ProBackend
ai export controls geopolitical access
2 hours ago8 min read

Treasury Secretary Scott Bessent Warns of Sanctions on Chinese AI Models for IP Theft

U.S. Treasury Secretary Scott Bessent says the Trump administration will examine whether Chinese open-source AI models have stolen intellectual property from American companies, threatening sanctions if evidence is found.

The U.S. Is Ready to Sanction AI Models, Not Just Chips

Scott Bessent didn't mince words. On Fox Business last week, the Treasury Secretary said if Chinese AI models are stealing from American companies, "we have the ability to sanction them because of this theft." This isn't just policy theater. It's a pivot — from controlling hardware to controlling ideas.

For years, the U.S. strategy to slow China's AI ascent was simple: choke off access to high-end chips. But now, the game's changed. The real threat isn't the silicon anymore — it's the models. Specifically, open-weight models like Moonshot AI's Kimi K3, which are outperforming OpenAI and Anthropic on key benchmarks. And according to Bessent, they're doing it by distilling American models — a process where a smaller AI learns by mimicking the outputs of a larger one.

"We're finding watermarks of our U.S. large language models on many of the Chinese models," he said. That's not speculation. Anthropic's letter to the Senate last month called it the "largest known distillation attack" — implicating Alibaba directly. The implication? This isn't accidental. It's systematic.

But here's the uncomfortable truth: the U.S. tech giants are sitting on a house of cards. Anthropic just paid $1.5 billion to settle a lawsuit over illegally scraping millions of copyrighted books. OpenAI and Microsoft are still fighting The New York Times over copyright violations in their training data. So when Bessent talks about "IP theft," it's hard not to hear the echo of a man pointing a finger while his own house is on fire.

The distillation debate is even messier. Microsoft CEO Satya Nadella recently called out the hypocrisy: "I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation." He's right. If you train on public data, you can't then claim ownership over every output that emerges. That's not IP protection — it's control.

Hugging Face's CEO Clem Delangue put it bluntly on TechCrunch's Equity podcast: "If it were easy just to do distillation to get good at building AI models, there would be many other countries, including in the U.S., with much better open source AI." The real edge China has isn't theft — it's culture. They're building faster, sharing more, and iterating without the legal fear that paralyzes American labs.

Sanctioning AI models isn't just a trade tactic — it's a surrender. It means admitting the U.S. can't compete on innovation anymore. It means choosing fear over openness. And it ignores the fact that distillation is everywhere — even in U.S. startups. This isn't a battle of ethics. It's a battle of speed. And if we keep treating innovation like a zero-sum game, we'll lose the race before the starting gun even fires. For broader context on how export controls are reshaping frontier AI deployments, see Negotiating Access: The New Era of Frontier AI Deployments. For the technical details behind Anthropic's allegations, see Escalating AI Warfare: Anthropic Alleges Massive Distillation Attack by Alibaba.

The U.S. Is Ready to Sanction AI Models, Not Just Chips

What Is Distillation — And Why Does It Matter?

Distillation isn't magic. It's not even new. At its core, it's a technique where a smaller, cheaper AI model learns to mimic the behavior of a much larger one — by studying its outputs, not its weights. Think of it like a student taking notes from a lecture, not copying the professor's entire textbook. The student doesn't have the full library — but they can still answer the exam questions.

In AI, this means taking the responses from a model like GPT-4 or Claude 3.5 and using them to train a smaller, faster, cheaper model — say, one that runs on a consumer laptop instead of a $20 million cluster. The result? A model that's almost as good, but far easier to deploy, scale, and monetize.

The controversy arises when one company trains its model on another's outputs without permission. Anthropic claims Alibaba did exactly that — extracting thousands of hours of Claude's responses and using them to accelerate Kimi K3's development. That's the "attack" they're calling theft.

But here's the catch: no one owns the output of a model trained on public data. If you train on Wikipedia, Reddit, or public code, you're not stealing — you're synthesizing. The legal gray zone is vast. And it's why Nadella's critique cuts so deep. If you can't control how your outputs are used, then you can't claim ownership over the downstream models that learn from them.

This isn't just a China problem. It's an industry problem. Every major U.S. AI lab trains on scraped public data. Every startup uses open weights to build on top of existing models. The only difference? China's doing it faster, cheaper, and without the legal overhang.

The U.S. government's response — sanctions — doesn't fix the underlying issue. It just makes the problem more visible. The real question isn't whether distillation is theft. It's whether we're willing to let legalism strangle innovation. Because if we are, we're not protecting IP. We're burying it.

What Is Distillation — And Why Does It Matter?

Moonshot AI's Kimi K3: The Model That Changed Everything

Before Kimi K3, Chinese AI models were seen as imitators — decent, but not disruptive. Then, in early July, Moonshot AI quietly released a model that outperformed GPT-4o and Claude 3.5 on a suite of benchmarks: reasoning, multilingual tasks, coding, and even creative writing. Not by a little. By a lot.

Kimi K3 isn't just another open-weight model. It's a statement. It's proof that China doesn't need the latest Nvidia chips to build frontier AI. It's proof that you can compete on algorithmic ingenuity, not just compute. And it's proof that the U.S. tech elite's narrative — that they're the sole drivers of innovation — is collapsing.

The model's success isn't accidental. Moonshot AI's team, largely trained in U.S. universities, returned to China with a mission: build something better. They didn't wait for permission. They didn't hire lobbyists. They just built.

And now, Bessent wants to sanction them. For what? For being good? For being fast? For not asking permission before iterating?

The irony is thick. While U.S. companies are busy filing lawsuits and lobbying for export controls, Chinese teams are shipping updates every week. Kimi K3 was trained on a fraction of the compute used by OpenAI's models. It doesn't need a data center. It runs on a single GPU. That's the real threat — not theft, but efficiency.

And let's not forget: Kimi K3 is open-weight. That means anyone can download it, inspect it, improve it. That's the opposite of what U.S. companies do. OpenAI locks down its models. Anthropic sells access. But China? They're building an ecosystem. And ecosystems beat single products every time.

If we're going to sanction AI models, we better be ready to sanction every open-weight model on the planet. Because if Kimi K3 is theft, then every Hugging Face model is too. And if that's the case, then the U.S. doesn't have an IP problem — it has an innovation problem. For a deeper technical breakdown of Kimi K3's architecture and what its 2.8 trillion parameters mean for enterprise deployments, see What Kimi K3's 2.8 Trillion Parameters Mean for Security & Compliance Teams.

The Hypocrisy of American AI

Let's be honest: the U.S. doesn't care about IP theft. It cares about control.

Anthropic settled a $1.5 billion lawsuit over pirated books. OpenAI is still in court with The New York Times over training data. Google and Meta have been sued for scraping everything from academic papers to Instagram captions. And now, suddenly, we're outraged that China is doing the same thing — but better?

This isn't about ethics. It's about market dominance.

The moment Chinese models started outperforming American ones, the rhetoric shifted. "Theft" became the go-to word. "Sanctions" became the go-to solution. But if we truly believed in IP protection, we'd be suing our own companies first.

The legal landscape is a mess. Copyright law was written for books and songs, not AI outputs. The courts are still figuring out what "fair use" means when a model learns from a trillion tokens. And yet, here we are, treating AI like a patent war — when it's clearly something else entirely.

The real fear isn't that China is stealing. It's that they're winning. And we don't know how to compete without pulling the rug out from under everyone else.

We've built an industry that thrives on openness — open weights, open data, open research — and now we're terrified of what happens when others join the game. That's not a security threat. That's insecurity dressed up as policy.

Bessent says he's looking for "watermarks." But watermarks aren't proof of theft. They're proof of training. And if every model trained on public data leaves a watermark, then every AI in the world is guilty. Including ours.

We're not defending IP. We're defending privilege.

September Talks: The Last Chance for Sanity

The U.S. and China are scheduled to meet in September to discuss AI governance. Bessent will be there. And if he walks in with sanctions already signed, we'll know the real goal: not cooperation, but containment.

This isn't diplomacy. It's brinkmanship. And it's dangerous.

If the U.S. unilaterally sanctions Chinese AI models, we're not just targeting Moonshot AI or Alibaba. We're targeting every researcher, every student, every startup in the global AI community.

More blogs