Treasury Sanctions Loom—White House Accuses Moonshot of Distilling Anthropic’s Fable
In Brief
- White House tech adviser Michael Kratsios accused China’s Moonshot AI of distilling Anthropic’s Fable model to build its Kimi K3 open-weight release.
- Treasury Secretary Scott Bessent threatened sanctions and Entity List designation, saying “open source is not open season on American IP.”
- Moonshot reportedly acquired Nvidia GB300 servers and accessed them in Thailand to train the model, raising export-control concerns.
The Trump administration escalated its AI confrontation with China on Wednesday, with White House science and technology policy director Michael Kratsios alleging that Beijing-based Moonshot AI ran a “large-scale, covert industrial distillation” campaign against Anthropic’s Fable model. In a post on X, Kratsios said the U.S. government has “information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” the 2.8 trillion-parameter open-weight system Moonshot released on July 17. He added that Moonshot had “developed a sophisticated internal platform to conduct large-scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.”
Treasury Secretary Scott Bessent doubled down within hours. “Open source is not open season on American IP,” Bessent posted on X. “When [Chinese] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.” In a separate interview with Fox Business, Bessent said U.S. authorities were “finding watermarks of our US large language models on many of the Chinese models, and that’s unacceptable.”
Model distillation—where a smaller model learns from a larger one’s outputs—is a widely used training technique. But Kratsios alleged Moonshot deployed it at scale using fake accounts and automated access to bypass payment and rate limits. In February, Anthropic identified Moonshot among three Chinese companies that generated over 16 million interactions with Claude using roughly 24,000 fake accounts, violating its terms of service and regional access restrictions.
How Distillation Became a National Security Flashpoint
The U.S. has been constructing a legal framework to treat AI model theft as a sanctions-worthy offense for months. In April, the White House issued National Security Technology Memorandum 4, designating adversarial distillation as a national security threat. Anthropic itself urged Congress in June to penalize companies behind distillation attacks and tighten chip access loopholes after alleging that Alibaba mounted a campaign generating 28.8 million exchanges through nearly 25,000 fraudulent accounts targeting agentic reasoning and software engineering capabilities.
Expert reaction has been cautious. Some researchers note that Kimi K3 arrived only 16 days after Fable’s public debut, and they dispute whether Moonshot could have trained a frontier-class model primarily through distillation in that window. Still, the accusation has sharpened Washington’s willingness to treat model extraction as an export-control violation rather than a competitive inevitability.
What the GB300 Chip Allegation Changes
Kratsios’s claim that Moonshot acquired Nvidia GB300 servers and accessed them in Thailand is the escalation. The GB300, part of Nvidia’s Blackwell generation, is banned from sale to Chinese entities under U.S. export controls. If verified, the server allegation would give Treasury a clearer path to blacklist Moonshot under existing authorities rather than relying on the murkier IP-theft framework.
The pattern echoes a February disclosure that DeepSeek trained models on banned Nvidia chips—a revelation that led to tightened export rules but stopped short of direct sanctions against the company. Bessent’s Entity List threat would cut off Moonshot’s access to U.S. technology stacks and payment rails. For an Alibaba-backed startup, that would be significant. But without public evidence of the distillation pipeline or precise server locations, the administration risks treating national security claims as routine competitive weapons.
FAQ
What is AI model distillation?
Distillation is a training technique where a smaller model learns to mimic a larger one by learning from its outputs, often to make models faster or cheaper to run.
Did Moonshot actually steal Anthropic’s model?
The U.S. government alleged it, but no public evidence of the distillation pipeline has been released. Anthropic previously reported suspicious activity from Chinese accounts.
Can the U.S. really sanction Chinese AI startups?
Yes. Treasury can add companies to the Entity List, blocking access to U.S. technology and financial systems. Bessent said sanctions are “on the table.”