U.S. officials accuse China’s Moonshot of stealing from Anthropic’s Fable in Kimi K3 production

AI NewsJuly 22, 2026·5 min read

The White House has accused Chinese AI startup Moonshot of systematically stealing Anthropic’s proprietary Fable model to develop its new Kimi K3 system, marking an unprecedented escalation in U.S.-China AI competition that could reshape how regulators police cross-border model development. The accusation centers on large-scale model distillation routed through obscured channels and powered by sanctioned NVIDIA chips, raising questions about enforcement of export controls and the enforceability of intellectual property claims in AI.

  • Michael Kratsios, White House Office of Science and Technology Policy director, publicly accused Moonshot of covertly copying Anthropic’s Fable model for Kimi K3.
  • Anthropic tracked 3.4 million Claude conversations routed through hundreds of fabricated accounts to Moonshot between January and February 2025.
  • Moonshot’s Kimi K3 reached 2.8 trillion parameters, the largest open-weight model released to date, with full weights scheduled for public release July 27.
  • 3.4M Claude conversations Anthropic traced to Moonshot accounts versus prior undisclosed baseline activity.
  • 2.8T parameters in Kimi K3, exceeding all prior open-weight model releases by scale.
  • July 27 deadline for Kimi K3 full model weights public release per Moonshot announcement.

On Wednesday, Michael Kratsios, the White House’s chief technology policy official, posted a detailed allegation on X accusing Moonshot AI of running an industrial-scale operation to extract training data from Anthropic’s Claude model and use it to build Kimi K3, a new large language model set for broader public deployment this week.

Kratsios stated that his office had obtained intelligence showing Moonshot constructed a purpose-built internal platform to conduct what he termed “large-scale, covert industrial distillation” against U.S. models, cycling through multiple access routes to mask the activity from detection.

The accusation centers on model distillation, a technique in which outputs from a stronger, more capable AI model are fed into a weaker one to train it to replicate the stronger model’s behavior.

The timing of Kratsios’s statement is significant: Moonshot released Kimi K3 to limited users on July 16 and suspended new sign-ups within two days due to overwhelming demand.

The company announced that full model weights would enter the public domain by July 27, a date that has now become the focal point of a potential regulatory standoff over whether the model can be freely distributed or whether the U.S. government will attempt to block its release.

Anthropic’s February discovery of 3.4 million fabricated accounts accessing Claude

The White House accusation builds directly on a report Anthropic published in February 2025, in which the company said it had tracked more than 3.4 million conversations involving its Claude model back to Moonshot through hundreds of accounts that appeared to be falsely created.

Anthropic stated that some of the account profiles matched publicly listed senior staff members at Moonshot, suggesting the activity was coordinated and not the result of routine user testing or competitive research.

Anthropic said the campaign systematically probed Claude’s known strengths in reasoning, coding, and vision tasks, the three categories most relevant to building a competitive general-purpose language model.

The scale and targeting of the data collection indicated to Anthropic’s investigators that the activity was designed to extract enough information to allow Moonshot engineers to train a model that could replicate Claude’s capabilities, rather than simply auditing Claude’s safety features or benchmarking its performance.

Model distillation itself is not inherently illegal. Researchers and companies routinely use outputs from public-facing models to train smaller, more efficient versions; this is considered a standard engineering practice when conducted at small scale and without concealment.

The distinction Kratsios draws is between that legitimate practice and what he characterizes as covert, industrial-scale theft of proprietary technology using deliberate obfuscation and sanctioned hardware.

Moonshot’s use of Thailand-based NVIDIA GB300 servers to evade U.S. export rules

According to Kratsios’s statement, Moonshot conducted the distillation work using NVIDIA GB300 servers stationed in Thailand. The GB300 is among NVIDIA’s most advanced and powerful chips, and U.S. export control regulations bar the sale of chips of that capability tier directly to China, a restriction intended to limit China’s ability to train state-of-the-art AI models independently.

By routing the work through Thailand, a country with fewer export control restrictions on advanced semiconductors, Moonshot would have circumvented the intent of the U.S. restrictions while remaining in a technical gray zone of legal violation.

This detail carries significant implications for U.S. export policy. Over the past three years, the Commerce Department has repeatedly tightened restrictions on advanced chip sales to China, citing national security concerns.

The use of third-country infrastructure to work around those rules, if substantiated, would suggest that export controls alone are insufficient to protect sensitive U.S. AI research and that enforcement requires international cooperation or secondary sanctions on companies that help circumvent the primary restrictions.

The accusation also raises questions about the vulnerability of cloud-based AI services to state-sponsored or well-resourced corporate espionage. Anthropic’s ability to detect the activity through account patterns and conversation logs is noteworthy, but it also underscores that large-scale extraction may be possible to hide in plain sight if the attacker has sufficient resources and planning.

Kimi K3’s July 27 release deadline and competing claims over safety and control

Moonshot announced that Kimi K3’s full model weights will be released publicly by July 27, just five days after Kratsios’s accusation. The model stands at 2.8 trillion parameters, making it the largest open-weight model ever released, surpassing prior releases like Meta’s Llama series.

Open-weight models, where the underlying trained parameters are published and freely downloadable, are harder to contain or regulate once released, since anyone with sufficient computing resources can run, modify, or fine-tune the model.

Anthropic has signaled that it views the public release of Kimi K3 as a material risk, arguing that models derived from copied training data lose the safety guardrails and alignment work that the original developers embedded.

Once weights are public, the company stated, they can be modified, combined with malicious training data, or deployed in uncontrolled environments beyond the reach of any policy or governance framework.

The White House has not explicitly announced enforcement action to block the release, but Kratsios’s public accusation on Wednesday appears designed to establish a political and legal record for potential future intervention.

U.S. regulators have limited direct authority over Moonshot, a Beijing-based company, but they could theoretically press NVIDIA or other U.S. technology providers to deny Moonshot access to infrastructure, or could coordinate with allies to impose restrictions on companies that distribute or build upon Kimi K3 weights.

The critical open question is whether the U.S. government will attempt to block Moonshot’s July 27 release or take secondary measures against companies that use or distribute the model. Anthropic has made clear its view that the release poses a safety and security risk, and the White House accusation suggests the government is preparing a rationale for intervention, but no explicit regulatory action has been announced. The outcome will test whether the U.S. can enforce IP claims and export policy in AI development across jurisdictions, or whether open-source distribution has become effectively beyond government control once code leaves U.S. soil.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe