Factlen ExplainerModel DistillationExplainerJul 25, 2026, 4:18 AM· 6 min read· #1 of 5 in ai

How 'Model Distillation' Became the AI Industry's Biggest Security Gray Area

The White House has accused Chinese startup Moonshot AI of using "covert industrial distillation" to train its new K3 model on Anthropic's Fable. The dispute highlights a growing technical loophole where AI companies can effectively clone a rival's capabilities simply by asking it millions of questions.

By Factlen Editorial Team

Frontier AI Developers 40%Legal & Copyright Scholars 35%Open-Source & Challenger Labs 25%
Frontier AI Developers
Argue that unauthorized distillation is intellectual property theft that undermines the massive capital investments required to build foundational models.
Legal & Copyright Scholars
View distillation as a complex gray area akin to reverse engineering, noting that copyright protects expression rather than functional behavior.
Open-Source & Challenger Labs
Treat distillation as a standard, highly efficient training technique, arguing that API outputs cannot be permanently monopolized by early market leaders.

What's not represented

  • · Independent AI Developers

Why this matters

As AI models become the most valuable intellectual property on Earth, the ability to 'clone' a billion-dollar system for pennies through API queries threatens the economic foundation of the tech industry and complicates global export controls.

Key points

  • The White House accused China's Moonshot AI of using "covert industrial distillation" to copy Anthropic's Fable model.
  • Model distillation involves querying a target AI's public API millions of times to generate training data for a competing system.
  • The technique allows competitors to bypass the hundreds of millions of dollars typically required to train a frontier model from scratch.
  • Copyright law struggles to address distillation because it involves observing a model's behavior rather than stealing its underlying code.
  • AI developers are increasingly relying on strict Terms of Service and technical countermeasures like output watermarking to protect their models.
2.8 trillion
Parameters in Moonshot's Kimi K3 model
$100M+
Estimated cost to train a frontier model from scratch
16 million
Fraudulent API exchanges detected in previous Anthropic attacks

The White House has leveled a severe accusation against one of China's leading artificial intelligence startups, alleging that Beijing-based Moonshot AI illicitly copied the capabilities of Anthropic's most advanced AI system. According to Michael Kratsios, Director of the White House Office of Science and Technology Policy, Moonshot utilized a technique known as "covert industrial distillation" to train its newly released Kimi K3 model on Anthropic's proprietary Fable model. The accusation highlights a growing crisis in the AI industry: the realization that a company's most valuable intellectual property can be systematically extracted without anyone ever breaching a server or stealing a line of code.[1][6]

The controversy centers on Moonshot AI's Kimi K3, a massive 2.8-trillion-parameter open-source model released in mid-July 2026. Upon its debut, Kimi K3 shocked the industry by benchmarking neck-and-neck with the most powerful proprietary systems from US developers, including Anthropic and OpenAI. For a three-year-old startup to match the capabilities of labs backed by billions in Big Tech funding raised immediate questions about how the model was trained. The US government now claims the answer lies in model distillation, a process where a newer AI learns by copying the inner workings and reasoning patterns of a more mature system.[1][2][6]

In traditional machine learning, model distillation is a standard and legitimate practice. It involves taking a massive, highly capable "teacher" model and using it to train a smaller, more efficient "student" model. The teacher model generates millions of high-quality answers, reasoning traces, and coding solutions, which are then fed into the student model as training data. When a company does this internally with its own models, it is considered one of the smartest ways to ship a fast, cost-effective AI product.[3][4]

A black-box distillation attack extracts capabilities without ever accessing the target model's underlying code.
A black-box distillation attack extracts capabilities without ever accessing the target model's underlying code.

However, the technique becomes highly controversial—and potentially malicious—when applied to a competitor's proprietary system. In a "black-box distillation attack," the attacker does not need access to the target model's underlying weights, source code, or internal architecture. Instead, they simply open an account and query the target model's public Application Programming Interface (API) at a massive scale. By feeding the target model millions of carefully crafted prompts and recording the responses, the attacker can essentially outsource their data labeling and capability development to their rival.[3][4][6]

The economics of this strategy are overwhelmingly favorable to the attacker. Training a frontier AI model from scratch requires hundreds of millions of dollars in specialized compute hardware and painstaking human data curation. In contrast, distilling a competitor's model via API queries might cost only a few hundred thousand dollars in usage fees. To the victim company, the attack often looks indistinguishable from a highly active, paying enterprise customer utilizing the service exactly as designed.[3][4][6]

White House officials were quick to draw a line between standard industry practices and the actions allegedly taken by Moonshot AI. Kratsios noted that while legitimate AI distillation plays a vital role in creating efficient models, "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable." Under Secretary of State Jacob Helberg echoed the sentiment, describing the incident as an assault on economies that rely on fair and honest competition.[1]

White House officials were quick to draw a line between standard industry practices and the actions allegedly taken by Moonshot AI.

Despite the strong rhetoric from Washington, the legal reality of model distillation is incredibly murky. Legal scholars point out that distillation sits in an uncomfortable space between imitation and outright appropriation. Because the attacker never copies files, extracts weights, or duplicates source code, traditional intellectual property laws struggle to classify the behavior as theft. Copyright law fundamentally protects the expression of ideas, not the ideas themselves or functional methods of operation.[5][6]

Experts often compare model distillation to reverse engineering, or to a student attending a brilliant professor's public lectures. If the student takes meticulous notes and later builds a condensed course based on what they learned, they haven't stolen the professor's brain—they have simply learned from observing their behavior. In the context of AI, the student model is statistically inferring patterns by treating the teacher model as a black box, a process that many argue does not meet the legal threshold for copyright infringement.[5]

The US government has increasingly viewed advanced AI model weights as a matter of national security.
The US government has increasingly viewed advanced AI model weights as a matter of national security.

With copyright law offering little protection, the real battleground has shifted to contract law. Most frontier AI developers, including Anthropic and OpenAI, have updated their Terms of Service to explicitly prohibit users from using their model's outputs to train competing artificial intelligence systems. While this gives companies grounds to terminate accounts and potentially sue for breach of contract, enforcing these terms globally—especially against state-backed or international competitors—is notoriously difficult.[4][5][6]

The Moonshot AI incident is not the first time US labs have faced this threat. In recent years, Anthropic, Google, and OpenAI have all reported variations of distillation attacks originating from competing labs. In one notable case, Anthropic alleged that attackers used approximately 24,000 fraudulent accounts to conduct 16 million API exchanges in an attempt to extract reasoning traces from its Claude models. As these attacks become more sophisticated, attackers are developing internal platforms that quickly switch between multiple access methods to evade detection.[1][3][6]

To protect their billion-dollar investments, AI companies are racing to develop technical countermeasures. Security teams are implementing behavior-aware rate limiting to identify accounts that query the API in patterns indicative of automated dataset generation. Developers are also experimenting with subtle cryptographic watermarks embedded in the text outputs, which can later be detected if a competitor's model begins reproducing those specific linguistic quirks. However, determined attackers continually find ways to strip these watermarks or obfuscate their queries.[4][6]

Distilling a competitor's model via API queries costs a fraction of training a frontier model from scratch.
Distilling a competitor's model via API queries costs a fraction of training a frontier model from scratch.

The geopolitical stakes of the Moonshot AI dispute are particularly high, coming just weeks after the US Commerce Department imposed unprecedented export controls on Anthropic's Fable 5 and Mythos 5 models. In June 2026, the US government forced Anthropic to suspend global access to its top models for all foreign nationals, citing severe national security concerns. The revelation that a Chinese lab may have bypassed these restrictions by distilling the model's capabilities through API access highlights the immense difficulty of containing digital intelligence.[1][6]

As the AI industry moves forward, the line between learning and stealing will remain one of its most contentious debates. For policymakers, the challenge is to strengthen guardrails against industrial-scale model theft without outlawing the legitimate distillation techniques that allow open-source developers to build smaller, more accessible AI tools. Until a clear legal framework emerges, frontier AI labs will have to accept that their most dangerous competitors might also be their highest-paying API customers.[1][4][6]

How we got here

  1. March 2023

    Moonshot AI is founded in Beijing by a team of Tsinghua University graduates.

  2. June 2026

    The US Commerce Department imposes unprecedented export controls on Anthropic's Fable 5 model.

  3. July 16, 2026

    Moonshot AI releases Kimi K3, a 2.8-trillion-parameter model rivaling top US systems.

  4. July 22, 2026

    White House officials publicly accuse Moonshot of using industrial distillation to copy Anthropic's model.

Viewpoints in depth

Frontier AI Developers' view

Leading US AI labs view unauthorized distillation as a direct threat to their business models and national security.

Companies investing billions in foundational research argue that 'industrial-scale' distillation allows foreign competitors to free-ride on American innovation. By outsourcing the most expensive parts of data curation and reinforcement learning to a rival's API, attackers can clone capabilities for pennies on the dollar. These developers are increasingly lobbying for stronger legal protections and deploying technical countermeasures like output watermarking to defend their intellectual property.

Legal & Copyright Scholars' view

Legal experts see distillation as a complex challenge that doesn't neatly fit existing intellectual property laws.

Scholars point out that copyright law was designed to protect the expression of ideas, not the ideas themselves or functional behavior. Because distillation involves observing outputs rather than copying source code or model weights, it closely resembles legal reverse-engineering. While it may violate a company's Terms of Service, proving that a model's 'behavior' was stolen remains a significant hurdle in court.

Open-Source & Challenger Labs' view

Smaller labs and open-source advocates argue that distillation is a standard, necessary technique for industry progress.

Challenger companies view distillation as a legitimate way to create smaller, more efficient models that can run on consumer hardware. They argue that early market leaders should not be allowed to monopolize AI capabilities simply because they were first to scale. In this view, learning from a competitor's outputs is no different than a human engineer studying a rival's product to build a better alternative.

What we don't know

  • It remains unclear exactly how much of Anthropic's data Moonshot AI allegedly extracted to train the Kimi K3 model.
  • Courts have yet to definitively rule on whether violating an API's Terms of Service for model distillation constitutes actionable intellectual property theft.
  • It is unknown how the US government plans to enforce export controls if foreign labs can simply distill models through proxy API accounts.

Key terms

Model Distillation
The process of training a smaller AI model to replicate the behavior of a larger, more complex model by using the larger model's outputs as training data.
Black-Box Attack
A method of extracting an AI model's capabilities without having access to its underlying code or weights, relying entirely on observing its inputs and outputs.
Frontier Model
The most advanced, highly capable artificial intelligence models available at any given time, typically requiring massive computational resources to build.
API (Application Programming Interface)
A software intermediary that allows two applications to talk to each other, commonly used by developers to integrate AI models into their own products.

Frequently asked

What is AI model distillation?

It is a machine learning technique where a smaller 'student' model learns by studying the outputs and reasoning patterns of a larger, more capable 'teacher' model.

Did Moonshot AI hack Anthropic's servers?

No. Distillation attacks typically rely on querying a model's public API at a massive scale, interacting with it just like a normal customer would.

Is model distillation illegal?

It exists in a legal gray area. While it often violates a company's Terms of Service, copyright law generally protects the expression of ideas rather than functional behavior, making traditional IP theft hard to prove.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Frontier AI Developers 40%Legal & Copyright Scholars 35%Open-Source & Challenger Labs 25%
  1. [1]NextgovFrontier AI Developers

    White House says Moonshot AI illegally trained its model off of Anthropic's Fable

    Read on Nextgov
  2. [2]VentureBeatOpen-Source & Challenger Labs

    Moonshot AI releases Kimi K3, a 2.8 trillion-parameter open-source AI model

    Read on VentureBeat
  3. [3]MindStudioOpen-Source & Challenger Labs

    AI Model Distillation Attacks: What They Are and Why They Matter

    Read on MindStudio
  4. [4]RedwerkOpen-Source & Challenger Labs

    Model Distillation Attacks: How Your Proprietary AI Gets Stolen Through Its Own API

    Read on Redwerk
  5. [5]Monash UniversityLegal & Copyright Scholars

    Anthropic says rivals learned from Claude via millions of queries. But if AI outputs aren't copyrightable, is model distillation theft or just learning?

    Read on Monash University
  6. [6]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.