Top White House technology official Michael Kratsios leveled serious accusations against Chinese artificial intelligence startup Moonshot AI on Wednesday, alleging the company engaged in deceptive practices to extract data from Anthropic’s advanced Fable 5 model. Kratsios claims Moonshot then used this pilfered data to train its recently released Kimi K3 system, a move the administration is framing not as a competitive AI practice, but as the theft of American intellectual property. This framing signals a potential escalation in U.S. policy responses, including tighter API restrictions and expanded export controls on advanced AI chips.
Kratsios, speaking through a post on the social media platform X, asserted that the U.S. government possesses information indicating Moonshot developed a sophisticated, purpose-built platform and employed multiple access methods specifically designed to evade detection while siphoning data from Fable 5. "Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable," Kratsios stated.
Further adding to the gravity of the allegations, Kratsios also claimed that Moonshot had acquired servers equipped with highly sought-after Nvidia GB300 AI chips and deployed them in Thailand, "likely to train its AI models." This move suggests a deliberate effort by the Chinese company to circumvent U.S. export controls by leveraging computing infrastructure located outside of American jurisdiction.
At the time of reporting, neither Moonshot, Anthropic, nor the White House Office of Science and Technology Policy (OSTP) had immediately responded to requests for comment from The New Stack.
Understanding Model Distillation in the AI Landscape
To fully grasp the implications of the White House’s accusations, it is crucial to understand the technical process of model distillation. In essence, model distillation is a widely accepted and prevalent technique in AI development. It involves training a smaller, more cost-effective AI model by utilizing the outputs generated by a larger, significantly more resource-intensive "frontier" model. This process is instrumental in reducing the prohibitive computing costs traditionally associated with training novel AI tools from scratch.
The dispute, therefore, is not with the concept of distillation itself, but with the alleged methodology employed by Moonshot. The White House contends that Moonshot accessed Fable 5 through deceptive means, purportedly violating Anthropic’s terms of service. Kratsios alleges that the access methods were specifically engineered to evade detection, enabling the large-scale harvesting of proprietary outputs.
Key questions remain unanswered regarding the specifics of the alleged operation. The nature of the telemetry supporting the administration’s claims has not been publicly disclosed, nor has it been confirmed whether Anthropic has independently identified or documented such activity within its own system logs.
A History of Suspicion: Previous Allegations Against Moonshot
These latest allegations do not emerge in a vacuum. In February, Anthropic itself publicly accused Moonshot, alongside DeepSeek and MiniMax, of orchestrating coordinated distillation campaigns against its Claude model. Anthropic attributed over 16 million exchanges across approximately 24,000 fraudulent accounts to these three companies. Moonshot, in particular, was linked to 3.4 million of these suspicious exchanges. This prior accusation by a leading AI developer lends a degree of credibility to the current U.S. government’s concerns.
Kimi K3’s Rapid Rise Raises Red Flags
Kratsios’s accusation followed the public unveiling of Moonshot’s Kimi K3 model by just six days. On July 16, the Chinese AI startup announced Kimi K3, a massive 2.8 trillion-parameter model. Moonshot promoted K3 as the world’s largest open-weight AI system, claiming its performance capabilities were approaching those of Anthropic’s frontier Fable 5 model. The full model weights were scheduled for release on July 27 and were not yet publicly available for download at the time of the announcement.
The apparent parity in capabilities between Kimi K3 and Fable 5 immediately drew scrutiny from Washington. The Kimi K3 launch occurred approximately five weeks after the U.S. government issued an export control directive that compelled Anthropic to temporarily suspend access to its Fable 5 and Mythos 5 models, citing national security concerns. Anthropic subsequently resumed global Fable 5 access on July 1 and restored Mythos 5 for approved U.S. organizations more than two weeks before K3’s launch. Nevertheless, the swift release of Kimi K3 highlights the rapid pace at which China’s open AI ecosystem appears to be closing the gap with heavily guarded U.S. systems, thus prompting investigations into the mechanisms driving this convergence.
Thailand’s Compute Loophole: A Growing Concern
The specific allegation that Moonshot accessed Nvidia GB300 servers in Thailand addresses a growing concern among U.S. policymakers. While restricting chip exports is a direct measure, preventing companies from renting computing power in other countries presents a far more complex challenge.
If Kratsios’s claim proves accurate, Moonshot would have either obtained or remotely accessed GB300 systems located in Thailand. Such an arrangement would not necessarily constitute a violation of U.S. export controls in itself. The legality would hinge on various factors, including the ownership of the servers, the identity of the computing access provider, and the presence of any relevant licenses.
This scenario suggests a potential strategy for Chinese AI companies: instead of importing restricted chips into China, they could rent access to servers in locations like Thailand or the Middle East. This outsourced computing power could then be utilized remotely to perform large-scale distillation workloads, effectively bypassing direct U.S. export restrictions.
Export Controls Face Evolving Limitations
The accusations against Moonshot represent the latest escalation in a broader administration-wide campaign targeting the suspected extraction of U.S. AI intellectual property. In February, OpenAI alerted U.S. lawmakers to DeepSeek’s alleged efforts to replicate leading American AI labs’ models. Following this, the U.S. State Department initiated a global diplomatic outreach in late April. A diplomatic cable reviewed by Reuters revealed that the State Department aimed to inform allies about widespread attempts by Chinese companies, explicitly naming Moonshot AI, to siphon intellectual property from American laboratories.
A key passage from the April cable articulated the administration’s concern: "AI models developed from surreptitious, unauthorized distillation campaigns enable foreign actors to release products that appear to perform comparably on select benchmarks at a fraction of the cost but do not replicate the full performance of the original system."
Implications for U.S. AI Policy
Regardless of whether these claims are definitively proven, they possess the potential to accelerate policy initiatives already under consideration in Washington. U.S. model developers, such as Anthropic and OpenAI, may face increased pressure to implement stricter access controls for their APIs. This could involve measures to make it more difficult for companies to create proxy accounts for large-scale distillation operations.
Furthermore, the Commerce Department could expand its export control measures. This might involve directly targeting remote cloud service access in countries like Thailand, thereby limiting their ability to lease Nvidia GPU clusters to Chinese companies. Beyond these measures, the administration might consider imposing sanctions on Moonshot or other implicated organizations. Additionally, there could be a concerted effort to encourage allied governments to enhance their monitoring of AI training activities within their borders and to report any potential violations of U.S. export controls.
For the technology sector, the immediate future remains uncertain. The industry awaits whether the administration will provide concrete technical evidence to substantiate Kratsios’s claims, or if these pronouncements will serve as the prelude to a new phase in the ongoing AI trade war. The delicate balance between fostering technological innovation and safeguarding national security interests continues to be a central challenge for global AI governance.
