AI
White House Accuses China’s Moonshot AI of Stealing Anthropic’s Fable
Washington accused Moonshot AI of distilling Anthropic’s Fable model, the same theft claim it made twice against DeepSeek without ever producing evidence.
The White House says Moonshot AI stole from Anthropic to build Kimi K3, the free, 2.8 trillion parameter model that rattled tech stocks last week. Michael Kratsios, director of the White House Office of Science and Technology Policy, made the accusation Wednesday on X. He said the Chinese startup distilled Anthropic’s Fable model and ran banned Nvidia GB300 chips out of servers in Thailand.
Washington has filed this exact complaint before. Twice, against a different Chinese lab, and neither round produced public evidence or a single lawsuit.
What Kratsios Actually Alleged
Kratsios laid out three separate claims in one post on X. Chinese AI lab Moonshot AI, he wrote, had targeted Anthropic’s flagship Fable model specifically.
- Distillation of Fable – Moonshot allegedly trained Kimi K3 on outputs pulled from Anthropic’s model.
- A covert access platform – the company built internal tools that could switch between different ways of reaching US models to dodge detection.
- Restricted hardware in Thailand – Moonshot acquired servers built on Nvidia’s GB300 chips and ran some of them from Thailand, likely for training.
Kratsios drew a line between that and normal industry practice. a sophisticated internal platform to conduct large scale distillation is how he described what set Moonshot apart from ordinary use of the technique.
However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.
That is Kratsios, in the same post. He called legitimate distillation, meaning training a smaller model on a bigger one’s outputs, a normal and even valuable part of open AI development. The problem, in his telling, is scale plus concealment.

Washington Tried This Playbook on DeepSeek Twice
This is not the first time a US official has made this precise argument about a Chinese lab. In January 2025, OpenAI told reporters it suspected DeepSeek of distilling its models to train R1, the reasoning model that had just rattled markets and was built, DeepSeek said, for about $5.6 million. No lawsuit followed.
Then, on February 12, 2026, OpenAI escalated. It sent a formal memo to the House Select Committee on China alleging DeepSeek had moved to “obfuscated methods” to keep extracting results from its models, timed right before DeepSeek’s expected Lunar New Year launch. Once again, no public evidence, no suit.
Researchers outside both companies noticed the pattern in the timing. Austin Horng-En Wang, an associate political scientist at the think tank RAND Corporation, offered a blunt explanation for why the accusation surfaces right before a rival launch: it can help slow “China companies from acquiring more chips to distill the U.S. model, so that the U.S. models can keep their leading position.”
Ambuj Tewari, a University of Michigan statistics professor, made a related point about proof. Because only a finished model is public and not its training data, he said in a university expert Q&A on the DeepSeek dispute, an accusation like this is hard to either prove or disprove from the outside. A separate think tank analysis noted the pattern plainly: distillation claims against Chinese labs keep surfacing as a way to circumvent U.S. export controls on advanced AI chips rather than a straightforward IP dispute.
Why Didn’t Kratsios Show His Evidence?
Kratsios did not publish logs, timestamps or technical detail behind the Moonshot claim, the same gap that marked both DeepSeek rounds. Anthropic’s Fable model came out about a week before Kimi K3 was unveiled, a tight window for the kind of large scale distillation the White House describes.
Moonshot’s own numbers make the case for genuine capability harder to wave away. On its website, the company describes K3 as beating other tested models across its evaluation suite, trailing only Claude Fable 5 and GPT 5.6 Sol overall. Building a 2.8 trillion parameter system that competes with the two best-funded labs in the industry, on a fraction of their budget, is either the product of theft or the product of very fast, very cheap Chinese AI research. The accusation does not resolve which.
Moonshot is also, separately, in the middle of a funding round targeting a 30 billion dollar valuation, and Kimi’s product team is now led by a former HoYoverse executive brought in to run the model, a detail that underscores how much commercial weight rides on K3 landing as a credible frontier release rather than a copy.
Anthropic’s Paper Trail Kept Getting Heavier
Before the White House said anything, Anthropic had already been building its own case for months. In February 2026, the company publicly named DeepSeek, Moonshot AI and MiniMax, saying the three had run a combined pool of roughly 24,000 fraudulent accounts against Claude. By June, it said Alibaba’s Qwen lab had gone further than all three combined.
| Accused Company | Alleged Claude Exchanges | Fraudulent Accounts | Disclosed |
|---|---|---|---|
| DeepSeek | About 150,000 | Shared pool of ~24,000 | February 2026 |
| Moonshot AI | More than 3.4 million | Shared pool of ~24,000 | February 2026 |
| MiniMax | More than 13 million | Shared pool of ~24,000 | February 2026 |
| Alibaba (Qwen) | 28.8 million | About 25,000 | June 2026 |
Sarah Heck, Anthropic’s head of public policy, described the Alibaba campaign to senators as carried out “illicitly, systematically, and at industrial scale to harvest US AI capabilities across frontier labs.” She thanked Kratsios publicly once the White House backed a version of her argument this week, framing distillation at this scale as industrial espionage that can feed foreign military and intelligence work down the line.
The model at the center of the newest claim, Fable, had only recently become easier to reach outside the US after Fable’s return to global markets once export curbs lifted, which makes it an odd target for a covert access scheme if the model was already becoming more widely available through legitimate channels.
The Thailand Chip Trail
The GB300 claim sits on firmer regulatory ground than the distillation claim, because Blackwell-class Nvidia chips, the family that includes GB300, already sit under a formal presumption of denial for export to China. The Commerce Department’s Bureau of Industry and Security has spent over a year chasing the same leak: Chinese buyers routing advanced chips through third countries to dodge that ban.
In January, a revised license review policy for semiconductor exports to China eased rules for older Nvidia H200 chips, while Blackwell-generation hardware stayed under the tightest restriction. By May, Commerce issued fresh guidance aimed at closing a separate loophole, one that let China-headquartered buyers acquire restricted chips through subsidiaries outside the mainland, with industry estimates suggesting hundreds of thousands of advanced processors had already moved through that gap.
Thailand fits a pattern regulators have flagged since mid-2025, when draft restrictions first targeted suspected chip diversion through Thailand and Malaysia. Kratsios’s claim that Moonshot ran GB300s from Thai servers lands inside a smuggling story that predates this week’s accusation by more than a year.
Palihapitiya and Delangue Aren’t Buying the Theft Story
Not everyone in the industry accepts Washington’s framing, and the disagreement runs along familiar lines.
- Chamath Palihapitiya, venture capitalist, calls the theft narrative a “China boogeyman” that mainly protects the equity of a small group of US AI investors.
- Clem Delangue, Hugging Face CEO, argues that if distillation explained everything, more countries would already have produced competitive open models. He says Chinese research teams are simply better and more open right now.
- Kratsios and Treasury Secretary Scott Bessent maintain the evidence points to organized, covert copying, with Bessent telling Fox Business the administration is finding watermarks from American models turning up inside Chinese ones.
Bessent has said he supports open source generally but argued that open source is not open season on American intellectual property, floating sanctions on Chinese AI companies as a live option rather than a distant threat.
Sanctions Talk Grows as the Clock Runs to July 27
Axios has reported the White House is weighing a rule that would let US companies host Chinese models only if they guarantee security and accept liability for any breach, an idea reportedly killed internally last year before national security hawks regained the argument. Any such rule would target US hosting companies, not the underlying software, which points to the real limit on what sanctions can do once weights are already public.
Moonshot has said nothing publicly since Kratsios’s post. The Chinese embassy in Washington has not responded either. The full Kimi K3 weights are still scheduled to go live on July 27, free to download and modify, exactly as planned before any of this week’s accusations landed.
Frequently Asked Questions
Has Any Chinese AI Lab Faced Legal Action Over Distillation?
No. Despite two rounds of public accusations against DeepSeek in 2025 and 2026 and now a third against Moonshot AI, no US AI lab has filed a distillation lawsuit against a Chinese competitor. Anthropic has taken its case to Congress instead, pushing for new legislation rather than litigation.
Why Do GB300 Chips in Thailand Matter So Much?
GB300 chips belong to Nvidia’s Blackwell generation, which sits under a presumption of denial for export to China under current Commerce Department policy. Regulators have flagged Southeast Asian countries, including Thailand and Malaysia, as suspected diversion routes for these chips since mid-2025, well before this week’s specific claim.
Could the US Actually Stop Kimi K3’s Release?
Not easily. Once model weights are published and downloaded worldwide, there is no clean legal mechanism to retract them. The hosting rule reportedly under White House consideration would target US companies that host Chinese models, requiring security guarantees and liability, rather than banning the software itself.
What Rule Is the White House Considering for Chinese AI Models?
Axios has reported the proposal would let US firms host Chinese models only if they guarantee security and accept liability for breaches. A similar idea was reportedly shelved internally last year before national security officials pushed it back onto the table.
-
AI3 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
APPS1 month agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
CRYPTO1 month agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
