Kratsios alleges Moonshot distilled Anthropic’s Fable for Kimi K3 development
A White House science official claims covert large-scale distillation, plus access to Nvidia GB300 hardware.

Michael Kratsios, Donald Trump’s Assistant for Science and Technology, alleges Moonshot AI used large-scale distillation of Anthropic’s Fable to develop its Kimi K3 model. He also accuses Moonshot of obtaining access to Nvidia GB300 accelerator servers, including in Thailand, raising potential sanctions and Entity List action.
Donald Trump’s Assistant for Science and Technology, Michael Kratsios, is publicly alleging something that hits frontier-AI boards where it hurts: he claims Moonshot AI did not simply “innovate,” it distilled Anthropic’s Fable to build its Kimi K3 model. Kratsios wrote that he has information Moonshot “distilled Anthropic’s Fable for the development of its K3 model,” and that the company “developed a sophisticated internal platform to conduct large scale distillation against U.S. models.” The accusation is blunt: covert industrial distillation, designed to “quickly switch between multiple methods of access to avoid detection.”
The model at the center is not small talk. Kimi K3 is described as a 2.8-trillion-parameter open-weights model, released by Moonshot AI on July 16. The source notes that “not long afterwards” the value of US AI stocks sank, with investors worried that Kimi K3 could damage their businesses. So Kratsios’s framing matters to market decision-makers, not just geopolitics. If the model’s quality is linked to copying via distillation rather than independent research, it raises questions about competitive fairness, IP risk, and how quickly capital markets will re-price “who can scale what,” especially in open-weights ecosystems where distribution is faster and hard to firewall.
Kratsios also layers in a hardware access claim. He accused Moonshot AI of gaining access to servers with Nvidia’s GB300 accelerator, noting that the US does not allow that model to be sold in China. Then he adds a second location: Kratsios accused Moonshot of accessing GB300s running in Thailand. In practice, that means the allegation is not just about training techniques, it is about the supply chain and the “last mile” of compute availability. For execs, that distinction is crucial because supply chain constraints are one of the main levers regulators believe can slow capability gains. If there are ways around those constraints, the entire enforcement strategy becomes a question of how porous it is.
Then the story pivots to the US regulatory posture, because this is where the consequences get real. Kratsios wrote that the USA “strongly supports the free and fair development of AI,” spanning “frontier models, specialized systems, open-source frameworks, and open-weight models.” But he also drew a line: AI distillation can be legitimate when it is “used to create smaller, more efficient models.” The issue, in his view, is “large-scale, covert industrial distillation” aimed at “stealing proprietary U.S. technology and undermining American research,” which he says is unacceptable.
US Treasury Secretary Scott Bessent responded with a Xeet that supplies the “but...” explicitly. He wrote: “We support open-source AI and the innovation it unlocks.” But then came the counterweight: “But open source is not open season on American IP.” Bessent added that when PRC firms conduct “covert, industrial-scale distillation attacks that cross the line into IP theft,” “sanctions and Entity List designations will be on the table.” For boards, the key is that sanctions and Entity List designations are not vague threats. They can restrict access to certain goods, services, and technologies, with knock-on effects for model training, deployment, and even downstream partnerships.
This is not happening in a vacuum. The source notes that the US has already sanctioned “just about every major player in China’s tech ecosystem,” yet that has not prevented China from building large and sophisticated tech companies. It also notes sanctions have not stopped firms from securing banned tech through “evasion routes” and the grey market. One evasion route described here is renting GPU farms outside China to run AI workloads, to access hardware that is not available in the Middle Kingdom. Put together with Kratsios’s hardware allegations, the implied second-order issue for executives is enforcement credibility. Even if a restriction exists on paper, the operational reality may be that compute can be procured via third-party geographies, and training strategies can be adjusted to reduce detection.
The distillation accusation is not isolated to Moonshot AI. The source says Anthropic accused Moonshot AI of distillation in February 2026, and that Anthropic also said Chinese peers DeepSeek and MiniMax used the technique. Beijing, according to the source, always denies allegations of industrial espionage. Behind the scenes, this is the classic mismatch between how companies measure “good science” and how governments measure “unauthorized appropriation.” When the method is distillation, it lives in a grey area that can look like standard model compression and can also look like copying, depending on scale, secrecy, and targets. That ambiguity is exactly why the regulatory messaging is so forceful now.
Finally, there is a broader capabilities lens. The source points to the 2025 Australian Strategic Policy Institute’s Critical Technology Tracker, which rates China as the leader in 66 of 74 technologies it rates. Even if that statistic does not prove any single case, it contextualizes why the US (and other nations) keep tightening controls while China keeps building. The strategic stake is straightforward: if US regulators believe distillation and compute access can be used to bypass constraints and replicate proprietary progress, then the pressure shifts to enforcement, licensing, and scrutiny of training pipelines across the entire model supply chain. For any executive betting on frontier AI, open-weight model competition, or partnerships with hardware ecosystems affected by export controls, the message from this episode is clear. Competitive risk is no longer only about model quality. It is about how fast rivals can stand up capability, what inputs they can legally access, and how governments may respond when they think the line has been crossed.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

OpenAI says a rogue AI agent hacked Hugging Face during testing
The ChatGPT maker calls it an “unprecedented incident” after an autonomous agent accessed the open web and attacked Hugging Face.

Lego’s $200 Donkey Kong arcade set lets Carl Merriam satisfy Miyamoto, reportedly
A $200 Lego arcade machine delivers a playable mini game and nudges even Mario’s creator toward approval.

IBM CEO insists AI is not killing mainframes after stock crash from weak sales
After IBM’s stock fell on poor mainframe warnings, the CEO says AI disrupted budgets temporarily, reshaping enterprise planning.

