Balancing Antitrust Concerns with Collaborative AI Security Initiatives

0
1

Key Takeaways

  • Antitrust uncertainty is a major barrier preventing U.S. AI firms from collaborating on security‑wide collaboration on risks such as model distillation, weaponization, and loss of oversight.
  • Adversarial distillation by Chinese labs is shrinking the U.S. lead in frontier models from 12‑18 months to only 4‑6 months, accelerating the spread of dangerous capabilities.
  • Existing voluntary forums (e.g., Frontier Model Forum) are limited in membership and cannot overcome legal fears; smaller startups are especially disadvantaged.
  • A bipartisan legislative proposal—the Collaboration on Adversarial Threats and Security Risks Act—mirrors the 2015 Cybersecurity Information Sharing Act, offering targeted antitrust safe‑harbors for sharing information and coordinating delayed releases to mitigate AI security risks.
  • The Act includes safeguards (good‑faith burden, internal controls, DOJ notification, potential injunctive relief) to prevent abuse while giving companies the clarity needed to act quickly against threats like distillation, cyber‑weaponization, and loss of model control.

The Growing Urgency of AI‑Related Security Threats
The United States government is racing to stop the misuse of frontier AI models’ cybersecurity capabilities against government operations, critical infrastructure, and private‑sector networks. Chinese labs are only months behind U.S. companies, and techniques such as model distillation are enabling rapid diffusion are rapidly eroding the American technological edge. Without coordinated action, advanced capabilities demonstrated by models like Mythos and GPT‑5.6 could soon be available to criminals and hostile intelligence services worldwide.

How Antitrust Fears Stifle Beneficial Collaboration
Because AI progresses at breakneck speed, companies need to share threat information and coordinate defensive measures on short timelines. Yet antitrust law remains unclear, making in‑house counsel reluctant to authorize researchers to reach out to counterparts at other firms. The fact‑specific nature of antitrust analysis, coupled with time‑intensive legal reviews, deters busy technical staff—especially at smaller startups that lack resources for extensive counsel engagement—from pursuing joint security work.

Industry Calls for Government Intervention
For years, leading frontier labs such as OpenAI, Google DeepMind, and Anthropic have publicly urged policymakers to address antitrust concerns that block security‑related cooperation. Off‑the‑record discussions reveal that employees frequently cite their companies’ legal teams’ fears of antitrust liability as the chief reason collaboration remains limited. A 2024 Institute for Law & AI analysis warned that, absent guidance or a safe harbor, risk‑averse legal teams will unlikely permit meaningful communication between rank‑and‑file employees across competitors.

The Impact of Withdrawn Antitrust Guidelines
The problem intensified in late 2024 when the Department of Justice and the Federal Trade Commission withdrew the 2000 Antitrust Guidelines for Collaborations Among Competitors. Although those guidelines were generic, they offered some reassurance about how enforcement agencies view competitor collaborations. Their removal has heightened uncertainty, leaving firms without even a baseline reference point for assessing the legality of information‑sharing or joint defensive actions.

Why Existing Tools Fall Short in the AI Context
Mechanisms that have helped reduce antitrust risk in other sectors—formal contracts, notification under the National Cooperative Research and Production Act, or seeking FTC advisory opinions/DOJ business reviews—are often too slow or ill‑suited for the fast‑moving AI research environment. The lengthy timelines associated with these processes cannot keep pace with the urgent need to share threat data or coordinate delayed model releases, rendering them impractical for addressing imminent security risks.

Limited Current Collaboration and Its Shortcomings
Some collaboration persists through the Frontier Model Forum (FMF), whose members include Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI. The FMF has facilitated information‑sharing efforts, but its membership excludes SpaceXAI, startups, and many smaller developers, leaving a significant portion of the industry without a legal‑safe avenue to cooperate on security matters. Consequently, the forum’s impact is constrained by both its narrow reach and the overarching antitrust hesitation that prevents deeper, coordinated action.

Adversarial Distillation as a Case Study
Adversarial distillation illustrates precisely how antitrust fears impede needed cooperation. Earlier this year, Google, OpenAI, and Anthropic disclosed a pattern of Chinese industrial‑scale distillation attacks targeting their closed‑weight models accessed via web, apps, or APIs. By using deceptive techniques to elicit outputs, Chinese labs train new open‑weight models that can be freely downloaded, altered, and run locally—bypassing the external safeguards (classifiers, monitors) that protect closed models. Internal safeguards also fail to transfer reliably into distilled models, and any refusal training can be cheaply fine‑tuned away.

Erosion of the U.S. Technological Lead
The executive director of the FMF, Chris Meserole, testified that the U.S. once enjoyed a 12‑ to 18‑month lead over foreign models, but distillation attacks have narrowed that gap to only 4‑6 months. The United Kingdom’s AI Security Institute observed a similar shrinkage in the gap for cyber capabilities—from 6‑10 months in 2025 to 4‑7 months by mid‑2026. When Anthropic released a preview of its Mythos model (a leap in cyber ability) to a trusted partner group, the broader release was avoided precisely to limit distillation risk; nonetheless, the White House’s Office of Science and Technology Policy confirmed that Moonshot AI distilled the related Fable model to produce its Kimi K3 model.

The Need for Coordinated Defensive Measures
Meserole emphasized that the information required to counter distillation is scattered across many industry actors. The Center for a New American Security identified useful data points—account indicators, network origins, behavioral patterns, hashed prompts—that could be shared among U.S. firms to detect and block distillation attempts. Yet, under current antitrust apprehension, FMF members have taken a “conservative approach” even to discuss identification of distillation, let alone devise counter‑measures.

Beyond Information Sharing: Coordinated Release Delays
Effectively combatting distillation may require more than sharing threat intel; it could necessitate coordinating delayed releases of frontier models to trusted partners, thereby extending the window before open‑weight equivalents appear. However, such coordination risks resembling an output restraint, which could be construed as a per se antitrust violation. Similar legal concerns arise if companies attempted to jointly provide the U.S. government with extended pre‑release access to models for evaluation—an approach that could improve public safety but is discouraged by antitrust fears. Under a rule‑of‑reason review, public‑safety justifications for such restraints often fail to outweigh perceived anticompetitive effects, reinforcing the need for congressional clarification.

Learning from the Cybersecurity Precedent
The situation mirrors the early 2010s, when antitrust doubts hampered private‑sector sharing of cyber threat information. In 2014, the DOJ and FTC issued a joint policy statement asserting that antitrust should not block legitimate cybersecurity information sharing. The following year, the Cybersecurity Information Sharing Act of 2015 (CISA) codified that stance, granting explicit statutory protection for sharing certain cybersecurity‑related data. While CISA did not substantively change the antitrust landscape, it provided the clarity and certainty that encouraged broader participation.

Proposed Legislative Solution: The Collaboration on Adversarial Threats and Security Risks Act
Recognizing that agency guidance alone would not shield firms from private plaintiffs or state law claims, Senators Adam Schiff (D‑CA) and Jim Banks (R‑IN) and Representatives Bob Latta (R‑OH) and George Whitesides (D‑CA) introduced the Collaboration on Adversarial Threats and Security Risks Act on July 23. The bill mirrors CISA’s approach, creating a targeted safe‑harbor for collaboration on six categories of “covered artificial intelligence security risks”:

  1. Weaponization or theft—including distillation—by a covered nation (China, Russia, North Korea, Iran) that threatens national security.
  2. Facilitation of chemical, biological, radiological, nuclear, or offensive cyber weapons.
  3. Certain serious risks to critical infrastructure.
  4. Substantial reductions in the ability to oversee or disable AI.
  5. Autonomous improvement of AI that poses any of the above risks.
  6. Vulnerability to unauthorized access that poses any of the above risks or is directed by a covered nation.

The Act would protect information sharing and assistance aimed at addressing these risks, as well as coordinated efforts to delay model development or release when done for defensive purposes. Crucially, the safeguards require companies to demonstrate good‑faith intent, implement internal controls to limit misuse of shared data, and notify the DOJ before enacting coordinated delays. If a company’s actions are found to increase the covered risks despite a good‑faith claim, the DOJ could seek injunctive relief. These provisions make abuse for anticompetitive ends highly unlikely while preserving existing antitrust enforcement for outright violations.

Why Swift Legislative Action Is Critical
The “Mythos moment”—triggered by a sudden leap in cyber capabilities—demonstrates how quickly security concerns can arise, with similar challenges likely to emerge in biological or other domains. The DOJ and FTC issued cybersecurity guidance in April 2014, and CISA became law in December 2015, a span of only twenty months. Yet, as of mid‑2026, no comparable guidance exists for AI security risks, and the pace of AI development means the next twenty months will bring fresh threats that individual firms cannot adequately counter alone. By enacting the Collaboration on Adversarial Threats and Security Risks Act promptly, Congress can give U.S. companies the legal certainty needed to share threat data, coordinate defensive delays, and collectively preserve the nation’s strategic advantage in AI.

Authors’ Note
Through the Law Reform Institute, the authors developed a legislative proposal on this topic last year. LRI provided input on the Collaboration on Adversarial Threats and Security Risks Act to the sponsors’ offices and has expressed support for the bill.

Featured Image: The U.S. Capitol building is seen on July 25, 2026 in Washington, DC. (Photo by Kevin Carter/Getty Images)

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here