White House accuses Chinese AI developer of IP theft

Samuel Boivin/NurPhoto via Getty Images
Tech policy leadership in the White House say Moonshot AI illegally trained its model off of Anthropic’s Fable.
A Chinese artificial intelligence developer allegedly stole Anthropic’s intellectual property through a machine learning technique, a top U.S. government tech official shared on Wednesday.
White House Office of Science and Technology Policy Director Michael Kratsios said on X that Beijing-based Moonshot AI illicitly trained its new K3 model on Anthropic’s Fable through a technique called model distillation, a process in which an AI model learns and copies the inner workings of a more mature and complex model, usually focusing on one aspect of the larger model. This results in the newer model working like the more complex version and producing comparable outputs.
Anthropic’s Fable model is itself a safer version of the company’s powerful Mythos model.
“We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” Kratsios wrote. “To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.”
Kratsios also said that Moonshot AI used NVIDIA's GB300 chip to support its AI training, which he assessed was likely obtained in Thailand. He noted that there is a difference between “legitimate AI distillation” and the alleged intellectual property theft that occurred between Moonshot AI and Anthropic.
“The United States strongly supports the free and fair development of AI, including a thriving competitive ecosystem that spans frontier models, specialized systems, open-source frameworks, and open-weight models,” Kratsios wrote. “Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem. However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”
Under Secretary of State Jacob Helberg commented on Kratsios’s post, echoing the severity of the incident.
“This is more than a heist of invaluable American Intellectual Property,” Helberg wrote. “It is an assault on every economy that prizes the entrepreneur, rewards private capital, and relies on fair and honest competition.”
Sarah Heck, head of Public Policy at Anthropic, also took to X to thank Kratsios for denouncing Moonshot AI’s actions.
“Illicit, adversarial distillation is IP theft and industrial espionage that supports adversary military and intelligence capabilities,” Heck wrote. “It is a national challenge that creates serious national security risks for the United States and democratic allies. We'll continue to crack down on it and work with the Administration and Congress to maintain American AI leadership.”
Moonshot AI and the White House did not respond to requests for comment.
Michelle Lopes Maldonado, the associate director of AI policy at the Information Technology and Innovation Foundation, told Nextgov/FCW that the allegations against Moonshot AI underscore the need for more policies to clarify the legal distillation of models against illegal distillation.
“Distillation is a valuable technique in which a smaller ‘student’ model learns from the outputs, behaviors and capabilities of a larger ‘teacher’ model, allowing developers to create AI systems that are smaller, more efficient, and more accessible,” Lopes Maldonado said. “When distillation is used to replicate or extract the capabilities of proprietary models without authorization, it can enable the transfer of costly research and development investments and the retrieval of data that fails to retain its original safety guardrails.”
Lopes Maldonado said that policymakers should work to strengthen guardrails against AI model theft while preserving lawful distillation rules.
Alon Yamin, CEO and co-founder of Copyleaks, a plagiarism detection software, said that model distillation is becoming a “new norm” given the global pressure to win the AI race.
“It’s hard to police. And critics of AI and the frontier labs will point out that many of these models were built using copyrighted content without permission in the first place,” Yamin told Nextgov/FCW.
Yamin agreed with Lopes Maldonado that more regulation and governance will likely be needed to help protect U.S. AI companies and clarify rules, but he noted that the capitalistic nature of accessing a cheaper model could undermine these efforts.
“Ultimately, businesses don’t care which model they use as long as it’s effective, safe and compliant,” Yamin said. “That’s where this is headed.”
NEXT STORY: Genesis Mission kicks off with over 270 projects




