When U.S. Treasury Secretary Scott Bessent declared that “open source is not open season on American IP,” he wasn’t speaking in abstractions. Hours earlier, the White House had named a specific target: Moonshot AI, the Chinese company behind the recently released Kimi K3 model, accused of systematically siphoning proprietary technology from Anthropic. The episode has brought US Treasury AI sanctions from a vague threat into an active policy instrument — and the broader AI industry is taking notice.
Summary
Key takeaways
- Treasury Secretary Scott Bessent warned that sanctions and Entity List designations are on the table for Chinese AI firms found to have stolen U.S. intellectual property through covert model distillation.
- White House science and technology policy chief Michael Kratsios publicly accused Moonshot AI of conducting large-scale distillation of Anthropic’s Fable model to build its Kimi K3.
- Kratsios alleged Moonshot acquired Nvidia GB300-equipped servers — banned exports to Chinese companies — and accessed them in Thailand, likely to train its AI models.
- Moonshot released K3 last week as an open-weight model; experts question whether it could have been primarily built through distillation of Fable, which has only been publicly available since July 1.
- The incident has reignited calls in Washington to restrict or ban the use of Chinese open-weight AI models on national security grounds.
US Treasury issues sanctions warning over AI intellectual property theft
Bessent’s position is direct: the U.S. government will examine open source AI models coming out of China for signs of intellectual property theft, and if violations are confirmed, sanctions and Entity List designations will follow. He posted on X that when Chinese firms “conduct covert, industrial-scale distillation attacks that cross the line into IP theft,” consequences are coming.
This wasn’t a first warning. Earlier in the week, Bessent had already put Chinese AI developers on notice, framing the issue as one of economic security and technological sovereignty. Wednesday’s statement — timed to amplify Kratsios’s accusation — signals a coordinated escalation from the administration, not an isolated comment.
What “industrial-scale distillation attacks” actually means
Model distillation is a legitimate and widely used technique in AI development. It works by training a smaller, more efficient model on the outputs of a larger one — compressing capability without rebuilding from scratch. AI labs use it routinely. The problem, according to U.S. officials, is when that process is applied covertly and at scale against a competitor’s proprietary system without authorization — crossing from optimization into what they’re calling theft.
The legal and technical line between legitimate distillation and IP infringement is genuinely blurry. That complexity is part of why the government’s framing matters: by calling it “industrial-scale” and “covert,” officials are signaling intent to prosecute cases where the scale and concealment suggest deliberate misappropriation, not routine model compression.
White House accuses Moonshot of misusing Anthropic’s Fable via AI distillation
Michael Kratsios, director of the White House Office of Science and Technology Policy, went further than general warnings. “We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” he wrote on X, making the accusation specific and public.
Kratsios described a deliberate concealment operation. According to his account, Moonshot developed a sophisticated internal platform designed to conduct large-scale distillation against U.S. models, with the ability to switch quickly between multiple access methods to avoid detection. That framing — emphasizing evasion infrastructure — is significant. It suggests the White House is presenting this not as accidental boundary-crossing but as a structured program to extract proprietary capability from American AI systems.
Anthropic’s head of public policy, Sarah Heck, responded positively on X, thanking Kratsios and calling illicit adversarial distillation “IP theft and industrial espionage that supports adversary military and intelligence capabilities.” She said Anthropic would continue working with the White House and Congress on the issue. Notably, Anthropic had already publicly accused Moonshot — along with two other companies — of distillation attacks violating its terms of service, back in February.
A notable alignment between the Trump administration and Anthropic
The political dynamic here is worth flagging. The Trump administration previously imposed export controls blocking Anthropic from releasing its most advanced model internationally, and the Pentagon moved to blacklist the company in February. The White House and Anthropic have not been natural allies. This episode represents a rare convergence of interests — and Heck’s public endorsement of Kratsios’s statement underlines just how seriously Anthropic views the distillation threat.
Moonshot’s use of restricted Nvidia GB300 servers raises export control concerns
Beyond the distillation allegations, Kratsios raised a second serious concern: Moonshot allegedly acquired Nvidia GB300-equipped servers, which are part of Nvidia’s Blackwell generation and are explicitly banned from sale to Chinese companies under U.S. export-control rules. He further alleged that Moonshot accessed those servers in Thailand, likely to train its AI models — a potential attempt to use third-country infrastructure to circumvent the restrictions.
This matters because export controls on advanced AI chips are one of Washington’s primary tools for limiting China’s ability to develop frontier AI. If Chinese companies are successfully routing around those controls through third-party access points in countries like Thailand, the policy effectiveness is substantially undercut. The allegation, if confirmed, would represent a significant enforcement failure — and likely accelerate pressure for stricter extraterritorial controls on Nvidia hardware.
Release of Moonshot’s K3 model sparks debate on AI innovation and security
Moonshot released K3 last week as an open-weight model, and its performance has been striking. According to Business Insider, Kimi K3 is widely regarded as the most impressive open source AI model released to date, performing at or above the level of Anthropic and OpenAI’s leading frontier models in benchmark testing. That performance, achieved apparently at a fraction of the cost, has unsettled discussions about whether leading U.S. AI labs can continue justifying the enormous capital requirements of the frontier AI race.
The timing of the distillation accusation, however, introduces an important complication. Some experts dispute the idea that K3 could have been developed primarily through distillation of Fable, given that Fable only became publicly available on July 1. Building a model of K3’s apparent sophistication primarily through distillation in such a short window would be technically ambitious, to say the least. That skepticism doesn’t necessarily clear Moonshot of wrongdoing — distillation may have played a partial role — but it does complicate a clean narrative of straightforward IP extraction.
The broader policy consequence is already taking shape. Dean Ball, former White House AI adviser and current Head of Strategic Futures at OpenAI, has argued that the U.S. should restrict or effectively ban the use of Chinese open-weight models entirely, citing both national security risks and the threat to American technological advantage. That position is gaining traction in Washington even as the technical facts of this specific case remain contested.
TechCrunch reported that it has reached out to both Moonshot and the U.S. Treasury for comment; neither had responded at time of publication.
What makes this moment consequential isn’t just the specific allegations against Moonshot. It’s the infrastructure being built around them — a framework in which open-weight AI models from China become subject to sanctions review, export-control scrutiny, and potential Entity List designations. Whether the K3 accusations hold up under technical examination, the machinery of enforcement is now clearly in motion, and any Chinese AI firm releasing capable open models will need to reckon with that reality.
FAQ
What is AI model distillation and why is it controversial?
Model distillation is a technique where a smaller AI model learns from the outputs of a larger, more powerful one. It’s a common and legitimate method for creating more efficient models, but it can infringe on intellectual property rights when applied without authorization to proprietary systems — particularly at scale and with deliberate concealment, as U.S. officials allege in Moonshot’s case.
Why is Moonshot being accused of IP theft?
The White House, through science and technology policy chief Michael Kratsios, alleges that Moonshot conducted large-scale, covert distillation of Anthropic’s Fable model to develop its Kimi K3 AI model, going so far as to build an internal platform designed to switch between access methods to avoid detection. Anthropic had previously accused Moonshot of distillation attacks violating its terms of service in February.
What hardware did Moonshot allegedly use that raised export concerns?
Moonshot allegedly acquired Nvidia GB300-equipped servers — part of Nvidia’s Blackwell generation — which are banned from being sold to Chinese companies under U.S. export-control rules. Kratsios alleged that Moonshot accessed these servers in Thailand, likely to train its AI models, raising questions about circumvention of export restrictions.
How is the US government responding to these allegations?
Treasury Secretary Scott Bessent has warned that sanctions and Entity List designations are on the table for Chinese AI firms found to have engaged in covert, industrial-scale distillation attacks that cross into IP theft. The U.S. government has also stated its intention to examine Chinese open source AI models for signs of intellectual property violations and act accordingly.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

