- White House OSTP Director Michael Kratsios alleged that Moonshot AI distilled Anthropic’s Fable model to develop Kimi K3.
- Kratsios said Moonshot built an internal platform for large-scale distillation against US models, designed to switch between access methods to avoid detection.
- He also said Moonshot acquired GB300-equipped servers and accessed GB300s in Thailand — Blackwell-generation hardware the US bars from sale to Chinese companies.
- Treasury Secretary Scott Bessent warned the US could sanction Chinese AI models found to have been built through IP theft.
What Happened
Michael Kratsios, Director of the White House Office of Science and Technology Policy, accused Chinese AI company Moonshot of improperly using US AI models and restricted Nvidia chips to build its Kimi K3 system, Bloomberg reported on July 22, 2026. Kimi K3 was released on July 17 and drew attention as the largest open-weights model published to date.
“We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” Kratsios said. “To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.”
Why It Matters
The allegation targets both inputs a frontier model needs — training signal and compute — and the second is the one export controls were built to restrict. Kratsios said Moonshot “acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models.” GB300 systems are part of Nvidia’s Blackwell generation, which the US forbids selling to Chinese companies, and the Thailand reference points at third-country access rather than direct import.
Kratsios drew an explicit line between permitted and prohibited practice, saying “legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem,” while covert large-scale efforts to take proprietary US technology are not acceptable. Distillation itself is a standard technique: outputs from a teacher model are used to train a student model. What is being alleged is scale, concealment, and terms-of-service circumvention.
Technical Details
The described platform’s distinguishing feature is access rotation — switching between multiple methods of reaching US models to avoid detection — which is an operational-security design rather than a training innovation, and it is what separates this claim from ordinary API use. Detecting distillation from outputs alone is difficult, which is why the accusation rests on access patterns rather than on model forensics.
Anthropic, whose Fable model is at the center of the claim, has not said it holds evidence tying Kimi K3 specifically to distillation, though it accused Moonshot of the practice in February. That distinction matters: the US government is asserting information it has not published, and the company whose model was allegedly copied has not corroborated the specific K3 link.
Kimi K3 is a 2.8-trillion-parameter open-weights model. Bloomberg Intelligence separately measured the Chinese-US model performance gap at 6% in June, down from 9% in May.
Who’s Affected
Moonshot faces the most direct exposure. Treasury Secretary Scott Bessent warned that the US could sanction Chinese AI models found to have been built through intellectual property theft — a measure that would target a model rather than only a company, which is a novel application of sanctions authority. Congressional legislation aimed at Chinese firms conducting unauthorized distillation of US models has advanced in both chambers.
Nvidia’s channel is implicated by the Thailand claim, since GB300 access through a third country implies either diversion or a compliant local deployment being used remotely. Thai data center operators, which just recorded an 80% surge in foreign investment applications largely tied to AI infrastructure, sit in the middle of that question.
US labs face a narrower operational consequence: if distillation at scale is being conducted through rotating API access, the countermeasure is tighter identity verification and rate governance on frontier endpoints, which raises friction for legitimate enterprise and research customers as well. Anthropic, OpenAI, and Google all publish terms prohibiting training competing models on their outputs, and enforcement has so far depended on detection rather than prevention.
What’s Next
The government has not published the underlying evidence, and Moonshot has not responded publicly to the specific allegations. The concrete next steps are the sanctions authority Bessent invoked and the distillation bills moving through Congress; either would apply prospectively, and neither addresses a model whose weights are already public and downloaded.