On 22 July 2026, Michael Kratsios, director of science and technology policy at the White House, did something no senior American official had done before: publicly name a specific Chinese laboratory, and accuse it of copying a specific American model. “We have information that Moonshot AI distilled Anthropic’s Fable to develop its K3 model,” he said.
A few hours later, Treasury Secretary Scott Bessent went a step further: “sanctions and Entity List designations will be on the table”.
Five days afterwards, on 27 July, Moonshot AI published the full weights of Kimi K3 as a free, unrestricted download anyway, under one of the most permissive licences in existence. Without a single sanction having been taken.
Between those two dates lies a case that says a great deal — but not about what it claims to.
What exactly Washington holds against Moonshot
The accusation has two distinct strands, often conflated in the coverage.
The first strand is distillation. Kratsios claims that Moonshot did not merely query Claude occasionally: the company allegedly built a dedicated internal platform to run large-scale querying campaigns against American models, alternating access methods to avoid detection. That precise point is what turns a commonplace practice into a grievance: distilling a competitor is routine and legal on a small scale; industrialising the operation while getting round detection mechanisms belongs to another category.
The second strand, largely passed over in silence, concerns hardware. Kratsios also claims that Moonshot got hold of servers fitted with Nvidia GB300 chips — subject to American export restrictions — and accessed them from Thailand, in all likelihood to train its models. If that strand were established, it would amount to a direct breach of export control, far firmer legal ground than distillation, which falls under no clear prohibition in American law.
That second grievance is the more serious one. It is also the one least talked about.
The fifteen-day hole nobody has filled
Here is the fact most of the coverage left out, and which changes how the whole case reads.
Claude Fable 5 was not accessible. Launched on 9 June 2026 by Anthropic, the model was suspended as early as 12 June on the orders of the American government itself, under export control, after a report by Amazon researchers on a circumvention technique was reviewed. Cut off for everyone, everywhere — including for Anthropic’s own foreign-national staff. The first time a frontier model had been switched off by regulatory decision.
Fable 5 only became accessible worldwide again on 1 July 2026, after 19 days offline.
Kimi K3 came out on 16 July.
Fifteen days. That is the window during which Moonshot is alleged to have siphoned off Fable 5 at scale and then trained a model of 2,800 billion parameters on that data.
The problem is not political, it is arithmetical: training a model of that size is counted in months of compute, whatever the source of the data. Distillation can refine an existing model in a few weeks; it cannot produce one from scratch. That is precisely the argument put forward by several AI researchers interviewed by the international press, including the South China Morning Post: Kimi K3’s overall capability cannot be explained by distilling Fable alone within that window.
That does not clear Moonshot. Anthropic had already accused the company, in February 2026, of exploiting 3.4 million exchanges with Claude to train its earlier models. A screenshot that went viral also shows Kimi K3 introducing itself as “Claude, an AI assistant created by Anthropic” — real evidence, but weak: Claude’s answers are copied massively across the web, and a model trained on public data can inherit that identity confusion without any direct querying having taken place.
What is missing is the proof. Kratsios says he holds information. He has not published it.
What was announced, and what was actually done
This is the most striking gap in the file.
| Announcement | Actual status |
|---|---|
| Public accusation of distillation (22 July) | No technical element published |
| Treasury threat of sanctions (22 July) | No sanction taken |
| Threat of Entity List designation | No designation |
| Access to GB300 chips via Thailand | No formal investigation announced |
| Restrictions on access to the Chinese model under consideration | No measure published |
As of this article’s publication date, every consequence in circulation is announced, threatened or under consideration. None is applied.
The Chinese embassy, for its part, has denounced accusations it called “entirely unfounded”.
This scenario has already played out, identically
The Moonshot file has an almost perfect precedent, and its outcome is instructive.
In January 2025, a few days after the release of DeepSeek’s R1 model, OpenAI and Microsoft publicly accused the Chinese laboratory of training its model on ChatGPT outputs. The elements put forward were more precise than today’s: Microsoft’s security team, which monitors abnormal usage of OpenAI’s infrastructure, said it had detected large-scale data extraction from accounts linked to DeepSeek, with access restrictions circumvented through third-party routers. OpenAI formalised its accusations in a memo sent to the US Congress committee on China, published on 12 February.
The result, eighteen months on: no legal action brought, no formal sanction imposed. The affair stayed at the stage of public accusation and parliamentary hearing.
The Moonshot file has the same ingredients — large scale, circumvention of access methods, public communication through a government channel — and, so far, the same absence of judicial follow-up.
Why nobody goes to court
This is not a procedural accident. It is a fundamental problem.
Distillation probably does not fall under copyright. For there to be infringement, the outputs of a model would themselves have to be protectable. Yet, according to the dominant view, a text produced by an AI without sufficient human creative input is not protected by copyright. If Claude’s answers are not protectable, training another model on them does not, as the law stands, amount to infringement.
That is why the vendors — OpenAI, Anthropic, Mistral, xAI — do not fight on that ground. All of them have inserted anti-distillation clauses into their terms of use, explicitly prohibiting the use of their services or outputs to develop a competing model. The legal basis is therefore not intellectual property but contract law: a breach of a contractual commitment, possibly backed by trade secrets or unfair competition.
That changes everything. A breach of terms of use by a foreign company, with no assets or presence on the territory, is hard to enforce — and the harm is very hard to quantify.
Hence the shift we observe: for want of solid judicial leverage, the conflict moves to diplomatic and trade tools — sanctions, the Entity List, export control. That is precisely what the second strand of the accusation, the GB300 chips, would allow to be triggered if the facts were established. Unlike distillation, breaching an export control is a clear offence, with penalties set out in law.
27 July made the debate largely theoretical
Moonshot’s timetable did not shift by a single day. Five days after the accusation, the company published the full weights of Kimi K3 on Hugging Face, under an Apache 2.0 licence — commercial use, modification and redistribution permitted without restriction. A file of around 594 GB, downloadable by anyone.
This is the turning point of the whole affair, and it is structural.
As long as a model exists only behind an online interface, a state has real levers: it can block access, sanction the vendor, ban payments. Once the weights are out, those levers disappear. A file copied onto thousands of servers around the world cannot be withdrawn from circulation. A country can still ban its commercial use on its territory; it can no longer prevent its existence.
In other words: at the very moment when Washington was threatening to restrict access to the model, Moonshot was making the restriction unenforceable. It was probably not a reaction — 27 July had been announced since launch — but the effect is the same.
For the technical detail of what those weights are really worth against the model they are accused of copying, we have published a full comparison between Claude Fable 5 and Kimi K3: independent benchmarks, cost per task solved, speed, and a point the American accusation never addresses — the Chinese model’s hallucination rate, measured at 51%, a clear regression on the previous generation. A copied model would have inherited the original’s reliability. It has not.
Meanwhile, China is advancing its pieces
The American accusation is part of a wider sequence, and it serves one narrative against another.
Beijing has made open AI an explicit diplomatic axis: freely published models, cooperation and training programmes offered to developing countries. The message is easy to grasp for states that have neither the chips, nor the compute centres, nor the capital required: the Americans sell you access, we give you the tool.
That strategy took shape in July 2026 with China’s launch of a world AI governance organisation, designed to weigh on international standards. Kimi K3 is its most spectacular technical illustration to date.
Against that, the American position is harder to hold than it looks. The United States has restricted Chinese access to the most advanced chips, then switched off its own frontier model for 19 days for security reasons. In the meantime, a Chinese laboratory published a model of comparable power, cheaper, and gave it to the whole world. Whether or not the distillation accusation is well founded, it does not answer that problem.
Europe, and the diagnostic error
This is where the French debate most often asks the wrong question.
Mistral AI remains the European champion: open models, hosting in Europe, GDPR compliance, real deployments in banking and healthcare. It is a coherent sovereignty strategy, but one that does not play on the field of raw power — and does not claim to.
The error lies in believing that owning a model is enough. A model is a snapshot: it ages within months. What confers lasting independence is the ability to produce new ones, again and again. That means mastering a full stack: chips, energy, compute centres. On those three building blocks, Europe remains dependent — as the “GB300 chips” strand of the American accusation indirectly reminds us: in this race, the real control point is not the model, it is the silicon.
The second blind spot is more mundane. AI does not spread by decree. It enters the economy company by company, process by process. A country can have the best model in the world and get no productivity gain from it if nobody integrates it into real work. Conversely, a country with no national model but whose economy quickly and effectively integrates existing tools can capture most of the value.
In other words: in this race, power does not go only to those who create the models, but to those who know how to put them to work.
What it concretely changes in France
For a company, the case changes nothing in the short term. No sanction is in force, no use is prohibited. Kimi K3 is usable, via API or self-hosted. The real trade-off remains technical and budgetary, not political — that is the subject of our comparison.
For a regulated sector — banking, healthcare, government, defence — the calculation is different. Adopting today a model targeted by American threats of sanctions exposes you to a risk of regulatory reversal in the medium term. The fact that the weights are open mitigates that risk without cancelling it: a European deployment on European infrastructure no longer depends on the vendor, but diplomatic pressure does not go away.
For French public debate, the case ought to shift the question. It is not “do we need a French Fable or a French Kimi”. It is: what share of the chain — chips, energy, compute, integration — are we able to hold, and by when. Our AI rankings and our tracking of open models make it possible to measure where European players really stand against this double competition.
What to remember
- On 22 July 2026, the White House accused Moonshot AI of distilling Claude Fable 5 to build Kimi K3, and the Treasury threatened sanctions and an Entity List designation.
- No technical evidence has been published, and no enforcement measure has been taken to date.
- The timeline is the accusation’s weak point: Fable 5, switched off for 19 days on American orders, had only become accessible again 15 days before Kimi K3’s release — a gap several researchers consider too short to explain the Chinese model’s capabilities.
- A second strand of the accusation, less commented on but legally firmer, concerns access to Nvidia GB300 servers from Thailand, in possible breach of export control.
- On 27 July, Moonshot published Kimi K3’s weights under an Apache 2.0 licence, making any blocking largely unenforceable.
- For Europe, the lesson is not to pick a side but to look at the right variable: the production chain (chips, energy, compute) and the speed of integration into the real economy, rather than ownership of any given model.
The figure to remember
15 days. That is the interval between Claude Fable 5’s return to worldwide access, on 1 July 2026, and Kimi K3’s release, on 16 July. It is also, on the evidence published so far, all that separates the American accusation from a demonstration.