The accusation against Moonshot runs on sanctions authority. Anthropic's own proposal to Washington runs on compute thresholds and would bind Anthropic too - they only sound like the same fight.
Tips, corrections, or questions? support@omniscient.media

There's one of these every weekday.
The Omniscient Bulletin turns the day's AI news into 5 to 7 items with the take, not the recap. Free.
The Advanced AI Framework, as written, is a proposed US federal law. It would have no jurisdiction over Moonshot's servers, wherever they sit. Nothing in Anthropic's own rulebook touches Kimi K3. The tool actually being used against Moonshot right now is a Treasury sanctions threat and a public accusation from a White House science office, running through existing trade and export authority, not through anything Anthropic has proposed.[1] The two policy threads, Anthropic's capability-based framework and the administration's China-specific enforcement, share a vocabulary. They are not, mechanically, the same lever. That mechanism has already drawn a countermeasure. China's commerce ministry accused Washington of "AI hegemonism" on July 27th and pledged "all necessary measures" to protect Chinese firms, treating the sanctions threat itself, not just its enforcement, as the injury.[9] Whatever Anthropic's framework eventually becomes, it isn't what's currently escalating into a trade dispute.
The read above treats Anthropic's stated worry, that open weights are irreversible in a way API access isn't, as the honest core of its position, with competitive advantage as a side effect rather than the point. That's a genuinely contestable call. Anthropic is also the party that stands to benefit most if Washington slows down the one category of competitor, cheap, near-frontier, open-weight, that its own business model can't easily match. The framework's nationality-blind thresholds complicate a pure moat-protection read, but they don't rule it out; a rule that happens to bind you exactly as hard as it binds your rivals is not proof you didn't help write it for other reasons.
The bigger uncertainty is evidentiary, not motivational. The government still hasn't published its evidence, and the independent researchers who've weighed in, Hancock among them, are skeptical the timeline supports the theory at all[8], whatever Moonshot's own denial is worth.[9] If the accusation doesn't hold up, the live enforcement action collapses, and the broader argument that this is really about irreversibility rather than geography loses its clearest supporting case. It's also possible this isn't a coordinated strategy at all: a company protecting its IP and an administration already committed to a China-hawk trade posture can arrive at the same rhetoric by convergence, without either one designing the other's move.
Kratsios never published the evidence behind his accusation. Beijing didn't wait for him to: its commerce ministry called the threat itself "AI hegemonism" this week and promised countermeasures of its own, treating an unpublished allegation as grounds enough for retaliation. Whether Kratsios ever makes his evidence public will say more about how this policy actually gets applied than anything Anthropic has written down.
Get this every weekday.
The Omniscient Bulletin: consequential AI, explained and evaluated. 5 to 7 items a day with the take, not the recap.
Sign in to join the discussion.
"Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem," Michael Kratsios, who runs the White House Office of Science and Technology Policy, wrote on X on July 22nd. Then came the turn: "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable."[1] The target was Moonshot AI, the Beijing lab behind Kimi K3, which Kratsios said had built "a sophisticated internal platform to conduct large scale distillation" against Anthropic's Fable model, switching between access methods to dodge detection, and training on GB300 servers acquired directly or routed through Thailand.[1]
It reads like a US-China story. It isn't quite one. Kratsios drew his line inside distillation itself, between the "legitimate" and the "covert," not between open and closed models, and not between American and Chinese ones. That's close to the distinction Anthropic has spent the past year trying to get Washington to formalize, though it isn't the same one: Kratsios is drawing a line around intent and theft, while Anthropic's own framework draws its line at a compute threshold, with a distillation-reporting duty tucked inside it as one clause, not the whole of it.
The Moonshot case is the third time in five months Anthropic's fingerprints have shown up on a distillation accusation. In February, Anthropic said DeepSeek, Moonshot, and MiniMax had run "industrial-scale" extraction campaigns against Claude using roughly 24,000 fraudulent accounts.[2] In June, it named Alibaba specifically: 25,000 fake accounts, 28.8 million exchanges with Claude between April 22nd and June 5th, aimed, in the words of one cybersecurity executive who reviewed the pattern, at nothing but "replication."[3] Treasury has since threatened sanctions over the Moonshot case specifically, warning that Chinese firms could face financial penalties or a spot on the Commerce Department's Entity List, the same trade blacklist Washington used against Huawei starting in 2019. "We support open-source AI and the innovation it unlocks," Treasury Secretary Scott Bessent wrote on X. "But open source is not open season on American IP."[9] US officials now put a dollar figure on the whole problem too: distillation is costing American labs as much as $6 billion a year, according to an internal government estimate reported by Bloomberg.[4]
None of that evidence has been published. Kratsios didn't say how the government determined Kimi K3 came from Fable, and Moonshot didn't respond to US outlets asking about its training process.[1] It did deny the charge to a Chinese outlet, National Business Daily, attributing Kimi K3's gains to changes in the model's underlying architecture rather than to copying anyone else's work.[9] Independent researchers have their own reason for doubt, and it has nothing to do with taking Moonshot's word for it: the timeline is tight. "I don't think you get a model this strong and this quickly on the heels of Fable doing strictly distillation," Braden Hancock, a researcher at the Laude Institute and co-founder of Snorkel AI, told TechCrunch. Fable had only been public since July 1st, three weeks before Kratsios's post, and reproducing frontier-level reasoning takes more than a fast fine-tune.[8] The accusation is doing real policy work anyway.
Distillation is the technique of training a smaller model to reproduce a larger one's outputs, and it is completely ordinary: labs do it to their own models constantly to make cheaper, faster versions. What Anthropic wants regulated isn't the technique. It's a threshold.
In June, Anthropic published its Advanced AI Framework, a proposal for how the US government should handle catastrophic risk from frontier models.[5] The framework would apply only to models trained on more than 10²⁵ floating-point operations, built by companies earning over $500 million in AI revenue or spending over $1 billion on AI research. Those companies would have to test their models for biological, cyber, and loss-of-control risk, publish the results, submit to independent evaluation, and maintain a security program, including, explicitly, "channels to report model distillation attacks" to a designated federal agency. In exchange, the government would get legal authority it doesn't currently have: the power to block a dangerous model's deployment outright, with civil penalties that scale with a company's global revenue.
That threshold doesn't mention China. Written as law, it would bind Anthropic, OpenAI, and Google DeepMind exactly as it would bind any US-regulated lab that crossed the same lines. That's a real complication for anyone assuming this is simply a China play dressed up as safety policy: the rule Anthropic is asking for would apply to itself.
Chip export controls protect access to compute.[6] API-based deployment protects access to a running model, since a company can monitor it, patch it, or cut it off. Once weights are released, neither lever works anymore.
That is the frame Anthropic keeps returning to across its own policy documents: not who owns a model, but whether anyone can still turn it off. It explains why the company isn't running a campaign against every open-weight release. A 7-billion-parameter coding model poses a different problem than Kimi K3, which Moonshot's own site says "demonstrated frontier-level performance" across its evaluation suite, trailing only Claude Fable 5 and GPT 5.6 Sol.[1] The alarm isn't about weights. It's about frontier weights becoming irreversible in public, at a scale nobody can undo. Moonshot set July 27th as its own deadline for putting those weights on Hugging Face; independent trackers reported them live a day early, on July 26th.[10] Whatever the government's case against Moonshot amounts to, the scenario Anthropic's framework actually worries about, a frontier model nobody can recall, stopped being hypothetical for this one this week.
Every serious lab distills its own outputs into smaller models. Every serious lab also trained its frontier system by ingesting enormous amounts of other people's content from the open internet, a fact several ongoing lawsuits against Anthropic and OpenAI exist specifically to litigate.[1] Drawing a clean line between "a competitor learning from your API" and "a competitor stealing your model" requires distinguishing intent and scale in a way that current law doesn't do well.
The volume in the Alibaba case, 28.8 million exchanges through 25,000 accounts built to evade detection, reads less like normal usage than like a coordinated extraction effort.[3] "When a model has learned to reason through software weaknesses, security gaps, and attack paths, copying its behavior also copies that analytical capability," one industry executive told CyberScoop of the pattern.[1] That's a real distinction. It's also one that depends entirely on evidence the public hasn't seen, in a case where the accuser and the alleged victim happen to be the same company lobbying for the rule that would formalize the distinction.
OpenAI and Anthropic spend most of their energy trying to poach each other's enterprise customers. On July 22nd, they landed in the same place for a moment: both were telling policymakers that Chinese open-weight models pose a risk serious enough to warrant scrutiny.[7] Axios reported that critics, including Trump adviser David Sacks, argue the scrutiny amounts to regulatory capture, since rules pitched as safety measures could just as easily entrench the largest labs by making it harder for smaller competitors to release models at all.[7] Suresh Venkatasubramanian, a former Biden White House tech adviser, put the researcher's version of the same worry more plainly: cutting off access to Chinese models "would be a big problem for doing research," since open weights are precisely what let outside scientists study a model instead of just querying it.[7]
Two developments moved this story after we first published it. On July 24th, a coalition led by Nvidia and Microsoft published a letter, "Open Weights and American AI Leadership," urging Washington to avoid "premature restrictions on open models that stifle competition or drive innovation overseas" and to route unlawful-extraction complaints through "targeted legal and commercial frameworks" instead.[11] It launched with 25 named signatories, and OpenAI, Anthropic, and Google were conspicuously not among them.[12] That didn't hold: by the time the list stabilized, it ran past 130 names, and OpenAI, Google, and Amazon had all joined Meta, Microsoft, and Nvidia on it. The letter never names China, Moonshot, or DeepSeek. Anthropic was the one frontier lab still missing from it.
Being the last major holdout on a hundred-plus-company letter got noticed. By the weekend, Anthropic was fielding a specific charge: that it wanted Chinese open-weight models banned outright, and that national security was cover for protecting its own business against cheaper competition. On July 27th, Dario Amodei answered that directly, in a post titled "Our position on open-weights models." "Anthropic has never advocated for a ban on open-weights models," he wrote, adding that models "that don't have dangerous capabilities are a public good" and that "protectionist bans would not address my most serious national security concerns."[13] What Amodei says Anthropic actually wants lines up closely with the read of the Advanced AI Framework above: keep powerful chips out of authoritarian hands, crack down on industrial-scale distillation, and require safety testing for "all sufficiently capable models, open and closed," evaluated "regardless of their country of origin or whether they are open or closed."[13]
Worth weighing that response for what it is. It arrived only after Anthropic was left the sole frontier lab off the letter, which makes it a reply to isolation and public pressure rather than an unprompted account, and it is still the subject's own word about its own motives. It doesn't overturn this piece's original read, that Anthropic's actual ask is capability-based and nationality-blind on its face; it's Anthropic confirming that reading in its own words, on the same day Beijing escalated the sanctions dispute into a trade fight. Read it, as with everything else in "The risk in the reading" above, as evidence, not as the last word.
CyberScoop: "White House accuses Chinese company of distilling Anthropic's Fable," July 22, 2026 Inline ↗
TechCrunch: "Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports," Feb. 23, 2026 Inline ↗
Reuters: "Anthropic says Alibaba illicitly extracted Claude AI model capabilities," June 24, 2026 Inline ↗
Bloomberg: "Anthropic, OpenAI Warnings Prompt Distillation Debate in DC," July 13, 2026 Inline ↗
Anthropic: "Policy on the AI Exponential" and Advanced AI Framework, June 2026 Inline ↗
Anthropic: "Securing America's compute advantage: Anthropic's position on the diffusion rule," April 30, 2025 Inline ↗
Axios: "OpenAI and Anthropic unite against China's open models," July 22, 2026 Inline ↗
TechCrunch: "Experts say exploiting Anthropic's Fable isn't how Kimi K3 got so good," July 23, 2026 Inline ↗
Reuters: "China accuses US of 'AI hegemonism,' threatens countermeasures over potential probes," July 27, 2026 Inline ↗
Moonshot AI: Kimi K3 tech blog, "Open Frontier Intelligence" Inline ↗
Microsoft: "Open Weights and American AI Leadership" letter text and signatory list, July 24, 2026 Inline ↗
CNBC: "Nvidia, Microsoft, Meta warn against 'premature restrictions' of open-weight models," July 24, 2026 Inline ↗
Anthropic: Dario Amodei, "Our position on open-weights models," July 27, 2026 Inline ↗