← Back to Research
AI Sovereignty / Geopolitics

The Distillation War: When Model Distillation Is Recast as IP Theft — The 2026 US-China Rules Conflict and Its Investment Implications

FutureX Research · AI Lab · 2026.07.24 · 14 pp · preview 3 pp

🎧

Listen · Audio Summary

5-8 min · AI narration in English · abstract + all key findings

Abstract

(Data updated as of 2026-08-01) On July 22, White House OSTP Director Michael Kratsios accused Moonshot AI of distilling Anthropic's Fable to build Kimi K3 and of obtaining export-restricted Nvidia GB300 servers, including access via Thailand; Treasury Secretary Scott Bessent simultaneously threatened sanctions and Entity List designation. As of August 1, no publicly verifiable evidence has been released and no formal sanctions have landed, though BIS has reportedly opened an investigation. Late July moved fast: K3's full 2.8-trillion-parameter weights were open-sourced on July 27; 20-plus companies including Nvidia, Microsoft and Meta signed a July 24 letter against blanket restrictions, while Anthropic declined and clarified it "never advocated a ban"; China's Commerce Ministry warned of countermeasures against "AI hegemonism"; and Moonshot closed a $3.5B round at a $35B valuation while advancing a Hong Kong IPO. This report layers the facts, dissects the rules conflict and maps transmission channels. Not investment advice.

Key Findings

  • 01The timeline has hardened into fact: Fable public July 1 → K3 released July 16 → July 17 Nasdaq -1.40% (close 25,520.24), Nvidia -2.2%, SMH -6.4% over three sessions → White House accusation July 22 → full K3 weights open-sourced July 27. Researchers publicly question whether a two-week window can support 'industrial-scale distillation built K3'; Bessent himself confirmed on Fox Business (July 24) the matter is still under 'investigation'. As of Aug 1: no verifiable public evidence, no sanctions.
  • 02Enforcement is advancing but has not landed: multiple US outlets report the Commerce Department's BIS has opened an investigation into GB300 export-control violations; Jensen Huang reportedly met Commerce Secretary Lutnick on July 28; the Thailand transshipment route is the enforcement focus. No Entity List designation as of Aug 1 — export controls remain the harder, more actionable of the two accusations.
  • 03Industry coalitions realigned on July 24: 20-plus firms including A16z, Dell, Microsoft, Meta, Nvidia and Palantir signed a letter opposing broad open-weight restrictions and backing targeted legal remedies for 'unlawful extraction'; signatories later grew and OpenAI joined. Anthropic declined; Amodei stated July 27 it 'never advocated a ban on open-weights models', instead backing chip controls, a distillation crackdown and mandatory safety testing — a rare convergence on 'targeted legal frameworks'.
  • 04The commercial shock is quantifiable: K3 API pricing of $3/$15 per million input/output tokens is roughly 30% of Fable 5 ($10/$50) and half of GPT-5.6 Sol ($5/$30); Coinbase's CEO says switching to Chinese open models nearly halved its AI spend. Self-hosting barriers remain high (officially at least 64 accelerators), so the 'open' dividend actually flows to cloud and inference providers.
  • 05Two-way controls are forming simultaneously: per Axios, Washington revived discussion of restricting Chinese models — centered on procurement rules, Entity List threats and public pressure rather than an unenforceable download ban; per FT/Reuters (July 19-21), China's MOFCOM consulted Alibaba, ByteDance and Zhipu on export controls covering model weights and training data, and publicly warned of countermeasures on July 27 — confirming this report's original call that control gravity shifts to deployment and procurement.
  • 06Moonshot's capital agenda accelerated and the numbers have converged: Bloomberg reported July 19 it circulated a shareholder resolution for a Hong Kong listing within six months; on July 28-29 it confirmed a $3.5B round at a $35B post-money valuation (~8x its end-2025 $4.3B), and opened a pre-IPO round targeting $50B pre-money; ARR is reportedly ~$300M (implied P/ARR above 100x) and Kimi runs on a ~20,000-GPU Nvidia cluster provisioned through Alibaba (36% shareholder), after pausing new subscriptions July 20 amid a compute crunch.

I. Layering the Facts: Verified, Reported, and Doubtful

Verified (multi-source): Fable public July 1; K3 released July 16, Nasdaq -1.40% and Nvidia -2.2% the next day; Kimi paused new subscriptions July 20 amid a compute crunch (Reuters); on July 22 Kratsios accused Moonshot on X of building an internal platform for large-scale covert distillation of US models and of acquiring GB300 servers and accessing GB300s in Thailand, while Bessent declared 'open source is not open season on American IP'; on July 27 K3's full weights shipped, China's MOFCOM warned of countermeasures, and Amodei clarified Anthropic's stance. As of Aug 1: no sanctions, no Entity List designation, no verifiable public evidence. Reported (watch): BIS has opened an investigation; Bessent claims US-model 'watermarks' were found but showed no evidence; Bloomberg (July 31) says Kimi runs on a ~20,000-GPU cluster provisioned through Alibaba. Doubtful: only ~two weeks separate Fable's release from K3's — researchers question whether that window supports the distillation claim; Moonshot denies it, citing original architecture changes. This report renders no verdict.

II. Distillation's Technical and Legal Gray Zone

Distillation — training a weaker model on a stronger model's outputs — is an industry-standard technique; Kratsios himself concedes 'legitimate distillation plays a vital role' in open innovation, hanging his accusation on 'industrial-scale, covert'. Legally it sits in a gray zone: copyrightability of model outputs is unsettled, and violating terms of service is a contract matter, not 'theft' in a criminal sense — recasting distillation as IP theft is a rule change, not a rule application. The July 24 industry letter revealed a telling convergence: 20-plus signatories opposed broad restrictions on distillation techniques while backing targeted legal remedies for 'unlawful extraction' — a remedy path Amodei explicitly endorsed even as he declined to sign. The consistency problem persists: Replit's CEO notes Thinking Machines Lab's open model Inkling was trained with help from Moonshot's Kimi 2.5 ('banning Chinese open models is as good as banning open models'), while Anthropic itself accused Alibaba's Qwen in June of the 'largest known distillation attack' on Claude (Nikkei). Accusation and usage run both ways; one-directional enforcement will keep facing consistency challenges.

III. Two Accusations, Two Weights: Distillation Is Hard to Prove; Export Controls Are Enforceable

Late July widened the gap between the two accusations. Distillation: proof depends on provider-side access logs and the counterparty's training records — nearly impossible to establish publicly. Bessent's 'watermarks' claim came with no technical detail, the White House released no evidence, and Anthropic's official response addressed policy stance without presenting K3-specific evidence. This track functions mainly as public pressure and negotiating leverage. Export controls, by contrast, come with mature tools and precedent: multiple US outlets report BIS has opened a GB300 case; the Thailand transshipment angle sits squarely in EAR extraterritoriality and diversion enforcement — Washington's most practiced terrain; and the Entity List has the full Huawei 2019 precedent — designation would cut Moonshot off from US chips, software and cloud. Pressure is already propagating through the supply chain: Jensen Huang reportedly met Commerce Secretary Lutnick on July 28, even as The Information reports Moonshot seeks more Blackwell compute for its next-gen K4. We maintain our call: if formal action comes, export controls land first.

Loaded but Not Fired: DeepSeek Ships Anyway (data through 2026-09-02)

The tail end of August bears out this report's central claim: the political redefinition of distillation as IP theft is still running ahead of any machinery to enforce it.

Confirmed (DeepSeek release notes; Investing.com, Aug 13): DeepSeek, the most-named target of Washington's accusations, moved its flagship V4-Pro to general availability with upgraded agent capabilities, adding half-price off-peak billing from Aug 16. Reported (Releasebot, Aug 21): an experimental vision model followed a week later. The accusations have not slowed its shipping cadence.

How close it sits to the US frontier is genuinely contested. Reported (Codersera citing Vals AI): 96.4% on SWE-bench Verified, second only to Claude Opus 5; BenchLM's own run put it at 80.6%. Neither figure is cross-verified. When evaluators cannot even agree on the gap, proving how much capability was "distilled away" is harder still — exactly the mismatch between political definition and technical fact this report describes.

On the policy side, ammunition keeps piling up while no trigger gets pulled. Confirmed (Sen. Hagerty's office; Nextgov, Aug 5): the BLADE Act would have Commerce impose export controls and Treasury levy financial sanctions on designated distillation entities. Yet DeepSeek remains off the Entity List, a listing earlier reports said the White House deliberately shelved. The containment toolkit is migrating from copyright rhetoric toward export controls. Watch that variable next.

Mid-to-Late-September Update · Verified (data current as of 2026-09-25): Anthropic moves the distillation charge from government assertion to account-level data; Beijing's two ministries deny; no sanctions action has appeared as of September 25

Verified (VOA Chinese, September 12, 2026): On September 10 Anthropic published a report naming operators linked to Alibaba, Moonshot AI, DeepSeek, Xiaomi and other Chinese companies for extracting Claude outputs at scale for training. The report gives account-level figures: Alibaba-linked operators used more than 3,500 fake accounts and made over 151 million exchanges between May and July, peaking near 3 million a day; about 23 million Moonshot and 12.1 million DeepSeek user requests were forwarded to Claude. These are the first comparable numbers since the White House accusation of July 22.

Reported (Dealroom, September 11, 2026; runtimewire, September 10, 2026): Anthropic alleges that Moonshot silently forwarded some Kimi user requests to Claude and displayed Claude's answers as Kimi's own; the report covers December 2025 to August 2026. runtimewire says most of the 5,380 accounts tied to the Moonshot traffic appeared to be in Singapore and Japan, that the routing allegation itself covers nearly 300,000 requests sent mainly to an Opus model, and that the available record does not tie the traffic to K3 or any particular Kimi release. The Moonshot figures differ across reports and are not combined here. As of September 11 Moonshot had made no public response; Anthropic's launch post drew about 30 million impressions in roughly a day.

Verified (VOA Chinese, September 12, 2026): On September 9 the Ministry of Commerce said it "firmly opposes" the US government's joint report of September 8, calling the accusations groundless in fact and in law; on September 11 the Ministry of Foreign Affairs said it was "not aware" of the Anthropic report and opposed distortion and smearing of China. None of the reports cited here mentions an Entity List designation of Moonshot by BIS or a published conclusion of the GB300 export-control inquiry.

Effect on this report's conclusions: Section three's judgment that "distillation is hard to prove" needs revision. The party carrying the evidence has changed from a government to a model developer, and the evidence has changed from verbal accusation to account counts, request counts and proxy locations. That is a material shift. Three caveats remain: the numbers come from the accuser's own logs, without third-party audit or judicial finding; the Moonshot routing allegation mainly concerns an Opus model and cannot be tied to K3, which is a different matter from the original charge of distilling Fable into K3 within 15 days; Moonshot's silence is not an admission, and 30 million impressions do not make a claim true. The "trigger not pulled" judgment is reinforced: a month on, the reports cited here show no US sanctions or Entity List action, Beijing's response is denial rather than cooperation with an inquiry, and the conflict remains at the level of statements.

Late-September to Early-October Update · Verified (data current as of 2026-10-02): Following Anthropic, OpenAI attributes a reasoning-extraction campaign to individuals linked to Moonshot; the public AI outcome of the Trump-Xi summit is an incident communication channel, and no sanctions had been reported as of October 2

Per company disclosure (OpenAI, as reported by CNBC, September 30, 2026): OpenAI said it identified and disrupted a coordinated campaign to extract protected reasoning from its models, attributing a core cluster of the activity to individuals associated with Moonshot AI. By OpenAI's account, the activity began in early July, later surged to 16,000 requests from more than 4,000 users over two days, ultimately spanned more than 15,000 users, and was fully disrupted by July 28. The operators did not breach its encryption, databases or stored user conversations. OpenAI said it was unclear whether all operators were tied to a single actor and that it shared its findings through the Frontier Model Forum and government information-sharing channels. Moonshot did not immediately respond to CNBC. CNBC also noted that weeks earlier Anthropic had accused Chinese developers including Moonshot and Alibaba of using its model to train their own systems.

Verified (Al Jazeera, CBS News and The Washington Post, September 26, 2026; Beijing News relaying Xinhua, September 28, 2026): After the Trump-Xi summit in Washington, the White House said the two sides agreed to set up a bilateral communication channel for AI incidents. The other summit outcomes listed by Al Jazeera centered on extending the trade truce and similar items, with no mention of distillation or chip export controls. On September 28 Foreign Ministry spokesperson Guo Jiakun said China is willing to keep communicating with the US through channels such as intergovernmental AI dialogue.

Impact on this report's thesis: both facts are consistent with our layered view that distillation is hard to prove while export controls are enforceable. The US AI companies publicly accusing Moonshot have grown from Anthropic alone to two, but the evidence is still company-reported account and request counts, with no finding from a regulator or court, and OpenAI itself says it cannot confirm that all operators were a single actor. On policy, the summit's public AI outcome was a communication channel rather than penalties, so our view that the ammunition is loaded but the trigger has not been pulled still holds. The thresholds for changing it remain two: a Commerce Department entity-list designation of Moonshot, or a published conclusion to the GB300 export-control probe. The two leaders are next due to meet at the APEC summit in Shenzhen in November.

Key Questions

Did the White House accusation that Moonshot AI distilled Anthropic's model come with evidence? Have sanctions landed?

As of 2026-08-01, no publicly verifiable evidence has been released and no formal sanctions have landed. On July 22, White House OSTP Director Kratsios accused Moonshot AI of distilling Anthropic's Fable to build Kimi K3 and of obtaining export-restricted Nvidia GB300 servers; Treasury Secretary Bessent confirmed on July 24 (Fox Business) it is still under 'investigation'. Researchers question whether the two-week window (Fable public July 1, K3 released July 16) can support industrial-scale distillation. BIS has reportedly opened an export-control probe; no Entity List designation yet.

How much cheaper is the Kimi K3 API than Claude or GPT, and is self-hosting worth it?

K3's API costs $3/$15 per million input/output tokens — roughly 30% of Fable 5 ($10/$50) and half of GPT-5.6 Sol ($5/$30). Coinbase's CEO says switching to Chinese open models nearly halved its AI spend. K3's full 2.8-trillion-parameter weights were open-sourced on July 27, but self-hosting officially requires at least 64 accelerators, so the 'open' dividend actually flows to cloud and inference providers; most firms are better off with API or hosted options.

What is Moonshot AI's latest valuation, and when is its Hong Kong IPO?

On July 28-29, Moonshot confirmed a $3.5B round at a $35B post-money valuation — about 8x its end-2025 $4.3B — and opened a pre-IPO round targeting $50B pre-money. Bloomberg reported July 19 that it circulated a shareholder resolution for a Hong Kong listing within six months. ARR is reportedly ~$300M (implied P/ARR above 100x); Kimi runs on a ~20,000-GPU Nvidia cluster provisioned through Alibaba (36% shareholder), after pausing new subscriptions on July 20 amid a compute crunch.

Watch & Listen

In China: search WeChat Channels for 「倩姐投AI」; full library → Qian on AI

Sourcing and standards

Compiled from public sources; data current as of 2026.07.24. The text separates verified facts, reported claims, our own estimates and disputed points, and states the derivation behind every estimate. When we get something wrong, the correction is written into the report body with the original call left visible, and logged publicly.

Research standards & corrections →

📄 Full Report

Full report: 14 pages · provided to professional investors & partners only

This is the public preview. The full report includes the sections below. For compliance reasons it isn't posted publicly or offered as a free download. To request a copy, contact the FutureX team.

  • 🔒IV. Open Weights Approach the Frontier: Stress-Testing the Closed-Lab Capex Narrative
  • 🔒V. K3's Technical Facts: What's Overrated and What's Underrated
  • 🔒VI. The Policy Toolbox Upgrades: From the Chip Layer to the Model Layer
  • 🔒VII. Transmission to Cross-Border AI Assets: Who Benefits, Who Bears Risk
  • 🔒VIII. Chinese AI Assets' Capital-Market Agenda and Compliance Friction
  • 🔒IX. Scenario Analysis and a Watchlist of Observable Indicators
Request the full report →

Where we stand on this

Questions people ask next

Building in this space, or want to discuss this report? Write to us. We usually reply within 48 hours →

Related Research

Industry research from FutureX Capital's AI Lab, compiled from public information; not investment advice; contains no fund performance, AUM, or offer to raise capital.