The Chinese government has warned of countermeasures against US sanction proposals that cite AI model "distillation" as their basis. On July 27, 2026, China's Ministry of Commerce criticized US investigations into and consideration of sanctions against Chinese AI companies as "lacking factual and legal grounds," stating that if substantial damage occurs to Chinese interests, it will take "all necessary measures."

The trigger was the disclosure of distillation allegations against Chinese companies including Moonshot AI by US government officials and Anthropic. But the two sides don't use "distillation" to mean the same thing. The technique of using one model's outputs to train another model is being conflated with the extraction of capabilities from closed APIs via fake accounts or circumvention of regional restrictions. What determines the legitimacy of sanctions is not the name of the technique, but who accessed what, under what authorization, and how.

AD

Sanction Warning Turns a Corporate Dispute Into a Trade Issue

What's new in the Chinese Ministry of Commerce's response is the possibility of concrete countermeasures. The ministry criticized the US move to sanction Chinese companies on grounds of "stolen intellectual property," stating that if actual damage occurs, it will take necessary measures. However, it did not disclose the content of such measures or the conditions that would trigger them.

China laid out two counterarguments. First, it argued that since Chinese companies' models and leading US models were released around the same time—with some Chinese models even ahead in certain areas—the distillation allegations lack grounds. Second, it stated that "many US AI companies" also distill Chinese models for research and training purposes.

The latter claim names no companies or target models, and provides no figures on access counts or usage methods. The claim that US companies used Chinese models is also not distinguished from the claim that such use was unauthorized. What can be confirmed from this response is only that the Chinese government criticized the US sanction argument as a double standard and countered that the same technique is being used by US companies as well.

The Ministry of Commerce also stated that around 200 US startups oppose blocking access to Chinese open-source models. The statement includes no company names or links to any request letter, leaving no way to independently verify the figure. Still, the intent behind citing this number is clear: it argues that sanctions against Chinese companies would not only cause losses for China but would also backfire on US developers who choose Chinese models for their cost and ease of modification.

Two Different Premises Behind the Same Word "Distillation"

Anthropic acknowledges that distillation is a legitimate training technique widely used across the industry to create smaller, cheaper models. That said, in February 2026 the company disclosed that DeepSeek, Moonshot AI, and MiniMax generated over 16 million interactions with Claude through roughly 24,000 fraudulent accounts.

For Moonshot AI specifically, Anthropic put the scale at over 3.4 million interactions. The company explains that hundreds of fraudulent accounts and multiple access pathways were used, and that metadata from the requests matched the public profiles of Moonshot AI executives. The targets were reportedly agentic reasoning and tool use, with coding and data analysis outputs also said to have been collected.

However, this is Anthropic's own attribution. The access logs and detection methodology have not been disclosed in a form that third parties could independently reproduce, and this is not material that independently proves any specific Moonshot AI model was trained on Claude's outputs. When Michael Kratsios, Director of the US Office of Science and Technology Policy, claimed on July 22 that there was information suggesting Kimi K3 was developed using Claude Fable, the post came with no verifiable evidence attached either.

When the two governments' claims are placed side by side, the gap in evidence also becomes clear. China has not provided specific examples involving named US companies. Anthropic, for its part, disclosed figures, access pathways, and its attribution method, but verification of these depends on the company's internal information. What can be confirmed at this stage, therefore, is not the act of distillation itself, but what basis each side used when making its public claims.

AD

What Does a 37-Day Release Gap Actually Rule Out?

China's Ministry of Commerce used the proximity of release timing between Chinese and leading US models as a counterargument. Claude Fable 5, which appears in the current US government claims, was first released on June 9, and Kimi K3 was announced on July 16—a gap of 37 days.

This short interval does cast doubt on any explanation that the entire Kimi K3 development process was carried out from scratch after Fable 5's release. However, what the US side claims is additional training or capability extraction built on an existing development foundation, and the Ministry of Commerce did not specify which models' release dates it was actually comparing. The gap in release dates alone cannot determine whether distillation occurred.

Moreover, Anthropic had already disclosed the over-3.4-million access count attributed to Moonshot AI back in February—before Fable 5's release. This is not evidence supporting the claim that Kimi K3 distilled Fable 5, but it also means the US side's suspicions were not fabricated only after Kimi K3's release. The real issue is less about whether 37 days is long or short, and more about which model's outputs, at which point in time, went into which training process.

The Name of a Technique Cannot Draw the Line for Sanctions

Kimi K3's official weights were released on Hugging Face on July 27. According to Moonshot AI's model card, the total parameter count is 2.8 trillion, the context length is 1,048,576 tokens, and the distributed files total 1.56TB. The Kimi K3 License permits use, modification, and creation of derivative works in principle, and also allows sale.

Of course, it is not unconditional. Model-as-a-Service providers with total revenue exceeding $20 million over 12 consecutive months must enter into a separate agreement with Moonshot AI before commercial use. Products with more than 100 million monthly users or more than $20 million in monthly revenue are also required to display "Kimi K3" attribution. Even so, as long as the license terms are followed, the scope within which US companies can use these weights for research and training is broad.

This is where the gap remaining in China's counterclaim becomes clear. Even if US companies did distill Chinese models, if the use falls within what the published weights and license permit, the conditions differ from the fraudulent accounts and access-restriction circumvention that Anthropic alleges. Conversely, if the US government defines sanction targets solely by the label "distillation," it risks ensnaring properly licensed research and derivative model development as well.

Before sanctions become reality, what the US government should present are the target companies, the access pathways, the grounds linking terms-of-service violations to intellectual property infringement, and the legal authority being invoked. China's countermeasures, too, can only be assessed by companies once the targets and triggering conditions are disclosed. The back-and-forth over model provenance will not be settled until verifiable evidence and licensing terms are made public.