- Michael Kratsios, President Trump's science and technology adviser and director of the White House Office of Science and Technology Policy, said on July 22 that he has information Moonshot AI used Anthropic's Fable model while building its 2.8-trillion-parameter Kimi K3.
- Kratsios alleged Moonshot ran the copying through a purpose-built internal platform, rotating access routes to avoid detection, and separately reached restricted Nvidia GB300 servers through Thailand.
- His statement is the first time a senior US official has named a specific Chinese lab and a specific US model. It is Kratsios's own accusation, not a formal administration finding, though he said sanctions and Entity List designations could follow.
From general warning to a named target
For most of 2026, Washington's complaint about Chinese AI distillation stayed abstract. Officials described "industrial-scale" extraction of American models, labs warned Congress about proxy accounts and jailbreak prompts, and the theft was always attributed to "China-based entities" in the plural. On July 22 that changed. Michael Kratsios, President Trump's science and technology adviser and the director of the White House Office of Science and Technology Policy, said he has information that Moonshot AI used Anthropic's Fable model while developing Kimi K3, the 2.8-trillion-parameter system that topped coding leaderboards last week. For the first time, a senior US official attached a specific American model to a specific Chinese lab and called the result theft. It is worth being precise about who said it: this is Kratsios's accusation as Trump's top tech adviser, not a formal position adopted by the administration, which has issued no official finding or designation.
The specificity is the story. Kratsios did not simply repeat that Chinese firms distill US models. According to CyberScoop, he alleged that Moonshot built a sophisticated internal platform capable of running distillation across multiple US models while rotating between access methods to stay hidden. He was careful to separate that from ordinary practice.
Legitimate distillation trains a smaller model on a larger one's outputs and is a normal part of AI development. Concealed, industrial-scale extraction of proprietary technology is not.
That distinction matters because distillation itself is not exotic. Every major lab uses a stronger model to teach a smaller one. What Kratsios described is different in kind: a covert pipeline built to harvest a competitor's frontier model at scale while evading the terms of service and detection systems meant to stop it.
The evidence trail Washington is pointing to
The accusation did not arrive from nowhere. Anthropic told Capitol Hill earlier this year that it traced roughly 3.4 million Claude exchanges to Moonshot, and the same pattern has now been alleged against several Chinese labs. In February, OpenAI gave Congress's China Select Committee a memo alleging DeepSeek had pulled from ChatGPT over the prior year. Anthropic separately flagged what it called the largest known distillation attack on its Claude models, attributed to Alibaba's Qwen lab and run through thousands of fraudulent accounts. In April, the White House began accusing "China-based entities" of industrial-scale distillation in general terms.
| Claude exchanges traced to Moonshot | Roughly 3.4 million, per Anthropic |
| Kimi K3 size | 2.8 trillion parameters |
| Feb 2026 | OpenAI's DeepSeek memo to the House China Select Committee |
| Apr 2026 | Deterring American AI Model Theft Act introduced; US export controls placed on Anthropic's Mythos 5 and Fable 5 |
Kratsios added a hardware allegation that raises the stakes beyond software. He said Moonshot acquired servers built on Nvidia's GB300 system and reached the same class of hardware in Thailand. The GB300 carries Nvidia's Blackwell chips, which cannot be legally sold to China. If accurate, the claim ties model distillation to chip smuggling, the two halves of the same effort to close the capability gap without the compute the US has tried to withhold.
Why this escalation has teeth the earlier ones lacked
Naming a company is not a press-release flourish. It is the predicate for enforcement. Kratsios said sanctions and Entity List designations could follow for firms running concealed distillation campaigns, and any Treasury involvement would move the matter from rhetoric toward financial consequences. Those are stated possibilities, not actions the government has yet taken. An Entity List placement would cut Moonshot off from US suppliers and complicate its access to Western cloud and hardware, the same lever that reshaped Huawei's trajectory.
Washington spent a year describing the problem. Naming Moonshot is the first step toward pricing it.
The harder question is proof. Distillation leaves a statistical fingerprint, not a receipt. Demonstrating that Kimi K3's behavior derives from Fable, to a standard that survives legal and diplomatic challenge, is genuinely difficult, and Moonshot has not responded to the latest claims. Beijing dismissed Anthropic's earlier allegations as groundless, and it will almost certainly do the same here. That gap between what officials assert and what they can prove in public is where this fight will be contested.
What it means for the industry
The immediate signal is to the labs. If the US is willing to name a foreign company over a specific model, American firms now have a government partner in protecting their weights, and a stronger case for locking down API access, tightening rate limits, and treating their frontier models as controlled technology rather than open products. Anthropic already sits under export controls on Fable 5 and Mythos 5. Expect more of that posture across the industry, not less.
The broader signal is that the US-China AI contest is consolidating into a single doctrine: restrict the chips, control the model weights, and now, name and penalize the firms accused of stealing what the controls were meant to protect. Distillation is the workaround that made export controls look porous, because a rival can approximate a frontier model's behavior without the hardware to train one. Washington's answer is to attack the workaround directly and personally.
Whether that holds depends on evidence Kratsios has so far described but not fully shown, and on whether the administration chooses to adopt his charge as formal policy. Name a company and you invite a demand for proof. If the government backs the accusation with a finding or a designation, July 22 will read as the day US AI policy grew an enforcement arm. If it stays a single adviser's statement, Moonshot's silence may prove to be the stronger position.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.