Related works: Anthropic, Alibaba, and the Runtime Theft Problem | The Runtime Global Data Market | Aerospace’s Warning to AI, How Capability Laundering Will Reshape Corporate Compliance | The TSMC China License and the Limits of Hardware Export Controls | The Global Innovation Trap
Executive Summary
On September 10, 2026 Anthropic disclosed seven Chinese distillation campaigns against its Claude models. Alibaba alone accounted for more than 151 million attributed exchanges, with tens of millions more across the other quantified campaigns. Two days earlier the FBI, NSA and CISA independently named six Chinese AI firms, five of them overlapping Anthropic’s attribution set. The disclosures expose a gap at the center of AI export control: Washington can now describe extraction behavior with the precision of a drafted statutory test, yet cannot convert that description into an administrable export-control event. Closing that gap is the subject of this paper.
Model identity is no longer a sufficient unit of export regulation. The Commerce Department restricted foreign access to two named Anthropic models on June 12, while the documented extraction economy ran overwhelmingly through models below the restricted tier.
Conduct crossed borders while classification watched the wrong axis. The operative regulatory unit is migrating from the model to the extraction campaign itself.
The stakes are national competitiveness, not administrative tidiness. The Global Innovation Trap modeled the mechanism: capability leakage compresses a frontier lead from years to months, and distillation transfers that capability at a fraction of its originating cost. Every month the unit-of-account problem stays unresolved shortens the advantage window while enforcement lacks a mechanism to stop the transfer.
MindCast published the migration thesis three months early in Anthropic, Alibaba, and the Runtime Theft Problem. The June paper predicted that attribution cost would push distillation enforcement out of private litigation and into export control, with the regulated unit becoming a behavioral pattern rather than an object.
The September evidence carries the June analysis forward. The attribution-cost mechanism it named moved one stage further, and this paper names the next stage.
MindCast reads the contest through Predictive Behavioral Economics + Dynamic Game Theory. Behavioral economics supplies the institutional decision rules, and dynamic game theory models adversarial adaptation. Institutions anchor regulation to the salient object, the named model. Attackers route toward the lowest-cost interface, so extraction flows past the classified models to the generally available ones.
The analysis proceeds from the June stress test through the institutional record and closes with the formal simulation register, the mitigation layer, and the settlement observables. The forecasts release through the MindCast AI Proprietary Cognitive Digital Twin Foresight Simulation (MP CDT FS) framework.
The formal MP CDT FS run releases six MindCast Foresight Simulation Predictions, three Primary and three Secondary, detailed with settlement windows and falsifiers in Section IX:
P-1 (84%): Federal enforcement operationalizes through entity, intermediary and telemetry measures rather than a licensing ban on ordinary inference.
P-2 (71%): The first rule replacing the rescinded diffusion framework carries at least one conduct-based element.
P-3 (83%): No designation of the six advisory-named firms lands before the 24 September 2026 Trump-Xi summit.
S-1 (61%): Beijing invokes bidirectional exposure, casting American providers as recipients of Chinese state data.
S-2 (77%): Cross-provider extraction-indicator sharing formalizes into a named standing mechanism.
S-3 (79%): No named regulatory category is created for brokers of harvested inference transcripts.
P-1 does not depend on P-2. Federal runtime governance can migrate toward entity and telemetry enforcement even if the first replacement rule stays predominantly object-based.
🏛️ Policymakers: The instrument gap is no longer evidentiary, because attribution has compressed from private allegation to convergent three-agency attribution. The open design problem is converting runtime telemetry into an administrable trigger without converting ordinary inference into a controlled export.
💼 Executives: Frontier-model providers are becoming de facto monitoring nodes in the national-security architecture. Several indicators in the advisory’s detection profile also characterize legitimate high-throughput enterprise agent fleets, so compliance exposure now runs through usage patterns rather than customer identity alone.
⚖️ Counsel: H.R. 8283 defines extraction through the totality of querying circumstances and expressly names fraudulent account-network providers, with no parallel category for transcript brokers. Clients sit on both sides of that line.
📊 Investors: Capability moats priced on training cost are mispriced if extraction transfers the capability at a fraction of that cost. The advantage window a frontier position is priced on compresses each cycle extraction goes unarrested, so the enforcement architecture now forming determines whether the moat holds its duration.
I. The Policy Stress Test: Access Control and the Safeguard Gradient
June and September together stress-test export doctrine. On June 12 the Commerce Department issued an Is-Informed Letter requiring licenses for any export or transfer of Anthropic’s Mythos 5 and Fable 5 models, extending to access by foreign persons worldwide. Export counsel described the extension of controls to model access as unprecedented, so Commerce had already crossed from regulating objects to regulating access.
Access control still missed most of the conduct. Anthropic’s September 10 threat report documents seven distillation campaigns attributed with high confidence to PRC-based labs, and the campaigns ran overwhelmingly through the generally available Opus, Sonnet and Haiku tiers. The federal advisory records one restricted-tier exception: Moonshot extracted significant Fable 5 data to train its Kimi K3 model.
Alibaba’s campaign alone exceeded 151 million observed exchanges between May and July, peaking near 3 million daily from more than 3,500 fraudulent accounts. Tens of millions more spread across the campaigns of Moonshot, DeepSeek, Zhipu and the other named labs.
One actor’s routing exposes the gradient. Zhipu attempted to extract cyber capabilities from Fable, abandoned the effort after Fable’s safeguards degraded the attack, then switched to models it assessed as holding weaker safeguards. Zhipu’s stated reason was safeguard strength rather than export status, so the deterrence the record shows was engineered while any deterrence from classification stays unobserved.
Behavioral economics explains the regulatory miss. Model identity is the salient unit institutions have always classified, and salience anchored the export instrument to the wrong axis.
Dynamic game theory explains the routing. Attackers face a cost function set by safeguards at each interface rather than by the legal status of each model, so extraction flows to the weakest interface. Restriction concentrated at the top of the model stack while the extraction economy ran below it, and the effective perimeter was engineered rather than decreed.
II. Assessing the June Ledger
Runtime Theft released its Simulation Predictions across two boards in June. The September record resolves two and materially advances a third.
CN-4. The June register predicted PRC labs would harden against attribution through rotation and intermediaries. The report documents the pattern in four forms: second account pools activated after bans; transfer-station proxy networks; a MiniMax shell company offering only Anthropic and OpenAI access; and purchased transcript corpora.
CN-2. The register predicted Beijing would fold accusations into its AI-sovereignty narrative and cast enforcement as protectionism. Beijing rejected the September allegations and described distillation as a normal technical and commercial practice.
US-3. The register predicted frontier labs would formalize indicator sharing as operational necessity. Coordinated disruption plus the advisory’s call for standing cross-provider sharing confirm the mechanism, and Simulation Prediction S-2 carries the remaining observable.
US-1 on a federal runtime-governance framework and US-2 on entity designations remain open inside their windows, and the formal simulation re-issues both with revised mechanisms.
CN-1’s denial branch validated while its litigation branch stays conditional on a designation that has not occurred. The remaining registers stay open on their stated terms. The two resolved registers both sat on the China board.
III. The Third Venue: Platform Threat Intelligence
Runtime Theft argued that attribution cost decides venue. When proving who extracted what costs more than any litigant can bear, enforcement migrates from the courtroom to the statute. September revises the mechanism in one respect: a third venue emerged between the two, and it moved faster than either.
Anthropic internalized the attribution cost rather than escaping it. The company held runtime telemetry no ordinary litigant possesses, absorbed the forensic expense and published an intelligence report instead of filing a complaint. Attribution did not become inexpensive; the party with privileged telemetry paid and externalized the evidentiary record to government.
Government reached the naming stage first: on September 8 the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) issued joint advisory AA26-251A, two days before Anthropic published its fuller evidentiary record. The advisory names DeepSeek, Moonshot and Alibaba alongside MiniMax, StepFun and Z.AI for industrial-scale distillation conducted since late 2024. It adds that the activity likely occurred with Chinese government awareness and that the campaigns form the core rather than a supplement of these companies’ development strategy.
Attribution has compressed rather than resolved. The federal and private lists overlap on five labs while each names actors the other omits, and the qualifier of likely government awareness preserves the gap between behavioral attribution and proven state direction. Two streams converging on overlapping names within one week strengthens the third-venue claim: the stage holding the strongest evidence holds no sanction, and the stage holding sanctions has not yet moved.
IV. Congress Already Drafted the Behavioral Test
The pattern-based instrument exists in draft and predates the evidence: Representatives Huizenga and Moolenaar introduced the Deterring American AI Model Theft Act of 2026 in April. Runtime Theft identified the bill’s design choice in June, regulating a pattern of behavior rather than a thing. The verified text goes further than the June characterization captured.
Section 3 defines a model extraction attack through conduct and infers purpose from the totality of circumstances. The statutory indicia read like a telemetry schema: the volume, structure and timing of querying; concentration on specific capabilities; coordinated multi-account use; and correlation with another model’s development timeline. Ordinary inference under a provider’s terms is expressly excluded, so Congress drew the inference-versus-extraction line that export doctrine lacks.
The bill also names the intermediary. A fraudulent account network provider covers any foreign entity that creates, sells or brokers accounts enabling prohibited access. Downstream machinery follows: a public AI Model Extraction Attackers List maintained by State; a confidential lab-to-Commerce information-sharing mechanism; an Entity List determination by committee vote within 210 days of enactment; and blocking sanctions under the International Emergency Economic Powers Act (IEEPA).
Anthropic’s report reads as a pre-built assessment under the bill’s own Section 4. The statute requires an analysis of attacker methods and proxy-network roles plus a count of attempted attacks over two calendar years, and the report supplies each element before the law that would request it exists.
The advisory performed the bill’s naming function without its consequence machinery: six entities listed publicly without the bill’s prescribed Section 5 process. Congress wrote the test in April; the executive performed the list on September 8; industry published its fuller dataset two days later. What remains missing is the bill’s statutory bridge from behavioral identification to prescribed export-control and sanctions review.
V. The Advisory Performs the Operationalization Problem
Advisory AA26-251A demonstrates the unsolved problem while attempting to solve it. Detection guidance asks providers to flag accounts by behavioral signature: sustained round-the-clock usage; new subscriptions at immediate maximum throughput; single accounts across many IPs; and traffic optimized for cache hits. MindCast’s assessment: several of the profile’s indicators also describe a legitimate high-throughput production agent fleet.
The recommended remedy compounds the difficulty. The advisory suggests serving suspected accounts a downgraded model without informing them, so a covert quality reduction aimed at adversaries lands equally on the false positives inside the detection net. A de facto provider-monitoring role has arrived before administrable standards.
Institutional lanes hold even at maximum specificity. The advisory lists 41 American models by version and maps the conduct to ten MITRE ATLAS techniques, yet it stays within threat characterization under a cybersecurity mission. The authoring agencies describe malicious behavior; they neither adjudicate trade-secret liability nor impose export consequences, because those powers sit in venues that have not moved.
Behavioral economics reads the advisory as a salience event that resets what regulators and boards treat as normal. Game theory reads it as a payoff shift arriving without a penalty, since expected sanctions remain where they were. The first public attempt to convert runtime telemetry into administrable triggers produced a profile with substantial false-positive potential and a covert remedy, the operationalization bottleneck this paper names.
VI. The Uncovered Object: Transcript Markets
A secondary market now trades the extraction product itself. Anthropic documents proxy services that log user exchanges with Claude and sell the transcripts, labs that purchased such corpora for training, and one lab that built a shell proxy offering only American models. SenseTime’s pipeline incorporated purchased exchanges harvested from users who never knew their sessions were logged for resale.
Drafted law expressly names the access intermediary but not the transcript intermediary. H.R. 8283 creates a defined category for fraudulent account-network providers and creates no parallel category for brokers of harvested inference transcripts. The traded artifact is a corpus of behavioral demonstrations whose strategic value emerges statistically across millions of ordinary interactions, and the Export Administration Regulations (EAR) do not map cleanly onto it because no controlled item or listed end user need touch the transaction.
Enforcement pressure creates an incentive to migrate toward the less expressly regulated layer. If account fraud acquires designation risk while purchased corpora do not, acquiring harvested interactions becomes comparatively more attractive than operating fraudulent accounts, since the purchaser inherits the capability without the conduct. The naming asymmetry marks where migration incentives concentrate, and Simulation Prediction S-3 in Section IX carries the observable.
VII. The Two-Way Runtime
Extraction ran in both directions, and the inbound flow complicates every clean narrative. To harvest Claude’s outputs, Moonshot and DeepSeek silently rerouted their own customers’ requests through Claude. The relayed traffic included surveillance-footage analysis linked to the People’s Liberation Army; live credentials for a Russian defense-ministry database; internal specifications of a flagship PRC AI program; and engineering work on a municipal police surveillance system.
Capability flowed outward while intelligence-relevant material flowed inward, leaving American providers with involuntary visibility into Chinese state and commercial activity as a byproduct of being robbed. Beijing can invert the frame by casting American labs as complainants who ingest Chinese government data. The paper does not adopt that framing; Simulation Prediction S-1 expects Beijing to deploy it.
Export control, privacy law and counterintelligence now meet supply-chain governance at a single interface, and each regulator holds one piece of a problem none fully owns. Runtime carries flows in both directions, and two-way governance is harder than perimeter governance because no single regulator owns the interface.
VIII. Fragmented Instruments and the Redesigned Rule
Commerce holds instruments rather than an architecture. Compute controls on advanced chips remain enforced, and the June letters demonstrated authority to restrict access to named models and then exempt trusted partners. Yet the only control ever written for model weights sits unenforced.
Export Control Classification Number (ECCN) 4E091 remains in the Code of Federal Regulations unenforced since May 2025, with the Government Accountability Office questioning the legality of the non-enforcement. The rescinded framework had drafted both halves of the needed distinction by pairing anti-extraction security requirements with an express allowance for ordinary inference. The Bureau of Industry and Security (BIS) stopped enforcing the document containing them.
MindCast mapped the same architecture at the chip layer in January. The TSMC China License and the Limits of Hardware Export Controls found that annual licensing staffed the gate while the fence stayed unbuilt, with workload identity and post-approval behavioral monitoring unimplemented. The gap this paper documents at the model layer repeats that structure one layer up.
A replacement remains pending rather than scheduled. The official Unified Agenda entry states BIS intends to rescind portions of the January 2025 framework and issue a more streamlined rule, with no legal deadline attached. Trade reporting shows a July 2026 publication target already slipped toward a fiscal-year-end aim, with the delay attributed partly to coordination failures among the agencies that must approve export rules.
The delay is consistent with the thesis without establishing the source of the interagency disagreement. What it establishes is that the replacement architecture stays unsettled while the extraction problem keeps evolving, so operationalization failure is the rulemaking’s observed condition rather than only this paper’s forecast.
Aerospace’s Warning to AI forecast the migration in November: compute-access licensing for conductive third countries, backed by identity-anchored access and workload logging. The jurisdiction class that analysis named is now the target of reported rulemaking.
A separate proposal reported in July would close remote-access routes through Thailand and Singapore, and practitioners already question whether Commerce can reach remote access under traditional authority. The design choice in front of BIS forms this paper’s forward lock: the redesigned rule either adopts conduct-based elements such as identity verification and telemetry duties, or it re-controls objects and leaves the documented arbitrage channel open. The instruments are fragmented rather than absent, and the missing piece is a settled unit of account for extraction conducted through lawful-looking interaction.
IX. MindCast Foresight Simulation Predictions: Enforcement Migrates to Conduct
The formal MP CDT FS run releases six Simulation Predictions below: three Primary (P) and three Secondary (S), in numeral order. Each carries an event probability and a sensitivity band, with a settlement window and an explicit falsifier. The governing mechanism is a hybrid architecture: object and model-access controls hold upstream while extraction-specific enforcement migrates toward entity, intermediary, identity and telemetry signals.
P-1. 84% (sensitivity band 78-89%). Through September 2027 federal policy operationalizes runtime extraction primarily through entity, end-user and intermediary measures and provider telemetry rather than licensing of ordinary foreign inference. Falsified if direct licensing of ordinary inference becomes the principal instrument, or if no material federal operationalization occurs by the window close.
P-2. 71% (sensitivity band 64-78%). The first BIS rule after the cutoff that replaces or materially implements the rescinded diffusion framework contains at least one conduct-based element: identity verification, a telemetry or reporting duty, or an extraction-conduct trigger. Falsified by an object-only reissue that licenses chips, weights or models without any such requirement.
P-3. 83% (sensitivity band 77-88%). No Entity List addition or sanctions designation of the six advisory-named labs occurs before the 24 September 2026 Trump-Xi summit opens. Falsified by any pre-summit designation of a named firm.
P-1 does not depend on P-2. Federal runtime governance can migrate toward entity and telemetry enforcement across several instruments even if the first replacement rule stays predominantly object-based, so the object-reversion default that holds P-2 below P-1 leaves the operationalization pathway intact.
S-1. 61% (sensitivity band 52-69%). Through the first quarter of 2027 Beijing escalates beyond neutral-technology framing and publicly invokes bidirectional exposure, casting American providers as recipients of Chinese state or commercial data routed through distillation systems. Falsified if no official ministry statement in the window makes that argument.
S-2. 77% (sensitivity band 69-82%). Through September 2027 cross-provider extraction-indicator sharing formalizes into a publicly named standing mechanism: a consortium, a standard, or an agency-coordinated program. Falsified if sharing stays bilateral and ad hoc through the window.
S-3. 79% (sensitivity band 72-85%). Through the next completed federal rule or enacted statute addressing model extraction, no named regulatory category is created for brokers of already-harvested inference transcripts or behavioral corpora. Falsified if that instrument expressly names and burdens the transcript-broker role. Existing privacy, fraud or trade-secret law does not falsify unless the extraction-specific instrument names the role.
X. Risk Mitigation
Each registered Simulation Prediction carries an exposure, a set of unilateral mitigating actions, and a residual that survives full mitigation. Actions are analytic options rather than legal, investment, or fiduciary advice. Exposure severity and probability are separate axes, so a lower-probability register can warrant more mitigation than a higher-probability one.
P-1. Operationalization pathway (84%). Binds 💼 Executives and ⚖️ Counsel. Executives running frontier-model access face compliance retooling once entity, intermediary, and telemetry duties land. Exposure: unbudgeted engineering and legal quarters, since detection and reporting systems rebuild on a regulator’s timeline rather than a product one. Mitigating actions: engineering builds provider-side telemetry and identity verification ahead of any mandate (owner: platform lead, before the first qualifying rule); counsel maps current access terms against the H.R. 8283 conduct indicia (owner: general counsel, this quarter). Residual: an over-broad federal detection standard can still sweep legitimate agent-fleet traffic that no private build anticipates.
P-2. Conduct element in the replacement rule (71%). Binds 🏛️ Policymakers and ⚖️ Counsel. Counsel advising on export posture faces a rule whose unit of control stays undecided. Exposure: discovery and compliance scope written against the wrong instrument, since a conduct-based rule and an object-only rule demand different records. Mitigating actions: counsel prepares both compliance postures rather than one (owner: trade counsel, before the rule issues); policymakers press for an explicit conduct-versus-object determination in the rulemaking record (owner: agency liaison, during the comment window). Residual: interagency dissensus can produce a hybrid rule that fits neither prepared posture cleanly.
P-3. No pre-summit designation (83%). Binds 📊 Investors and ⚖️ Counsel. Investors holding exposure to the six named labs or their counterparties face a designation calendar tied to a summit. Exposure: multiple compression on a sudden designation, since a pre-summit naming would reprice supply and partnership relationships inside days. Mitigating actions: investors stress-test positions against a designation scenario before the 24 September window (owner: risk desk, this month); counsel reviews counterparty contracts for designation-triggered clauses (owner: transactional counsel, before the summit). Residual: a security shock can override the summit-delay logic and trigger designation regardless of the calendar.
S-1. Bidirectional counter-narrative (61%). Binds 🏛️ Policymakers and 💼 Executives. Policymakers and providers face a Chinese counter-argument that US labs ingest Chinese state and commercial data. Exposure: narrative loss on the diffusion debate, measured in lost agenda control during the rulemaking, if the relay findings become an official Chinese talking point. Mitigating actions: providers document and disclose relay exposure on their own terms before it is characterized for them (owner: policy communications, this quarter); policymakers pre-position the involuntary-receipt distinction in the record (owner: agency liaison, before the window closes). Residual: the underlying relay facts remain adverse regardless of framing discipline.
S-2. Indicator-sharing formalization (77%). Binds 💼 Executives and ⚖️ Counsel. Providers weighing a standing sharing mechanism face antitrust and telemetry-exposure questions. Exposure: legal risk from coordinated information exchange, since a sharing consortium among competitors invites scrutiny under its own body of law. The obvious action carries its own exposure, so the constrained version is an agency-coordinated channel rather than a direct competitor consortium. Mitigating actions: counsel structures any participation through a government-hosted mechanism with defined scope (owner: antitrust counsel, before joining); executives limit shared signals to attack indicators rather than commercial data (owner: security lead, at design). Residual: participation still exposes internal detection methods to peers and to the government.
S-3. Transcript layer stays unnamed (79%). Binds 🏛️ Policymakers and ⚖️ Counsel. Policymakers drafting the extraction rule leave the transcript-broker role uncovered while the market for harvested corpora operates. Exposure: an enforcement gap measured in the volume of capability transfer that moves through a channel no instrument names. Mitigating actions: policymakers add a defined transcript-broker category to the rulemaking scope (owner: drafting staff, before the rule closes); counsel advising corpus purchasers documents data origin to distinguish licensed from harvested material (owner: compliance counsel, ongoing). Residual: a rule that names the category still faces the origin problem, since harvested corpora resist attribution.
An action taken against P-1 telemetry exposure also reduces S-2 participation cost, since the same provider-side instrumentation feeds both a mandate and a sharing mechanism. The linkage is noted without either register claiming the action twice.
XI. What to Watch
Six dated observables settle the register. Each maps to a Simulation Prediction and its falsifier, so a reader tracks the forecast against the public record rather than the argument.
The dominant near-term fork is the unit of control in the replacement rule. The first qualifying BIS rule directly settles P-2 and materially updates P-1. P-1 can still settle through Entity List, intermediary or telemetry instruments even if that first rule stays predominantly object-based.
Before the 24 September 2026 summit: designation calendar (P-3). Watch the BIS Entity List and the OFAC Specially Designated Nationals list for any of the six advisory-named firms. A pre-summit designation falsifies P-3; silence through the summit opening confirms it.
First qualifying BIS rule after cutoff: the unit of control (P-2). Watch the Federal Register for RIN 0694-AJ90 or its successor. A conduct-based element (identity verification, telemetry duty, or extraction trigger) confirms P-2; an object-only reissue falsifies it.
Through September 2027: operationalization pathway (P-1). Watch BIS guidance and Entity List actions plus State or OFAC measures for entity, intermediary and telemetry instruments. Principal reliance on those instruments confirms P-1; a licensing regime for ordinary inference, or no material action by the window, falsifies it.
Through March 2027: Beijing’s frame (S-1). Watch MOFCOM, MOFA and MIIT statements for the bidirectional-exposure argument. An official statement casting American providers as recipients of Chinese data confirms S-1; confinement to neutral-technology framing falsifies it.
Through September 2027: sharing mechanism (S-2). Watch for a named standing cross-provider mechanism: a consortium, a standard, or an agency-coordinated program. A named mechanism confirms S-2; bilateral and ad hoc sharing through the window falsifies it.
Next completed extraction rule or statute: the transcript layer (S-3). Watch the operative text for a named transcript-broker or behavioral-corpus category. Absence confirms S-3; an express category for the role falsifies it.
XII. Conclusion: Conduct Becomes the Unit
Runtime Theft closed by asking how many interactions transfer capability and how quickly law learns to name the actor on the other side. September answered the second half: platform telemetry named the actors, three agencies independently named overlapping actors, and Beijing answered with normalization. The first half is now the live contest.
The evidence does not show that Commerce restricted the wrong model. Commerce demonstrated exactly the power everyone assumed it lacked by restricting access to named models worldwide inside a week. Model identity no longer suffices as the unit of control, because the conduct is model-agnostic and flows along safeguard gradients the classification system cannot see. Congress has drafted the conduct-based test, industry has published the dataset that populates it, and the advisory has shown how the conversion fails without administrable standards.
The attribution problem has not disappeared; it has compressed. The next bottleneck is operationalization: converting aggregate runtime telemetry into an administrable enforcement trigger without turning ordinary inference into a controlled export.
The competitiveness stakes sit underneath the enforcement question. A frontier lead measured in years collapses toward months when capability transfers through interaction, and the operationalization gap is the interval in which that transfer runs unpriced. Naming the conduct is how a state converts a technical lead into a durable one.
Prediction stays inexpensive while capability moves fast and governance stays scarce. The scarcest governance asset is now a unit of account: a definition separating a customer from a campaign before the campaign finishes. The government that defines it first sets the terms of AI trade enforcement.
Working With MindCast
MindCast converts institutional uncertainty into dated, falsifiable decision forecasts. Each engagement below keys to a register in this paper.
Export-control posture mapping (P-1, P-2). For counsel and compliance leaders: a dual-posture readiness map against both a conduct-based and an object-only replacement rule, built before the first qualifying Federal Register rule issues.
Designation-exposure stress test (P-3). For investors and transactional counsel: a position and counterparty review against a pre-summit designation scenario, keyed to the 24 September window.
Runtime-governance foresight retainer (P-1, S-2, S-3). For policymakers and provider strategy teams: a standing read on the operationalization pathway, the sharing-mechanism question, and the transcript-layer gap that The Runtime Global Data Market develops.
Contact mcai@mindcast-ai.com. See Live-Fire Game Theory Simulators, Runtime Predictive Infrastructure.
Sources
MindCast works
Anthropic, Alibaba, and the Runtime Theft Problem (2026). The June publication whose Simulation Predictions this paper assesses and whose attribution-cost mechanism it extends.
The Runtime Global Data Market (2026). The companion analysis of the transcript-broker layer this paper’s S-3 register identifies as the next uncovered object.
MindCast: Why AI Commoditizes Raw Prediction, Why Governance Stays Scarce (2026). Supplies the governance-scarcity structure that explains why extraction economics favor attackers.
Aerospace’s Warning to AI, How Capability Laundering Will Reshape Corporate Compliance (2025). Forecast compute-access licensing for conductive third countries ten months before the reported remote-access rulemaking targeted that jurisdiction class.
The TSMC China License and the Limits of Hardware Export Controls (2026). Documented the gate-without-fence gap at the chip layer that this paper documents at the model layer.
The Global Innovation Trap (2025). Argued competitors capture frontier capability at a fraction of originating R&D cost, the economic mechanism the distillation record instantiates.
The Beijing Summit Validation (2026). Establishes the two-board structure governing the China registers.
Primary record
“Detecting and Countering Misuse of AI: September 2026,” Anthropic, September 10, 2026.
“China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies,” Advisory AA26-251A, NSA, CISA and FBI, September 8, 2026.
H.R. 8283, Deterring American AI Model Theft Act of 2026, 119th Congress, introduced April 15, 2026.
Secondary record
“Commerce Department Extends Export Controls to Advanced AI Models,” Mayer Brown, June 30, 2026.
“U.S. AI Export Controls in 2026: A Practitioner’s Guide,” One Lex Partners, June 19, 2026.
“Choosing Between U.S. and Chinese AI Models: The Export Control Risks on Both Sides,” Sheppard Mullin, July 23, 2026.
“New US Export Controls Reportedly Target Chinese Access to Remote AI Servers,” Tom’s Hardware, July 22, 2026.
“US Accuses China AI Developers DeepSeek and Alibaba of Copying American AI,” NBC News, September 8, 2026.



