Export Controls
U.S. export controls have not yet been adjusted to account for the ability of AI to output controlled information. The Law Reform Institute is working to identify where the current regime is ill-equipped to address the challenges posed by AI and how policymakers can update the regime in response.
Export Controls and AI Model Outputs
Publicly available frontier models can provide users with information that may require a license depending on the user’s nationality and location, and unreleased models may have even fewer safeguards.
Current export-control frameworks were designed to govern discrete transfers of already-existing information between known parties. By contrast, AI models can create customized outputs in response to user queries. As capabilities increase, AI developers and the U.S. government face an untenable choice: accept systemic national security risks from frontier AI models or enforce restrictions against developers in ways that would undermine American technological competitiveness.
LRI’s work suggests that the U.S. government should establish a voluntary safe-harbor framework that protects U.S. innovation while minimizing the risk to national security.
-
Read our article in Just Security: AI Model Outputs Demand the Attention of Export Control Agencies
-
Read the full draft report: AI Outputs and National Security Controls
Export Controls and Bio-Risk Evaluations of AI Models
Current export-control regulations are motivated by non-proliferation concerns but actually make it more difficult for AI developers and model evaluators to ensure that AI cannot assist with developing biological weapons.
As frontier AI models may lower barriers to creating or modifying pathogens, rigorous evaluations are essential to ensure they cannot be exploited to create or enhance biological threats. However, these evaluations may use or generate export-controlled information. Because a limited number of specialists possess the biological threat-assessment expertise to perform such evaluations, U.S. firms that perform this testing often must engage foreign experts. Thus, in certain situations, export control licenses may be necessary to conduct these evaluations.
Given the importance of ensuring that the models do not create new non-proliferation risks, the export control regime should not serve as a barrier to these evaluations. LRI has proposed adjustments to the export-control regulations that would facilitate evaluations. Such changes could be implemented by the export-control agencies using their existing authorities, or new legislation could be passed to provide the agencies with a clear mandate.
-
Read our discussion draft of legislation: AI Authorization Evaluation Act
-
Read our article (with Doni Bloomfield) in Lawfare: How U.S. Export Controls Risk Undermining Biosecurity
-
Read the full report: Application of U.S. Export Controls to AI Biosecurity Evaluations and Mitigations
Export Controls and Open-Weight AI
Open-weight AI models can be modified, stripped of safeguards, and deployed in contexts that prevent monitoring. As their capabilities increase, they may enable cyberattacks, weapons programs, and other military and intelligence uses. However, given the availability of non-U.S. open-weight models with advanced capabilities, restricting U.S. models unilaterally may not reduce these risks. Thus, export controls may have a limited role in addressing open-weight models.
LRI has released a draft report on this topic. It examines how existing export-control regulations apply to open-weight models, outputs from those models, and downstream services, and how responsibility for export-control compliance is allocated at different stages. It also evaluates the extent to which export controls are likely to work in practice, and it identifies where existing authorities can materially reduce risks and where other approaches are needed.
-
Read the draft report by Joe Khawam: Export Controls and Open-Weight AI