
Image: Flickr / Wikimedia Commons / Unsplash
Moonshot AI Is at the Center of Anthropic's Distillation Fight With China
Dario Amodei's allegations against Chinese AI labs escalated into a White House sanctions threat over Kimi K3. Here is the full timeline and what it means for US builders.
This article was produced by the AETW editorial team.
Anthropic has spent 2026 building a public paper trail accusing Chinese AI labs of stealing Claude's capabilities through distillation, and the fight reached the White House after Moonshot AI's Kimi K3 model rattled Silicon Valley.
A distillation fight goes fully public
Moonshot AI has spent the last two weeks at the center of the sharpest US-China AI dispute of 2026. The Beijing-based startup released Kimi K3 on July 16, an open-weight model that immediately posted benchmark scores at or above Anthropic's and OpenAI's best systems, despite Moonshot operating on a fraction of the compute budget of its American rivals. Within a week, a senior White House official was publicly accusing the company of building K3 by covertly copying Anthropic's Claude Fable 5 model.
That accusation did not appear out of nowhere. It capped months of escalating claims from Anthropic CEO Dario Amodei's company about Chinese labs extracting Claude's capabilities through a technique called distillation, and it landed in the middle of an industry-wide brawl over whether Washington should restrict open-weight AI models at all. Anthropic, notably, sat out a 25-company letter defending open models, and Amodei has now laid out exactly why in a lengthy blog post responding to critics who accused him of using national security as cover for commercial self-interest.
For US teams building on open-weight models or watching the chip export debate, the Moonshot AI case is now the clearest real-world test of how the government plans to police the boundary between ordinary AI competition and what it considers theft.
The paper trail: DeepSeek, Moonshot AI, MiniMax, then Alibaba
Anthropic's public case against Chinese AI labs did not start with Kimi K3. In February 2026, the company disclosed that three Chinese labs, DeepSeek, Moonshot AI, and MiniMax, had run coordinated campaigns using roughly 24,000 fraudulent accounts to extract Claude's outputs and use them to train competing models, a practice known as distillation. MiniMax accounted for the bulk of that activity, with Moonshot's share put at just over 3.4 million exchanges at the time.
Anthropic escalated again in June, telling the Senate Banking Committee in a letter that operators tied to Alibaba's Qwen lab had run a far larger campaign between April 22 and June 5, generating more than 28.8 million exchanges with Claude through nearly 25,000 fake accounts. That campaign specifically targeted Claude's software engineering and agentic reasoning capabilities, the parts of the business Anthropic considers hardest to build and most commercially valuable. Alibaba has denied wrongdoing, and Chinese state media has dismissed Anthropic's claims as unsubstantiated.
Each disclosure followed the same pattern: bigger numbers, more sophisticated evasion, and a named Chinese AI company Anthropic had not previously called out. Kimi K3 became the fourth chapter in that pattern, and the first to draw a direct, public accusation from the White House itself rather than from Anthropic alone.
Kratsios accuses Moonshot AI of distilling Fable for Kimi K3
On July 22, Michael Kratsios, director of the White House Office of Science and Technology Policy, posted on X that the administration had information showing Moonshot AI had distilled Anthropic's Fable model to build Kimi K3. He described a purpose-built internal system that let Moonshot pull outputs from US models while rotating between access methods to dodge detection, and separately alleged the company had obtained Nvidia GB300 servers, chips barred from sale to Chinese firms, both directly and through access in Thailand.
Treasury Secretary Scott Bessent followed within hours, warning that industrial-scale distillation crossing into intellectual property theft would put sanctions and Entity List designations on the table for Chinese firms. The Bureau of Industry and Security has since opened a formal investigation. As of late July, no formal sanctions had been issued and Moonshot had not substantively responded to the allegations.
Moonshot's own marketing has leaned into how close Kimi K3 gets to the frontier: the company has said the model trails only Claude Fable 5 and GPT 5.6 Sol on its own evaluation suite while beating every other tested system. That framing, ironically, is part of what makes the distillation claim plausible to some officials and dubious to others.
Sources for this section
Amodei draws a line: no ban, but chips, distillation, and testing
The Moonshot accusation landed while Anthropic was already under industry pressure over open-weight policy. When Nvidia, Microsoft, Meta, and more than 20 other companies published a letter on July 24 urging Washington to avoid "premature restrictions" on open-weight models, Anthropic and Amazon were the notable holdouts among major AI players. That silence, paired with Anthropic's steady drumbeat of distillation accusations, fed accusations from figures including White House AI adviser David Sacks that Anthropic was using national security cover to protect its closed-model business.
Amodei responded directly on July 27 with a post on Anthropic's site titled "Our position on open-weights models." His central claim: Anthropic has never advocated for a ban on open-weights models, and open models without dangerous capabilities are, in his words, a public good. What he does support is narrower: tighter controls on advanced chips and chipmaking equipment flowing to authoritarian governments, a crackdown on industrial-scale distillation, and mandatory safety testing for all sufficiently capable models, open or closed, before release.
Amodei separately laid out two fears distinct from ordinary business use of open models. One is that an authoritarian government, and he named the Chinese Communist Party specifically as the most capable one he worries about, could use a sufficiently powerful open model to pursue lasting military advantage or deepen domestic repression. The other is that open weights make it harder to apply guardrails against biological or cyberattack misuse once a model is out in the world, since released weights cannot be pulled back.
Sources for this section
The timeline that doesn't quite add up
The weakest part of the Kratsios accusation, according to independent researchers, is timing. Claude Fable 5 has only been publicly accessible since July 1, 2026, and Kimi K3 shipped just over two weeks later on July 16. Building a frontier-competitive 2.8 trillion parameter model primarily by distilling another model's outputs in that window would require a scale and speed of data collection that several AI researchers have publicly questioned, even as they note smaller-scale distillation from earlier Claude releases remains entirely plausible.
Neither the White House nor Anthropic has published the underlying evidence for the Fable-specific claim, leaving outside observers to weigh a serious accusation against a compressed and, by some accounts, implausible production schedule. Moonshot has denied the allegations but has not offered a detailed technical rebuttal, and the full Kimi K3 weights were released publicly regardless, on schedule, days after the accusation.
What US builders and operators should watch
- Whether the Bureau of Industry and Security investigation produces public evidence, or whether the Fable-distillation claim quietly fades the way earlier accusations have.
- Whether Congress moves on mandatory pre-release safety testing for frontier models, the one policy in Amodei's post that applies to open and closed models alike.
- Whether chip export enforcement tightens further, given the added allegation that Moonshot AI accessed restricted Nvidia GB300 hardware through Thailand.
- Whether US teams already running Kimi K3 or other Chinese open-weight models face new compliance exposure if sanctions or Entity List designations follow.
- Whether other Chinese AI labs, given Anthropic's pattern of naming a new company every few months, become the next public accusation.
Sources
Brian Weerasinghe is the founder and editor of AI Eating The World, where he covers artificial intelligence, tech companies, layoffs, startups, and the future of work. His reporting focuses on how AI is transforming businesses, products, and the global workforce. He writes about major developments across the AI industry, from enterprise adoption and funding trends to the real-world impact of automation and emerging technologies.

