# Washington threatens to sanction Chinese AI firms over distillation theft as Beijing fires back

> Source: <https://startupfortune.com/washington-threatens-to-sanction-chinese-ai-firms-over-distillation-theft-as-beijing-fires-back/>
> Published: 2026-07-27 14:16:45+00:00

*Washington is turning model distillation into a sanctions fight, and Beijing is answering with the language of retaliation. If you use Chinese open models in production, this is no longer an abstract policy argument.*

The fight over Chinese AI models has moved from lab blogs and Senate letters into trade war territory. Treasury Secretary Scott Bessent said last week that Chinese companies using distillation to learn from American AI models could face sanctions, according to The Washington Post, and China's commerce ministry answered on July 27 by calling the threat a case of "AI hegemonism."

The numbers behind the accusation are serious. Reuters reported in June that Anthropic accused operators tied to Alibaba and its Qwen lab of generating more than 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts between April 22 and June 5. Anthropic called it the largest known attack of its kind against the company. Earlier, Anthropic said DeepSeek, Moonshot AI and MiniMax generated more than 16 million exchanges with Claude through about 24,000 fraudulent accounts.

That is not a few engineers stress-testing a chatbot. It is industrial behavior.

Bessent's warning, made on July 21 and reported by outlets including The Washington Post and the New York Post, put sanctions and Commerce Department Entity List designations into the conversation. He also said US officials had found watermarks or other signs of American model outputs inside Chinese systems. That point needs care. A watermark claim is an allegation, not a completed legal case, and the companies accused have not all had their day in any public enforcement record.

The Entity List is not a tariff. It can cut companies off from US-origin chips, software, tools and suppliers unless they receive a license. Huawei's 2019 listing is the obvious reference point: the company survived, but it had to rebuild around domestic alternatives and lost access to major US technology channels. For an AI model company, the punishment would look different, but it would still bite. If Washington uses the list against a Chinese AI lab, it will be trying to break hardware access and the commercial relationships that make model deployment useful.

The White House has already moved the issue into national security policy. A June 5 National Security Presidential Memorandum directed agencies to work with private companies on protecting US AI systems, including from malicious distillation attacks. That corrects an important point: this was not an April memo from the Office of Science and Technology Policy, and calling it that gives the reader a false paper trail.

## Beijing has a real counterargument

China's commerce ministry did not deny that distillation exists. It argued that the US is turning a common AI training technique into a political weapon. In its July 27 statement, the ministry said the accusations lack factual and legal basis, accused Washington of double standards, and warned that China would take necessary measures if its interests are harmed.

That counterargument has force because distillation is not automatically theft. Anthropic's own February post says distillation is widely used and legitimate when a lab trains smaller versions of its own systems. The line Washington is trying to draw is narrower: covert extraction through fake accounts and systematic scraping is different from building on open weights or public research.

Here's the thing: that distinction is easy to state and hard to enforce.

Rest of World noted this month that US companies are also building with Chinese models. The Washington Post reported that an open letter signed by 25 tech firms, including Microsoft, Meta and Nvidia, warned the US government not to restrict open AI models and said policymakers should not confuse legitimate model development with misappropriation. Google, OpenAI, SpaceX and Anthropic did not sign, though Sam Altman and Elon Musk welcomed the letter on X, according to the Post.

China's commerce ministry went further, saying nearly 200 US startups had urged Washington not to cut off access to Chinese open-source models. Business Insider reported a similar push from the Little Tech Association, including startups backed by or associated with names like Y Combinator and Proton. You do not have to accept Beijing's framing to see the problem. If US firms are using Qwen, Kimi and DeepSeek because they are cheap, capable and open, then a broad ban would hit American developers too.

## The risk lands on customers first

For enterprise buyers, the legal theory matters less than the timeline. If your product depends on a Chinese model API, or if your pipeline quietly uses Chinese open weights because they are cheaper than Claude or GPT, you now have a regulatory risk sitting inside the stack. That risk can move quickly. Sanctions do not arrive with a product migration plan attached.

Frankly, Washington has a stronger case when it sticks to the conduct Anthropic described: fake accounts, blocked-region access, coordinated querying and attempts to reconstruct reasoning traces. That is not normal competitive learning. It is extraction by deception. The case gets weaker when officials talk as if strong Chinese benchmark performance is itself evidence of theft. Performance overlap is not proof, and you cannot sanction a competitor simply for being good.

The smarter path is narrower and harder: punish covert extraction when the evidence is solid. Keep open-weight development usable. And stop pretending the AI world still runs through one national pipeline. Chinese models are already inside global development workflows. American companies know it. Beijing knows it. Now Washington has to decide whether it wants an enforceable rule against theft or a broader fight with the very developers it says it wants to protect.

**Also read:** [Nvidia takes a stake in Safe Superintelligence and gets access to Ilya Sutskever's research in return](https://startupfortune.com/nvidia-takes-a-stake-in-safe-superintelligence-and-gets-access-to-ilya-sutskevers-research-in-return/) • [Brian Armstrong tells crypto founders who pivoted to AI they got it backwards](https://startupfortune.com/brian-armstrong-tells-crypto-founders-who-pivoted-to-ai-they-got-it-backwards/) • [JPMorgan eliminates its standalone AI chief role and the move says everything about where enterprise AI is headed](https://startupfortune.com/jpmorgan-eliminates-its-standalone-ai-chief-role-and-the-move-says-everything-about-where-enterprise-ai-is-headed/)
