Michael Kratsios, director of the White House Office of Science and Technology Policy (OSTP), publicly accused Chinese AI startup Moonshot AI on July 22, 2026, saying the US has information that the company distilled Anthropic’s flagship model Fable to develop its latest model, Kimi K31. The same day, Treasury Secretary Scott Bessent warned that distillation amounting to intellectual property theft could trigger sanctions or Entity List designations23.
Distillation—training one model on the outputs of another—is itself a widely used and legitimate technique (see our explainer on model distillation and quantization). What is at issue here is covert, industrial-scale distillation in violation of terms of service. The accusation lands at a sensitive moment: Kimi K3 is a closely watched open model whose weights are slated for release by July 27 (see our coverage of the K3 announcement).
Kratsios’s Claim: An Internal Platform Built to Evade Detection
In his post on X, Kratsios wrote, “We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model”1. He further alleged that Moonshot built a sophisticated internal platform to conduct large-scale distillation against US models, designed to switch quickly between multiple methods of access to avoid detection14.
Kratsios also claimed Moonshot made use of export-controlled NVIDIA GB300 servers—“either newly acquired or through Thailand.” He did not explain how the government obtained this information, a point security-focused outlet CyberScoop noted in its reporting4.
Moonshot AI did not respond to CyberScoop’s request for comment before publication4.
Treasury Echoes: “Open Source Is Not Open Season on American IP”
Following Kratsios’s post, Bessent posted on X the same day. “We support open-source AI and the innovation it unlocks,” he wrote, before adding that “open source is not open season on American IP” and condemning covert, industrial-scale distillation by PRC firms2.
According to TechCrunch, Bessent indicated that if distillation-based IP theft is established, the US may impose sanctions or add companies to the Entity List, which effectively restricts exports of US products to designated firms3. The dispute over AI training practices has thus been elevated from a private terms-of-service matter between companies to a government-level issue that could carry trade and national-security consequences.
The Backstory: Anthropic’s February Report on 3.4 Million Exchanges
The accusation did not come out of nowhere. In its report “Detecting and preventing distillation attacks,” published on February 23, 2026, Anthropic said Moonshot AI had conducted a distillation campaign against Claude involving more than 3.4 million exchanges5. The targeted capabilities—agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision—overlap with the strengths the Kimi series markets.
The same report described distillation attacks by DeepSeek (over 150,000 exchanges) and MiniMax (over 13 million exchanges), and outlined Anthropic’s countermeasures: classifiers and behavioral fingerprinting systems designed to identify distillation attack patterns, sharing technical indicators with other AI labs and cloud providers, and tightening account verification5.
Kratsios’s claims align directionally with Anthropic’s report, but the government has not disclosed what independent evidence it holds4.
One Year After K2 Went Open Source
Moonshot AI open-sourced the 1-trillion-parameter Kimi K2 in July 2025, establishing itself as a leading maker of agent-oriented open models (see our earlier coverage). Kimi K3, announced on July 16, 2026, has 2.8 trillion parameters; the company bills it as the world’s first open 3T-class model, and third-party evaluations have placed it near the frontier.
Meanwhile, the US–China AI split has widened this year. On the Chinese side, Alibaba has restricted internal use of Claude Code, accelerating a move away from US-made AI tools; now the US has targeted the training methods behind a Chinese model. Fable is Anthropic’s flagship model announced in June (see our launch coverage), and the claim that its capabilities were the target of distillation underscores how frontier-model competitiveness has itself become a national-security issue.
Geopolitical Risk Enters Model Selection
For readers evaluating AI for business use, this dispute bears directly on how to choose open-weight models. Kimi K3’s weights are due out by July 27, and on performance and price it could be a compelling option. But if US sanctions or an Entity List designation materialize, embedding the model in business workflows would carry contractual, procurement, and reputational risks that are hard to ignore.
For now, the US government has not disclosed its evidence and Moonshot has not responded, so the facts are unlikely to be settled quickly. Even so, the episode reinforces a trend we have noted before: model selection increasingly requires weighing not just performance and price but also the provider’s capital ties, the provenance of training data, and regulatory developments across jurisdictions. The open-model landscape is shifting rapidly—as covered in our Alibaba Qwen 3.8 article—and we will keep tracking this story as it develops.
Sources
- Michael Kratsios’s post on X - Original statement by the OSTP director
- Scott Bessent’s post on X - Original statement by the Treasury Secretary
- Treasury threatens sanctions after White House claims Moonshot distilled Anthropic’s Fable - TechCrunch
- White House accuses Chinese company of distilling Anthropic’s Fable - CyberScoop
- Detecting and preventing distillation attacks - Anthropic official report (February 2026)