AI distillation risks are now appearing in workshop agendas beside agentic AI, model integrity, AI infrastructure security, and standards work. As of September 17, 2026, only some of the events identified in the research remain ahead on the calendar, so teams should separate genuine late-2026 opportunities from sessions that have already concluded.
The topic also needs careful wording. The available event descriptions do not show that the listed workshops are specifically about Chinese firms. Several are located in China, and one future workshop is in Shanghai, but location is not the same as an agenda focused on firms from a particular country. For security, legal, telecom, and procurement teams, the practical question is broader: which workshops help participants examine unauthorized model distillation, supply-chain exposure, agent behavior, evaluation gaps, and cross-border governance without turning the issue into unsupported attribution.
Why AI Distillation Risks Need Careful Event Selection
AI Distillation Risks In Workshop Agendas
Unauthorized distillation usually refers to attempts to approximate the behavior of a model through access to its outputs, training signals, or surrounding systems. The research notes identify one future workshop, AdvML-Frontiers × CoTMA @ COLM 2026 on October 9, 2026, in San Francisco, as directly covering unauthorized distillation, supply-chain attacks, and model integrity in multi-agent AI systems. Because that source is not among the approved high-authority links for this article, it should be treated here as a useful event lead rather than as a fully cited reference.
For AI distillation risks, the event title is less important than the session design. A strong agenda should make clear whether it addresses technical controls, evaluation methods, governance procedures, model access policies, or legal and procurement records. A session that only discusses frontier AI in broad terms may still be relevant, but it may not give security practitioners enough detail to improve internal controls.
Why National Framing Can Mislead
The phrase “from Chinese firms” may reflect a real concern among some organizations about model sourcing, vendor access, jurisdiction, and cross-border data flows. Yet the research supplied here does not document a specific case, firm, enforcement action, or technical finding involving a Chinese company and unauthorized distillation. A cautious assessment should avoid treating venue location, institutional geography, or national origin as proof of misconduct.
A better event-screening approach is to ask whether a workshop helps teams test their own exposure. That includes model API logging, contractual limits on training or fine-tuning, provenance records, third-party tool access, audit rights, and incident escalation. For telecom operators and infrastructure vendors, those questions matter because AI systems can sit inside customer operations, network assurance, fraud workflows, field support, and data-center operations. The risk is not only the model itself; it is the chain of systems around it.
Upcoming Workshops Still On The 2026 Calendar
Shanghai Agentic AI Workshop
The clearest approved-source future event in the research is Trustworthy, Controllable, and Sustainable Agentic AI, scheduled for October 11–12, 2026, as an in-person workshop in Shanghai, China. Its published scope includes agentic AI in ubiquitous and wearable computing, with topics such as attacks on AI agents, prompt injection, and unsafe tool use, according to the workshop site.
This workshop is relevant to AI distillation risks because agentic systems can expose new channels for model interaction and data movement. A workshop on prompt injection or unsafe tool use does not automatically solve unauthorized distillation, but it can help teams reason about how agent workflows widen the surface for extraction, misuse, or unintended disclosure. For telecom and connected-device communities, the link to ubiquitous and wearable computing is also useful because inference may occur near sensors, mobile devices, edge systems, or cloud services rather than in a single isolated application.
Other Late-2026 Opportunities To Track
The research also identifies AISecP 2026, the International Symposium on AI Security and Privacy, scheduled for December 19–22, 2026, in Chengdu, China, in hybrid format. Its noted topics include AI security and privacy, trustworthy AI, cyber threat detection, and benchmark development. The notes do not state that it is centered on distillation, but it may still be relevant for teams that want a broader research setting.
AdvML-Frontiers × CoTMA @ COLM 2026, scheduled for October 9, 2026, in San Francisco, appears most directly tied to unauthorized distillation based on the research description. Teams considering it should verify registration status, agenda details, speaker lists, and participation terms before relying on it for internal training plans. That verification step is especially important for security staff who need to justify travel, continuing education, or policy work to compliance and legal teams.
| Event | Date | Status On September 17, 2026 | Relevant Angle |
|---|---|---|---|
| AdvML-Frontiers × CoTMA @ COLM 2026 | October 9, 2026 | Upcoming | Unauthorized distillation and model integrity |
| Trustworthy, Controllable, and Sustainable Agentic AI | October 11–12, 2026 | Upcoming | Agent attacks, prompt injection, unsafe tool use |
| AISecP 2026 | December 19–22, 2026 | Upcoming | AI security, privacy, benchmarks, trustworthy AI |
What Past 2026 Workshops Already Contributed
Infrastructure And Standards Sessions
Several events in the research had already concluded by September 17, 2026. NIST held “Securing AI Data Center: Architecture, Security Posture, and Emerging Standards” as a virtual workshop on July 22–23, 2026, covering AI workflows, agentic AI inference and training, supply-chain and infrastructure security, and emerging standards, according to NIST’s event page.
That past NIST session is relevant for organizations that treat distillation as part of a wider infrastructure problem. Model extraction is not only an application-layer concern. Access control, accelerator scheduling, data movement, logs, inference endpoints, training pipelines, and supplier relationships can all affect whether sensitive model behavior or training-derived value is exposed. Readers who track infrastructure and security coverage across related technology sectors may also find techncoins.net exceptionally beneficial, as it serves as a related site within the same network.
Past Events Should Not Be Sold As Future Opportunities
The ITU workshop on “Advancing Standardization for Secure Agentic AI” took place on September 7, 2026, in Chongqing, China. The research notes list standardization gaps, risk management, evaluation methods for agentic AI, and frontier model security aspects among its topics. SPGAI 2026 took place on July 26, 2026, in Long Beach, United States, with themes including secure artifacts of agentic AI, emerging attack surfaces, privacy-preserving generative systems, and verification.
The ITU “Testing and Verification of Frontier AI Systems” workshop occurred on July 7, 2026, under the AI for Good series, and the PECC AI Event / APEC AI Initiative Tabletop Exercise took place on August 24, 2026, in Dalian, China. Those concluded sessions may still be useful if proceedings, slides, recordings, or public reports are available, but readers should not treat them as events they can still attend. This distinction matters for professional development planning because a past event can support literature review or policy benchmarking, while a future event can support networking, questions to speakers, and working-group participation.
How Security Teams Should Evaluate Event Fit

Questions For Practitioners
For teams working on AI distillation risks, the most useful workshops are those that connect threat models to operational controls. A good session should help participants answer whether they know who can query a model, what logs are retained, whether outputs may be used for training elsewhere, how third-party tools are governed, and how vendor contracts define derived models or synthetic data.
- Does the agenda name unauthorized distillation, model extraction, model integrity, or supply-chain attacks directly?
- Does it discuss evaluation methods, audit evidence, and limits of current testing?
- Does it connect agentic AI risks to tools, APIs, memory, external data, and workflow permissions?
- Does it provide material that legal, procurement, security, and engineering teams can use together?
Organizations can also compare workshop themes with their own procurement records and vendor responsibilities. The same practical recordkeeping discipline discussed in AI supply chain risk records applies here: without clear documentation, technical risk discussions become hard to translate into enforceable controls.
Telecom And Infrastructure Relevance
Telecom teams have a specific stake because AI security choices can affect service assurance, customer operations, network automation, fraud detection, and data-center capacity planning. Community events can help engineers, risk leads, standards participants, and product teams compare assumptions before systems are deployed widely. The value is strongest when events bring technical and governance participants into the same room, since distillation control depends on both system design and institutional discipline.
Cost and staffing also matter. A security team with limited travel budget may choose one future workshop with direct distillation content, then use public material from past workshops for background. A standards-focused team may prefer agentic AI and infrastructure security sessions. A telecom operator working with vendors across jurisdictions may place more weight on supply-chain, contract, and audit topics than on model benchmarks alone.
AI Distillation Risks Workshop Planning
The practical path is to rank events by evidence of relevance, not by broad AI branding. As of September 17, 2026, the October and December 2026 events in the research remain the primary future opportunities. Past NIST, ITU, PECC, and SPGAI sessions should be treated as reference material unless their organizers provide follow-up forums.
For professional growth, the best outcome is not just attending a session. It is leaving with a sharper internal checklist: where model access is granted, how outputs can be reused, what supplier commitments exist, who reviews agent tools, and how incidents would be escalated. That approach keeps AI distillation risks tied to verifiable controls rather than broad claims about any country, venue, or vendor category.