White House accuses Moonshot of siphoning Anthropic data

Wait 5 sec.

Top White House technology official Michael Kratsios on Wednesday accused Chinese artificial intelligence startup Moonshot of using deceptive practices to extract data from Anthropic’s highly advanced Fable 5 model, allegedly using the outputs to train its newly released Kimi K3 system.The allegations themselves are significant, even though they have not been backed by publicly verifiable evidence. Just as notable is how the White House is describing them. By framing large-scale model distillation as the theft of American technology rather than a competitive AI practice, the administration is signaling that it could pursue a much tougher response, from tighter API restrictions to expanded export controls on advanced AI chipsIn a post on X, Kratsios claims the administration has information that Moonshot used a purpose-built platform and multiple access methods to avoid detection in order to siphon data from Fable 5.We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model. To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of…— Director Michael Kratsios (@mkratsios47) July 22, 2026“Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable,” Kratsios states.Kratsios also alleges that Moonshot had acquired servers equipped with highly coveted Nvidia GB300 AI chips and deployed them in Thailand, “likely to train its AI models.”Moonshot, Anthropic, and the White House Office of Science and Technology Policy (OSTP) did not immediately respond to requests for comment from The New Stack.“Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”Distillation as trade weaponTo understand the administration’s accusations, it is necessary to understand how smaller AI models are currently built.To put it simply, model distillation is the process of training a smaller, less expensive AI model using the outputs generated by a larger, vastly more expensive “frontier” model. Distillation itself is a common and widely accepted technical practice used to lower the extreme computing costs associated with training new AI tools from scratch.The dispute here is not over the concept of distillation, but rather the execution. The White House alleges that Moonshot accessed Fable 5 deceptively — purportedly bypassing Anthropic’s terms of service through access methods Kratsios says were designed to avoid detection — and harvested proprietary outputs at an industrial scale.Key questions remain unanswered: What specific telemetry supports the administration’s claim, and has Anthropic independently identified or documented this activity in its own logs?The administration’s allegations do not exist in a vacuum. In February, Anthropic publicly accused Moonshot, DeepSeek, and MiniMax of running coordinated distillation campaigns against Claude, attributing more than 16 million exchanges across roughly 24,000 fraudulent accounts to the three companies. Moonshot alone was linked to 3.4 million of those exchanges.Kimi K3’s suspicious timingKratsios’s accusation followed K3’s release by six days. On July 16, the Chinese AI startup unveiled Kimi K3, a massive 2.8 trillion-parameter model. Moonshot touted K3 as the world’s largest open-weight AI system, claiming its performance approaches that of Anthropic’s frontier Fable 5 model. (The full weights were scheduled for release July 27 and were not yet publicly downloadable.)That apparent proximity in capabilities immediately raised eyebrows in Washington. The Kimi K3 launch comes roughly five weeks after the U.S. government issued an export control directive that forced Anthropic to temporarily suspend access to its Fable 5 and Mythos 5 models, citing national security concerns. Anthropic resumed global Fable 5 access beginning July 1 and restored Mythos 5 for approved U.S. organizations more than two weeks before K3’s launch. Still, the quick release of K3 demonstrates how quickly China’s open AI ecosystem appears to be narrowing the gap with heavily guarded U.S. systems, triggering investigations into how that gap is being bridged.Thailand’s compute loopholeKratsios’s allegation that Moonshot accessed Nvidia GB300 servers in Thailand illustrates a growing concern for U.S. policymakers. Restricting chip exports is one thing; preventing companies from renting compute in other countries is much harder.If the claim is accurate, Moonshot obtained or remotely accessed GB300 systems located in Thailand. That would not necessarily constitute a workaround of U.S. export controls; whether the arrangement violated the rules would depend on factors including who owned the systems, who supplied the computing access, and what licenses were in place.Chinese AI companies may not need to bring restricted chips into China at all. They could instead rent access to servers in places such as Thailand or the Middle East and use that computing power remotely to run large-scale distillation workloads.Export controls face limitsThe Moonshot allegations are the latest escalation in a more extensive administration campaign against the suspected extraction of U.S. AI intellectual property.In February, OpenAI warned U.S. lawmakers that DeepSeek was actively targeting leading American AI labs to replicate their models. Following this, the U.S. State Department launched a worldwide diplomatic push in late April. According to a diplomatic cable seen by Reuters, the State Department sought to alert allies to widespread efforts by Chinese companies—explicitly naming Moonshot AI—to siphon IP from American labs.“AI models developed from surreptitious, unauthorized distillation campaigns enable foreign actors to release products that appear to perform comparably on select benchmarks at a fraction of the cost but do not replicate the full performance of the original system,” the April cable noted.“AI models developed from surreptitious, unauthorized distillation campaigns enable foreign actors to release products that appear to perform comparably on select benchmarks at a fraction of the cost but do not replicate the full performance of the original system.”Whether or not the claims are ultimately proven, they could accelerate policy initiatives that were already under discussion in Washington. U.S. model developers such as Anthropic and OpenAI could face pressure to tighten access to their APIs, making it harder for companies to create proxy accounts for large-scale distillation. The Commerce Department could also expand export controls by targeting remote cloud-service access more directly in countries such as Thailand, limiting their ability to rent Nvidia GPU clusters to Chinese companies. Beyond that, one scenario is that the administration could impose sanctions on Moonshot or other organizations it believes were involved, while pushing allied governments to more closely monitor AI training activity within their borders and report potential violations of U.S. export controls.For now, the technology sector is waiting to see whether the administration will release technical receipts to back up Kratsios’s claims — or if this rhetoric will simply serve as the justification for the next wave of the AI trade war.Restricting chip exports is one thing; preventing companies from renting compute in other countries is much harder.The post White House accuses Moonshot of siphoning Anthropic data appeared first on The New Stack.