Treasury Secretary Scott Bessent said Wednesday that financial sanctions and trade-blacklist designations remain available against Chinese AI firms accused of stealing American model outputs through distillation. Distillation is a standard training method where a compact model learns by studying a larger one’s outputs, a technique used across the industry and one that is legal unless the underlying data was obtained improperly. Bessent’s warning followed an accusation from White House science and technology policy chief Michael Kratsios that Moonshot, the China-based lab behind Kimi K3, built the model by improperly distilling Anthropic’s Fable.
“Open source is not open season on American IP,” Bessent wrote on X, adding that “covert, industrial-scale distillation attacks” against U.S. labs would trigger sanctions and Entity List designations.
The accusation has a timing problem the administration has not addressed. Fable became publicly available on July 1. Moonshot shipped Kimi K3 as an open-weight release the following week. That leaves roughly two weeks for Moonshot to have queried Fable at industrial scale, distilled its outputs into a training set, and completed a full training run, a sequence several AI researchers say does not match how distillation projects typically unfold. The compressed timeline undercuts the White House’s version of events more than it supports it.
Kratsios’s accusation includes a second, separate claim: that Moonshot obtained Nvidia GB300 servers, part of the Blackwell line barred from sale to Chinese buyers, and accessed them through Thailand. That is an export-control question distinct from the IP claim tied to Fable, though the administration is presenting both as evidence of the same pattern of rule-breaking.
Proving distillation actually happened is technically hard. A model trained partly on another model’s outputs carries no signature as clear as a copied codebase or a leaked document. Investigators can compare stylistic fingerprints, matching error patterns, or overlapping refusal behavior, but none of that rises to proof solid enough to anchor a sanctions designation. Treasury has not disclosed what evidence, if any, sits behind Kratsios’s public accusation.
The bigger story is the tool the administration is reaching for. Those instruments were built for export-control violations and financial crime, not for settling disputes over how a machine learning model was trained. Deploying them here would put the Treasury Department, rather than a court, in the position of adjudicating AI IP fights between labs, with the evidentiary bar set wherever the administration chooses.
That carries a chilling implication for open-weight releases generally. A capable model published soon after a rival lab’s release now invites a distillation accusation almost by default, since two systems built on similar data will share behavioral overlap regardless of lineage. Kimi K3’s release already reopened a related argument, pushed by Dean Ball, OpenAI’s Head of Strategic Futures and a former White House AI adviser, that Chinese open-weight models should be restricted outright regardless of how they were trained. If Treasury moves from public accusation to an actual designation without releasing technical evidence, labs on both sides of the Pacific have reason to slow open releases rather than risk a sanctions fight over a training method that neither side can conclusively prove or disprove.
Reported by TechCrunch on July 22, 2026.