American Enterprise Institute publishes strategy to prevent China from freeriding on US AI advantages through asymmetric access controls.
The release of Chinese open-weight AI model Kimi K3 compressed a year of unresolved AI policy debate into a single news cycle. On July 21, Treasury Secretary Scott Bessent threatened sanctions against Chinese labs that built models on "theft," reporting that the government is "finding watermarks of our U.S. large language models on many of the Chinese models." The following day, White House science advisor Michael Kratsios clarified that Moonshot AI, the lab behind K3, had built sophisticated infrastructure to copy Anthropic's Fable model while evading detection.
Industry voices diverged sharply. Nvidia's Jensen Huang said American companies should "absolutely" use Chinese models that outcompete American counterparts on price. Investor Bill Gurley argued in the Washington Post that treating open models as a danger to be licensed and contained contradicts the free-market principles underlying American innovation.
Chinese open-source AI models now account for the majority of global AI workloads. Washington split into two camps. One, alarmed by security risks from Chinese AI diffusion and intellectual property theft, favored restricting or banning Chinese models outright. The other, represented by software engineers relying on Chinese models, warned that restrictions would hamper development and claimed no genuine harm had occurred.
The Trump administration navigated between these positions, supporting open-source software while targeting covert, industrial-scale extraction of American trade secrets. This distinction is defensible and actionable. The U.S. should sanction Chinese AI labs engaged in systematic fraud, not the underlying practice of "distillation" used industry-wide.
**Distillation as Technique, Extraction as Fraud**
Distillation—training a smaller "student" model on a stronger "teacher" model's outputs—is standard practice used by every AI lab, including American frontier labs and Chinese competitors. Banning it is technically unenforceable; anyone with access to a model's outputs, including legitimate customers, can convert them back into training data. Restricting AI development to un-distillable models would artificially protect two or three frontier labs while crippling broader innovation.
Chinese model performance stems not merely from distillation. DeepSeek R1's efficiency breakthrough in January 2025 came primarily from reinforcement learning advances rather than copying. Moonshot's focus on agent swarming in 2026 was likewise homegrown. Stopping distillation attacks will slow but not halt Chinese progress.
The distinguishing problem is not distillation itself but systematic, fraudulent theft of American trade secrets. A distillation attack—obtaining unauthorized access to a competitor's product through deception—differs from legitimate technique. Fraudulent schemes involving fabricated identities, purpose-built evasion infrastructure, and deliberate security circumvention fall under the Computer Fraud and Abuse Act and wire fraud statutes.
By February 2026, Anthropic traced over 3.4 million exchanges with its models to Moonshot, routed through hundreds of fake accounts using an internal evasion platform. Later in June, Anthropic told the Senate Banking Committee that Alibaba's Qwen lab had conducted the "largest known distillation attack" against it to date.
**Intellectual Property is Only Part of the Story**
Distinguishing distillation-as-technique from distillation-as-attack justifies which conduct the U.S. government can credibly punish, but does not capture the full concern.
Model outputs alone are not copyrightable under U.S. law as they require human authorship, making "intellectual property theft" legally dubious. Trade secret law applies better. Though skeptics note that outputs served through commercial interfaces cannot remain "secret," proprietary access to frontier models is neither public nor unauthenticated. The trade secret is not a single query's response but model behavior collectively encoded across millions of conversations—extractable only at scale.
Critics note that Anthropic itself trained on pirated books and paid a $1.5 billion settlement. This comparison proves the point: Anthropic faced an American court and paid the largest copyright settlement in history. Moonshot has no such recourse and will pay nothing for extracting and replicating Anthropic's trade secrets. Addressing this asymmetry should be central to policy.
More compelling than fraud allegations are national security grounds. Chinese labs convert billions in American R&D spending on compute and machine reasoning, then release results freely, undercutting American firms in price-sensitive global markets. This compounds other security risks: supply chains vulnerable to poisoned weights; intelligence collection through user traffic routed to servers subject to China's National Intelligence Law; capability uplift for malicious actors. Foundational software is written by San Francisco engineers using models answerable to Chinese state security services.
Whether open competition in AI markets is desirable is distinct from whether the U.S. should tolerate China's expanding influence. Competition in which one side pays for frontier advancement while the other harvests it through fraud, then leverages state-subsidized diffusion to lock global market share, is not free-market competition. It is free-riding backed by industrial policy—the playbook China deployed in steel, solar, and shipbuilding. The United States rejected this arrangement in those industries and should not accept it for AI.
The Trump administration is drawing a line between legitimate distillation, vital to machine learning as a scientific enterprise, and large-scale covert distillation attacks targeting proprietary U.S. technology. Four steps would operationalize this position.
First, the U.S. Center for AI Standards and Innovation or an equivalent independent oversight body should develop the capability to independently verify distillation attacks and distinguish them from firms merely trained on openly available data. Evidence for distillation attack attribution has so far come from victim labs' own forensics. Sanctioning foreign firms on the strength of an accuser's internal analysis raises adjudica