US Treasury threatens sanctions over Chinese AI model distillation
TECH

US Treasury threatens sanctions over Chinese AI model distillation

37+
Signals

Strategic Overview

  • 01.
    Treasury Secretary Scott Bessent said on July 21, 2026 that the U.S. would examine open-source Chinese models for signs of IP theft, stating officials have found 'watermarks of our U.S. large language models on many of the Chinese models' and that sanctions are possible if theft is confirmed.
  • 02.
    China's Ministry of Commerce responded on July 27, 2026, calling the accusations baseless 'AI hegemony' and warning it will take 'all necessary measures' if Washington imposes sanctions on Chinese AI firms.
  • 03.
    The dispute centers on specific companies: White House science adviser Michael Kratsios accused Moonshot AI of building Kimi K3 via industrial-scale distillation of Anthropic's frontier model, while Anthropic separately told the Senate Banking Committee that operators linked to Alibaba's Qwen lab ran roughly 25,000 fraudulent accounts to distill Claude.
  • 04.
    The accusations extend a pattern dating to early 2026, when Anthropic and OpenAI jointly flagged industrial-scale distillation campaigns by DeepSeek, Moonshot, and MiniMax involving over 24,000 fraudulent accounts and 16 million exchanges with Claude.

Deep Analysis

The Legal Gray Zone: Why 'Distillation' Isn't the Same as 'Theft'

Treasury Secretary Scott Bessent's own language reveals the fault line at the center of this dispute: the U.S. will investigate 'if' theft can be established, and only then would sanctions follow [1]. That conditional framing matters because Bessent has also said officials are finding 'watermarks of our U.S. large language models' embedded in Chinese models [2]- a claim that, according to technical observers debating the issue online, conflates two very different things: pure logit-level distillation, which would require access to a teacher model's raw output probabilities that a closed commercial API doesn't expose, versus fine-tuning on synthetic data harvested from ordinary API completions, a technique critics argue sits in much murkier legal territory. That distinction remains contested rather than officially settled, but it highlights how imprecise the government's own language has been so far. President Trump's own comments have done little to sharpen it - asked directly whether China is stealing American AI IP, he deflected rather than confirming or denying the theft claim, saying only 'we're leading China substantially,' a hedge that echoes Bessent's conditional framing rather than resolving it.

That distinction is exactly why AI researchers pushed back hard on the highest-profile individual case, Moonshot AI's Kimi K3. Braden Hancock of the Laude Institute argued the model's capability jump doesn't square with 'strictly distillation' given how little time elapsed, and Nathan Lambert of the Allen Institute for AI went further, arguing distillation's marginal value keeps shrinking as Chinese models close in on the frontier [4]. Beijing's Ministry of Commerce, for its part, has simply asserted the accusations have 'no legal basis' without engaging the technical distinction at all [3].

The Numbers Game: Anthropic's Evidence vs Beijing's Blanket Denial

The two sides aren't just disagreeing on interpretation - they're working from wildly different evidentiary standards. Anthropic's complaint to the Senate Banking Committee names names and numbers: roughly 25,000 fraudulent accounts linked to Alibaba's Qwen lab, generating 28.8 million conversations with Claude in a six-week window between April 22 and June 5, 2026, concentrated on agentic reasoning and coding capability [5]. That followed an earlier, similarly granular disclosure in February 2026, when Anthropic and OpenAI jointly flagged more than 24,000 fraudulent accounts and over 16 million exchanges tied to DeepSeek, Moonshot, and MiniMax [6][7].

Against that level of detail, China's Ministry of Commerce response on July 27 offers no counter-data at all - just a categorical denial that the accusations have 'no legal basis' and a description of distillation as 'a technique widely used across the industry' [3]. Moonshot AI did offer one specific rebuttal of its own: an employee publicly stated Kimi K3 was trained from scratch in 15 days after Anthropic's frontier model went public, calling it 'Guinness World Record stuff' [8]. That claim addresses the timeline objection but not the underlying question of whether Anthropic's API was used as a training-data source at all.

Whataboutism Cuts Both Ways

Beijing isn't the only party arguing distillation outrage is selective. Hugging Face CEO Clem Delangue has pushed back publicly that distillation is a minor factor in China's AI progress and a practice used industry-wide, including by U.S. firms themselves [9]. Microsoft CEO Satya Nadella made a related point from the other direction, criticizing frontier labs for leaning on 'fair use' to train their own models on public data while simultaneously imposing restrictive anti-distillation terms on others [10]- a hypocrisy charge that lands given the IP disputes U.S. labs have themselves faced over training data.

China's Ministry of Commerce has leaned into this framing too, casting the U.S. campaign as 'AI hegemony' rather than a genuine IP dispute [3]. A Chinese government spokesperson pushed the same argument further and more bluntly, telling NBC News the U.S. accusations amount to an unfounded 'smear' rooted in 'prejudice' - sharper language than the Ministry's own formal statement. The result is a rhetorical stalemate where neither side's moral high ground survives contact with its own industry's practices - distillation-adjacent techniques are, by multiple accounts, standard practice on both sides of the Pacific, which makes the selective outrage as much a story here as the underlying technical claims.

Sanctions Now Threaten the September Trump-Xi Summit

The dispute's real-world stakes go beyond any single company's training pipeline. Bessent's sanctions threat, if acted on, could cut Chinese AI firms off from Western cloud infrastructure, capital, and compute [1]- and China's Commerce Ministry has already promised to 'take all necessary measures in response to any action that causes material harm to its interests' [3], raising the prospect of a tit-for-tat trade escalation layered on top of an already fraught chip-export relationship. Officials including Michael Kratsios have tied the distillation accusations directly to that export-control fight, alleging Moonshot combined industrial-scale distillation with use of export-restricted chips [11].

The timing raises the diplomatic temperature further. Paul Triolo of DGA-Albright Stonebridge Group warned that depending on how many firms are targeted and how harsh the penalties are, retaliation 'has the potential to scuttle both the AI dialog and the September 24 meeting between Presidents Trump and Xi' [10]. Yoshua Bengio, the AI researcher often called a 'godfather of AI,' frames the stakes in starker terms still: open-weight deployment and sharing decisions are irreversible, and 'their safeguards are easier to remove' once a model has been distilled or shared further [10]- precisely the mechanism at the center of this dispute. Kristy Loke, who studies China's AI governance, offered the counter-scenario: rather than escalating, the two countries could use this moment to negotiate shared pre-release testing standards and red lines for advanced open models [10]- a path that looks narrower the longer both sides trade accusations instead of evidence.

Historical Context

2025-01
Released open-source reasoning model R1, claimed to match OpenAI's o1 at a fraction of training cost, sparking initial distillation allegations from OpenAI.
2026-02-12
Sent a memo to Congress's China Select Committee alleging DeepSeek circumvented access restrictions to train on ChatGPT outputs.
2026-02-24
Publicly flagged industrial-scale distillation campaigns by DeepSeek, Moonshot, and MiniMax involving roughly 24,000 fraudulent accounts and over 16 million Claude exchanges.
2026-04-23
A Kratsios memo publicly accused China-based entities of running industrial-scale distillation campaigns against U.S. frontier models using proxy accounts and jailbreak prompts.
2026-06-10
Sent a letter to the Senate Banking Committee alleging Alibaba operators ran the largest known distillation attack against it, using roughly 25,000 fraudulent accounts and 28.8 million exchanges between April 22 and June 5.
2026-07-16
Launched Kimi K3, quickly found competitive with top U.S. models, reigniting distillation accusations from U.S. officials.
2026-07-21
U.S. Treasury Secretary publicly threatened sanctions against Chinese AI firms over alleged IP theft via distillation, citing detected 'watermarks' of U.S. models.
2026-07-27
Publicly rejected the accusations as baseless 'AI hegemony' and warned of 'all necessary measures' if sanctioned.

Power Map

Key Players
Subject

US Treasury threatens sanctions over Chinese AI model distillation

SC

Scott Bessent (U.S. Treasury Secretary)

Publicly threatened sanctions against Chinese AI firms over alleged IP theft via distillation, citing detected 'watermarks' of U.S. models in Chinese systems.

CH

China's Ministry of Commerce

Denied the allegations as baseless 'AI hegemony' and warned it will take 'all necessary measures' if Washington imposes sanctions.

AN

Anthropic

Filed reports and a letter to the Senate Banking Committee alleging industrial-scale distillation attacks by DeepSeek, Moonshot, MiniMax, and Alibaba/Qwen using tens of thousands of fraudulent accounts.

MI

Michael Kratsios (White House Office of Science and Technology Policy)

Publicly accused Moonshot AI of running an internal platform to distill U.S. models at scale while using export-restricted chips.

MO

Moonshot AI

Chinese lab behind Kimi K3, accused of distilling Anthropic's model; an employee publicly denied the claim, saying the model was trained from scratch in 15 days.

OP

OpenAI

Sent a memo to Congress's China Select Committee (Feb 12, 2026) alleging DeepSeek used third-party routers to circumvent access restrictions and train on ChatGPT outputs.

DA

David Sacks (White House AI and Crypto Czar)

Anti-regulation voice warning the U.S. risks losing the AI race to China after Kimi K3's release; earlier said there was 'substantial evidence' DeepSeek distilled from OpenAI.

AL

Alibaba (Qwen lab)

Accused by Anthropic of running the largest known distillation attack (25,000 fake accounts, 28.8 million exchanges) against Claude.

Fact Check

11 cited
  1. [1] Bessent warns of sanctions against Chinese AI firms over IP theft
  2. [2] Scott Bessent warns China sanctions over AI model theft
  3. [3] China's Commerce Ministry rejects US AI theft accusations
  4. [4] Experts say exploiting Anthropic's Fable isn't how Kimi K3 got so good
  5. [5] Anthropic says Alibaba used 25,000 fake accounts to distill Claude
  6. [6] The costs of China's AI distillation campaign
  7. [7] Anthropic, OpenAI flag China AI firms' distillation of Claude, ChatGPT
  8. [8] Global AI experts push back on US distillation claims against Moonshot's Kimi K3
  9. [9] US threatens sanctions against Chinese AI companies
  10. [10] As AI grows more powerful, a US-China feud threatens safety efforts
  11. [11] Kratsios says Moonshot built Kimi K3 through industrial distillation of Anthropic's Fable

Source Articles

Top 5

THE SIGNAL.

Analysts

"Skeptical that Kimi K3's capabilities can be explained by pure distillation given the short timeline, arguing Chinese teams' technical expertise is being underestimated."

Braden Hancock
Researcher, Laude Institute; Co-founder, Snorkel AI

"Argues distillation's impact is diminishing as Chinese models approach the frontier, undercutting the theory that distillation alone explains the gap-closing."

Nathan Lambert
AI Researcher, Allen Institute for AI

"Argues for imposing costs on China's distillation campaigns, framing them as undermining the economic foundation of U.S. frontier AI leadership and stripping safety guardrails from distilled models."

Joe Khawam
Managing Director of Legal and AI Policy, Law Reform Institute

"Warns that sanctions retaliation could derail the U.S.-China AI safety dialogue and jeopardize the planned September 2026 Trump-Xi meeting."

Paul Triolo
Partner, DGA-Albright Stonebridge Group

"Argues the two countries should cooperate on common safety standards and red lines for advanced open models rather than escalate toward sanctions."

Kristy Loke
MATS Research Fellow studying China's AI governance
The Crowd

"China warned it would take “all necessary measures” if the US moves to sanction Chinese AI companies over allegations they improperly used American models to train their own systems"

@@business99

"🚨 Q: Treasury Sec. Scott Bessent said the administration will look into if Chinese AI models are STEALING from America AI models. Do you think China is stealing American IP? PRESIDENT TRUMP: They're look at us and we're looking at them — but we're LEADING China substantially in [continues, cut off]"

@@EricLDaugh268

"Bessent says U.S. could sanction China over AI model 'theft'"

@u/DrCalFun225

"China fires back at Trump administration claims that its AI companies steal U.S. tech"

@u/journalistdave203
Broadcast
US Accuses China's Moonshot of Stealing From Anthropic's Fable AI Model | Vantage on Firstpost | 4K

US Accuses China's Moonshot of Stealing From Anthropic's Fable AI Model | Vantage on Firstpost | 4K

Model Distillation: How to Steal a Billion-Dollar AI

Model Distillation: How to Steal a Billion-Dollar AI

What Is AI Distillation — And How DeepSeek Used It To Blindside OpenAI

What Is AI Distillation — And How DeepSeek Used It To Blindside OpenAI