The US government has threatened sanctions against Chinese AI model developers accused of carrying out “industrial-scale” distillation programs targeting American AI models. The warning follows months of pressure from leading US AI labs, including Anthropic and OpenAI, who argue that distillation has allowed Chinese competitors to close the performance gap while spending far less on training and infrastructure.
The most recent accusation was directed at Moonshot AI, which has drawn international attention for its Kimi K3 model. On Wednesday, White House science and technology policy chief Michael Kratsios alleged that Moonshot had distilled Anthropic’s Fable model and had also accessed servers equipped with Nvidia GB300 chips, which would represent another violation of US export control rules. Hours later, Treasury Secretary Scott Bessent warned that sanctions are on the table for companies found to be improperly distilling AI models. “Open source is not open season on American IP,” Bessent wrote on X. “When industrial-scale distillation attacks cross the line into IP theft, sanctions and Entity List designations will be on the table.”
Distillation increasingly becoming a dirty word
Model distillation is a common training technique in the AI industry, in which smaller models learn from the outputs of much larger foundation models. This can help AI developers reduce the overall cost of training and running a model. Distillation itself is widely used across the AI industry, although companies disagree over when learning from another model’s outputs crosses into intellectual property infringement.
Unlike some forms of copying, distillation does not clone model weights directly. Instead, it uses outputs generated by a larger model to train a smaller model. In the simplest form, a developer sends prompts to a frontier model, records the responses, and then fine-tunes a cheaper model on those responses. This allows the smaller model to imitate the style, reasoning patterns, and output quality of the larger model without requiring the same amount of proprietary data or compute. Most major AI labs use some form of distillation internally, often to create efficient student models from larger teacher models. The legal problem arises when distillation is done without authorization, particularly when a competitor uses a model’s outputs to replicate its functionality at a fraction of the cost.
Anthropic and OpenAI have alleged that Chinese companies go far beyond accepted distillation. They claim that some developers have automated the process at an industrial scale, potentially using thousands of API calls to harvest outputs from frontier models. The resulting models are then released commercially, undercutting the original developers on price and eroding their advantage. Anthropic and OpenAI have also raised concerns that the output of models like GPT-5.6 and Fable could be used to train models that eventually become embedded in government systems or weapons platforms.
The two leading US AI developers are spending huge amounts building and training their models, only to see competitors launch models with comparable performance weeks later and at much cheaper cost per token. While both companies have been pressing the Trump administration to do more to counter the practice, a wide range of technology leaders have signed an open letter arguing that access to Chinese AI models is benefiting the wider industry by lowering operating costs and providing a broader range of AI services.
Moonshot has not said whether it distilled Fable, although it cited only Fable and GPT-5.6 as outperforming its own Kimi K3 model in overall capability. OpenAI President Greg Brockman said in a recent interview that the model was “impressive” and that he was not aware of whether it had distilled GPT. The company’s refusal to confirm or deny the allegation reflects the legal uncertainty surrounding distillation in the absence of clear international rules.
What sanctions and Entity List designations would mean
If sanctions are imposed, businesses could face fewer choices among frontier AI models while governments tighten restrictions on cross-border AI deployment. An Entity List designation would restrict Moonshot AI or similar companies from purchasing US technology, including semiconductor components, software, and services. It would also put pressure on overseas suppliers to avoid dealing with the designated firms. Financial sanctions could freeze assets and bar US citizens and companies from transacting with the targets. The threat is significant because Chinese AI developers still rely on US-designed chips and cloud services for parts of their operations, despite efforts to build domestic alternatives.
These concerns are not new. Washington has spent years building an export-control architecture designed to limit China's access to advanced semiconductor technology. Nvidia GB300 chips are among the most powerful AI accelerators available, and US rules restrict their sale to certain Chinese entities. If Moonshot accessed GB300-equipped servers through a third-party cloud provider, that could be seen as a deliberate attempt to circumvent controls. The Trump administration's decision to link distillation to export-control violations suggests that AI model weights and training techniques are now treated as strategically important as advanced chips.
The situation is becoming increasingly critical, as Anthropic’s Mythos model is being deployed by several US departments and agencies to help prevent cybercrime and cyberattacks. The National Security Agency is reportedly using the model for offensive cyber planning. The integration of frontier AI models into national security infrastructure means that concerns about distillation extend beyond commercial competition into matters of cybersecurity and military advantage.
US and China tightening export restrictions
The White House has tightened export rules covering frontier AI models, banning Anthropic’s Fable from export and requiring OpenAI and Google to initially release frontier and cyber models in preview to selected partners before making them more widely available. This has led other countries and multinational institutions to look into sovereign AI services, which are not beholden to the American or Chinese government. Sovereign AI initiatives are gaining momentum as governments in Europe, the Gulf, and Southeast Asia seek to build their own model ecosystems to avoid being caught between Washington and Beijing.
On the other side of the Pacific, the Chinese government is also considering restricting the export of its frontier AI models. Chinese open-source and open-weight models have attracted significant attention from businesses around the world over the past few months, largely because of their lower costs compared with frontier models developed by OpenAI and Anthropic. If Beijing imposes export controls, the global AI market could become even more fragmented, with Western buyers locked out of some Chinese models and Chinese developers unable to legally use American technology.
The broader implications are significant. Businesses that have built their products on the assumption that they can mix and match frontier models from different countries may need to prepare for new compliance obligations. Legal teams will need to trace model provenance, verify training data, and assess whether their systems use models derived from unauthorized distillation. Governments may demand proof that imported models have not been trained through prohibited means.
As Washington and Beijing tighten controls over advanced AI technologies, businesses may face a more fragmented AI market with fewer cross-border model choices and greater compliance challenges. Whether sanctions are ultimately imposed, the dispute signals that AI competition is increasingly being shaped by geopolitics as much as technological innovation. The coming months will determine whether distillation remains a standard research technique or becomes another flashpoint in the US-China technology war.
Source: TechRepublic News