On July 22, the most powerful open model of the year acquired an asterisk. Michael Kratsios, director of the White House Office of Science and Technology Policy, stated publicly that Moonshot AI had built its Kimi K3 model by distilling Anthropic's Fable, calling it large-scale covert industrial distillation aimed at stealing American technology. It was the first time a senior US official had pointed at a specific Chinese lab and a specific American model and said, in effect, that one was copied from the other.
The target could hardly be bigger. Kimi K3 is the 2.8-trillion-parameter system that launched on July 16, took the top spot on a head-to-head coding leaderboard with a 76 percent win rate over Claude Fable 5, and became the largest open-weight release in history. An accusation that it was built by copying the very model it beat does not just dent Moonshot's reputation. It reframes the story the industry has been telling itself about how far ahead American labs really are.
The trouble is proof. Distillation, in which a smaller student model learns from a larger teacher's outputs, is a legitimate and routine technique; what makes it contentious is doing it to a competitor without permission. But model weights carry no watermark, and a distilled model looks nothing like its teacher on the inside. There is no source code to match. Investigators are left with behavioural forensics: does the student reproduce the teacher's quirks at rates that chance cannot explain? The public evidence so far is exactly that kind. Kimi K3 has been documented identifying itself as Claude, and Ryan Greenblatt of Redwood Research published a cross-entropy analysis finding that it does so far more often than random noise would predict.
Researchers, including the ones producing the analysis, are quick to list the innocent explanations. Claude transcripts are scattered across the public web, so any model trained on broad web data swallows some. Leftover system prompts, roleplay leakage and contaminated datasets can all make a model misidentify itself. The honest summary is that the statistical pattern is genuinely suggestive and genuinely not conclusive, and anyone claiming certainty in either direction has run ahead of the evidence.
The second allegation is sturdier, and potentially more damaging. Kratsios also said Moonshot had accessed Nvidia's restricted GB300 chips through Thailand, likely to train its models. Distillation sits in a murky corner of contract law, but routing export-controlled hardware through a third country is a specific regulatory offence with real enforcement teeth. It also answers a question that nagged observers when K3 launched: how a Chinese lab assembled the enormous compute such a model needs while under US chip restrictions. If it holds up, that claim will reshape policy faster than the copying charge, because it points at a gap legislation can actually close. A chip can be sold legally to a permitted country, installed there, and then rented to anyone with a credit card, which quietly turns an export question into a cloud-access one.
Timing sharpens all of it. Kimi K3's weights are scheduled to go free on July 27, four days after the accusation, which means every company weighing whether to download and self-host it now has a contested provenance claim sitting on top of its technical evaluation. The performance is real and independently measured, and no legal finding exists. But corporate legal teams are conservative about exactly this species of uncertainty, and the likeliest effect, whatever the merits, is to slow enterprise adoption while individual developers carry on regardless. For a government that spent the week accusing a rival of playing dirty, that may be precisely the point.