On July 22, the White House accused Chinese AI lab Moonshot AI of running a covert, industrial-scale operation to copy Anthropic's Fable model and use it to build Kimi K3. K3 is a 2.8-trillion-parameter open-weight model that, since its July 16 release, has outranked nearly every major AI system on coding and engineering benchmarks — trailing only OpenAI's GPT-5.6 and Anthropic's own Fable 5. Fable only became publicly available on July 1, fifteen days before K3 shipped. Treasury Secretary Scott Bessent said sanctions and Entity List designations remain on the table.

1. The Government: This Is Industrial Espionage (Michael Kratsios, Scott Bessent, Sarah Heck)

This is IP theft at industrial scale — not a gray area.

Moonshot designed the platform to evade detection. Michael Kratsios, the White House science and technology chief, said Moonshot built a "sophisticated internal platform" to run large-scale distillation against U.S. models while rapidly switching between access methods to avoid getting caught. He also alleged Moonshot acquired Nvidia GB300 servers — hardware that's banned from export to China — likely through Thailand.

Anthropic's own data backs the pattern. Back in February, Anthropic reported that Moonshot had already generated 3.4 million Claude exchanges through fake accounts, targeting reasoning, coding, tool use, and computer vision. Some of those accounts matched the public profiles of senior Moonshot employees. This isn't a first offense; it's a documented pattern.

The government calls it espionage, not a business dispute. Under Secretary of State Jacob Helberg said: "This is more than a heist of invaluable American Intellectual Property." Anthropic's public policy head Sarah Heck called it "illicit, adversarial distillation — IP theft and industrial espionage that supports adversary military and intelligence capabilities." Dmitri Alperovitch, CrowdStrike co-founder, said Chinese AI's rapid progress has been built on "theft via distillation of U.S. frontier models."

2. But the Timeline Doesn't Hold (Braden Hancock, Nathan Lambert)

The specific charge about Fable is almost certainly wrong.

You can't distill a frontier model in 15 days. Braden Hancock, a researcher at the Laude Institute and co-founder of Snorkel AI, put it plainly: "I don't think you get a model this strong and this quickly on the heels of Fable doing strictly distillation." Fable went public on July 1. K3 shipped July 16. Distillation at that scale takes months, not two weeks.

Distillation doesn't make frontier models frontier. Nathan Lambert of the Allen Institute for AI argued that reinforcement learning — not supervised fine-tuning from distillation — is what drives frontier capability. As models grow more capable, copying a competitor's outputs yields diminishing returns. By this argument, K3 didn't get good by mimicking Fable's responses.

Neither official provided evidence. Kratsios and Bessent made their accusations publicly but answered no follow-up questions and shared none of the underlying data. The U.S. government's case rests on what officials asserted, not what they've shown.

3. And Moonshot Has Real Credentials (Yang Zhilin, Guillermo Rauch)

Moonshot's founder has the pedigree to build this without copying anyone.

Yang Zhilin built frontier AI before Moonshot existed. Moonshot AI's CEO has a PhD from Carnegie Mellon, worked at Meta and Google, and co-authored XLNet and Transformer-XL — foundational AI research papers. Before founding Moonshot, he contributed to Huawei's PanGu model and Beijing's Wu Dao project. His team has the background to produce K3 legitimately.

Independent evaluators say the model is genuinely strong. Vercel CEO Guillermo Rauch called K3 "the first open model to outperform proprietary systems on a comprehensive web engineering benchmark." Wharton professor Ethan Mollick described it as "the closest open model to the AI frontier." Neither has a stake in the U.S.-China dispute.

This technique is standard across the industry. Distillation — training one model on another model's outputs — is a normal AI development method. Elon Musk testified that xAI distilled OpenAI models to train Grok. Copyleaks CEO Alon Yamin noted that distillation is "becoming normalized due to competitive AI pressures, making enforcement difficult." There is a line between legitimate and adversarial use — but people disagree about where it falls.

Where This Lands

Anthropic tracked the February activity directly: fake accounts, 3.4 million Claude exchanges, Moonshot employee profiles linked to the fraud. The July charge about Fable is shakier — researchers say the 15-day window makes it essentially impossible that Fable is the primary source of K3's capabilities. Whether that distinction matters legally is still open: Moonshot's prior distillation against older Claude models may be enough to trigger sanctions regardless of Fable's exact role. Moonshot has said K3's full weights will go public July 27, when independent researchers will be able to probe its training signals directly.

Sources