S3 (83%, band 76–89): Beijing does not burden its own labs' use of foreign-harvested corpora, by June 30, 2027.
Every prediction carries a deadline, a falsifier, an activation rule and a public settlement source. Fourteen registers release across the two papers, with event probabilities ranging from 61% to 84%.
🏛️ Policymakers and agency staff. The replacement for the rescinded diffusion framework decides the unit of control, and the choice between conduct-based and object-based elements settles P-2 directly. Risk mitigation: scope the first reachable public duty as a counterparty obligation rather than a corpus definition, and press for an explicit conduct-versus-object determination in the rulemaking record before the comment window closes.
🧠 Think tanks and policy researchers. The register functions as a public natural experiment in conduct-based export control: fourteen dated forecasts with pre-committed falsifiers settle against the Federal Register and agency dockets rather than against post-hoc interpretation. Risk mitigation: anchor tracking programs to the settlement calendar now, since the analytical value of the register accrues to institutions positioned before the first qualifying rule issues.
⚖️ Counsel. Clients sit on three sides of one trade — providers whose outputs are harvested, enterprises whose sessions are logged for resale, and purchasers whose training data carries unknown provenance. Risk mitigation: prepare dual compliance postures against both a conduct-based and an object-only replacement rule, and build a data-origin record on every corpus acquisition before any duty attaches.
💼 Executives. Frontier providers are becoming de facto monitoring nodes whose visibility ends at the interface, while the corpus market operates past it. Risk mitigation: budget provenance marking in the same line as extraction detection, and pre-commit a disclosure standard for detection capabilities rather than releasing case by case.
🗄️ Enterprise data-governance leads. A training pipeline built on unattested corpora converts a completed model into a contingent liability. Risk mitigation: condition high-risk training-input purchases on source attestation at intake, with audit rights in the standard acquisition template.
📊 Investors. Capability moats priced on training cost were already mispriced against querying-based extraction, and the corpus channel transfers the same capability at lower cost and lower legal exposure. Risk mitigation: rebuild moat-duration assumptions with an explicit channel-substitution term, and stress-test positions against a post-summit designation scenario before September 24.
The 151-million-exchange record now reads as more than an enforcement gap at the model tier. Alibaba's campaign demonstrated that the model was never the operative unit, SenseTime's purchases demonstrated that the campaign will not stay the unit either, and the corpus is the last observable object before capability dissolves into a rival model. The government that defines the unit of account first sets the terms of AI trade enforcement.
MindCast AI converts institutional uncertainty into dated, falsifiable decision forecasts across two verticals: geopolitical and national-innovation intelligence, and litigation-regulatory foresight. Engagements keyed to these registers include export-control posture mapping, designation-exposure stress tests, corpus-exposure audits, provenance-readiness assessments, corpus-instrument design briefs and standing runtime-governance retainers, alongside briefings and joint research programs for policy institutions. Contact [email protected].
Related Works
The Runtime Export Problem (2026). Documents attribution compression and names operationalization as the binding constraint, carrying registers P-1 through S-3.
The Runtime Global Data Market (2026). Maps the transcript-market supply chain and carries registers RD-P1 through RD-S4.
Anthropic, Alibaba, and the Runtime Theft Problem (2026). The June publication whose predictions the arc assesses and whose attribution-cost mechanism it extends.
Aerospace's Warning to AI, How Capability Laundering Will Reshape Corporate Compliance (2025). Forecast compute-access licensing for conductive third countries ten months before reported rulemaking targeted that jurisdiction class.
The TSMC China License and the Limits of Hardware Export Controls (2026). Documented the gate-without-fence gap at the chip layer that the arc documents at the model and corpus layers.
US Outsourcing, What Leaves America's AI-Quantum Buildout When the Megawatts Stay (2026). Maps deemed-export doctrine, the closest existing analogue to a controlled corpus.
The Global Innovation Trap (2025). Established capability capture at a fraction of originating R&D cost, the economics the transcript market perfects.
Why AI Commoditizes Raw Prediction, Why Governance Stays Scarce (2026). Supplies the governance-scarcity structure explaining why extraction economics favor attackers.
Share Your High-Stakes Matter
Contact Us
Office location
Bellevue, Washington, 98006Send us an email
[email protected]