President Donald Trump put the artificial intelligence race in blunt terms Sunday: “whoever wins AI wins.” His comment came as Anthropic CEO Dario Amodei urged AI companies to slow the development of increasingly capable frontier models and strengthen independent evaluation, industry coordination, and international safeguards.
Amodei’s warning deserves serious attention. But Trump is right about one strategic fact: a unilateral slowdown by American laboratories would not automatically slow Chinese competitors.
That creates a harder policy problem. If Washington wants U.S. companies to keep moving fast, it also has to make it more difficult for strategic competitors to harvest the capabilities those companies spend billions developing.
On Monday, I argued in these pages that American AI leadership requires continuity controls strong enough to withdraw a system’s authority without shutting down the services around it. The China problem is the external counterpart: preserve American speed while making organized extraction of restricted capabilities harder and more expensive.
Last week, the National Security Agency, FBI, and Cybersecurity and Infrastructure Security Agency described what they called industrial-scale distillation campaigns by China-based AI companies against U.S. frontier models. According to the advisory, the activity was distributed across model providers, cloud platforms, and other infrastructure to avoid single-point detection while extracting restricted proprietary capabilities for use in Chinese models.
The distinction matters because distillation itself is not misconduct. It is a standard machine-learning technique in which a smaller model learns from the outputs of a larger one. The policy concern begins when access restrictions are deliberately evaded, identities or origins are concealed, and coordinated querying is used at scale to acquire capabilities a provider has chosen not to make available that way.
This is where the slowdown debate and the China competition meet.
If the United States responds to AI risk mainly by slowing domestic development, while organized foreign extraction remains cheap, fragmented, and difficult to detect, Washington could impose the largest burden on the firms it most wants to remain ahead. A race strategy that ignores leakage risks subsidizes whoever can copy fastest.
The answer should be targeted enforcement rather than a blanket brake on American AI.
The federal advisory itself points toward the first step: model providers, cloud companies, API aggregators, and infrastructure firms need a faster way to share indicators of coordinated extraction. A campaign deliberately divided among multiple services may look harmless from any one company’s dashboard. The government’s useful role is to help connect those fragments without turning ordinary model use into a licensed activity.
Commerce and Treasury should also focus on the infrastructure that makes deceptive extraction scalable: proxy networks, intermediaries, payment channels, and commercial entities that repeatedly conceal origin or end use to defeat lawful restrictions. The objective is not to regulate model outputs as a category. It is to raise the cost of organized evasion.
Federal procurement offers another pressure point. Providers seeking sensitive government business should be able to demonstrate that they can detect industrial-scale extraction, preserve evidence, coordinate with other providers, and interrupt a campaign without degrading service for legitimate users. That treats model security such as other forms of supply-chain and cyber resilience as a measurable operational capability.
None of these measures resolves the larger safety questions Amodei is raising. Nor should Trump’s dismissal of exaggerated claims become an excuse to ignore genuine model risk. Safety evaluation, continuity planning, and competitive protection address different problems.
That distinction is precisely why Washington should resist choosing between slowing down and doing nothing.
America can move quickly while making its systems easier to evaluate, easier to suspend safely when necessary, and harder to exploit at an industrial scale. The common principle is control: know what a system can do, know when its authority should change, and know who is trying to acquire capabilities outside the rules.
TRUMP IS RIGHT ABOUT QUANTUM. NOW THE PENTAGON HAS TO PROVE IT WORKS
Trump’s formulation is blunt but strategically useful. If whoever wins AI wins, the United States cannot define winning only as building the strongest model first. It also has to keep that lead defensible.
Winning the AI race means moving fast without making American breakthroughs cheap to copy.
Burak Oktenli is based in Washington, D.C., and studies applied intelligence at Georgetown University. The views expressed are his own.
