As China's open-source artificial intelligence (AI) models drew market attention for strong performance, U.S. government officials moved to rein in what they said was Chinese companies' unauthorized copying of U.S. AI models.
U.S. Treasury Secretary Scott Bessent wrote on X (formerly Twitter) on the 22nd, local time, "I support open AI and the innovation it enables, but that does not mean granting an open season on U.S. intellectual property (IP)."
The Minister said, "If Chinese corporations secretly cross the line into IP theft and carry out 'distillation' attacks at an industrywide scale, we will consider sanctions and adding them to the Entity List under export controls," signaling a response.
The Minister appeared to be referring to Chinese startup Moonshot AI's recently released "Kimi K3" model. Kimi K3 allegedly copied U.S. commercial AI models through unauthorized "distillation."
Distillation is a technique that trains a new model using the responses of a more capable AI model as data. It can produce a model comparable to an existing AI model without collecting massive datasets.
Most closed commercial AI developers, including OpenAI and Anthropic, ban such unauthorized distillation in their terms and have built systems to defend against it. However, Chinese AI corporations are suspected of having circumvented these defenses.
Michael Kratsios, head of the White House Office of Science and Technology Policy (OSTP), pointed to Moonshot AI on X, saying it had distilled Anthropic's AI model.
The Deputy Minister said, "We received information that Moonshot AI distilled Anthropic's AI model '(Claude) Fable,'" adding, "Moonshot AI developed a sophisticated internal platform capable of large-scale distillation of U.S. models and used tactics to rapidly and variably change its approach to evade detection."
He said Moonshot AI trained its AI models using GB300, an AI supercomputer based on Nvidia's "Grace Blackwell," which is banned for export to China, and was believed to have accessed the GB300 facility from Thailand.
He said he supports legitimate AI distillation technology used to build smaller and more efficient models, but emphasized that "large-scale, covert distillation aimed at stealing America's proprietary technology and undermining U.S. research is unacceptable."
Sarah Heck, head of public policy at Anthropic, responded to the Deputy Minister's remarks, saying, "Thank you for speaking out on this issue," and noted that "illegal and hostile data extraction is IP infringement and industrial espionage that strengthens adversaries' military and intelligence capabilities."
She went on to stress again that such AI data extraction is a national challenge that poses national security risks.
Anthropic earlier claimed in February that three Chinese corporations—DeepSeek, Moonshot AI, and MiniMax—used distillation methods to extract Claude's responses without authorization. It also told U.S. senators and White House officials in a letter last month that Alibaba carried out a similar distillation attack.
Anthropic is also pursuing a joint response through the Frontier Model Forum, which it founded with competitors OpenAI, Google, and Microsoft (MS), to block such "adversarial distillation" by Chinese corporations.
China, meanwhile, flatly denied the unauthorized distillation allegations. Liu Chang, Spokesperson for the Chinese Embassy in the United States, countered the Deputy Minister's remarks, saying they were "entirely groundless," and said, "U.S. figures should respect facts and abandon prejudice, and stop slandering or belittling the development achievements of China's AI industry."