Skip to main content
Live
Main content

Treasury's Bessent threatens sanctions on Chinese AI models over IP theft

Bessent says Washington will examine open-source models from China for stolen IP, days after reports of a possible wholesale ban.

Jaeden Schafer
Editor in Chief · · 5 min read
Treasury's Bessent threatens sanctions on Chinese AI models over IP theft

Treasury Secretary Scott Bessent said Tuesday that the US will examine open-source AI models from China for signs of intellectual property theft and is prepared to sanction the companies behind them. Speaking on Fox Business, Bessent framed the move as consistent with an administration that supports open-source AI in principle but treats copied model weights and training data as a distinct category. The warning arrives one day after Axios reported the Trump administration is weighing a wholesale ban on Chinese open-source models, a step some inside the administration have disputed.

The immediate context is Moonshot AI's Kimi K3, the latest Chinese open-weight model whose capabilities are close enough to frontier US systems to threaten the pricing power and fundraising narratives of OpenAI and Anthropic. If customers can run a comparable model for free on their own hardware, the case for signing eight- and nine-figure API contracts weakens. Sanctions would be Washington's first attempt to target the models themselves rather than the chips underneath them.

This administration supports open source models, but what we do not support is IP theft. If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft.
Scott Bessent, US Treasury Secretary

Bessent's comments follow months of lobbying from US AI labs, which have argued that foreign actors are copying proprietary models via distillation and redeploying the results as open-source releases. The White House said in April it would work with AI firms to combat the practice. Export controls on advanced chips, tightened repeatedly since 2022, have so far been Washington's primary lever; targeting model developers directly is a meaningful escalation.

Key facts

  • 01Treasury Secretary Scott Bessent said Tuesday the US can sanction Chinese AI firms if their models are found to contain stolen US intellectual property.
  • 02The warning follows a Monday report that the Trump administration is weighing a wholesale ban on Chinese open-source models.
  • 03The trigger is Moonshot AI's Kimi K3, whose capabilities are pressuring the business models of OpenAI and Anthropic.
  • 04The White House said in April it would work with AI firms to combat foreign IP theft; sanctions would escalate beyond current chip export controls.
  • 05Anthropic this week got approval to begin payouts under its $1.5B settlement for illegally downloading millions of copyrighted books.

Distillation is the technique at the center of the dispute. It uses outputs from a larger model to train a smaller one, transferring much of the capability at a fraction of the compute cost. US labs argue that distilling a competitor's proprietary model without permission is theft. Not everyone in the industry agrees on either the legal framing or the technical claim that distillation alone explains China's progress.

AI Chat Daily covered the split inside the administration earlier this month, when Kimi K3's release exposed a rift between officials who see Chinese open weights as a strategic threat and those who see US open-source as the answer. Bessent's remarks land squarely on the hawkish side of that debate, though his framing — sanctions triggered by proven IP theft, not the mere existence of a capable Chinese model — leaves room for the softer camp.

Microsoft CEO Satya Nadella pushed back on the theft framing earlier this month, pointing out the tension in labs asserting fair-use rights over public training data while denying others the right to learn from their outputs. Microsoft has a foot in both camps: it is OpenAI's largest backer while also distributing DeepSeek and other open-weight Chinese models through Azure.

While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation.
Satya Nadella, Microsoft CEO

The labs pressing for sanctions face their own legal exposure on the training-data question. Anthropic this week received approval to begin cutting checks under its $1.5 billion settlement with authors, after a judge ruled the company had illegally downloaded and stored millions of copyrighted books to train Claude. Similar suits from Sony Music against Udio and from authors and publishers against OpenAI remain active. The argument that competitors stole training material is harder to make from that position.

Hugging Face CEO Clem Delangue, whose platform hosts most of the Chinese open-weight releases at the center of the debate, argues the distillation narrative overstates a minor technical factor. He points out that if distillation were the whole story, other countries — including well-funded US startups — would already be producing frontier open-source models, and they are not. His alternative explanation credits Chinese research teams working in a more open and collaborative culture than their US counterparts.

We know distillation to be a very small factor in the ability to create good models, and it's a practice that everyone is doing, including companies in the U.S.
Clem Delangue, Hugging Face CEO
Related · from this week
Researchers extract hidden reasoning from Claude, GPT, and Gemini via API trick
Jaeden Schafer · 5 min read →

How sanctions would work in practice is unclear. Treasury has broad authority to name specific companies, block US persons from transacting with them, and pressure allied jurisdictions to follow suit. Applying that machinery to open-weight models raises harder questions: the weights, once released, live on Hugging Face, GitHub, and countless mirrors. Sanctioning Moonshot AI does not delete Kimi K3 from the internet. It does complicate cloud hosting, enterprise deployment, and any commercial fine-tuning business built on top.

The move also cuts against the administration's stated support for open source. If the practical effect of sanctions is that US developers cannot legally touch the strongest open-weight models on the market, the domestic open-source ecosystem inherits the closed labs' pricing structure by default. That outcome would please OpenAI and Anthropic and displease the researchers, startups, and defense contractors who have built workflows around cheap open weights — a constituency the White House has also cultivated.

The near-term signal for AI companies is that Washington now views frontier models as strategic assets on par with the chips that train them, and is willing to use the full sanctions toolkit to defend that position. For OpenAI and Anthropic, that is a favorable regulatory tailwind at exactly the moment their business models need one. For Hugging Face, Microsoft's open-source distribution, and any US firm building on Chinese weights, the calculus just got harder — and the definition of what counts as a legally usable model may be about to narrow considerably.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Researchers extract hidden reasoning from Claude, GPT, and Gemini via API trick

The method also recovered API keys and passwords from reasoning traces, and suggests Moonshot's Kimi K3 may have been distilled from US models.

Jaeden Schafer5 min read
Moonshot's Kimi K3 forces OpenAI, Google, and Anthropic to rethink closed AI
Analysis

Moonshot's Kimi K3 forces OpenAI, Google, and Anthropic to rethink closed AI

China's open-weight strategy is pulling US developers toward cheaper Chinese models — and 25 tech companies want Washington to keep hands off.

Jaeden Schafer5 min read
Moonshot's Kimi K3 aims to match Anthropic's Opus 4.8 as valuation hits $31.5B
Models

Moonshot's Kimi K3 aims to match Anthropic's Opus 4.8 as valuation hits $31.5B

The Chinese lab's next open-weight model will run 2–3 trillion parameters, the largest ever released from China.

Jaeden Schafer4 min read