The launch of China's open-weight AI model, Kimi K3, has sharply condensed a year’s worth of ongoing discussions about AI policy into a brief news cycle. On July 21, Treasury Secretary Scott Bessent issued a warning, stating that sanctions could be imposed against Chinese laboratories found to have developed their models through “theft.” He noted that the government has detected traces of U.S. large language models in numerous Chinese variants. The next day, White House science advisor Michael Kratsios explained that the Chinese AI lab responsible for K3, Moonshot AI, had created a sophisticated platform aimed at replicating Anthropic’s Fable model while remaining undetected.
The tech industry has expressed its opinions, with Nvidia's CEO Jensen Huang asserting that American firms should definitely utilize Chinese models that offer better prices than their own options. Investor Bill Gurley emphasized in the Washington Post that classifying open models as threats to be regulated undermines the free-market principles that have historically driven American innovation.
China's open-source AI models are steadily making headway into international markets and currently handle the majority of global AI workloads. This situation has resulted in a polarized debate in Washington, divided into two distinct perspectives. One faction, concerned about the real security risks posed by the proliferation of Chinese AI technology, advocates for restricting or banning these models from being integrated into U.S. infrastructure. They cite the theft of American intellectual property among the various reasons for enforcing stricter controls on Chinese AI. Conversely, the other faction, comprised of software engineers and tech professionals who depend on Chinese models, cautions against the excessive costs associated with curtailing software development and argues that no significant harm has occurred to American intellectual property.
In this charged environment, the Trump administration finds itself navigating a complex landscape. While officials have endorsed open-source software, they are also keen on deterring covert, large-scale theft of American trade secrets. Striking the right balance is essential, and the U.S. already possesses applicable legal frameworks to enforce appropriate actions. Clearly, the focus should be on imposing sanctions on Chinese AI labs engaged in fraudulent practices rather than on the legitimate use of “distillation,” a common technique within the AI industry.
Understanding the nuance between distillation as a technique and extraction as fraud is crucial. Distillation refers to the training of a smaller “student” model using the outputs generated by a more robust “teacher” model—an accepted practice among all AI labs, including both American and Chinese players. Enforcing a ban on distillation would be nearly impossible, as individuals with access to a model's outputs can easily repurpose that data for training. Even if such a ban were feasible, restricting the U.S. AI ecosystem to un-distillable models would place unnecessary limits on developers and hinder broader innovation.
Moreover, attributing recent advancements in Chinese models solely to distillation would oversimplify the issue. While distillation aids Chinese labs in enhancing reasoning capabilities, they are also making significant strides through original engineering research. For example, the efficiency breakthrough of DeepSeek R1 in January 2025 stemmed chiefly from improvements in reinforcement learning techniques, rather than merely copying American models. Similarly, Moonshot's pioneering work on agent swarming in early 2026 was a result of its own initiatives. While constraining distillation strategies targeting U.S. frontier labs remains a valid goal, Washington should recognize that such actions will only slow Chinese advancements, not eliminate them.
Critically, the troubling behavior of Chinese AI labs extends beyond mere distillation—it involves systematic and deceitful practices aimed at appropriating U.S. trade secrets. Distinguishing between ethical distillation and exploitative distillation attacks is vital. Traditionally, violations of user agreements are seen as civil matters; however, a well-orchestrated scheme aimed at unlawfully accessing and copying a competitor’s product falls under the purview of the Computer Fraud and Abuse Act and wire fraud statutes.
By February 2026, Anthropic had identified over 3.4 million interactions with its models traced back to Moonshot, facilitated through hundreds of fabricated accounts, all utilizing an internal platform designed to evade detection. Later, in June, Anthropic informed the Senate Banking Committee that Alibaba's Qwen lab had executed the largest known distillation attack against them thus far.
The distinction between legitimate techniques and fraudulent practices is important for determining U.S. government responses but does not encompass the full scope of why the administration should be wary of Chinese models. Legally, model outputs are not copyrightable without human authorship, making the term “intellectual property theft” somewhat misleading; trade secret laws are actually more applicable.
Critics might argue that outputs provided through commercial interfaces can’t be kept confidential. Nonetheless, access to advanced models isn’t wholly public; it’s gated by authentication, payment, and rate limits, governed by terms of service. Additionally, the trade secret in question encompasses the underlying model behavior compiled over countless interactions, which can only be extracted in a systematic and large-scale manner.
Critics have pointed out that Anthropic itself trained its models using pirated literature, leading the company to settle a legal dispute for $1.5 billion. This illustrates the regulatory gap: while Anthropic faced legal repercussions in the U.S., no similar accountability exists for Moonshot regarding its illicit activities.
Aside from the fraud issues, a more compelling rationale for penalizing Chinese AI labs rests on national security concerns. By transforming billions invested in American research and development into free offerings, Chinese labs are significantly affecting U.S. firms operating in sensitive market sectors globally.
The economic impact of American firms is compounded by the potential national security risks these models introduce. Supply chains are left vulnerable to compromised algorithms, there’s a threat of intelligence gathering through user data directed toward servers influenced by China’s National Intelligence Law, and these models may enhance the capabilities of malicious entities. Current foundational software is being produced by engineers in San Francisco who utilize Chinese models subject to state control.
Whether open competition in the AI landscape is beneficial is a separate issue, distinct from whether the U.S. should accept China’s ever-growing influence over the sector. When one participant invests heavily while the other engages in fraudulent tactics, supported by state policies for market dominance, this is not the fair competition that advocates for a free market purport. It mirrors the predatory practices China has employed in various other industries. The U.S. has not acquiesced to similar strategies in steel, solar, or shipbuilding and should reject them in AI as well.
To level the playing field, the Trump administration must delineate the difference between genuine AI distillation—which is essential for scientific progress—and covert distillation attacks aimed at purloining U.S. technology. This can be operationalized through four key measures.
First, an independent oversight entity, such as the U.S. Center for AI Standards and Innovation, should be established to verify distillation attacks and differentiate them from firms training in line with publicly available data sources. Sanctioning an organization based solely on allegations made by their competitors raises issues related to due process and could lead to arbitrary government actions in the AI domain. Criteria for assessing activities deemed unacceptable from a national security standpoint should be established.
Secondly, the administration should impose sanctions on labs involved in extraction schemes—not to limit model accessibility, as open model weights can't be retracted, but to dissuade further distillation attacks. Regulatory tools, such as designations under the Commerce Department's Entity List, sanctions via the International Emergency Economic Powers Act, or restrictions on cloud service access, could sever Chinese labs from U.S. infrastructure and capital, as well as Western enterprise clients.
Third, to address legitimate concerns about national security linked to Chinese open-weight models, the government should enforce disclosure requirements regarding their usage. Instead of seeking to obstruct access to open-weight technology, U.S. policymakers should ensure that businesses are informed about the platforms they utilize, incorporating potential security risks into their calculations. The Federal Trade Commission should mandate that AI services operating in the U.S. disclose the origins of their foundational models and the handling of user data—essentially a “nutrition label” for AI supply chains.
Lastly, both the government and American frontier labs should actively support domestic open-weight alternatives. Advocates of open-source AI are correct that fostering competitive U.S. models is the best response to China’s expanding dominance. Developers opt for Qwen or Kimi not out of ignorance but because these models are accessible, easily adjusted, and cost-effective.
Federal support for American open-model initiatives exists, requiring minimal new authority to implement. Congress could pass the long-awaited CREATE AI Act, which recently gained unanimous approval from the House Science Committee. Alternatively, the establishment of an open-weights track within the National Artificial Intelligence Research Resource has potential. Additionally, the Pentagon could follow historical precedents by guaranteeing a market for American open-weight models, which would stimulate private sector investments necessary for their development.
While it’s essential to safeguard companies like Anthropic and OpenAI from theft, it's equally important not to shield them from competition. Thoughtfully crafted policy should delineate a set of shared rules that not only protect American trade secrets but also stimulate industry growth.
Critics are correct that ultimately, the primary responsibility for thwarting distillation efforts lies with America’s premier labs. Thus far, China’s extraction initiatives have thrived because API interfaces of models remain alarmingly vulnerable. Labs that desire government intervention to protect their output as strategic must prioritize securing their technology through customer verification and behavioral detection mechanisms, making industrial-scale extraction challenging and costly. Sanctions should serve as a final line of defense, not the first response. Additionally, laboratory leaders should avoid mischaracterizing the term “distillation attack” to unfairly target the broader open AI ecosystem.
As history has shown, the U.S. will not litigate its way out of technology copying by China. What it can control is whether American companies will continue to invest in a frontier that Chinese firms exploit through deceit or if a solid set of regulations will guide the establishment of a truly free and open AI market.



