As Chinese models have moved closer to the US models in capabilities, there is growing chatter from US government sources that they could end up being regulated or banned in some way.
The latest round came within hours of each other on Wednesday, when three senior US officials used the same platform to accuse a single Chinese company, Moonshot AI, of stealing American AI technology through what they called covert, industrial-scale distillation. Treasury Secretary Scott Bessent sent out a warning that walked a careful line. The US supports open-source AI, he wrote, but “open source is not open season on American IP.” When Chinese firms conduct covert, industrial-scale distillation attacks that cross into IP theft, he said, sanctions and Entity List designations will be on the table.
OSTP Director Michael Kratsios followed with the specific allegation: the US has information that Moonshot AI distilled Anthropic’s Fable model to help build its K3 model. Kratsios said Moonshot built a sophisticated internal platform to run large-scale distillation against US models, switching between multiple methods of access to dodge detection. He also claimed the company has acquired GB300-equipped servers and accessed GB300 chips in Thailand, likely to train its models, a workaround that would sidestep US export controls on advanced Nvidia hardware.
Under Secretary of State Jacob Helberg rounded out the trio with the most pointed language of the three, calling the alleged distillation “more than a heist of invaluable American Intellectual Property” and an assault on any economy that rewards private capital and fair competition. Lying, cheating, and stealing, he wrote, is not innovation and not “win-win.”
The pattern is familiar
This is not the first time Washington has made this accusation. In February, OpenAI told the US government that DeepSeek and other Chinese labs were using hidden techniques to distill US models. In April, the White House Office of Science and Technology Policy went further with a formal memo saying it would “explore a range of measures to hold foreign actors accountable” for distilling American AI models. That memo also noted that Anthropic had previously flagged DeepSeek, Moonshot AI, and MiniMax for creating over 24,000 fraudulent accounts and generating more than 16 million exchanges with Claude, in violation of its terms of service.
Moonshot AI’s Kimi line has had a remarkable run since then. Kimi K2 became the strongest open-source model on several benchmarks last July. K2.5 followed in January, beating every US model on Humanity’s Last Exam and BrowseComp. K2.6 arrived in April, edging out GPT-5.4 and Claude Opus 4.6 on several agentic benchmarks. Kimi K3, the model now at the center of the distillation allegation, has reportedly been trading benchmark blows with the best OpenAI and Anthropic have to offer.
The analysis holds less weight than the accusation
There’s a lot to be skeptical of here, and it starts with timing. This accusation lands one day after a federal judge gave final approval to Anthropic’s own $1.5 billion settlement with authors and publishers, the largest copyright payout in history, over claims that the company downloaded roughly 500,000 pirated books to train Claude. Judge William Alsup, who oversaw the case before retiring, had already ruled that the way Anthropic acquired those books was illegal on its own terms. Anthropic avoided a trial by settling. A company that just paid out over a training data scandal of its own is not the most credible messenger for a lecture on intellectual property theft, and the government backing that message would do well to notice the irony.
Then there’s the matter of proof. None has been offered. Kratsios’s claims about an internal distillation platform and GB300 access in Thailand are specific enough to sound authoritative, but specificity is not evidence. No documentation, no technical trail, no third-party verification has accompanied any of these three posts. Governments have made confident public claims about tech companies before that didn’t hold up once independent researchers looked. Given that a designation on the Entity List can cut a company off from American hardware and software entirely, that’s a significant threat to make on the strength of unverified assertions.
The deeper problem is definitional. Every major AI lab, American ones included, trains its models substantially on data scraped or distilled from the open web, and increasingly from the outputs of other models. Distillation itself, training a smaller model on a larger one’s outputs, is a completely mainstream technique that OpenAI, Google, and Anthropic all use internally to produce lighter versions of their own frontier systems. The April OSTP memo itself acknowledged as much, calling legitimate distillation “a vital part” of the AI ecosystem. Where exactly the line sits between that and the “industrial-scale” version Washington now wants to sanction remains vague. If a Chinese company is paying for API access the same way any other customer does, and using the outputs to train a new model, it’s not obvious what makes that theft rather than an expensive, if aggressive, business practice. The terms-of-service violations Anthropic flagged earlier this year are a real complaint, but a ToS breach and a national-security-grade IP heist are different categories of offense, and officials seem to be treating them as interchangeable.
None of this means Moonshot AI is innocent, or that concerns about the flow of American research to Chinese competitors are baseless. But the current strategy of stacking rhetorical pressure across three cabinet-level accounts on the same day, without releasing anything a journalist or researcher could independently check, looks a lot more like an attempt to shape the narrative around China’s AI gains than a serious enforcement action. Chinese self-sufficiency in AI chips has already climbed sharply, and export controls have not slowed the release cadence of labs like Moonshot, Z.AI, or DeepSeek in any visible way. Sanctions rhetoric may be the next lever Washington reaches for, but rhetoric alone won’t close a capability gap that’s been narrowing for over a year now.