8-minute read | 1,700 words
What to know this week
China is using US AI models for research.
Chinese military research units are allegedly using US AI models to train their smaller, portable models.
US water system cyberattack continues to expand.
Since originally beginning in Minnesota, the cyberattack targeting water facilities has expanded to impact over half a dozen states.
This week's full stories
China researchers using US AI models for defense systems.
THE NEWS
On Friday, researchers released key findings that alleged Chinese military units are using US AI models to train AI defense systems. In the report, researchers reviewed over eighty Chinese academic papers and patents looking specifically at how Chinese military units are using frontier AI models to speed up development processes.
More specifically, reports found that Chinese units were using a technique known as “model distillation.” This technique involves using a more powerful AI system to train smaller, more specialized models that are capable of being deployed rapidly and without the need for major computing power.
Researchers also noted that Chinese defence institutions see these frontier models as both a source of technical insight and a way to close the AI gap with the US.
Sunny Cheung, a Jamestown fellow who analysed over sixty papers published by the Chinese military on AI, noted:
“These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally.”
For example, in one paper published by PLA Unit 96941, the group highlighted using GPT-3.5 to process sensitive military source code. In their findings, Chinese researchers emphasized that third-party models were unsuitable for handling classified information and that GPT-3.5 could summarize software code and train domestic models.
THE KNOWLEDGE
This research comes as the US and China plan to meet in September to hold AI talks. While the specifics of when this meeting will occur have not been announced, the two nations are looking to discuss how to mitigate the risks posed to each other by frontier AI models.
Additionally, the topic of China using the US’s frontier models despite restrictions will inevitably be discussed. In an interview, Treasury Secretary Scott Bessent commented:
“We are finding watermarks of our US large language models on many of the Chinese models, and that’s unacceptable.”
Outside of this future conversation, given how close the two nations are for advanced AI models, it is also possible that the US looks to strengthen its export controls on AI model diffusion.
While the former Biden administration did implement the AI diffusion framework in January 2025, the Trump administration undid these rules in May 2025. At the time, the Trump administration stated that these requirements would have "stifled American innovation and saddled companies with burdensome new regulatory requirements.” Afterwards, the Trump administration looked to focus more on chip export controls rather than model diffusion.
THE IMPACT
This latest research represents one of the greatest challenges within the global AI race.
While the US has spent years restricting China’s access to advanced semiconductor chips, preventing access to frontier AI models is considerably more challenging. Techniques such as model distillation allow researchers to extract capabilities from larger proprietary models and transfer them into smaller systems that can be operated domestically with far less computing power. By using these techniques, nations that lack access to major computing reserves can still create advanced models.
The findings will also likely increase calls for the federal government to increase controls on frontier AI models. While the Trump administration did shift away from the former Biden administration's AI diffusion framework, this new evidence could reignite debate over how model access and national security are intertwined.
More broadly, the report also highlights a growing reality for AI competition. As frontier AI models continue to become tied to military assets, policymakers will have to evaluate who is developing these models, who has access to them, and how these models are being used both domestically and internationally.
US water system cyberattacks continue to grow.
THE NEWS
Throughout last week, reports continued to emerge that water providers across several states were experiencing a coordinated cyberattack. More specifically, water providers in at least seven states were impacted, forcing facilities to switch to manual operations and prompting the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) to warn facilities nationwide of hackers.
These water utility attacks began sometime between July 26-27 when over thirty Minnesota water facilities were targeted. In the initial cyberattack, Minnesota IT Services released a statement that the group had "immediately activated the state’s cybersecurity incident response capabilities."
Days later, Michigan also began reporting that it was experiencing cyberattacks on nine of its water systems.
The FBI and EPA also released a joint statement writing that the attackers had remotely accessed internet-connected systems and proceeded to change administrator passwords and cause operational disruptions. These disruptions included flooding and pressure loss, which “could potentially allow untreated ground water to seep into pipes.”
The Cybersecurity and Infrastructure Security Agency (CISA) also issued an alert noting that:
“Even water organizations with mature cybersecurity processes should validate their external connections.”
The alert also outlined mitigation techniques to increase security.
The FBI is still investigating who launched these attacks, though Iran is a top suspect.
THE KNOWLEDGE
While it is unclear who launched the attack, this incident comes shortly after several agencies released a joint statement last week discussing ongoing Iranian-affiliated cyber activity. Specifically, the agencies warned about attacks targeting the US’s water systems, energy services, and government services and facilities.
In the alert, the agencies warned that hackers were oftentimes aiming to exploit programmable logic controllers (PLCs) from a variety of device makers. To counter these attacks, the agencies urged organizations to apply strict access control limitations on PLC devices and validate all project files running the PLCs.
These attacks highlight a continuing concern regarding critical infrastructure cybersecurity within the US. Whether telecommunications, energy, water, or government services, critical infrastructure sectors remain attractive targets as many rely on legacy operational technology, internet-connected systems, and difficult-to-patch equipment. At the same time, disruptions can have immediate consequences for millions, making these organizations attractive targets.
Previously, Iranian-linked threat actors targeted water systems in 2023 shortly after the war in Gaza began in 2023. In this cyber incident, the Iranian-linked group, CyberAv3ngers, targeted multiple PLCs and human machine interfaces across several states. By compromising these devices, actors were able to gain deeper device and network-level access, having the potential to leave "profound cyber-physical effects on processes and equipment.”
While the incident was contained and mitigation steps were published, the attack demonstrated the gaping hole in the sector’s cybersecurity defenses. Afterwards, the EPA conducted a follow-up cybersecurity audit, which found hundreds of critical vulnerabilities, including in drinking water systems, remained present.
THE IMPACT
The latest attacks suggest that cyber campaigns against US water infrastructure are becoming both more coordinated and more operationally focused. Being able to force multiple utilities to switch to manual operations across multiple states demonstrates the severity and complexity of the threat actors.
While disruptions are contained, the incident illustrates how even brief unauthorized access to these industrial systems can create major real-world consequences. Changes to pressure levels, chemical treatment, or pumping operations can quickly affect drinking water availability and safety, making these facilities all the more attractive for adversarial governments to target.
If investigators attribute the campaign to Iran, it would also reinforce a broader concern regarding Iran’s ability to successfully disrupt water facilities within the US multiple times in a short period of time. For defenders, the latest campaign serves as another example that operational technology security is not a niche concern but an essential component of national security.
This Week's Caveat Podcast: Tracking people, training AI.
Ben Yelin and Ethan Cook look at two stories focused on privacy and AI. The first story looks at how Flock cameras were abused by a police officer to track down and harass a former partner. The second looks at recent research that shows how the Chinese military is using frontier AI models to train its smaller models through a technique known as model distillation.
OTHER NOTEWORTHY STORIES
White House finalizes AI safety testing requirements.
What: The White House has finalized the details for its voluntary AI cybersecurity testing requirements.
Why: On Monday, the White House announced that it had finalized its voluntary cybersecurity testing requirements for AI models. Technology leaders met with the Trump administration Tuesday to discuss these requirements. The framework will be used to address potential safety and national security risks.
In a statement, a White House official stated:
“The voluntary framework outlined in the June 2nd executive order was complete by the deadline. Discussions with industry about next steps are underway.”
The specific details of these tests have not been made publicly available.
AUGUST 3, 2026 | Source: Politico
China increases chip design protections.
What: China is tightening its protections on chip layout designs.
Why: On Monday, China released revised regulations regarding chip designs. For these new regulations, China is prioritizing protecting integrated-circuit layout designs, tightening registration standards, and allowing for punitive damages for serious infringement.
These rules cover chip layouts, including how components are arranged, though there are no new regulations related to export controls.
These revised regulations are expected to take effect on October 15.
AUGUST 3, 2026 | Source: Reuters
VA fails watchdog FISMA audit on IT security.
What: An independent review found the Department of Veterans Affairs (VA) was deficient in several areas related to IT security.
Why: In an independent review, the Office of the Inspector General reported that the VA is still failing its Federal Information Security Modernization Act audits.
The audit was conducted by CliftonLarsonAllen LLP (CLA) in 2025. According to the results, the VA was deficient in vulnerability management, incident response and monitoring, configuration management, identity management and access control, contingency planning, background investigations, and security management programs.
In the report, the CLA stated:
The “VA continues to face significant challenges in complying with FISMA due to the nature and maturity of its information security program.”
The VA has pushed back on these findings, emphasizing that the department has already implemented security measures following relevant recommendations.
JULY 28, 2026 | Source: FedScoop
