The Trump administration is split over how to respond to the rise of China's leading AI labs, with the White House pushing for stricter controls on Chinese model development and the Commerce Department calling those restrictions unworkable. The immediate trigger: Moonshot AI released its Kimi K3 model last week, which senior officials say rivals the top systems from Anthropic and OpenAI. The White House alleges Moonshot built Kimi K3 by distilling Anthropic's Claude Fable 5, and it is preparing presidential action in response.
That action is not expected to take the form of an executive order, according to one person familiar with deliberations. Instead, senior White House officials have spent recent days discussing measures aimed specifically at stopping Chinese labs from training their own models on the outputs of US frontier systems. Distillation — the practice of using a stronger model's outputs to train a smaller or competing model — has moved from a technical debate to a national-security flashpoint.
The escalation follows Anthropic's allegation last month that Alibaba carried out what it called the largest known distillation attack against it to date. The administration confirmed on Wednesday that Moonshot used the same playbook against Claude Fable 5. That two-for-two pattern — two of China's most prominent AI efforts accused of training on a single US lab's outputs inside the span of a month — is what has pushed the issue to the president's desk.
Key facts
- 01Moonshot AI released Kimi K3 last week, a model the White House says rivals top offerings from Anthropic and OpenAI.
- 02The White House alleges Moonshot built Kimi K3 by distilling Anthropic's Claude Fable 5 model.
- 03Anthropic last month accused Alibaba of the largest known distillation attack against it to date.
- 04Treasury Secretary Scott Bessent warned on Fox Business that covert distillation could trigger sanctions as IP theft.
- 05Presidential action is expected but not in the form of an executive order, per one person familiar with deliberations.
Treasury Secretary Scott Bessent told Fox Business that covert distillation could lead to sanctions, describing it as IP theft. Sanctions would represent a sharper escalation than export controls, which have historically targeted chips and compute rather than the training data pipeline itself. Bessent's framing — that the outputs of a US model are protected intellectual property when copied to train a foreign competitor — is the legal theory the administration would need to sustain any enforcement action.
The Commerce Department, which oversees export controls through the Bureau of Industry and Security, has its own ideas and has not yet received a formal request for input on the White House proposals. Commerce Secretary Lutnick has been contemplating ways to incentivize top US labs to release their own open-weight models as a counterweight to Chinese releases, and has spoken with leaders at several AI labs in recent weeks. That approach treats the problem as a market-share question rather than a legal-enforcement one.
Lutnick has staked out a middle ground. He imposed export controls on Anthropic to bring the company to heel earlier this year, but has been more freewheeling than Cairncross on questions of how tightly to regulate the sector. The Commerce Department's skepticism of tighter distillation controls appears to rest on enforcement math — proving that a Chinese model was trained on a specific US model's outputs is technically difficult, and the practice can be obscured through intermediary datasets.
The stakes for Anthropic in particular are unusual. Earlier this month, the administration's biggest AI concern was Anthropic's own Claude Mythos and Claude Fable 5, because of their demonstrated ability to find vulnerabilities in government systems and critical infrastructure. Now the same Fable 5 model is at the center of a distillation dispute in which Anthropic is the victim rather than the risk vector. The company is simultaneously the target of export controls and the beneficiary of proposed distillation sanctions.
The rise of Chinese open-weight models complicates the picture further. Models that can be downloaded and run by anyone, with few or no safeguards against being repurposed to attack government systems, are harder to contain than API-gated frontier systems. Export controls on compute can slow training runs, but they cannot recall a model that has already been posted to Hugging Face. That is the specific policy gap the White House is trying to close, and the one Commerce argues cannot be closed with a rule.
Skeptics inside the administration and at the AI labs themselves have questioned how any distillation ban would be enforced in practice. Detecting distillation requires either forensic analysis of a suspect model's outputs against a reference model, or evidence of API misuse at the source. Anthropic's allegations against Alibaba and Moonshot suggest the labs are doing that detection themselves, but sanctions built on lab-supplied evidence will face legal challenges from any target with the resources to fight back.
The direction of travel is clear even if the mechanism is not. Washington now treats the training data behind a Chinese frontier model as a matter of US policy, and the specific pathway from Claude Fable 5 to Kimi K3 has become the test case. For US labs, that means the outputs of their models are being reframed as strategic assets deserving of government protection — a status that comes with restrictions attached. For Chinese labs, the calculus shifts from whether Washington can slow their compute to whether it can criminalize their training pipeline. Neither side wins that fight cleanly, and the ambiguity itself is now the policy.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




