White House Accuses Moonshot AI of Smuggling Nvidia GB300s and Distilling Anthropic’s Fable

Crated server hardware on a pallet between rows of Nvidia-branded AI server racks in a dimly lit data center

The Trump administration’s top science official accused Chinese startup Moonshot AI on Wednesday of running a covert operation to strip-mine American AI models and of getting its hands on Nvidia chips it is legally barred from buying.

The accusation arrives six days after Moonshot shipped a model that, by several benchmark accounts, closed most of the gap with the best systems Silicon Valley has produced, which is the part of this story that actually explains the timing.

Michael Kratsios, who directs the White House Office of Science and Technology Policy, laid out the charge in a post on X first reported Wednesday. Moonshot, he wrote, “developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” He went further on hardware, alleging the company “acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models.” The GB300 belongs to Nvidia’s Blackwell line, which Washington forbids selling to Chinese firms.

Neither Moonshot nor Nvidia had responded publicly as of Wednesday evening. Anthropic, whose Fable model sits at the center of the theft allegation, has not said it possesses evidence tying Kimi K3 specifically to distillation, though it accused Moonshot of the practice back in February. That distinction matters, and most coverage is blurring it.

What Kratsios Is Actually Alleging

Distillation is the practice of training a smaller or cheaper model on the outputs of a larger, more capable one. The student learns to imitate the teacher. Kratsios was careful to concede that this is ordinary, legitimate engineering when a lab does it to its own models, and he is right about that: distillation is how most production systems get small enough to serve at scale.

His claim is narrower and sharper. He is describing industrial-scale extraction, run through infrastructure purpose-built to rotate access methods and dodge the rate limits and abuse detection that American labs use to police their APIs. That is not a lab compressing its own work. That is, in his framing, a systematic harvest of someone else’s.

The pattern is not hypothetical. Anthropic has said operators tied to Alibaba’s Qwen unit ran nearly 25,000 fraudulent accounts to pull more than 28.8 million interactions out of Claude. Whatever you think of the policy response, the technique is real and documented.

The Chip Story Is an Admission of Failure

Focus on Thailand for a moment, because it is the most revealing detail in Kratsios’s post.

The United States has spent years building an export-control regime designed to keep exactly these chips out of exactly these hands. If GB300 servers are sitting in Bangkok and reachable by a Beijing lab, the regime leaked. Transshipment through Southeast Asia is a known and recurring hole: federal prosecutors charged a Supermicro co-founder and two others over a scheme to move roughly $2.5 billion in Nvidia-equipped servers to China through shell companies in the region, and researchers have tracked hundreds of millions of dollars in diverted hardware moving in single quarters.

Nvidia’s own chief executive has been blunt about this for over a year. Jensen Huang told reporters at Computex that “the export control was a failure,” arguing the restrictions handed Chinese firms the motivation and the state backing to build domestic alternatives faster than they otherwise would have. He has a commercial interest in that position, obviously. He also has a point that the past six days made harder to dismiss.

So the administration is announcing a chip-smuggling violation and a policy failure in the same breath. Those are the same sentence.

Why the Government Is Suddenly Talking About Theft

Here is the structural move, and it is worth naming plainly.

Kimi K3 is open-weight. Moonshot released it on July 16 as a roughly 2.8-trillion-parameter system, among the largest openly released models to date, and claimed it trails only Anthropic’s Claude Fable 5 and OpenAI’s GPT-5.6 on overall capability. Axios put it more starkly, framing the release as the moment China erased America’s AI lead.

An open-weight model cannot be recalled. The weights are downloaded, mirrored, and running on hardware Washington does not control. Export restrictions are a tool for stopping capability from being built. They do nothing once the capability has already been built and given away for free.

Which is why the vocabulary shifted this week from export control to theft. Treasury Secretary Scott Bessent told CNBC and Fox Business a day before Kratsios’s post what the administration is considering: “If we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft.” He said Treasury has spotted “watermarks of our U.S. large language models on many of the Chinese models.” Sanctions reach further than export bans. They can touch the company, its financing, and the firms that do business with it, and they do not require the model to still be unreleased.

This is the administration reaching for a second lever after the first one failed to hold. The lever it picked is intellectual property.

The Contradiction Nobody in Washington Wants to Litigate

There is an uncomfortable problem sitting underneath the theft framing, and it is going to surface the moment anyone tries to write this into an enforceable rule.

American AI labs built their frontier models by ingesting enormous quantities of text they did not license: books, news archives, code repositories, the open web. Their legal defense, argued in court repeatedly and with real success, is that training on material you did not pay for is transformative use rather than copying. The industry’s entire foundation rests on the claim that learning from data is not the same as taking it.

The government is now arguing that a Chinese lab learning from the outputs of an American model is theft.

Both positions may be defensible on their specifics. Terms-of-service violations and fraudulent account creation are genuinely different from scraping a public web page, and the deception Kratsios describes is doing real work in the argument. But the distinction is narrower than the rhetoric suggests, and it will get tested. If the operative principle is that training on another party’s outputs without permission is theft, that principle does not stay conveniently pointed at Beijing. Publishers and authors suing OpenAI and Anthropic in American courts will read Kratsios’s post with considerable interest.

The administration has previously shown it will move fast and then reverse on AI export policy when the commercial pressure builds, as it did when it lifted the export ban on Anthropic’s Fable and Mythos models earlier this month. Consistency has not been the organizing principle here.

What to Watch

Bessent is scheduled to represent the United States in AI talks with China in September. Between now and then, the administration has to decide whether the sanctions threat was leverage or policy.

The harder question is whether any of it changes the underlying position. Kimi K3’s weights are already public. Sanctioning Moonshot might punish the company, deter the next lab, and give American negotiators something to trade in September. It will not un-download a model that a few hundred thousand people already have.

Export controls were built for a world where advanced capability lived inside a small number of buildings you could put a fence around. That world is ending, and the response so far has been to look for a bigger fence.