THE CORRIDOR · Policy
The White House says Moonshot AI trained its model on Anthropic's, and accessed restricted Nvidia chips in Thailand
Washington built export controls to keep advanced chips out of Chinese hands. The allegation is that a Chinese lab reached them in Thailand instead, and that the model capability never needed to cross a border at all.
Chandni Melwani
Founder & Editor
Jul 23, 2026 · 2 MIN READ
The News
On July 22, 2026, Michael Kratsios, director of the White House Office of Science and Technology Policy, publicly alleged that China's Moonshot AI distilled Anthropic's Fable model to develop its own Kimi K3. Kratsios said Moonshot built a sophisticated internal platform to run large-scale distillation against US models, switching between multiple methods of access to avoid detection. He further alleged that Moonshot has acquired servers equipped with Nvidia GB300 chips and has accessed GB300s in Thailand, likely to train its models. The GB300 is part of Nvidia's Blackwell line, which Washington forbids selling to Chinese firms. Moonshot released Kimi K3 on July 16 and has denied the allegation, with an employee publicly arguing that the window between Fable's release and K3's launch was too short for the training Kratsios described.
Know More
- — Who said it: Michael Kratsios, director of the White House Office of Science and Technology Policy, in a public statement on July 22, 2026.
- — What distillation is: training a new model on the outputs of an existing one, so the second model absorbs much of the first's capability without ever touching its weights or its training hardware.
- — The chip: Nvidia's GB300, part of the Blackwell line, which US export rules bar from sale to Chinese firms.
- — The route alleged: servers Moonshot is said to have acquired directly, plus access to GB300s located in Thailand.
- — Status: an allegation. Kratsios published no supporting evidence and did not say how the US government knew, Moonshot has denied it, and a number of AI researchers publicly disputed the claim within a day — several noting that a model's outputs are not copyrighted.
- — What may follow: the Treasury has raised the prospect of sanctions and Entity List designations against Chinese AI firms.
Governments usually keep this kind of accusation behind closed doors. On July 22, the director of the White House Office of Science and Technology Policy put it in public, naming the company, the model he says was distilled, the chip involved and the country where he says it was accessed: Moonshot AI, Anthropic’s Fable, Nvidia’s GB300, and Thailand.
The technical claim needs unpacking, because it is the more interesting half. Distillation means training a new model on another model’s outputs until the student reproduces much of the teacher’s behaviour. It is routine when a lab does it to its own models. Kratsios alleges Moonshot did it to a US model at industrial scale, through a purpose-built platform that rotated between access methods to stay hidden, and shipped the result as Kimi K3 on July 16.
Set that beside the chip allegation and the shape of the problem becomes clear. Washington has spent two years building a fence around the hardware, and it is a taller fence than it looks: the rules follow the buyer, so a firm headquartered in China needs a licence even for chips sitting in a third country. If the Thailand claim is true, it describes a rule broken rather than a rule missing. Distillation is where the rule is actually missing, and no export control reaches it. Capability leaves through the front door, in the form of ordinary answers to ordinary queries, and it never needs a shipping container or a customs declaration.
None of this is proven. No evidence has been published, Kratsios did not say how the government learned of it, Moonshot has denied the allegation, and within a day AI researchers were publicly calling the claim political and pointing out that a model’s outputs are not copyrighted. What has changed is the register: a named senior official making a specific technical accusation in public, while the Treasury has raised the prospect of sanctions against Chinese AI firms. For anyone building on frontier APIs, the thing to watch is what gets restricted next, because the obvious response to a distillation problem is not another chip rule. It is tighter terms on who gets to query a model, and how much.
Related
Frequently Asked Questions
What does it mean to "distill" another company's model?
Distillation means training a new model on the outputs of an existing one. The student model learns to reproduce the teacher's answers, absorbing much of its capability without ever seeing the original's internal weights or using the hardware it was trained on. It is a standard technique when a lab distills its own models. The allegation here is that it was done to a competitor's model, at scale, through access routes designed to avoid detection.
Has any evidence been published?
No. Kratsios made the claim publicly and described the methods, but released no supporting evidence and did not say how the US government learned of it. Moonshot has denied the allegation, with an employee arguing that the window between Fable's release and K3's launch was too short for the training described, and a number of AI researchers publicly disputed the claim. Treat this as a serious accusation from a named senior official rather than an established fact.
Why does the distinction between chips and distillation matter?
Because it means hardware controls and capability controls are different problems. Export rules do more than say who a chip may be sold to: they follow the buyer, so US guidance requires a licence for firms headquartered in China even when the hardware sits outside it, and licence conditions on advanced-computing exports can require a recipient to prevent remote access by Chinese end users. That makes the Thailand allegation a question about whether the chip rules were broken, not a gap in them. Distillation is the genuine gap, because if capability can be extracted through an ordinary interface, no amount of hardware control reaches it. One is an access problem, the other is a design problem.
What happens next?
The Treasury has raised the possibility of sanctions and Entity List designations against Chinese AI firms. An Entity List placement would restrict US companies from supplying the named firm without a licence. Nothing has been imposed on Moonshot on the basis of these claims so far.
Sources
- Michael Kratsios (@mkratsios47), OSTP Director — the allegation in full (July 22, 2026)
- CyberScoop, "White House accuses Chinese company of distilling Anthropic's Fable" (July 22, 2026)
- TechCrunch, "Treasury threatens sanctions after White House claims Moonshot distilled Anthropic's Fable" (July 22, 2026)
- South China Morning Post, "Global AI experts push back on US 'distillation' claims against Moonshot's Kimi K3 model" (July 23, 2026)
- Bureau of Industry and Security, guidance on advanced computing export controls (May 31, 2026) — licence requirements follow entities headquartered in Country Group D:5, including outside it
- Export Administration Regulations, 15 CFR 748.15 — Data Center Validated End User authorisation, including use and remote-access conditions
Chandni Melwani
Chandni Melwani is the founder and editor of New in AI, covering AI agents, M&A, and enterprise adoption. She holds a Master's in Management of Artificial Intelligence from Queen's University and brings a practitioner's perspective from her work in Data and AI leadership.
Follow ↗The Corridor Briefing
Get the two-beat briefing before the market opens.
One email. Corridor capital moves and Commerce platform shifts, decoded daily.
No spam. Unsubscribe anytime.
More from The Corridor
Infrastructure
Nvidia is helping pay for the data centre that will buy its chips
A Korean internet company, an American chipmaker and a Canadian asset manager are building Korea's national AI capacity together. Look at who is funding whom.
Chandni Melwani · East Asia
Infrastructure
The UAE spent two years winning access to American AI chips. Now it is renting them out.
For a Gulf bank, the question was never whether sovereign AI was a good idea. It was what it costs, and who has to file the export paperwork. There is finally an answer to both.
Chandni Melwani · GCC
Infrastructure
Microsoft is paying to put Azure's European customers on compute it does not own
Europe is trying to build its own AI sovereignty and rent it back. A US hyperscaler is underwriting the capex, and structuring the cheque to stay clear of Brussels.
Chandni Melwani · Europe