There is no way to enforce access of one and not the other, not with the state of tech in the US (and most countries without a great firewall). Bypassing such controls is as easy as a pilfered credit card (or some other american-looking payment method) and a vpn - both trivial to come by.
But that in itself is telling in a way: if national security was a true concern, access should be limited to people who passed background checks.
I guess I'm possibly giving them too much credit, but if the people who sent the letter have their head screwed on straight, "protecting national security by disallowing specifically non-citizens from using it" can really only be read as a smokescreen, or at very best a small part of the actual picture.
I’ve wondered this but then wouldn’t a large amount of input now just be AI output from a previous PR/client email/spec document/chat. Training of that would be an issue leading to distillation?