Skip to content
News

Washington Threatens to Sanction Chinese AI Firms Over Alleged IP Theft — But the Timeline Doesn’t Add Up

Treasury Secretary Bessent threatens sanctions on Chinese AI firms for distillation attacks, naming Moonshot’s Kimi K3 — but researchers say the timeline makes the accusation hard to square.

6 min read
Washington Threatens to Sanction Chinese AI Firms Over Alleged IP Theft — But the Timeline Doesn't Add Up

Washington just turned up the heat on Chinese AI companies in a very public way. US Treasury Secretary Scott Bessent doubled down on his warnings to Chinese AI companies, saying that sanctions remain on the table after a White House official accused Moonshot of improperly distilling Anthropic’s Fable model. The target of the accusation: Kimi K3, a 2.8-trillion-parameter open-weights model of such impressive quality that its mere existence suggests Chinese AI researchers aren’t far behind their US rivals.

The accusations come wrapped in tough language, real policy teeth — and a timeline that several AI researchers say simply does not hold up.

Restricted chips, rerouted through Thailand.
Restricted chips, rerouted through Thailand.

What Washington Actually Claimed

Michael Kratsios, who leads the White House Office of Science and Technology Policy, claimed that Moonshot AI distilled Anthropic’s recently-released Fable model to develop its own K3 model, stating that “they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” The accusation goes beyond software: Kratsios also alleged that Moonshot had acquired Nvidia’s GB300-equipped servers and accessed GB300s in Thailand, likely to train its AI models — raising questions about whether the firm violated US export-control rules, given that these servers are part of Nvidia’s Blackwell generation, which are banned from being sold to Chinese companies.

Bessent backed it up with a post on X that left little room for interpretation. “Open source is not open season on American IP,” Bessent wrote. “When [Chinese] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.” A day earlier, on Fox Business, he went further: “We are finding watermarks of our U.S. large language models on many of the Chinese models, and that’s unacceptable,” Bessent said. “We’re going to be looking at that in the coming days or weeks.”

Kratsios did not provide details on how the US government learned that K3 had been distilled from Anthropic’s model. The Chinese embassy in Washington called Kratsios’ comments “entirely unfounded,” with spokesperson Liu Chang adding that China respects intellectual property protections.

A Pattern That Predates K3

The K3 accusation is not the first time Washington and Anthropic have pointed fingers at Chinese labs. Anthropic accused Moonshot AI of distillation in February 2026 and said its Chinese peers DeepSeek and MiniMax also used the technique. DeepSeek, Moonshot and MiniMax created more than 16 million interactions with Claude using roughly 24,000 fake accounts, in violation of Anthropic’s terms of service and regional access restrictions, the company said.

Then came the bigger bombshell. Anthropic sent a letter dated June 10, 2026 to Senate Banking Committee Chair Tim Scott and Ranking Member Elizabeth Warren alleging that operators affiliated with Alibaba’s Qwen AI lab conducted the largest known distillation attack on its Claude models — a campaign that generated more than 28.8 million exchanges with Claude through approximately 25,000 fraudulent accounts, targeting Claude’s software-engineering and agentic-reasoning capabilities. The disclosure is already driving legislative action: Senators Bill Hagerty and Andy Kim are moving to add an amendment to defense legislation to blacklist or sanction entities conducting such campaigns.

Training a frontier model is no two-week job.
Training a frontier model is no two-week job.

The Timeline Problem

Here is where the story gets complicated. Some experts dispute the idea that K3 could have been developed primarily through distillation of Fable, given that Fable only became publicly available on July 1. Building a model of K3’s apparent sophistication primarily through distillation in such a short window would be technically ambitious, to say the least — and that skepticism doesn’t necessarily clear Moonshot of wrongdoing, but it does complicate a clean narrative of straightforward IP extraction.

Braden Hancock, a researcher at the Laude Institute and co-founder of AI startup Snorkel AI, told TechCrunch it would be “almost impossible” to train a model as capable as Kimi K3 from Fable 5 outputs in that timeframe, saying “there’s just not even frankly time.” Nathan Lambert of the Allen Institute for AI and Elie Bakouch of Prime Intellect expressed similar skepticism about the technical timeline, and Dean Ball, head of strategic futures at OpenAI, said he did not believe distillation could account for the model’s performance.

Moonshot’s own employees threw the timeline back at Washington. “Yes, Fable went public on July 1 and K3 launched on July 15. We trained a brand new frontier model in JUST 15 DAYS. Guinness World Record stuff,” Moonshot AI employee Randy Xian wrote on X. The sarcasm landed. Nathan Lambert added that “distillation is becoming less and less impactful over time as the Chinese models get closer to the frontier and the training regime shifts to reinforcement learning.”

Some researchers raised a counter-argument, however: Ryan Greenblatt, chief scientist at Redwood Research, pointed out that Moonshot could have obtained unauthorized access before Fable was released via actors with prerelease access, or possibly by hacking Anthropic directly.

The Glass-House Problem

Washington’s righteous tone on IP theft runs into an awkward reality. Both Anthropic and OpenAI have faced their own accusations of theft in recent years: Anthropic agreed to pay $1.5 billion in September 2025 to settle a class action lawsuit with a group of authors, who alleged that the company illegally downloaded books from pirated databases. The New York Times sued OpenAI and Microsoft in 2023, alleging that the companies infringed on copyright by using its intellectual property to train models. The moral high ground here is, at minimum, contested terrain.

Meanwhile, Bessent floated another idea on Fox Business that could have sweeping implications for the industry: “If we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft,” Bessent told Fox Business. He also raised a separate question worth watching: whether companies using Chinese models should be required to disclose that fact to their customers — a disclosure requirement that could reshape enterprise AI procurement overnight.

What’s Next: Talks, Sanctions, or Both?

The confrontation arrives at a diplomatically awkward moment. The United States and China are planning to hold talks over AI in September, five sources familiar with the matter told Reuters, as the superpowers confront how to regulate the risks posed by their increasingly powerful rival frontier models — with talks likely to take place before Chinese President Xi Jinping’s planned September 24 visit to the US. The September talks will be led on the US side by Treasury Secretary Scott Bessent.

That means the same man threatening to sanction Moonshot AI is also set to sit across the table from Chinese counterparts to negotiate AI governance. Whether threatening sanctions before that meeting is a negotiating strategy or a genuine enforcement path is the open question in Washington right now. The targets of sanctions, the legal basis, and the certification process have not yet been made public — and the next policy decision will require more than repeated allegations. K3’s benchmarks made one thing undeniable: Chinese open-weight models are gaining steam against leading offerings from American companies like OpenAI and Anthropic, sparking real concerns about the durability of the US lead in the AI race. Sanctions or not, that gap is closing.

author avatar
Promptyze
Promptyze covers generative AI in plain English — hands-on reviews, tutorials and daily news, fact-checked and hype-free.

Promptyze

ADMINISTRATOR

Promptyze covers generative AI in plain English — hands-on reviews, tutorials and daily news, fact-checked and hype-free.

$ sitemap --all The whole site in one place — so you never get lost.