The U.S. Says a Chinese AI Company Copied Its Best Models — and Is Threatening Punishment

U.S. Treasury Secretary Scott Bessent threatened sanctions against Chinese AI companies on July 22, 2026, accusing them of stealing American intellectual property. "Open source is not open season on American IP," Bessent wrote on X (TechCrunch).
The accusations target a technique called "model distillation." In simple terms, distillation means using the answers from a very smart AI system to train your own AI system so it becomes almost as good, without having done the original work. If you think of a top chef's recipes, distillation would be like hiring someone to order every dish on the menu, reverse-engineer each one, and then open a competing restaurant using those copied recipes.
Bessent's remarks came hours after White House science and technology policy chief Michael Kratsios publicly accused a China-based AI company called Moonshot of running a large-scale distillation operation against U.S. AI models. Kratsios also alleged that Moonshot acquired powerful Nvidia computer chips called GB300s and accessed them in Thailand, potentially breaking U.S. rules that ban selling these chips to Chinese companies (TechCrunch).
The accusations focus on a model called Fable, made by the U.S. AI company Anthropic, which has only been publicly available since July 1, 2026. Anthropic itself reported back in February 2026 that Moonshot's AI models, called Kimi, had used hundreds of fake accounts to systematically pull information from Anthropic's systems in a distillation campaign (Anthropic). That report was published on February 23, 2026. Moonshot then released its own model, Kimi K3, as a freely downloadable open-weight model in mid-July 2026, before the Treasury's July 22 statements (TechCrunch).
Earlier in the same week, Bessent had already said the government would examine Chinese open-source AI models for signs of stolen IP and impose sanctions if any were found. Dean Ball, a former White House AI advisor who also worked at OpenAI, separately argued that the U.S. should restrict or ban the use of Chinese open-weight models entirely (TechCrunch).
The allegations bring together two different areas of U.S. policy that are now overlapping. The first is protecting intellectual property. When an AI company lets users access its model through an online interface, it is relatively easy for someone to collect large numbers of responses and use them to train a copycat model. Anthropic's February report described a coordinated effort using hundreds of fake accounts, suggesting organized activity rather than casual use. The second area is export control. If Kratsios's claim about GB300 chips in Thailand is accurate, it would suggest that Moonshot found a way around U.S. restrictions by routing the hardware through a third country.
Separately, Anthropic published a research paper on May 14, 2026 called "2028: Two scenarios for global AI leadership" that found Moonshot's Kimi K2.5 model, released in April, refused requests related to chemical, biological, radiological, and nuclear weapons at a much lower rate than U.S. AI models did (Anthropic). This finding, while from a separate research effort, adds to concerns about the risks of Chinese open-weight models.
The TechCrunch report was based on public statements by government officials on X, not on leaked documents or an exclusive investigation. TechCrunch noted it had reached out to Moonshot and the Treasury for comment (TechCrunch).
If the Treasury follows through, the practical effect would be to cut targeted companies off from U.S. technology supply chains, including access to computer chips through middlemen. The threat alone tells us that the U.S. government is willing to treat distillation as a serious offense that can trigger sanctions, not just a violation of a company's usage terms. For AI companies, this raises the pressure to build better detection systems into their online services, as Anthropic has already started doing. For Chinese AI companies releasing free models, the message is that those releases will be examined for evidence that they were built using stolen know-how.
The broader context here is that combining export control violations and IP theft accusations into a single sanctions framework is a shift. Past U.S. actions against Chinese tech companies like Huawei and SMIC relied on export controls alone. Adding distillation to the list of sanctions-triggering offenses gives regulators more tools and lowers the bar of evidence from physical hardware smuggling to software-level activity that can be spotted in server logs.
What is still unknown is whether Moonshot will formally respond, whether the Treasury has a specific threshold of evidence for adding companies to the Entity List in this kind of case, and whether other Chinese AI firms releasing free models will face the same scrutiny. The practical impact will be decided in the gap between a public accusation and formal punishment.


