Anthropic wants distillation stopped. It won the case that legalizes it.

The White House says Moonshot copied Anthropic to build Kimi K3 — but that copying is fair use a court already protected

// Share
Anthropic wants distillation stopped. It won the case that legalizes it.

On Wednesday, Michael Kratsios, the director of the White House Office of Science and Technology Policy, used a post on X to accuse a Chinese company of stealing from an American one. The Chinese company was Moonshot AI, a Beijing lab whose new model, Kimi K3, had been released six days earlier to a reception bordering on alarm: at 2.8 trillion parameters it is the largest open-weight model ever shipped, and on several benchmarks it runs level with the frontier systems American labs spent billions to build. The American company was Anthropic. Kratsios wrote that his office had information that Moonshot had distilled Anthropic's Fable 5, the lab's most capable model, using a purpose-built internal platform to query American systems at industrial scale while rotating its access methods to stay hidden. Sarah Heck, Anthropic's head of public policy, amplified him, calling the conduct IP theft and industrial espionage.

Three claims have been folded into that one word, and they are not equally sound. Pulling them apart is the whole exercise, because the word carrying the political weight is fastened to the weakest of them.

Access of evil

Start with distillation, the charge that supplies the drama. Training a cheaper model on a stronger one's outputs — feeding it prompts, keeping the answers, teaching the student to imitate the teacher — is ordinary practice; labs distill their own models before nearly every release. What Kratsios objects to is scale and stealth, not the technique itself. But strip the adjectives and ask the narrower question a court would ask: whose property was taken? When a model answers a prompt, the answer is machine-generated text, and the US Copyright Office concluded in January 2025 that such text, absent meaningful human authorship, is not copyrightable — a prompt, however elaborate, does not make its author the owner of the output. The teacher's answers belong to no one. A thing that cannot be owned cannot be stolen, which is an awkward foundation for a charge of theft.

It is more awkward for Anthropic than for almost anyone. In June 2025, in Bartz v. Anthropic, Judge William Alsup ruled that training a large language model on copyrighted books is "quintessentially transformative" fair use — that learning statistical patterns from another's expression is not theft but transformation. Anthropic won that argument. It is now the American company least able to say that learning statistical patterns from a model's uncopyrightable output is theft, because the principle that shielded its own training run shields Moonshot's. No court has tested that extension — Bartz concerned books, not model outputs, so the parallel is an inference rather than a holding — but it is the natural one, and it runs against the party now invoking the word. Distillation is that same act performed one floor up, on material that was never copyrightable to begin with. If the scanned novels were fair game, the exhaust is a weaker target still.

The next two charges are sturdier, and they cut hard against Moonshot. The second is not about distillation at all; it is about access. Anthropic alleged in a February report that it had traced more than 3.4 million Claude exchanges to hundreds of fraudulent accounts, some matching the public profiles of senior Moonshot staff, created to bypass the restrictions on its systems. That is a different species of wrong. Circumventing access controls through fake accounts is the conduct the Computer Fraud and Abuse Act was written to reach, and it does not turn on the outputs being anyone's property; the wrong lives in the breaking-in, not in what was carried out. The third charge sits further still from copyright. Kratsios alleged that Moonshot obtained servers fitted with Nvidia's GB300 processors, barred from sale to China, and ran them in Thailand — an export-control matter, enforced by the Commerce Department, with real penalties and no theory of intellectual property required at all.

The case changes shape as it is pulled apart. The charge with the moral voltage — theft, espionage, a stolen model — is the one with the flimsiest legal footing, resting on outputs that cannot be owned and a fair-use principle Anthropic itself established. The charges that can actually be enforced — fraudulent access, sanctioned hardware — are the quiet ones, and they say nothing about distillation as such. Anyone who followed the Huawei prosecutions has seen this before, where the sprawling espionage narrative gave way, when it came to what a court could actually hold, to bank fraud and sanctions-evasion counts. The espionage supplies the headline; the fraud supplies the conviction.

That gap is the part worth holding onto for anyone allocating around open models. The reason distillation is being narrated as espionage rather than breach is that espionage reaches instruments a broken terms-of-service clause cannot. Scott Bessent, the Treasury secretary, warned this week that the administration could sanction Chinese models found to be built on stolen American technology, and sanctions and export designations require a national-security predicate — industrial espionage qualifies, an unenforceable contract term does not. What is under way is the conversion of a private contractual grievance, which has no usable remedy, into a public security threat, which has many. And for an open-weight model — one that, once its full weights are posted, as Kimi K3's are due to be within days, cannot be recalled or throttled or sued into a settlement — making the thing legally radioactive to hold or build upon is close to the only lever left. That is a policy choice wearing the costume of a factual finding about theft.

None of this settles whether Moonshot did what it stands accused of. The fake accounts, if the metadata holds, are a real wrong; the chips, if the routing holds, are another, and both may cost the company dearly. But the model at the center of the case was not stolen in any sense a court has yet been willing to recognize, and the firm now calling it espionage spent the previous two years, and $1.5 billion in settlement, establishing precisely why. Anthropic won the argument that learning from someone else's work is not theft. It now needs Washington to say, on its behalf, that it is.

// The Daily

Get Vector in your inbox.

A free morning briefing on the AI revolution. Weekdays at 6am CT.