The accusation against Moonshot runs on sanctions authority. Anthropic's own proposal to Washington runs on compute thresholds and would bind Anthropic too - they only sound like the same fight.
Tips, corrections, or questions? support@omniscient.media

The Omniscient Bulletin turns the day's AI news into 5 to 7 items with the take, not the recap. Free.
OpenAI and Anthropic spend most of their energy trying to poach each other's enterprise customers. On one point in Washington, though, they've landed in the same place: both are telling policymakers that Chinese open-weight models pose a risk serious enough to warrant scrutiny.[7] That alignment has drawn exactly the pushback you'd expect. Axios reported that critics, including Trump adviser David Sacks, argue the scrutiny amounts to regulatory capture, since rules pitched as safety measures could just as easily entrench the largest labs by making it harder for smaller competitors to release models at all.[7] Suresh Venkatasubramanian, a former Biden White House tech adviser, put the researcher's version of the same worry more plainly: cutting off access to Chinese models "would be a big problem for doing research," since open weights are precisely what let outside scientists study a model instead of just querying it.[7]
The Advanced AI Framework, as written, is a proposed US federal law. It would have no jurisdiction over Moonshot's servers, wherever they sit. Nothing in Anthropic's own rulebook touches Kimi K3. The tool actually being used against Moonshot right now is a Treasury sanctions threat and a public accusation from a White House science office, running through existing trade and export authority, not through anything Anthropic has proposed.[1] The two policy threads, Anthropic's capability-based framework and the administration's China-specific enforcement, share a vocabulary. They are not, mechanically, the same lever. That mechanism has already drawn a countermeasure. China's commerce ministry accused Washington of "AI hegemonism" on July 27th and pledged "all necessary measures" to protect Chinese firms, treating the sanctions threat itself, not just its enforcement, as the injury.[9] Whatever Anthropic's framework eventually becomes, it isn't what's currently escalating into a trade dispute.
The read above treats Anthropic's stated worry, that open weights are irreversible in a way API access isn't, as the honest core of its position, with competitive advantage as a side effect rather than the point. That's a genuinely contestable call. Anthropic is also the party that stands to benefit most if Washington slows down the one category of competitor, cheap, near-frontier, open-weight, that its own business model can't easily match. The framework's nationality-blind thresholds complicate a pure moat-protection read, but they don't rule it out; a rule that happens to bind you exactly as hard as it binds your rivals is not proof you didn't help write it for other reasons.
Get this every weekday.
The Omniscient Bulletin: consequential AI, explained and evaluated. 5 to 7 items a day with the take, not the recap.
Sign in to join the discussion.
"Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem," Michael Kratsios, who runs the White House Office of Science and Technology Policy, wrote on X on July 22nd. Then came the turn: "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable."[1] The target was Moonshot AI, the Beijing lab behind Kimi K3, which Kratsios said had built "a sophisticated internal platform to conduct large scale distillation" against Anthropic's Fable model, switching between access methods to dodge detection, and training on GB300 servers acquired directly or routed through Thailand.[1]
It reads like a US-China story. It isn't quite one. Kratsios drew his line inside distillation itself, between the "legitimate" and the "covert," not between open and closed models, and not between American and Chinese ones. That's close to the distinction Anthropic has spent the past year trying to get Washington to formalize, though it isn't the same one: Kratsios is drawing a line around intent and theft, while Anthropic's own framework draws its line at a compute threshold, with a distillation-reporting duty tucked inside it as one clause, not the whole of it.
The Moonshot case is the third time in five months Anthropic's fingerprints have shown up on a distillation accusation. In February, Anthropic said DeepSeek, Moonshot, and MiniMax had run "industrial-scale" extraction campaigns against Claude using roughly 24,000 fraudulent accounts.[2] In June, it named Alibaba specifically: 25,000 fake accounts, 28.8 million exchanges with Claude between April 22nd and June 5th, aimed, in the words of one cybersecurity executive who reviewed the pattern, at nothing but "replication."[3] Treasury has since threatened sanctions over the Moonshot case specifically, warning that Chinese firms could face financial penalties or a spot on the Commerce Department's Entity List, the same trade blacklist Washington used against Huawei starting in 2019. "We support open-source AI and the innovation it unlocks," Treasury Secretary Scott Bessent wrote on X. "But open source is not open season on American IP."[9] US officials now put a dollar figure on the whole problem too: distillation is costing American labs as much as $6 billion a year, according to an internal government estimate reported by Bloomberg.[4]
None of that evidence has been published. Kratsios didn't say how the government determined Kimi K3 came from Fable, and Moonshot didn't respond to US outlets asking about its training process.[1] It did deny the charge to a Chinese outlet, National Business Daily, attributing Kimi K3's gains to changes in the model's underlying architecture rather than to copying anyone else's work.[9] Independent researchers have their own reason for doubt, and it has nothing to do with taking Moonshot's word for it: the timeline is tight. "I don't think you get a model this strong and this quickly on the heels of Fable doing strictly distillation," Braden Hancock, a researcher at the Laude Institute and co-founder of Snorkel AI, told TechCrunch. Fable had only been public since July 1st, three weeks before Kratsios's post, and reproducing frontier-level reasoning takes more than a fast fine-tune.[8] The accusation is doing real policy work anyway.
Distillation is the technique of training a smaller model to reproduce a larger one's outputs, and it is completely ordinary: labs do it to their own models constantly to make cheaper, faster versions. What Anthropic wants regulated isn't the technique. It's a threshold.
In June, Anthropic published its Advanced AI Framework, a proposal for how the US government should handle catastrophic risk from frontier models.[5] The framework would apply only to models trained on more than 10²⁵ floating-point operations, built by companies earning over $500 million in AI revenue or spending over $1 billion on AI research. Those companies would have to test their models for biological, cyber, and loss-of-control risk, publish the results, submit to independent evaluation, and maintain a security program, including, explicitly, "channels to report model distillation attacks" to a designated federal agency. In exchange, the government would get legal authority it doesn't currently have: the power to block a dangerous model's deployment outright, with civil penalties that scale with a company's global revenue.
That threshold doesn't mention China. Written as law, it would bind Anthropic, OpenAI, and Google DeepMind exactly as it would bind any US-regulated lab that crossed the same lines. That's a real complication for anyone assuming this is simply a China play dressed up as safety policy: the rule Anthropic is asking for would apply to itself.
Chip export controls protect access to compute.[6] API-based deployment protects access to a running model, since a company can monitor it, patch it, or cut it off. Once weights are released, neither lever works anymore.
That is the frame Anthropic keeps returning to across its own policy documents: not who owns a model, but whether anyone can still turn it off. It explains why the company isn't running a campaign against every open-weight release. A 7-billion-parameter coding model poses a different problem than Kimi K3, which Moonshot's own site says "demonstrated frontier-level performance" across its evaluation suite, trailing only Claude Fable 5 and GPT 5.6 Sol.[1] The alarm isn't about weights. It's about frontier weights becoming irreversible in public, at a scale nobody can undo. Moonshot set July 27th as its own deadline for putting those weights on Hugging Face; independent trackers reported them live a day early, on July 26th.[10] Whatever the government's case against Moonshot amounts to, the scenario Anthropic's framework actually worries about, a frontier model nobody can recall, stopped being hypothetical for this one this week.
Every serious lab distills its own outputs into smaller models. Every serious lab also trained its frontier system by ingesting enormous amounts of other people's content from the open internet, a fact several ongoing lawsuits against Anthropic and OpenAI exist specifically to litigate.[1] Drawing a clean line between "a competitor learning from your API" and "a competitor stealing your model" requires distinguishing intent and scale in a way that current law doesn't do well.
The volume in the Alibaba case, 28.8 million exchanges through 25,000 accounts built to evade detection, reads less like normal usage than like a coordinated extraction effort.[3] "When a model has learned to reason through software weaknesses, security gaps, and attack paths, copying its behavior also copies that analytical capability," one industry executive told CyberScoop of the pattern.[1] That's a real distinction. It's also one that depends entirely on evidence the public hasn't seen, in a case where the accuser and the alleged victim happen to be the same company lobbying for the rule that would formalize the distinction.
The bigger uncertainty is evidentiary, not motivational. The government still hasn't published its evidence, and the independent researchers who've weighed in, Hancock among them, are skeptical the timeline supports the theory at all[8], whatever Moonshot's own denial is worth.[9] If the accusation doesn't hold up, the live enforcement action collapses, and the broader argument that this is really about irreversibility rather than geography loses its clearest supporting case. It's also possible this isn't a coordinated strategy at all: a company protecting its IP and an administration already committed to a China-hawk trade posture can arrive at the same rhetoric by convergence, without either one designing the other's move.
Kratsios never published the evidence behind his accusation. Beijing didn't wait for him to: its commerce ministry called the threat itself "AI hegemonism" this week and promised countermeasures of its own, treating an unpublished allegation as grounds enough for retaliation. Whether Kratsios ever makes his evidence public will say more about how this policy actually gets applied than anything Anthropic has written down.
CyberScoop: "White House accuses Chinese company of distilling Anthropic's Fable," July 22, 2026 Inline ↗
TechCrunch: "Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports," Feb. 23, 2026 Inline ↗
Reuters: "Anthropic says Alibaba illicitly extracted Claude AI model capabilities," June 24, 2026 Inline ↗
Bloomberg: "Anthropic, OpenAI Warnings Prompt Distillation Debate in DC," July 13, 2026 Inline ↗
Anthropic: "Policy on the AI Exponential" and Advanced AI Framework, June 2026 Inline ↗
Anthropic: "Securing America's compute advantage: Anthropic's position on the diffusion rule," April 30, 2025 Inline ↗
Axios: "OpenAI and Anthropic unite against China's open models," July 22, 2026 Inline ↗
TechCrunch: "Experts say exploiting Anthropic's Fable isn't how Kimi K3 got so good," July 23, 2026 Inline ↗
Reuters: "China accuses US of 'AI hegemonism,' threatens countermeasures over potential probes," July 27, 2026 Inline ↗
Moonshot AI: Kimi K3 tech blog, "Open Frontier Intelligence" Inline ↗