Logo
FrontierNews.ai

Congress Targets AI Model Theft as Health Care Grapples With Defensive AI Risks

Congress is moving to criminalize AI model theft by foreign adversaries, while health care organizations confront a growing paradox: the same AI tools that can defend against cyberattacks also expand the attack surface if not properly secured. Two separate developments this week highlight how AI security has become both a national security priority and an operational challenge for vulnerable industries.

What Is AI Model Distillation and Why Does Congress Care?

Lawmakers introduced the Blocking Large-Scale Adversarial Distillation Efforts (BLADE) Act on Wednesday, targeting what the White House has flagged as a critical threat: foreign actors, particularly Chinese developers, training their own AI models by copying American AI systems in a process called distillation. Unlike traditional intellectual property theft, distillation allows adversaries to extract the knowledge embedded in a proprietary AI model without stealing the underlying code or weights.

Senator Bill Hagerty, who introduced the bipartisan bill alongside Senators Tim Scott, Andy Kim, and Catherine Cortez Mastro, framed the issue as essential to U.S. competitiveness. "As the United States must remain at the forefront of competitiveness in artificial intelligence, we cannot allow our adversaries to steal the intellectual property of America's top AI companies and thereby threaten U.S. national security and economic security," Hagerty stated. The BLADE Act would require the Executive Branch to identify foreign entities conducting distillation operations, then impose export controls and financial sanctions through the Department of Commerce and Department of Treasury.

How Would the BLADE Act Protect American AI Companies?

The bill operates in three stages. First, the Executive Branch must identify and publicly release a consolidated list of foreign entities engaging in illegal distillation campaigns. Second, the Department of Commerce would impose export controls on those entities. Third, the Department of Treasury would apply financial sanctions. The approach mirrors existing frameworks for protecting other sensitive technologies, but applies them specifically to AI model theft.

The timing reflects urgency: the White House raised concerns about Chinese AI developers training models on American systems only weeks before the BLADE Act was introduced. By consolidating enforcement across two major departments, the bill aims to create a coordinated deterrent rather than fragmented responses.

Why Are Health Care Systems Becoming Targets for AI-Powered Attacks?

While Congress addresses foreign threats, health care organizations face a more immediate problem: their own embrace of AI is creating new vulnerabilities. Medical records sell for as much as $1,000 on the dark web, compared to just $1 to $3 for email credentials, making health systems prime targets. About half of health system executives surveyed last fall cited cybersecurity as a top concern in 2026, with organizations dedicating close to 14 percent of their technology budgets to defense.

The paradox is stark: as health systems deploy AI to streamline operations and improve diagnostics, they're simultaneously expanding their attack surface. Leaders often don't fully understand the heightened security risks AI introduces, which include nonconventional threats such as model manipulation, adversarial inputs, and data poisoning. Among health care organizations that experienced breaches involving AI, 97 percent said they lacked proper AI access controls.

What Are the Key Vulnerabilities in Health Care AI Systems?

  • Access Controls: Nearly all health care organizations that suffered AI-related breaches lacked proper access controls, allowing unauthorized users to interact with or manipulate AI systems.
  • Medical Device Security: Devices that embed AI can open invisible back doors for cybercriminals if insecurely connected to the internet, bypassing traditional network defenses.
  • Third-Party Vendor Risk: Health systems depend on external vendors whose cybersecurity practices may not meet hospital standards, creating supply chain vulnerabilities.
  • Clinical Staff Practices: Staff increasingly rely on AI tools to write clinical notes and summarize patient data, but these tools carry hidden risks if speed is prioritized over security.

Can Defensive AI Actually Protect Health Care Systems?

Recent AI tools designed for offensive security research can detect vulnerabilities even in sophisticated systems, and health care executives are watching closely. However, Deloitte experts warn that defensive AI cannot compensate for foundational weaknesses. "Even the best and most sophisticated AI tools cannot offset foundational weaknesses," the analysis noted.

The real challenge is that vulnerability discovery may now outpace remediation. If health systems deploy AI to find security gaps, they could identify problems faster than their teams can fix them. This creates a new operational bottleneck: deciding which vulnerabilities matter most and acting quickly enough to address them before attackers exploit them.

Steps to Strengthen Health Care Cybersecurity Without Relying Solely on AI

  • Prioritize Cyber Hygiene: Keep systems patched, maintain secure configurations, and reduce the external attack surface through basic maintenance and network hardening.
  • Establish Asset Visibility: Know what systems your organization owns, where they run, and how they're exposed, including blind spots in cloud and third-party environments.
  • Enforce Identity and Segmentation: Implement strong identity and access management, restrict administrative permissions, and segment networks to limit lateral movement if a breach occurs.
  • Develop Incident Response Plans: Create well-rehearsed playbooks with clear decision rights and tested communications to prevent and respond to cyberattacks effectively.
  • Embed Cybersecurity in Leadership: Make cybersecurity part of executive decision-making from the start, not an afterthought added after an attack occurs.

Health care organizations that fall behind are not those with the fewest AI pilots, but rather those with slow patch cycles, weak identity controls, unsegmented networks, limited third-party visibility, and inadequately tested recovery plans. In other words, organizations vulnerable to traditional attacks remain vulnerable to AI-enhanced ones.

The convergence of these two stories reveals a fundamental tension in AI security: as the U.S. government works to protect American AI innovation from foreign theft, domestic organizations must grapple with the reality that deploying AI defensively requires solving older, harder problems first. For health care, that means treating cybersecurity as a strategic priority, not a technology problem to be solved by the next generation of AI tools.