Treasury Secretary Bessent just threatened sanctions on Moonshot after White House accused the Chinese AI firm of stealing Anthropic’s Fable model

12 Min Read

Treasury Secretary Scott Bessent has warned that the U.S. government could impose sanctions on Chinese AI companies after White House officials accused Moonshot of distilling Anthropic’s Fable model to develop Kimi K3. The accusation marks an escalation in the geopolitical battle over artificial intelligence, where American tech companies fear their proprietary models are being reverse-engineered by foreign competitors using a technique that leaves few forensic traces.

What’s at stake is not just one model or one company. The White House accusation against Moonshot signals that the U.S. government now views AI model theft as a national security threat worthy of economic punishment. If sanctions proceed, they would represent the first major enforcement action targeting a Chinese AI firm for allegedly stealing American AI intellectual property—a precedent that could reshape how both nations approach AI competition.

Key Findings:
  • The Accusation: White House officials allege Moonshot used distillation to replicate Anthropic’s proprietary Fable model without permission, producing Kimi K3.
  • The Enforcement Shift: Bessent’s sanctions threat marks the first time the U.S. government has treated AI model distillation as a sanctions-worthy offense equivalent to trade secret theft.
  • The Market Consequence: If sanctions proceed, they could accelerate the fragmentation of the global AI market into separate American and Chinese ecosystems, reducing open-source alternatives for all users.

Moonshot is a Beijing-based AI startup that has rapidly grown into one of China’s leading large language model developers. The company’s flagship product, Kimi, is a conversational AI system designed to compete directly with ChatGPT and other Western models. White House officials have alleged that Moonshot used a technique called distillation to create Kimi K3—a newer version of the Kimi system—by essentially learning from Anthropic’s Fable model without permission or compensation. This dispute sits at the intersection of intellectual property law, national security, and the global war for data that now defines great-power competition.

What Is Distillation and Why Is It So Hard to Prove?

Distillation is a machine learning technique where a smaller or more efficient model learns to mimic the behavior of a larger, more capable model. In practice, this means feeding a proprietary model’s outputs into a new system until the new system reproduces similar responses and reasoning patterns. A survey on knowledge distillation published in ScienceDirect describes the technique as a cornerstone of modern efforts to create more efficient and deployable machine learning models—a legitimate tool in controlled contexts that becomes legally and ethically contested when applied to proprietary systems without authorization.

From a technical standpoint, distillation is legal when applied to open-source models or when companies have explicit permission. But when applied to proprietary, closed models like Fable, it becomes a form of intellectual property theft—the AI equivalent of reverse-engineering a competitor’s software. The challenge for enforcement is that distillation leaves no obvious digital fingerprints. Researchers would need to compare Fable’s outputs with Kimi K3’s outputs, looking for statistical patterns that suggest one was trained on the other. That kind of forensic analysis is possible but time-consuming and not always conclusive.

What Research Shows:
Research published in the ACM Digital Library documents how knowledge distillation techniques have evolved to extract and recombine model knowledge, raising significant questions about intellectual property boundaries in AI development.
• The same body of literature confirms that distillation can transfer reasoning capabilities between models without direct access to training data or model weights—making forensic attribution genuinely difficult.
• Because every public interaction with a deployed model generates outputs that can serve as distillation training data, closed commercial models are structurally vulnerable to this form of extraction at scale.

Why the U.S. Government Is Treating This as a National Security Issue

Anthropic, the San Francisco-based AI safety company that created Fable, has not made a public statement about the White House accusation. Moonshot has also not publicly responded to the allegations. Treasury Secretary Bessent’s warning, however, suggests the U.S. government has gathered enough evidence to consider formal action. Sanctions against Chinese AI companies could take several forms: restrictions on access to advanced semiconductors, export controls on AI training infrastructure, or financial penalties that would cripple the company’s ability to operate internationally.

The accusation reveals a fundamental vulnerability in how American AI companies protect their models. Unlike traditional software, which can be locked behind code encryption and legal agreements, large language models are inherently harder to protect once they’re deployed. Every interaction with a model—every query and response—generates training data that could theoretically be used to understand how the model works. Distillation exploits this by turning public interactions into a blueprint for building a competing system. The pattern is structurally similar to how AI systems shape decisions through accumulated behavioral data—in both cases, the extraction of value from interaction patterns happens largely invisibly.

This threat has been lurking in the background of AI development for years. Researchers have published academic papers demonstrating that distillation can extract meaningful information from proprietary models. What’s new is that the U.S. government is now treating distillation as a sanctions-worthy offense, equivalent to stealing trade secrets or engaging in corporate espionage. That shift reflects how seriously Washington now views AI competition with China.

The Stakes:
Billions invested – American frontier AI labs have collectively invested tens of billions in building proprietary models that distillation could replicate at a fraction of the cost
First enforcement action – Bessent’s threat would represent the first sanctions targeting a Chinese AI firm specifically for alleged model distillation
Bifurcated market risk – Analysts warn that escalating AI IP disputes could split the global AI ecosystem into separate American and Chinese development tracks

How This Mirrors Earlier Patterns of Technology Extraction

The Cambridge Analytica scandal established a critical precedent that resonates here: the most consequential data extraction operations are often those that exploit the gap between what a system’s terms of service prohibit and what its architecture technically permits. Cambridge Analytica harvested Facebook user data at scale not by breaching security systems, but by exploiting a legitimate API in ways Facebook had not anticipated. Moonshot’s alleged distillation of Fable follows a structurally identical logic—using a system’s publicly accessible outputs in ways the developer never authorized, at a scale that converts interaction data into competitive intelligence. The U.S. government’s response in both cases has been to treat the exploitation of that gap as a violation serious enough to warrant formal sanction.

The timing matters. The U.S. and China are locked in a race to develop more capable, more efficient AI systems. American companies like OpenAI, Anthropic, and Google have invested billions in building frontier models. Chinese competitors like Moonshot, ByteDance, and Alibaba are catching up rapidly, partly through organic research and partly through techniques like distillation that allow them to learn from American models without building everything from scratch. If distillation becomes widespread, it could compress the timeline for Chinese AI development and reduce the competitive advantage that American companies have built through years of research and enormous capital investment. The use of AI in political and legislative contexts adds another dimension to why governments now treat AI capability gaps as direct national security concerns.

What Sanctions Would Actually Mean for the Global AI Market

For users of AI systems, this escalation has real implications. If the U.S. imposes sanctions on Moonshot, it could fragment the global AI market further, limiting access to certain models depending on geography or platform. It could also accelerate a trend toward more closed, proprietary AI systems—companies will invest more in security measures to prevent distillation, which means fewer open-source alternatives and less transparency about how AI systems work. The geopolitical competition over AI is beginning to reshape the tools people interact with daily.

Bessent’s warning also signals that the U.S. government is moving from passive concern to active enforcement. Previous accusations of AI theft have been met with diplomatic protests or quiet negotiations. Threatening sanctions is a different move—it’s a public declaration that AI model theft will be treated as seriously as other forms of intellectual property violation or national security breach. Whether those sanctions actually materialize depends on what additional evidence the Treasury Department and White House have gathered, and whether China retaliates with its own economic measures against American tech companies.

What happens next depends on whether the Treasury Department formally initiates a sanctions process, which typically involves investigation, opportunity for the accused company to respond, and final determination by the government. If sanctions are imposed, Moonshot would face restrictions on doing business with American companies, accessing American technology, or using the U.S. financial system. For a Chinese AI company, those restrictions would be severe but not necessarily fatal—China has its own technology supply chains and financial infrastructure. But they would signal to other Chinese AI companies that distillation carries real costs.

Is This Threat Real or Rhetorical?

The broader question hanging over this dispute is whether the U.S. government can actually enforce sanctions that slow Chinese AI development. China will likely respond with its own restrictions on American tech companies or accelerate its own AI research to reduce dependence on American models. The result could be a bifurcated global AI market, where American and Chinese systems develop separately, each optimized for their home markets and geopolitical interests. That fragmentation would reshape how AI develops and who controls the most powerful systems.

Bessent’s threat marks a turning point. AI model theft has moved from a corporate concern to a state-level priority. How the Treasury Department follows through will determine whether distillation becomes a risky move for any company, or whether it remains a gray-area technique that companies use quietly, knowing the enforcement risk is low. The next few months will show whether this threat of sanctions is real or rhetorical—and whether the architecture of global AI competition is about to change permanently.

Share This Article
Rivo Raphaël Chreçant is a sociologist and web journalist at CA Privacy Watch. Passionate about words, he digs into the facts, trends and behaviours shaping technology, privacy and society, turning complex developments into clear, grounded stories.