Tech News · 23 July 2026

White House Accuses Moonshot AI of Stealing US AI Tech for Kimi K3

US officials allege Moonshot AI covertly distilled Anthropic’s Fable model to develop Kimi K3, with sanctions now under consideration.

What you need to know

  • The White House says Moonshot AI used covert large-scale distillation of Anthropic’s Fable to develop Kimi K3.
  • Treasury Secretary Scott Bessent says sanctions and an Entity List designation are under consideration.
  • Kimi K3 is due to publish its full open weights by 27 July, though running it will require substantial computing infrastructure.

The White House has accused Chinese AI company Moonshot AI of covertly using Anthropic’s Fable model to develop Kimi K3, its newly released open-weight AI system. Michael Kratsios, director of the White House Office of Science and Technology Policy, made the allegation in a post on X on Wednesday 22 July.

Rows of server racks in an AI data centre
No enforcement action has been announced against Moonshot AI as of 23 July 2026, but US officials say sanctions could follow within weeks.

“We have information that Moonshot AI distilled Anthropic's Fable for the development of its K3 model,” Kratsios wrote. He alleged that the company had built “a sophisticated internal platform to conduct large scale distillation against U.S. models”, allowing it to switch access methods to avoid detection.

The accusation is significant because Kimi K3 is one of the most capable Chinese models yet to challenge US frontier AI systems. But it remains an allegation: Kratsios has not published logs demonstrating that Fable outputs were incorporated into K3, and Moonshot had not responded to a request for comment before publication.

Treasury raises prospect of sanctions

The row has already moved beyond a public exchange between AI companies. Treasury Secretary Scott Bessent said sanctions and Entity List designations would be considered if Chinese firms were found to have carried out covert, industrial-scale distillation that crossed into intellectual-property theft.

“Open source is not open season on American IP. When [Chinese] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.”

Bessent said action could come within weeks. An Entity List designation would generally restrict access to advanced US technology, including the most powerful Nvidia AI chips. The Commerce Department’s Bureau of Industry and Security has also begun examining whether Chinese companies gained access to restricted US AI chips through unofficial routes.

Kratsios additionally claimed Moonshot had acquired servers containing Nvidia GB300 chips, as well as accessing GB300 systems in Thailand. The Blackwell-generation hardware is barred from sale to Chinese companies. The White House has not revealed the alleged procurement route or supporting records for those claims.

An unusually public allegation

Distillation is a standard technique in AI development: a smaller or less capable model is trained using the responses of a stronger one, with the aim of producing a cheaper, more efficient system. Kratsios himself said that legitimate distillation has “a vital role” in the open innovation ecosystem.

The US allegation concerns scale and intent. The White House says Moonshot’s purported activity was covert and industrial in nature, aimed at extracting proprietary American technology. In April, the White House’s NSTM-4 memorandum formally classified systematic covert model distillation by adversarial nations as a serious national-security threat.

Anthropic had already levelled related accusations in February. It said it had traced more than 3.4 million Claude conversations to Moonshot, routed through hundreds of fabricated accounts, and said some account records matched public profiles of Moonshot senior staff. Anthropic also accused Moonshot, DeepSeek and MiniMax of using roughly 24,000 fake accounts to generate around 16 million Claude interactions.

Moonshot is not the only Chinese developer cited in the wider debate. The brief says MiniMax and DeepSeek generated more than 13 million and 150,000 exchanges respectively in alleged unauthorised data-siphoning campaigns, while Alibaba’s Qwen lab is said to have generated 28.8 million exchanges using nearly 25,000 fraudulent accounts.

There is, however, scepticism around the specific K3 claim. Some AI researchers argue that the timeline does not support the idea that Kimi K3 was developed primarily by distilling Fable, which only became publicly available on 1 July. No enforcement action, indictment or legal proceedings against Moonshot has been announced as of Thursday 23 July.

K3 is already a serious rival

Moonshot released Kimi K3 on 16 July. The Beijing-based company describes it as a 2.8-trillion-parameter mixture-of-experts model with native visual processing, always-on reasoning and a one-million-token context window. It has 896 experts, with 16 active for each token.

Independent testing cited in the brief places it fourth among frontier models, behind Claude Fable 5 and GPT-5.6 Sol, while edging past Claude Opus 4.8. It leads the Frontend Code Arena and recorded 88.3% on Terminal-Bench, 91.2% on BrowseComp and 93.5% on GPQA-Diamond.

OpenAI president Greg Brockman acknowledged K3’s competitiveness in an interview on Tuesday, saying: “It's a pretty good model. There's no question about it.” He said it was too early to determine whether Moonshot had distilled outputs from OpenAI’s own systems, and estimated China remained roughly four months behind the US in overall model development.

Moonshot prices K3’s API at $3 per million input tokens and $15 per million output tokens. In one design-prompt comparison cited in the brief, K3 cost three cents, compared with 38 cents for Fable 5 and 11 cents for GPT-5.6. UK sterling pricing has not been confirmed.

What happens next for UK users

Moonshot has released K3 as an open-weight model and says the full weights will be made public by 27 July. That could give UK developers a powerful system they can customise around their own data rather than sending every task to a US-hosted service.

There is a large practical caveat. A 2.8-trillion-parameter mixture-of-experts model needs serious GPU capacity, inference expertise and operational monitoring to serve reliably. It is not a straightforward local download for ordinary laptop owners.

For British businesses, the immediate issue is uncertainty. Sanctions or an Entity List designation could complicate access to K3 and related services, while any broader US action over alleged digital watermarks in Chinese AI products could affect firms using Chinese AI APIs. For now, K3 remains available, the allegations remain unproven publicly, and the next move rests with US authorities.

Why it matters

Kimi K3 could offer UK developers a lower-cost, open-weight alternative to leading US AI systems, but potential US restrictions may make access and commercial use more complicated. Even if the weights are released as planned, a 2.8-trillion-parameter model is far beyond the practical hardware budget of most consumers and many smaller firms. The dispute also raises fresh questions over how AI companies protect their models while competing against increasingly capable open releases.

Sources: TechCrunch · Bloomberg