Michael Kratsios, who runs the White House Office of Science and Technology Policy, posted a specific accusation and attached nothing to back it. He said the United States had information that Moonshot AI distilled Anthropic's Fable model to build Kimi K3, that Moonshot ran a covert internal platform to extract from US models while switching access methods to dodge detection, and that it reached Nvidia GB300 servers through Thailand to train on restricted silicon. Treasury Secretary Scott Bessent followed within hours, warning that sanctions and Entity List designations were on the table. "Open source is not open season on American IP," he wrote. What neither man produced was the evidence.
Start with what is actually verifiable, because the machine at the center of this is real and impressive. Moonshot released Kimi K3 on July 16, 2026, a mixture-of-experts model with roughly 2.8 trillion total parameters, 16 of 896 experts active per token, a context window a little over one million tokens, and open weights promised for July 27. Epoch AI's preliminary capabilities score put it around 155 to 156, edging past the closed frontier on that one composite, though the confidence intervals overlap enough that "beats Opus" is a point estimate dressed as a verdict. It took first place on the Frontend Code Arena and led Harvey's legal benchmark. It is the strongest open model anyone has shipped.
Put it on the trend line Epoch has been drawing and the drama drains out. Chinese models have lagged the US frontier by around seven months on average since 2023. K3 lands almost exactly where that curve said it would. A record and right on schedule at the same time. That is not the profile of a model built by copying a competitor released five weeks earlier. It is the profile of a lab that has been closing a known gap on a known slope.
The month that does not add up
The timeline is where the official story wobbles. Anthropic made Claude Fable 5 available in early June. K3 shipped July 16. You cannot gather enough data, train a 2.8 trillion parameter base, and test it against a model that has existed for a matter of weeks. People who work on these systems said so plainly. Greg Brockman called K3 "pretty good" and said it was too early to know whether it was distilled from anything. The bookmark that caught my eye made the sharper version of the point: K3 was reportedly in internal evaluation by April or May, before Fable was out long enough to be a plausible teacher, and it already beat Fable on BrowseComp. If K3.1 later beats Fable on coding, will the charge become that it distilled Fable 6?
There is a real distinction hiding here that the accusation flattens. Pretraining a giant base model in five weeks is impossible. Using a competitor's outputs to fine-tune or polish a base you have been training for months is ordinary, and Moonshot's own published work on K2 already leaned on synthetic data and distillation-style methods. A student model can also pass its teacher through reinforcement learning after distillation, so "it beat the model it supposedly copied" neither proves nor disproves anything. The honest read is that distillation of some Western outputs almost certainly happened across the Chinese labs, because it happens everywhere, and that the specific claim of K3 being distilled from Fable in the available window is the weakest possible version of a broadly true pattern.

What "theft" means when you look at the law
The word doing the heavy lifting is "distillation," and it is not a crime. It is a standard technique: train a smaller student model on the outputs of a larger teacher. Every serious lab uses it. The thing the labs actually object to is querying a competitor's hosted model at scale, often through fraudulent accounts and proxies, in violation of terms of service. That is the whole substance of the grievance, and it matters that it is a contract question, not a property one.
Copyright is a poor fit for distillation and the labs know it. It copies behavior, not protected expression. Model outputs are generally not copyrightable in the first place because no human authored them, and where they might be, the provider usually assigns ownership to the user. So the labs call it "IP theft" in public and reach for terms-of-service breach, trade secret, and now export-control and national-security tools in private, because the clean copyright case does not exist. Anthropic has explicitly urged Washington to treat distillation as IP theft, which tells you the category does not yet cover it. When you have to lobby to have something reclassified as theft, it is not yet theft.
This is the point at which the accusation curls back on the accuser. Anthropic agreed to pay roughly 1.5 billion dollars to settle Bartz v. Anthropic, the largest known copyright recovery in US history, about 3,000 dollars per work across nearly 500,000 titles. Judge Alsup's earlier ruling had split the question cleanly: training on lawfully acquired books can be fair use, but building a central library out of millions of pirated copies from LibGen and the Pirate Library Mirror is not. Anthropic took at least five million books from one pirate source and around two million from another. The settlement was about how the material was obtained, and the material was stolen.
Hold the two things side by side. A company that harvested millions of pirated books to build its product is asking the government to treat the harvesting of its own product's outputs as a national-security offense. The reply that went viral put it without decoration: you do not get to privatize human knowledge after stealing it. That is rhetoric, but it lands on a real asymmetry. The labs argue that training on the world's writing was fair use for them, while extraction from their models is theft by others. Both cannot be casual and criminal depending only on who is holding the output.
The evidence that is not evidence
Watch how thin the proof actually is once you inspect it. The circulating smoking gun is that K3 sometimes introduces itself as "Claude, made by Anthropic." This is close to worthless as evidence. Models are bad at knowing what they are. The open web is saturated with Claude and GPT text, so a model trained on scraped data will absorb the identity claims sitting in that data, and raw API calls with loose system prompts surface it easily. The mirror case makes the point: Claude Opus was itself caught introducing itself as Alibaba's Qwen, and nobody sane concludes Anthropic distilled Qwen. Ryan Greenblatt's cross-entropy analysis found K3 disproportionately claims to be Claude, but also noted it does not claim to be Fable specifically and claims versions Claude never used. Bessent spoke of finding "watermarks" of US models on Chinese ones and never showed one.
I am not being credulous about Moonshot. I am applying the same standard I would to any official telling me to trust a conclusion while withholding the working. A government that makes a precise, sanctionable charge and publishes no evidence is making a claim, not a case. The documented pattern is real. Anthropic's February report alleged around 16 million exchanges through 24,000 fraudulent accounts across DeepSeek, Moonshot, and MiniMax, and later accused an Alibaba-linked operation of nearly 29 million exchanges through 25,000 fake accounts. Those are the concrete data points, and they predate Fable by months. The July accusation rides on them without adding anything you can check.
Why the volume knob got turned up
The panic is not really about one model's parentage. It is about the floor falling out of a business. Chinese models now account for a majority of token traffic among US-origin requests on OpenRouter, up from under 10 percent at the start of 2025, with weekly peaks past 60 percent. That number needs its caveats stated out loud, and I will state them: OpenRouter is one routing marketplace, a small slice of global traffic, it measures token volume rather than revenue, and self-hosted usage is invisible to it. Premium closed models still capture more revenue per token on high-value work. But the direction is not in dispute. Bulk, repetitive workloads migrate to whatever is cheapest and good enough, and Chinese open-weight models run 60 to 90 percent cheaper. One startup cut inference costs by 90 percent moving off Anthropic. That is a structural shift at the inference layer, not a fad.
So the sequence reads cleanly. A Chinese lab ships an open model that matches the frontier at a fraction of the price, US developers vote with their tokens, and the labs whose economics depend on high prices and future revenue that has not arrived reach for the state. The financing under the American labs is the part rarely said in the same breath. OpenAI's revenue is a small fraction of its committed spend, tied up in circular deals where chipmakers invest in the customers who buy their chips. Michael Burry compared the AI debt to 1999. When your model is expensive, your commitments are enormous, and a free alternative is eating your volume, competition stops being a market problem and becomes, in your telling, a security threat.
The tools being reached for should worry anyone outside the Anglosphere who has watched this movie. Export controls extended to models themselves, a proposal to ban Chinese open-weight models outright, sanctions threats, and an administration that has already taken equity stakes in Intel and floated owning 5 percent of the AI labs. One of the bookmarks I kept was a furious rant about all of this, and it overreaches in places, but the core fear is not paranoid. If a handful of firms in one country get to set frontier prices while their government fences off every cheaper alternative as stolen, the rest of us pay monopoly rents on what is increasingly basic infrastructure. I have watched the same logic applied to medicine, where Americans pay several times what other countries pay for the same molecules, and the machinery that keeps those prices up is dressed in the same language of protection.
The person who wrote that rant ended with the only answer that actually addresses the fear: make the models a public resource, put open weights in people's hands, let them build. That is the outcome the Chinese open-weight releases have accidentally forced, and it is why the loudest objection to them comes wrapped in a flag. An empire that took everything it could reach and then rebranded the taking as civilization is a story I know from the inside. The version playing out now is smaller and faster and runs on tokens instead of textiles, but the move is the same one. Ingest the commons, wall it off, and call anyone who reaches back a thief.