The White House is turning Moonshot AI's Kimi K3 into a test case for two fights at once: model distillation and blocked Nvidia hardware. If the chip-routing claim holds, this is no longer only an argument about benchmarks.
Kimi K3 landed last week with the kind of numbers that get Washington's attention. Moonshot AI says the Beijing-built model has 2.8 trillion parameters, a 1 million-token context window, and open weights due on July 27. Tom's Hardware reported that it took first place on Frontend Code Arena with a score of 1,679, ahead of Anthropic's Claude Fable 5 on that coding benchmark, even while trailing Fable and OpenAI's GPT-5.6 Sol overall.
Then Michael Kratsios raised the temperature. Reuters reported on July 22 that the White House technology official said Moonshot had distilled Anthropic's Fable to develop K3, calling it large-scale, covert industrial distillation aimed at stealing proprietary US technology. In a separate post cited by BeInCrypto, Kratsios also alleged that Moonshot used GB300 servers, including in Thailand, to train the model. That's the harder claim. You can argue about distillation law for months. Export controls are less forgiving.
The distillation claim already had a paper trail #
Anthropic didn't start accusing Moonshot this week. On February 23, the company published a detailed account saying DeepSeek, Moonshot, and MiniMax generated more than 16 million Claude exchanges through roughly 24,000 fraudulent accounts. The Moonshot portion was smaller than the total, but still large: Anthropic said it traced more than 3.4 million exchanges to Moonshot, targeting agentic reasoning, tool use, coding, data analysis, computer-use agents, and vision.
That distinction matters. The earlier draft overstated the claim by assigning the full 16 million exchanges and 24,000 accounts to Moonshot alone. Anthropic's own post doesn't say that. It says those figures covered all three Chinese labs.
There is fresh smoke around K3 too. Glitchwire reported that Ryan Greenblatt, Chief Scientist at Redwood Research, ran a cross-entropy comparison of raw model responses and found that K3 claims to be Claude disproportionately often when probed about its identity. In one reported case, it identified itself as Claude 4.5. That isn't proof of theft. It is evidence worth testing once the weights are out.
Here's the thing: model identity confusion can come from messy training data, synthetic examples, or direct distillation. The public evidence doesn't let you convict Moonshot from the outside. It does let US officials ask sharper questions than they could a week ago.
The chip allegation is the bigger risk #
The GB300 claim is in a different lane. Advanced Nvidia AI chips are covered by US export controls meant to stop Chinese entities from obtaining the most powerful training hardware. Asia Times reported in June that US guidance had closed a loophole used by Chinese-owned firms buying restricted chips through overseas units in Southeast Asia, while Thailand's Board of Investment said in May that it was tightening checks to stop the country being used as a back door for high-end semiconductor shipments to China.
If Moonshot used GB300-equipped servers in Thailand because it couldn't legally get that hardware at home, the story stops being a clean tale of Chinese efficiency under constraint. It becomes a possible sanctions case. Frankly, that's why Kratsios's post matters even if the distillation evidence remains contested. Scott Bessent gave the same dispute a Treasury Department edge. Reuters reported that the Treasury Secretary told Fox Business on July 21 that US officials were finding watermarks of US large language models on many Chinese models and called that unacceptable. He said Washington would examine the issue in the coming days or weeks. Sanctions talk is no small footnote when American companies are deciding whether to test or deploy Kimi K3.
Moonshot's launch also created a practical problem at home. Business Insider reported that the company d new Kimi subscriptions after a 48-hour surge pushed GPU capacity to the brink. That is a useful fact, not a side detail. A model can be open, cheap on paper, and still hard to serve if the hardware stack is stretched.
The Trump administration is now reportedly reviving a push to restrict Chinese AI models in the US, according to Tom's Hardware, with cybersecurity concerns layered on top of the IP dispute. An outright ban would be awkward to enforce once open weights are downloadable. Procurement rules, Entity List designations, and compliance warnings are easier tools. Companies don't need a formal ban to feel the risk.
Moonshot has not publicly answered the Kratsios allegations, and at this point the silence is telling. Anthropic's February claims are still allegations, not a court finding - that matters. But the July 27 weight release should give outside researchers a far better shot at testing Greenblatt's identity-probe finding at scale. The GB300 question is harder to verify from the outside. It is also, if US officials can prove it, the one with the clearest legal path.
Also read: The US Army burned through its AI token budget in months and every enterprise should take note • Glow raises $180 million at a $1.2 billion valuation to secure the AI agents that CrowdStrike wasn't built to see • Alphabet reports Q2 2026 earnings today with its $190 billion AI bet under the microscope