Why it matters
  • Direct warning. Treasury Secretary Scott Bessent stated publicly on July 22 that sanctions and Entity List designations are “on the table” for Chinese AI companies that run coordinated distillation campaigns against American AI models—the first time a US cabinet official has named that specific technique as a potential sanctions trigger.
  • Named targets. White House science adviser Michael Kratsios cited Moonshot AI as having generated more than 3.4 million exchanges against Anthropic’s Claude platform in a coordinated campaign, and said Alibaba’s Qwen lab executed the largest known single campaign—28.8 million exchanges using nearly 25,000 fraudulent accounts.
  • Beijing’s counter. China threatened “all necessary measures” if Washington imposes sanctions on Chinese AI developers, framing the US position as “AI hegemonism.”

The escalation centres on model distillation, a legitimate technique in which a smaller AI model is trained on the outputs of a larger one to replicate its capabilities at lower cost. US companies and the White House argue that when done at industrial scale using fraudulent accounts and in violation of terms of service, the practice crosses into intellectual-property theft. Chinese developers dispute that characterisation.

Bessent’s exact language on July 22 was pointed: “Open source is not open season on American IP. When industrial-scale distillation attacks cross the line into IP theft, sanctions will be on the table.” The statement followed a National Security Technical Memorandum—NSTM-4—that the White House issued in April 2026, formally classifying systematic covert distillation by adversarial states as a severe national security threat.

The Mechanics of the Alleged Campaigns

According to figures cited by the White House, the Moonshot AI campaign involved automated query systems that extracted responses from Claude over an extended period, effectively using Anthropic’s frontier model as a training corpus without authorisation. The Alibaba Qwen campaign was larger still: 28.8 million exchanges attributed to nearly 25,000 accounts, each likely created to bypass rate limits and detection systems.

Kratsios also alleged that Moonshot AI accessed servers equipped with Nvidia GB300 chips, potentially in violation of US export controls that restrict advanced AI accelerators from reaching Chinese entities. That allegation, if substantiated, would constitute a separate enforcement pathway under Bureau of Industry and Security rules, independent of the sanctions mechanism.

The Export Control Dimension

The White House response to Anthropic’s alleged distillation included banning the export of Anthropic’s Fable model—the specific system cited in the Moonshot AI campaign—a step that reflects how the administration has linked IP protection to the broader export-control architecture governing advanced AI. That architecture was substantially tightened in early 2026, when the administration codified restrictions on AI chip exports that had previously operated on an informal basis.

The proposed sanctions mechanism would sit on top of the chip export controls, targeting the model layer rather than the hardware layer. Critics of the approach argue that model-level sanctions are harder to enforce because model weights can be transferred through channels that bypass conventional trade infrastructure.

Beijing’s Position

China’s government rejected the framing. Beijing’s response, issued through official channels, characterised the US position as an attempt to maintain dominance over AI development by criminalising legitimate training practices. Officials said China would take “all necessary measures” to protect its AI companies—language that typically signals potential retaliatory trade or regulatory action rather than immediate specific steps.

The dispute is unresolved. No sanctions have been formally imposed as of mid-August, and Chinese AI companies including Moonshot AI and Alibaba’s Qwen team have not confirmed or denied the specific figures cited by US officials. The outcome will depend in part on whether the administration can present evidence that meets the legal threshold for an OFAC designation—a bar that has proved difficult to clear in previous technology-sector enforcement actions.