The U.S. and China have been fighting over AI for a while now. Chip bans, export controls, benchmark competition, open-source model releases that sent shockwaves through Silicon Valley — most of it has been quiet enough that regular people didn’t notice.
July 22 was different.
Scott Bessent got on X (the former Twitter) and said something that caught the attention of every major AI company with international operations. The Treasury Secretary wasn’t talking about tariffs or trade. He was talking about how one Chinese AI company trained its model, and what he said was coming if Washington’s version of events held up.
What Scott Bessent said about Chinese AI companies and American IP
Bessent’s post had one line that stood out from everything else. “Open source is not open season on American IP,” he wrote on X. “When firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.”
Entity List. That’s the list Huawei is on. That’s the list the U.S. puts companies on when it decides they’re a national security problem. Bessent just dropped that word into a conversation about how a Chinese AI company trained its model. That’s the part of the post worth sitting with.
He had made a version of this threat the day before, too, saying the government would examine Chinese open-source models for signs of IP theft. The July 22 post was a doubling down, not a first shot.
Why Moonshot and Kimi K3 are at the center of this AI dispute
The target is Moonshot, a Chinese AI company that released Kimi K3 on July 16. It’s a 2.8 trillion parameter model, the largest open-weight AI model ever built, and Moonshot is promising to publish the full weights by July 27.
White House Science and Technology Policy Chief Michael Kratsios pointed the finger at them on July 22, posting on X that Moonshot had conducted large-scale distillation against U.S. models.
More AI:
- Workers just sent AI companies an ultimatum
- Palantir CEO has a blunt verdict on OpenAI and Anthropic
- Elon Musk pulls no punches with AI rivals as Grok 4.5 debuts
Kratsios went further than the IP angle. He alleged that Moonshot acquired Nvidia GB300-equipped servers and accessed GB300 systems in Thailand. That’s a separate and more serious problem.
GB300 servers are part of Nvidia’s Blackwell generation and are banned from being sold to Chinese companies. If those allegations are accurate, Moonshot may have violated export-control rules on top of the IP complaint.
Moonshot hasn’t responded publicly. Some experts are skeptical of the full picture. Fable only became available on July 1, and researchers have questioned whether Kimi K3 could have been built primarily through distillation from a model that’s only been out for three weeks, according to TechCrunch.
What model distillation actually is and why it’s become a legal and political problem
Distillation is one of the most common techniques in AI development. A smaller, cheaper model learns from the outputs of a larger, more powerful one.
Done properly, it’s a legitimate optimization method. Most AI companies do some version of it. The dispute is never really about whether distillation happened. It’s about whether it was done at a scale and in a manner that amounts to stealing someone else’s work.
Most major AI models have terms of service that say you can’t use their outputs to train a competing model. If Moonshot was systematically hitting Anthropic’s systems to generate training data, that’s a terms violation at minimum.
Whether it rises to the level of legal IP theft is a much murkier question, and whether Treasury sanctions are the right tool for a terms-of-service dispute is murkier still.
The open-source angle makes it more complicated. Moonshot released Kimi K3 as an open-weight model, which has drawn comparisons to DeepSeek’s approach earlier this year.
That release rattled U.S. AI labs because it suggested Chinese companies might be closing the gap faster than expected. Washington’s response appears to be that if the gap is closing because American IP is being stolen, that’s not acceptable competition.

Cho/Getty Images
Why Washington is pushing to restrict Chinese AI models more broadly
Bessent and Kratsios aren’t the only voices in this conversation. Dean Ball, formerly a White House AI adviser and now OpenAI’s Head of Strategic Futures, has been arguing that the U.S. should restrict or effectively ban the use of Chinese open-weight models entirely.
His case is partly about national security and partly about preserving the economic model that justifies the enormous capital costs behind frontier AI development. Bessent himself has been framing the U.S.-China AI competition in existential terms for months, saying at a Wall Street Journal event in April that the U.S. had just 12 to 18 months before AI defines daily life, as TheStreet reported.
Kimi K3 got attention because it was good, good enough that people started asking whether Chinese labs were closing the gap faster than anyone expected. That’s an uncomfortable question for U.S. AI companies that have been spending hundreds of billions on training runs.
If a Chinese company can match that output at a fraction of the cost, the whole investment thesis gets harder to defend. The IP theft accusation gives Washington a cleaner story. But the anxiety underneath it isn’t really about one model.
Anthropic has been lobbying Washington for tougher action against Chinese AI rivals. The company pressed officials earlier this year for stronger IP protections. In June, it sent a letter to the White House and U.S. senators alleging that Alibaba ran 28.8 million exchanges against its Claude models using 25,000 fake accounts in what it called the largest distillation attempt it had documented.
The Fable-Kimi K3 situation is, in some ways, the fight Anthropic was already trying to get Washington to take seriously, as TheStreet reported.
What Bessent’s AI sanctions threat means for the global AI industry
If the U.S. begins imposing sanctions over model training practices, it changes the rules of the AI race in a meaningful way. Companies building models with international teams, using open-source tools, or operating in multiple jurisdictions would have to think carefully about what they’re training on and where the data is coming from.
Entity List designations are particularly significant. Being placed on the Entity List cuts off a company from U.S. technology supply chains. For an AI company that depends on Nvidia chips, cloud infrastructure, or American software tools, that’s potentially a company-ending designation.
The broader implication is that AI intellectual property is becoming a national security issue. Washington is no longer treating model training as a purely commercial or technical dispute.
When Treasury starts using the same language it uses for financial sanctions in an argument about how one AI company trained its chatbot, the AI industry is operating in a different environment than it was a month ago.
Related: Scott Bessent shares the truth about American gold and dollars