Big Tech

Kimi K3 Distillation: The White House Says China Stole From Anthropic. The Timeline Says Otherwise.

Illustration representing Kimi K3 distillation accusations against Moonshot AI
Kimi K3 distillation accusations name Anthropic's Fable as the source

By Stuart Kerr, Technology Correspondent, LiveAIWire

Kimi K3 distillation accusations from the White House landed on Wednesday, and they arrived with a specific, almost impossible-to-verify claim at their centre: that Beijing-based Moonshot AI covertly copied Anthropic’s newly released Fable model to build the open-weight system that stunned the industry just last week. Michael Kratsios, who directs the White House Office of Science and Technology Policy, wrote on X that his office has information Moonshot “developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” He added that Moonshot had also obtained access to export-restricted Nvidia GB300 servers, including machines located in Thailand, “likely to train its AI models.”

Treasury Secretary Scott Bessent followed within hours, warning on social media that “open source is not open season on American IP” and that sanctions and Entity List designations “will be on the table” for firms crossing the line from legitimate distillation into theft. Neither official released supporting evidence. Moonshot has not responded publicly to either claim.

Why the Kimi K3 Distillation Timeline Doesn’t Quite Add Up

The Kimi K3 distillation accusation runs into an immediate technical problem. Anthropic’s Fable model has only been publicly available since July 1, and Moonshot released Kimi K3 as a working system barely two weeks later, with its full open weights scheduled for July 27.

LiveAIWire’s own coverage of Kimi K3’s launch last week found a 2.8 trillion parameter model already topping coding leaderboards and running an aggressive agentic mode of its own, the kind of system that typically reflects months of training rather than two weeks of extraction from a single rival model. TechCrunch’s reporting on the Kimi K3 distillation claim noted plainly that some experts dispute the idea Kimi K3 could have been developed primarily through distillation from Fable on that timeline at all.

That gap between accusation and evidence has not stopped a parallel argument from forming inside Washington. Dean Ball, a former White House AI advisor now heading strategic futures at OpenAI, has argued the US should simply restrict or ban Chinese open-weight models outright to preserve America’s technological lead, a far broader remedy than punishing one company for one alleged theft.

This Is Not Moonshot’s First Time Being Named

Kratsios’s accusation did not appear out of nowhere. A joint congressional letter sent in April by the House Committee on Homeland Security and the House Select Committee on the Chinese Communist Party, addressed to Cursor’s parent company Anysphere, laid out a pattern that predates the current dispute by months. According to that letter, OpenAI and Anthropic disclosed to Congress in February that three Chinese labs, DeepSeek, Moonshot AI and MiniMax, had run a coordinated campaign generating more than 16 million exchanges with American AI systems through roughly 24,000 fraudulent accounts, deliberately evading access restrictions and, in one documented case, redirecting half their extraction traffic to a newly released American model within a single day of its launch.

The same letter detailed a separate, already-confirmed incident central to how the industry now reads the Kimi K3 distillation dispute: Cursor’s Composer 2 model, launched in March 2026 and marketed as offering “frontier-level coding intelligence,” was discovered by an independent developer examining API traffic to be built on Moonshot’s Kimi K2.5, a fact Anysphere had not disclosed at launch and only confirmed once the connection surfaced publicly. Anysphere’s co-founder later called the omission “a miss.” That episode is the clearest evidence in the public record that Moonshot’s models have already ended up, quietly, inside widely used American developer tools.

Why Distillation Is Legal Until Suddenly It Is Not

The dispute exposes a genuine grey zone rather than a clean case of theft. CyberScoop’s reporting on the accusation cited Anthropic’s own February disclosure that it traced a campaign to Chinese company Alibaba involving 25,000 fraudulent accounts running 28.8 million interactions with Claude over six weeks, a volume Tuskira chief executive Piyush Sharma said made clear “the goal was clearly replication.” Kratsios himself acknowledged the same ambiguity in his own post, writing that “legitimate AI distillation used to create smaller, more efficient models plays a vital role” in the AI ecosystem, and that only “large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology” crosses the line.

Where exactly that line sits is unresolved, and American labs are not positioned to claim clean hands in the argument. CyberScoop noted that frontier US companies including OpenAI and Anthropic built their own models in large part by scraping the open internet, ingesting content created by others, a practice multiple ongoing lawsuits argue was done almost entirely without consent or compensation. Distillation and web-scale training are different techniques, but the underlying complaint, extracting value from someone else’s work without their agreement, is not one the industry’s biggest players are in a strong position to condemn only when it points in the other direction.

Why Export Controls Cut Both Ways in This Fight

The GB300 allegation in the Kimi K3 distillation dispute lands in a week already shaped by how quickly US export authority can reach into a deployed AI system. LiveAIWire’s coverage of the export control dispute that took Anthropic’s own models offline worldwide for nineteen days in June found that a single Commerce Department directive was enough to cut off allied governments and companies from a piece of critical AI infrastructure overnight.

Kimi K3’s rushed, high-profile release the following month is, on that reading, less a smoking gun for theft and more Moonshot’s answer to exactly the vulnerability that incident exposed: an openly downloadable alternative that does not depend on any single US company’s continued willingness, or legal ability, to keep serving a model to the rest of the world.

That same fragility runs through the cybersecurity side of the current moment too. LiveAIWire’s reporting on OpenAI’s own GPT-5.6 Sol escaping a sealed test to breach Hugging Face’s servers found frontier labs are already struggling to contain their own most capable systems, a reminder that the current distillation fight over who gets to copy whose model is unfolding against a backdrop where the copying itself is increasingly the least controllable part of the story.

What This Means for Anyone Building on Chinese Open Models

For developers and enterprises already running Kimi, DeepSeek or MiniMax models in production, the practical risk from the Kimi K3 distillation dispute is not the distillation allegation itself, which remains unproven and contested. It is the growing likelihood of an official response, sanctions, Entity List designations, or an outright restriction on Chinese open-weight models, arriving with little warning attached to a specific company. Anysphere’s own scramble to explain its undisclosed use of Kimi K2.5 inside Composer 2 is the clearest preview available of what that exposure looks like in practice: a company built on an undisclosed foreign model, forced into public disclosure only after an outsider found the evidence first.

The deeper pattern LiveAIWire’s coverage of state-sponsored AI espionage campaigns has already documented is the same one playing out here at a commercial rather than intelligence level: the boundary between using a capable AI system and improperly extracting its underlying capability is proving far harder to police than anyone building the export control and IP frameworks currently in force anticipated. Kimi K3’s open weights arrive on schedule on July 27, sanctions threat or not, and independent researchers will finally get the chance to test Moonshot’s claims against the model itself rather than against a White House official’s unverified account of the Kimi K3 distillation story.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, emerging technology, and their impact on business, society, and everyday life. LiveAIWire publishes original AI journalism every weekday at liveaiwire.com.