US may sanction China’s Moonshot for distilling Anthropic’s Fable

US may sanction China’s Moonshot for distilling Anthropic’s Fable

Washington is threatening to impose sanctions on Chinese artificial intelligence (AI) companies for building their models by distilling outputs from American AI systems, saying it has found evidence of large-scale, covert theft of proprietary US technology. US Treasury Secretary Scott Bessent said Washington would investigate whether China’s leading open-weight models had been built by illegally harvesting knowledge from American AI systems. “If we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft,” Bessent told Fox Business in an interview. “We are finding watermarks of our US large language models (LLMs) on many of the Chinese models, and that’s unacceptable.” He added that the US will be looking at this matter in the coming days or weeks. Knowledge distillation is a process often likened to a student learning by asking a teacher many questions and absorbing the answers. “We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” Michael Kratsios, Director of the White House Office of Science and Technology Policy, said in a X post on Wednesday. “To do this, they developed a sophisticated internal platform to conduct large-scale distillation against US models, allowing them to quickly switch between multiple methods of access to avoid detection,” he said. “Moonshot AI has also acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models.” He stressed that it’s legitimate to use AI distillation to create smaller and more efficient models, but large-scale, covert industrial distillation aimed at stealing proprietary US technology and undermining American research is unacceptable. Reuters reported on Tuesday that US and Chinese officials will hold talks over AI in September. The AI talks will take place before Chinese President Xi Jinping’s meeting with US President Donald Trump in the US on September 24. Bessent’s remarks came after Moonshot AI, backed by Alibaba, Meituan and Tencent, released Kimi K3 on July 17, which was accused of using data distilled from American AI models. A head-to-head benchmark comparison puts Claude Fable 5 ahead in 22 of 35 shared evaluations, with clear advantages in vision and knowledge tasks. Kimi K3 nevertheless leads in long-horizon coding and terminal-use benchmarks, and costs 70% less per token at US$3 per million input tokens against Fable 5’s US$10. In April, the White House issued a memorandum, known as National Security Technology Memorandum 4 (NSTM-4), to formally designate adversarial distillation as a national security threat. The document warned that foreign actors could rapidly clone frontier AI capabilities at relatively very modest cost by flooding American systems with targeted queries and collecting their responses. It directed federal agencies to share intelligence with AI companies and explore ways to hold foreign actors accountable. Moonshot AI’s business head Huang Zhenxin denied on Tuesday that Kimi K3 was built by distilling outputs from other AI models. He said its improved performance relies on three original innovations: Moon Clip, which doubles training efficiency while halving computing costs; Kimi Linear Tension, which expands the model’s context window tenfold; and Attention Residuals, praised publicly by Elon Musk, which boosts reasoning speed by 25%. In simplified terms, the three innovations can be understood as follows: Moon Clip: A strict data filter selects only Moonshot’s own training sources, blocking any externally derived content, much like cooking only with homegrown ingredients rather than buying pre-made food from a competitor. Kimi Delta Attention: Instead of comparing every word to every other word in a text, this technique approximates those relationships more efficiently, letting the model handle very long documents without a sharp rise in computing costs. Attention Residuals: A memory shortcut lets deeper layers of the model retrieve insights from earlier layers directly, rather than trying to recall everything from scratch, like a student flipping back to rough notes while solving a final exam question. Chinese media commentators have accused Washington of applying double standards, arguing that distillation is treated as innovation when American firms do it but as theft when Chinese developers do the same. A commentary published by Guancha.cn said it was unjust to brand Chinese AI developers as IP thieves for using distillation while US counterparts were lauded as engineers for doing the same. The piece cited Inkling, the debut model from Thinking Machines Lab, founded by former OpenAI Chief Technology Officer Mira Murati, which was built on DeepSeek’s architecture and trained on data generated by Moonshot AI’s Kimi K2.5. “Chinese open-weight models share their technology freely, cut costs and let the whole world build on top of them,” the commentary said, citing Chinese netizens. “Meanwhile, American closed labs hide everything, charge a premium and lobby for restrictions, then turn around and call everyone else a thief. The irony is breathtaking.” At the heart of the debate is a fundamental divide in how AI companies release their models. Open-source models make their underlying weights freely available for anyone to download, modify and build upon, as seen in DeepSeek, Kimi K3 and Alibaba’s Qwen series, while closed models like OpenAI’s GPT series and Anthropic’s Claude Fable 5 keep those weights proprietary, accessible only through a paid interface. At the launch of Inkling in July 2026, Thinking Machines Lab said the AI model’s architecture was largely modeled on DeepSeek-V3, a Chinese open-source model, with its post-training bootstrapped using synthetic data generated by Moonshot AI’s Kimi K2.5, a process critics say falls squarely within the definition of distillation that Washington has now threatened to sanction. Alibaba’s fake accounts The US sanctions threat had been building for months. In a February 12 memorandum to the US House Select Committee on China, OpenAI said DeepSeek had used distillation to free-ride on US frontier AI capabilities, and had detected new methods designed to bypass its safeguards. Anthropic said on February 23 it had identified industrial-scale distillation campaigns by DeepSeek, Moonshot and MiniMax to illicitly extract Claude’s capabilities, using covert methods to circumvent its access restrictions. In a letter to US Senators Tim Scott and Elizabeth Warren dated June 10, Anthropic said Alibaba had mounted a distillation campaign against its Claude models from April 22 to June 5, generating more than 28.8 million exchanges through nearly 25,000 fraudulent accounts, targeting capabilities including agentic reasoning, software engineering and long-horizon tasks. It urged Congress to facilitate intelligence sharing between AI companies, close chip access loopholes and penalize firms behind distillation attacks. “Some countries hype up distillation,” China’s Assistant Foreign Minister Bin said at the World AI Conference in Shanghai on July 18, without specifically naming the US. “This is misguided and counterproductive.” Although distillation has allowed Chinese AI firms to achieve rapid performance gains at a fraction of the cost, some commentators in China have pointed to a significant structural weakness in the approach. A commentator on Sina.com said that during the 2026 World Cup, users found DeepSeek’s V4-Pro unable to answer questions about the tournament. Its knowledge frozen at May 2025, it was fabricating excuses rather than admitting the gap. He called this an inevitable price of DeepSeek’s low-cost strategy, as its architecture struggles to perform inference on the latest information at a reasonable cost. Read: US sounds alarm on China’s AI distillation as DeepSeek V4 debuts Follow Jeff Pao on X at @jeffpao3

Original Source

Read the full article at Asiatimes →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.