Skip to main content
AI GeopoliticsPolicy Decision· 6 min read· in Artificial Intelligence

White House Defends Open AI Development While Accusing China of Tech Theft in New Policy Stance

The White House has issued a new policy defending domestic open-source AI ecosystems while simultaneously accusing Chinese firms of "industrial-scale" intellectual property theft through model distillation. The stance attempts to thread the needle between tech industry demands for open models and national security concerns over foreign adversaries extracting frontier capabilities.

By Ishani Patel

National Security Advocates 40%Open-Source Ecosystem 40%Policy Skeptics 20%
National Security Advocates
Argue that adversarial distillation is industrial espionage that threatens US technological supremacy and requires strict enforcement.
Open-Source Ecosystem
Argue that distillation is a standard development technique and restricting open models harms competition and entrenches monopolies.
Policy Skeptics
Highlight the technical and legal impossibility of recalling open-weight models or proving IP theft from API outputs.

Perspectives this story doesn't cover

  • Chinese AI developers accused of distillation
  • Global South nations relying on open-weight models for digital infrastructure

Key terms

Model Distillation
A technique where a smaller AI model is trained using the outputs of a larger, more capable model to replicate its performance.
Open-Weight Model
An AI system whose core architecture and trained parameters are publicly available for anyone to download and modify.
API (Application Programming Interface)
A software intermediary that allows two applications to talk to each other, commonly used to access proprietary AI models over the internet.
Entity List
A US trade restriction list that prohibits foreign companies from purchasing American technology without a special license.

Key points

  1. The White House accused Chinese AI firms of "industrial-scale" intellectual property theft through model distillation.
  2. Officials claim Moonshot AI used millions of fraudulent API queries to copy capabilities from Anthropic's proprietary models.
  3. The administration defended domestic open-source AI development while threatening sanctions against foreign extraction.
  4. A coalition of 179 startups and tech giants warned that restricting open-weight models would harm American competition.
  5. Policy experts note that enforcing bans on open-weight models is technically difficult once the files are downloaded globally.

The White House has formally accused Chinese artificial intelligence developers of conducting "industrial-scale" intellectual property theft, escalating the geopolitical battle over frontier AI. In a newly issued policy stance, the administration alleged that Chinese startups are systematically extracting the capabilities of top-tier American models to build their own systems. Yet, in a delicate balancing act, the administration simultaneously defended the broader open-source AI ecosystem, attempting to draw a line between domestic innovation and foreign espionage.[4]

The policy arrives via National Security Telecommunications Memorandum 4 (NSTM-4), which targets a practice known as "adversarial distillation." Distillation involves using a massive, highly capable AI model to generate training data for a smaller, cheaper model. While the White House Office of Science and Technology Policy (OSTP) acknowledged that distillation is a legitimate development technique, OSTP Director Michael Kratsios characterized the covert, large-scale extraction of US models by foreign adversaries as "unacceptable" industrial espionage.[4]

The primary catalyst for the administration's aggressive posture is the recent release of Kimi K3 by the Chinese startup Moonshot AI. Pronounced as one of the world's most capable open-weight models, Kimi K3 matches several benchmarks previously held only by proprietary American systems. The White House claims to possess evidence that Moonshot AI developed K3 by illicitly distilling Anthropic's advanced Fable and Claude models, utilizing a sophisticated internal platform to bypass security protocols.[1]

The evidence underpinning the government's claims originates from a forensic disclosure by Anthropic. The San Francisco-based AI lab reported that three Chinese companies—MiniMax, Moonshot AI, and DeepSeek—utilized roughly 24,000 fraudulent accounts to conduct more than 16 million automated exchanges with its systems. According to the logs, MiniMax accounted for over 13 million of these queries, while Moonshot AI executed 3.4 million exchanges specifically targeting reasoning and coding capabilities.[4]

Anthropic reported that three Chinese AI labs utilized thousands of fraudulent accounts to conduct millions of automated exchanges with its systems.

Anthropic's head of public policy, Sarah Heck, publicly backed the White House's assessment, labeling the activity as "IP theft and industrial espionage that supports adversary military and intelligence capabilities." The company argues that without these massive extraction campaigns, foreign competitors would be unable to match the performance of American frontier models using supervised fine-tuning alone.[1]

In response to the alleged theft, the US Treasury Department has threatened to deploy severe economic weapons. Treasury Secretary Scott Bessent warned that "open source is not open season on American IP," floating the possibility of placing Chinese AI model makers on the Entity List. Such a designation would subject the companies to strict export controls, effectively cutting them off from American cloud providers and advanced Nvidia hardware.[1]

However, the administration's attempt to surgically target Chinese distillation without harming the broader open-source community has ignited a fierce debate within the US technology sector. A coalition of 179 startups, alongside industry giants like Meta, Microsoft, and Nvidia, recently signed a letter warning the Trump administration against imposing "premature restrictions" on open-weight models.[1]

The coalition argues that distillation is a fundamental and widely accepted method for training efficient AI systems. For many AI-native startups, downloading and fine-tuning an open-weight model is the only economically viable way to build products, as relying entirely on API access from dominant players like OpenAI and Anthropic is prohibitively expensive.[1]

The coalition argues that distillation is a fundamental and widely accepted method for training efficient AI systems.

"Lobbyists are urging Washington to treat open model AI as a security threat. In fact, it is something more familiar: proper competition that should be welcomed," argued former venture capitalist Bill Gurley, reflecting the sentiment of the startup community. Critics within the open-source camp suggest that leading proprietary labs are leveraging national security concerns to construct a regulatory moat, protecting their market dominance ahead of anticipated initial public offerings.[1]

Startups argue that open-weight models are essential for keeping operational costs viable compared to paying per-token API fees to proprietary labs.

The legal and technical mechanics of enforcing a ban on adversarial distillation remain highly uncertain. Distillation occurs over the public internet through API calls, which can be easily routed through proxy servers in any jurisdiction. Furthermore, the legal status of an AI model's outputs is unsettled; it is not yet clear under US law whether harvested text completions qualify as protected trade secrets.[4]

The National Telecommunications and Information Administration (NTIA) recently highlighted this enforcement paradox in a comprehensive report on dual-use foundation models. The NTIA concluded that while open models pose undeniable geopolitical risks, there is currently insufficient evidence to justify broad restrictions. The agency noted that once an open-weight model's files are downloaded and mirrored across global repositories, regulatory action against the original developer cannot recall the existing copies.[2]

This reality complicates the Treasury Department's threat of sanctions. While adding a company like Moonshot AI to the Entity List might prevent them from purchasing new chips, it does nothing to stop developers worldwide from running the already-released Kimi K3 model on their local machines. As one policy analyst noted, by the time a risk from an open model is visible enough to regulate, the technology has already escaped the building.[2]

The intelligence community views the distillation dispute as merely the latest front in a broader campaign of economic espionage. During a recent House Intelligence Committee hearing, former officials testified that China's Ministry of State Security has pivoted aggressively toward targeting frontier AI companies. Because the US holds a massive structural advantage in semiconductor manufacturing, foreign adversaries are highly incentivized to steal the software outputs rather than attempting to replicate the hardware infrastructure.[3]

The America First Policy Institute recently published a brief echoing these concerns, arguing that the theft of frontier capabilities by state-backed actors is a national security threat that private companies have not fully internalized. The brief highlighted previous instances of Chinese nationals attempting to exfiltrate AI trade secrets from Google, suggesting that API distillation is simply a more scalable, remote method of achieving the same goal.[3]

Model distillation involves using the outputs of a highly capable AI to train a smaller, more efficient system.

To bolster domestic defenses, the White House has launched "Gold Eagle," a clearinghouse designed to coordinate cybersecurity vulnerability sharing between leading American AI firms and federal agencies, including the Department of Homeland Security. The initiative aims to develop faster exploit detection mechanisms to identify and block fraudulent API access before industrial-scale extraction can occur.

Meanwhile, Congress is moving to codify stricter oversight. The bipartisan AI Overwatch Act, recently introduced in the Senate, would require the Commerce Department to certify that exports of advanced AI chips do not facilitate remote access by unauthorized parties. Another proposed bill, the Deterring American AI Model Theft Act, attempts to create new civil remedies for companies whose models are illicitly distilled, though it has yet to advance out of committee.[4]

The geopolitical stakes extend beyond simple corporate competition. The NTIA report warned that the wide availability of advanced open-weight models from China could fragment the global digital ecosystem. As Chinese models see growing adoption in the Global South, the US risks losing its ability to steer the technological frontier toward systems that align with democratic values.[2]

Ultimately, the White House's new policy stance underscores the profound difficulty of governing artificial intelligence in a multipolar world. By attempting to punish foreign distillation while protecting domestic open-source development, the administration is testing whether traditional tools of economic statecraft—sanctions, export controls, and IP law—can effectively contain a technology that is inherently designed to be copied and shared.[4]

The dispute over open-weight AI and intellectual property theft has rapidly escalated throughout 2026.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

National Security Advocates 40%Open-Source Ecosystem 40%Policy Skeptics 20%
  1. [1]TechCentralOpen-Source Ecosystem

    Startups urge Washington not to treat open AI models as security threat

    Read on TechCentral →
  2. [2]NTIAPolicy Skeptics

    Dual-Use Foundation Models With Widely Available Model Weights Report

    Read on NTIA →
  3. [3]America First Policy InstituteNational Security Advocates

    AI and Emerging Technology: Countering Economic Espionage

    Read on America First Policy Institute →
  4. [4]NYU Center for CybersecurityPolicy Skeptics

    Analyzing NSTM-4: Adversarial Distillation of American AI Models

    Read on NYU Center for Cybersecurity →

Comments

Stay informed

Every angle. Every day.

Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.