White House Office of Science and Technology Policy Director Michael Kratsios put an official U.S. government label on what had been, until now, a private dispute: he said China's Moonshot AI ran a "sophisticated internal platform to conduct large-scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection," targeting Anthropic's Fable model in the process of building Kimi K3. Separately, Kratsios said Moonshot "acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models" -- a direct workaround of the U.S. export ban on Nvidia's most advanced Blackwell-generation chips to Chinese buyers. "Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem," Kratsios said, but "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable."
The accusation didn't come out of nowhere. Anthropic itself flagged Moonshot for distillation attacks that violated its terms of service back in February, arguing the startup was systematically querying Claude-family models to bootstrap its own training data rather than building from scratch. What's new is that the complaint has now moved from a company's ToS enforcement to the desk of a White House science and technology official, with Treasury Secretary Scott Bessent telling Fox Business the administration is actively examining whether Chinese AI models more broadly were built on stolen U.S. intellectual property. Kratsios said the government will begin screening open-source releases out of China for signs of theft going forward, with sanctions and Entity List designation -- the same tool used against Huawei and SMIC -- explicitly on the table if violations are confirmed.
The timing sharpens the politics considerably. Moonshot shipped Kimi K3 on July 16 to genuine acclaim -- Hacker News threads calling it competitive with Fable, benchmark charts putting it in the same tier as frontier U.S. labs -- and the model's quality is precisely what triggered the scrutiny. Within days, Nvidia CEO Jensen Huang went to a Wistron plant opening in Fort Worth, Texas, and told reporters American companies should "absolutely" be free to run Chinese models: "These Chinese models are excellent... open-source models that are excellent should be used." Huang's comments came hours after Bessent's remarks about IP theft, putting Nvidia's own CEO publicly at odds with the administration's framing during the same week his company's China revenue has fallen to essentially zero -- down from a business Huang once said could be worth $50 billion a year.
“The GB300 allegation matters as much as the distillation one.”
The GB300 allegation matters as much as the distillation one. GB300 is the current top of Nvidia's Blackwell lineup and is barred from sale into China under existing export controls; if Moonshot really did access GB300-equipped servers through Thailand-based intermediaries, it's evidence the chip-smuggling problem the administration has been fighting since the first Blackwell restrictions hasn't gone away, it's just routed through Southeast Asia. Huang himself has previously called black-market data centers built from smuggled parts a "dead end," which makes his defense of the resulting models -- as opposed to the chip access that trained them -- a nuance the administration doesn't appear willing to grant.
For VCs and founders, the read-through is about provenance risk. Any portfolio company quietly relying on Kimi K3, or any other Chinese open-weight model, for cost reasons now has a live question to answer in diligence: is the underlying model itself now a sanctions target, and does that expose downstream deployments? LPs backing funds with China-adjacent AI infrastructure exposure should expect this to become a standard diligence question by Q4. The distillation debate also cuts both ways for U.S. labs -- OpenAI, Anthropic and Google have all used distillation internally to cheapen smaller models, and a hard line on "large-scale covert industrial distillation" could eventually constrain domestic practices too if the definition isn't drawn carefully.
The bear case here is that this reads as protectionism dressed up as an IP claim. Distillation techniques are broadly legal and widely used across the industry; proving that Kimi K3 specifically was built via improper access to Fable, rather than legitimate training on public benchmarks and synthetic data, requires evidence the administration hasn't yet made public. If Treasury moves to sanctions without a clearer paper trail, it risks an escalation cycle that invites Chinese retaliation against U.S. firms' remaining China operations, and it hands Moonshot a talking point that Washington moves the goalposts whenever a Chinese lab gets competitive.
Watch three things next: whether Treasury actually opens a formal investigation or sanctions process against Moonshot, whether Nvidia faces new pressure to tighten GB300 distribution controls given the Thailand routing, and whether Moonshot's own reported IPO ambitions -- it's racing DeepSeek toward a public listing -- get complicated by a live U.S. government IP-theft allegation hanging over its flagship model.