Key Takeaways
- The White House claims Moonshot AI built a covert platform to systematically distill Anthropic's Fable model and evade detection.
- The accusation lands days after Anthropic settled a $1.5 billion copyright lawsuit for training Claude on pirated books.
- Critics say the US government is protecting a company's IP while that same company just paid for misusing others'.
The White House has directly accused Chinese AI startup Moonshot AI of distilling Anthropic's flagship Fable model to develop its recently released Kimi K3. The allegation escalates a months-long dispute over intellectual property theft in the AI industry into an official national security matter.
Michael Kratsios, Assistant to the President and Director of the White House Office of Science and Technology Policy (OSTP), posted the allegation on X on Wednesday, claiming the US government has evidence that Moonshot built "a sophisticated internal platform to conduct large scale distillation against U.S. models," and that the company deliberately rotated between multiple access methods to evade detection.
We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model.
— Director Michael Kratsios (@mkratsios47) July 22, 2026
To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of…
Kratsios also alleged that Moonshot AI has acquired servers equipped with Nvidia's GB300 chips and has accessed GB300 infrastructure in Thailand, likely for training its AI models — a claim that raises questions about how the Beijing-based company is circumventing US chip export restrictions.
What Is the Allegation?
Distillation in AI is the process of training a smaller, cheaper model by feeding queries to a larger, more capable model and harvesting its outputs. The White House says it supports legitimate uses of distillation as part of an open innovation ecosystem, but draws a hard line at what it describes as "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology."
This latest accusation is not the first of its kind. Back in February, Anthropic publicly accused Moonshot AI, along with DeepSeek and MiniMax, of running large-scale distillation attacks, claiming the labs generated more than 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.
In April, the OSTP formalized its position by issuing memorandum NSTM-4, titled "Adversarial Distillation of American AI Models," which directed federal agencies to share intelligence with AI companies and explore accountability measures against foreign actors.
Signs That K3 May Be a Distilled Model
The timing of these allegations coincides with growing technical evidence that Kimi K3 may not be entirely homegrown.
Shortly after the model's July 16 launch, a screenshot circulated online showing K3 identifying itself as "Claude, an AI assistant made by Anthropic" in at least one user conversation.
There’s a large grain of salt!🧂
— Denise Wu (@denisewu) July 17, 2026
Kimi is still calling itself Claude. pic.twitter.com/fiGAPdbJrP
Researchers have also flagged discrepancies in K3's efficiency profile. Ryan Greenblatt, Chief Scientist at Redwood Research, published a statistical analysis finding a statistically significant distribution of Claude-identifying responses in K3's outputs, which he said was difficult to explain as random noise.
This is well known, but I do find that Kimi K3 claims to be Claude disproportionately often.
— Ryan Greenblatt (@RyanGreenblatt) July 19, 2026
I had Opus 4.8 do some (slop?) research about this. I was curious if K3 would ever claim to be Mythos/Fable, but we don't see this. K3 does claim to be 4.5 while claude models don't. 1/ pic.twitter.com/qtJvpiQ1Tc
Technical observers noted that while Moonshot claims K3 was trained with far less compute than Western frontier systems, the model's inference costs remain comparable to Claude Opus 4.8 and GPT 5.5, a mismatch that suggests distillation rather than architectural efficiency gains.
K3's full model weights are expected to be publicly released by July 27.
Anthropic's Own $1.5 Billion Copyright Settlement
The White House's defense of Anthropic's intellectual property arrives just days after a federal judge approved a landmark $1.5 billion settlement in a class action copyright lawsuit against the company.
The case, first filed in 2024 by bestselling author Andrea Bartz and others, alleged that Anthropic downloaded and stored millions of copyrighted books to train Claude.
US District Judge Araceli Martínez-Olguín gave final approval to the settlement on July 21, calling it "fair, reasonable and adequate." The payout covers approximately 500,000 works, with authors receiving around $3,000 per title after fees. It is the largest known copyright recovery in history.
Notably, while the presiding judge in the preliminary phase ruled that training AI on copyrighted works qualifies as fair use, the settlement was necessitated by Anthropic's separate act of illegally downloading and storing the pirated copies.
Skepticism From All Sides
The White House announcement has drawn pointed responses across the tech industry, with several voices questioning both the substance of the distillation claims and Anthropic's standing to complain.
Adrius Useckas, co-founder and CTO of ZioSec, questioned the plausibility of the narrative on X:
"So Fable has 'broad anti-distillation controls', yet got covertly distilled at industrial scale by attackers whose big trick was rotating access methods - something any bot protection vendor catches? More likely the distillation story is being oversold."
So Fable has "broad anti-distillation controls", yet got covertly distilled at industrial scale by attackers whose big trick was rotating access methods - something any bot protection vendor catches? More likely the distillation story is being oversold.
— Andrius Useckas (@daronin) July 22, 2026
Thomas Unise, head of AI at eeko systems, claimed a concerted effort to block open-weight competition. “There is clearly coordinated effort by Anthropic and OpenAI and the Trump admin to block access to open weight models. I almost believe the huggingface hack incident was planned at this point.”
Yair Savlevi, a staff software engineer at Meta, drew a comparison to the music industry's piracy wars: "Remember Napster? This is a similar situation. Open your weights and models and there is no reason to steal from you anymore. There is absolutely no way to prevent this, if Anthropic and OAI moat is the model - they are screwed."
Amodei's Prior Warning Comes Full Circle
The current controversy brings back a warning Anthropic CEO Dario Amodei gave lawmakers in 2023, claiming open-source AI was heading down “a very dangerous path.”
Amodei argued at the time that once a powerful model is released openly, its developers lose the ability to monitor misuse, revoke access or update safety guardrails.
"When a model is released in an uncontrolled manner, there's no ability to do that. It's entirely out of your hands," Amodei told the committee. "And so I think that should be attended to carefully."
Three years later, the argument is being used to justify government intervention on Anthropic's behalf — but critics see it differently. A widely circulated Reddit thread resurfaced the testimony alongside accusations that Amodei's safety framing conveniently serves Anthropic's business interests.
"A guy who owns an AI company doesn't want AI companies to be competed with by free versions? Really?" was the top-voted comment.
What Comes Next
| Development | Expected Timeline |
|---|---|
| Kimi K3 full model weights public release | July 27, 2026 |
| Ongoing federal enforcement under NSTM-4 memo | Continuing |
| Deterring American AI Model Theft Act (H.R. 8283) | Under congressional review |
| Remaining AI copyright lawsuits (OpenAI, Google, others) | Pending in multiple courts |
The K3 weights release on July 27 is likely to be the next flashpoint. Once the model is publicly available, independent researchers will be able to scrutinize it for fingerprints of distillation, potentially either validating or undercutting the White House's claims.
In the meantime, the AI industry finds itself in an uncomfortable paradox: the US government is defending the intellectual property of a company that just paid $1.5 billion for misusing other people's intellectual property, while the company accused of theft is releasing its model for free.
Editor's Note: For more on AI's tumultuous political landscape...
- The Chips Cold War: How GPUs Became the World’s Most Valuable Political Resource — Are AI chips the new oil?
- Anthropic CEO Accuses OpenAI of 'Safety Theater' in Pentagon AI Deal — Anthropic’s CEO unloads on OpenAI in a leaked memo.
- President Trump Signs Executive Order to Block State AI Laws — Trump's AI executive order aims to block state regulations.