U.S. Capitol building exterior.

Antitrust Uncertainty and AI Security Collaboration: A Targeted Bipartisan Proposal

The clock is ticking as the U.S. government scrambles to prevent the cybersecurity capabilities of frontier AI models from being misused against government operations, critical infrastructure, and U.S. private sector networks. With Chinese labs only months behind U.S. companies, advanced cyber capabilities similar to those displayed by Mythos and GPT-5.6 may soon be available to criminals and intelligence services around the world. Distillation of U.S. models’ capabilities is helping Chinese labs remain “fast followers” and reducing the U.S. lead. Yet U.S. companies are not collaborating with each other to stop this adversarial extraction and replication of technical advances, even though a joint effort is required. The reason: fears that some of the necessary collaboration could violate U.S. antitrust law.  

Collaboration on risks posed by AI models themselves has also been limited by concerns about antitrust law. AI models are increasingly demonstrating capabilities that could be misused in developing biological weapons or exploiting cybersecurity vulnerabilities. Even maintaining oversight and control of increasingly capable AI models is becoming more challenging. Although competitive pressures and personal rivalries may also limit the extent to which the leading companies are willing to work together, antitrust fears are currently a central factor deterring AI developers from collaborating to reduce these risks or to ensure they take enough time to vet new models.   

These concerns represent a collective-action problem. Pressure to release more capable models reduces the time available for a company to build in safeguards and evaluate risks, lest it lose ground to competitors, and an inability to take joint action against distillation facilitates accelerated diffusion of advanced capabilities to adversaries. The same remedy would help ameliorate both aspects of the problem: providing a firm legal basis for collaboration. 

bipartisan bill has now been proposed that would provide targeted protections to collaboration on AI security risks, including adversarial distillation. The Collaboration on Adversarial Threats and Security Risks Act builds on the precedent set in 2015 for collaboration on cybersecurity issues. It would provide clarity to ensure that antitrust law does not deter legitimate collaboration while retaining safeguards against anticompetitive behavior. 

Antitrust Uncertainty Deters Beneficial Collaboration 

Because AI is developing so rapidly, collaboration on security risks needs to be possible on short timelines and in a flexible manner. Technical researchers may identify risks that also affect other companies’ models and that need to be addressed before hostile actors can take advantage of them. Yet analysis of antitrust risks can be highly fact-specific, and time-intensive review by counsel can deter busy researchers from seeking authorization to collaborate. The law is not clear enough for in-house lawyers to authorize technical researchers to reach out directly to counterparts at other companies to collaborate on security issues. The barrier may be even more daunting for smaller startups that have fewer resources to engage in legal reviews that distract from their core work.  

For years, U.S. frontier labs such as OpenAIGoogle DeepMind, and Anthropic have called for government action, suggesting that antitrust concerns serve as a barrier to collaboration on security-related risks. Similarly, in off-the-record fora, employees of some leading developers frequently cite in-house counsels’ concerns about antitrust risks as a central reason that more collaboration does not occur. A 2024 analysis by the Institute for Law & AI argued that “[i]n the absence of some sort of guidance or safe harbor, the risk-averse in-house legal teams at leading AI companies … are unlikely to allow any significant cooperation or communication between rank and file employees.” 

The problem was compounded in late 2024, when the Department of Justice and the Federal Trade Commission (FTC) withdrew the 2000 Antitrust Guidelines for Collaborations Among Competitors. Although the Guidelines were generic and not specific to the AI context, they provided some additional reassurance regarding how collaborations are viewed from the enforcement perspective. Their absence now creates even more uncertainty. 

Tools used in other areas to reduce antitrust risks are often not helpful in the AI context because of the fast-moving nature of the research. Formalized contractual arrangements will often not be helpful or appropriate, so the notification process under the National Cooperative Research and Production Act will generally not be available. Similarly, the procedures for seeking FTC advisory opinions or DOJ business review determinations often take months—too slow to provide useful guidance when collaboration is urgent. 

Some limited collaboration among frontier labs does still occur. Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI are all members of the Frontier Model Forum, which has facilitated a series of information-sharing efforts among its members. But FMF’s membership is limited. SpaceXAI is not a member, and no startups or smaller companies are members either. 

Adversarial Distillation of U.S. AI Models 

The lack of a coordinated response to adversarial distillation campaigns provides a useful case study on how antitrust fears deter beneficial collaboration. Earlier this year, GoogleOpenAI, and Anthropic each disclosed information that publicly revealed a pattern of Chinese industrial-scale distillation attacks. These U.S. companies’ most advanced models are “closed-weight” models that are accessed on the web, via an app, or through an application programming interface (API) that lets other programs send requests to the model.  

Chinese labs have been using deceptive techniques to access these U.S. models and elicit outputs that they use to train new models with similar capabilities, then release them as “open-weight” models. Because open-weight models can be freely downloaded, altered, and used locally, they pose a wider range of risks. Providers of closed models can use tools such as classifiers or monitors to identify and block attempts to misuse the model, but these types of external safeguards do not constrain open-weight models. Similarly, the internal safeguards that may be built into the closed-weight models do not reliably accompany those models’ capabilities into distilled models. Moreover, even to the extent that an open-weight model is trained to refuse certain queries, that training can be cheaply fine-tuned away. 

The executive director of the FMF, Chris Meserole, recently testified that U.S. models once had a 12-to 18-month lead over foreign models, but that distillation attacks have helped narrow that lead to 4 to 6 months before similar capabilities emerge. The United Kingdom’s AI Security Institute has similarly identified a narrowing of the gap between closed-weight and open-weight models on cyber capabilities in particular—from 6 to 10 months in 2025 to 4 to 7 months in mid-2026. 

When Anthropic released a preview version of its Mythos model, which represented a significant leap in cyber capabilities, it gave limited access to a trusted set of partners who used the model for bolstering defenses. (Similarly, OpenAI initially released GPT-5.6 to a “small group of trusted partners” at the U.S. government’s request.) A broader release of Mythos would not only have increased the risk of direct misuse but would have posed the risk of the capabilities being distilled. Over time, the executive branch’s concerns about the capabilities of Mythos and the company’s more-constrained Fable model led to the imposition of export controls on the models for 18 days. But despite precautions, Michael Kratsios, director of the Office of Science and Technology Policy at the White House, has said that the Chinese company Moonshot AI distilled Fable in developing its Kimi K3 model.

In his testimony, the FMF’s Meserole said that the challenge in countering distillation attacks is that the necessary information “is distributed amongst a wide array of industry actors.” The Center for a New American Security (CNAS) has identified information such as “account indicators, network origins, behavioral patterns, and hashed prompts” that could usefully be shared among U.S. companies trying to combat distillation. Yet, as Meserole stated, FMF members have “had to take a fairly conservative approach under antitrust law to even have a conversation about how to identify distillation” and “have not had a conversation about how to counter it, given existing antitrust concerns.” 

The Need to Enable Coordination 

A robust effort to combat distillation—and thereby extend the period before open-weight models make advanced cyber capabilities widely available—may require collaboration beyond information sharing. A forthcoming report from the Institute for Progress’s Saif Khan will analyze whether the new precedent for limited rollouts of cyber-capable models (like Mythos and GPT-5.6) could also help partially rebuild the lead that the U.S. models have over Chinese models. Even if adversarial distillation is unavoidable, limiting access to only trusted partners for an initial period could delay it (and thus delay China’s access to frontier-level capabilities). But if multiple U.S. companies are developing comparable new models, access to any one of them could be enough for Chinese labs to build their own via distillation. Thus, coordination would be necessary for such an approach to be effective—but such coordination could resemble an output restraint, potentially a per se violation of antitrust law. 

The need to enable coordination does not rest solely on the threat from China. Antitrust law could also prevent U.S. companies from coordinating to provide the U.S. government with greater access to unreleased models. Although a recent executive order called for a “voluntary” 30-day review by the government prior to the release of new frontier models, earlier reports suggested that a 90-day window was considered. If several companies wanted to provide more than 30 days’ access but were worried that doing so unilaterally would disadvantage them, coordination could help the government get greater access. Similarly, given the recent incident in which an OpenAI model hacked into Hugging Face’s servers during evaluations, companies could reasonably determine that U.S. government evaluation of models at earlier stages—rather than only immediately before release—would be beneficial. In either situation, though, antitrust fears would likely prevent companies from coordinating on such an approach, despite the possible benefits to the public. Even under a “rule of reason” analysis—a fact-specific inquiry into the anticompetitive effects and procompetitive justifications for a restraint on competition—public safety justifications for such restraints do not fare well. Thus, congressional action is needed to ensure that beneficial collaboration does not fall afoul of existing antitrust doctrine. 

Following the Cybersecurity Precedent 

Just as is the case now with AI security risks, antitrust fears once created private sector reluctance to collaborate on cybersecurity problems. In 2014, DOJ and the FTC found that “[s]ome private entities [were] hesitant to share cyber threat information with each other, especially competitors, because they have been counseled that sharing of information among competitors may raise antitrust concerns.” To counter this fear, the agencies issued a joint policy statement, unambiguously proclaiming that they “do not believe that antitrust is – or should be – a roadblock to legitimate cybersecurity information sharing.”  

A similar approach by the agencies would be a good first step here. As with cybersecurity information sharing, some amount of information sharing regarding AI security risks is presumably permissible under existing law, but uncertainty regarding enforcement risk is a deterrent. In April, the Trump administration pledged to “[e]nable the private sector to better coordinate against [distillation] attacks.” Such guidance, addressing not only distillation but other AI-related security risks, could be provided in the context of replacing the 2000 Guidelines—a project on which DOJ and the FTC sought public comments—or as a standalone, sector-specific guidance document. A number of comment letters urged the agencies to provide guidance in this area, including those from RAND, the Council on Strategic Risks, AEI’s Will Rinehart, the Mercatus Center’s Alden Abbott, the Competitive Enterprise Institute, and the Law Reform Institute. CNAS has also advocated for such guidance. 

But agency guidance—though valuable—would not suffice. A statement on the enforcement perspectives of federal agencies would not protect companies from private plaintiffs or claims under state law. Even after the 2014 cybersecurity policy statement, sufficient uncertainty remained that legislation was needed. The following year, the Cybersecurity Information Sharing Act of 2015 codified and expanded the agencies’ view, providing that “it shall not be considered a violation of any provision of antitrust laws” for private entities to share certain cybersecurity-related information—or to provide related assistance to each other—when done for cybersecurity purposes. These statutory protections may not have significantly changed the boundaries of what antitrust law permitted, but they dramatically improved clarity and certainty. Yet CISA, focused on traditional cybersecurity issues, does not cover the current set of risks. 

A Legislative Solution 

To facilitate needed private-sector collaboration on AI security risks, legislation is urgently needed to clarify what types of collaboration are permissible. To that end, the Collaboration on Adversarial Threats and Security Risks Act was introduced on July 23 by Senators Adam Schiff (D-CA) and Jim Banks (R-IN) and Representatives Bob Latta (R-OH) and George Whitesides (D-CA).  

The Act would take a similar approach to the protections granted in CISA. The core of the Act is a list of six categories of “covered artificial intelligence security risks” that may occur during the “development, training, testing, evaluation, deployment, use, or release” of AI: 

  • Weaponization or theft, including distillation, by a covered nation (China, Russia, North Korea, or Iran) in a manner that poses a significant threat to national security; 
  • Facilitation of a chemical, biological, radiological, nuclear, or offensive cyber weapon; 
  • Certain serious risks to critical infrastructure; 
  • Substantial reductions in the ability to oversee or disable AI; 
  • Autonomous improvement of AI in a manner that poses one of the above risks; and 
  • Vulnerability to unauthorized access that poses one of the above risks or is directed by a covered nation. 

Analogous to CISA, the Act would protect information-sharing and assistance aimed at addressing those risks. It would also protect efforts to address those risks by coordinating on delays in developing or releasing AI. The Act would thus cover the types of scenarios described above, in which companies may want to coordinate to give the U.S. government earlier access to models or to collaborate on combatting adversarial distillation by limiting the initial release of models. These protections would be available not just for large companies like FMF members but also for smaller developers whose current routes for collaboration on security risks are even more limited. 

The Act also contains safeguards to ensure the antitrust protections are not abused. Companies would have the burden of proving, as an affirmative defense, that they acted in good faith and for the exclusive purpose of addressing covered risks. They would have to implement reasonable internal controls to limit the extent to which any information or assistance they receive can be used for other purposes. For coordinated delays in particular, companies would have to notify DOJ before taking action. Additionally, DOJ could seek injunctive relief when a company’s action violates antitrust laws—and even if a company successfully demonstrates that it acted in good faith to address a covered risk, its conduct could still be enjoined if it is reasonably likely to increase those risks instead.  

Taken together, this set of safeguards would make it highly unlikely that the Act’s protections could be abused for anticompetitive ends. Coordination beyond good-faith efforts to address covered risks would fall entirely outside the Act’s protections and would be subject to all existing remedies. 

Moving Forward, Urgently 

Although the “Mythos moment” was triggered by cybersecurity capabilities, sequels will likely arrive soon enough in other areas such as biological capabilities. Thus, quick action is needed to enable collaboration between American companies. DOJ and the FTC issued their cybersecurity guidance in April 2014, and CISA was signed into law in December 2015, only 20 months later. But the agencies have not yet issued any guidance for collaboration on AI security risks, and even if they did so tomorrow, the pace of AI development means that the next 20 months will probably be full of challenges that individual companies cannot address adequately without a targeted legislative framework that facilitates coordination. By acting quickly, Congress can significantly improve the odds that U.S. companies rise to the occasion in future high-risk Mythos moments. 

Authors Note: Through the Law Reform Institute, the authors developed a legislative proposal on this topic last year. LRI provided input on the Collaboration on Adversarial Threats and Security Risks Act to the sponsors’ offices and has expressed support for the bill. 

Filed Under

, , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: