Not chips, not hardware: distillation — training a smaller AI to mimic a larger one's outputs. Treasury is moving, Nvidia is hedging, and the White House AI orbit is publicly feuding.
Treasury Secretary Scott Bessent said on X this week that "open source is not open season on American IP" and is moving to sanction a Chinese AI lab called Moonshot for what he calls "covert, industrial-scale distillation attacks" on Anthropic's model Fable. The threat, amplified earlier in the week by White House science advisor Michael Kratsios, has triggered an inter-agency review of Chinese open-source models — the first time the US has tried to sanction a model-training practice rather than a chipmaker.
That distinction is the story, because most readers have never heard of distillation.
Distillation is the legal and technical hook Treasury is using. It is a way of training a smaller, cheaper model to copy the behavior of a larger one: feed the big model millions of questions, save its answers, then teach a smaller model to produce similar outputs. It is a routine technique across the AI industry, and a Chinese lab doing it to a US lab's outputs is not the same thing as a fab shipping restricted chips. The Bessent framing treats open-source releases as the new export-control battleground, and the Treasury post names the Entity List as the tool. If the action holds, the precedent is that training a model on another model's outputs can be treated as a national-security violation.
The rest of Washington is not on the same page. Nvidia CEO Jensen Huang told Axios this month that America has nothing to fear from Chinese AI, a public rebuke of the sanction-first camp from the company whose chips sit underneath most of the global AI build-out. The hedger wing inside the administration is making the same argument: compete on models, not on entity listings.
The third camp is louder. Trump-era AI advisor David Sacks has publicly called Anthropic "lobotomized" and "woke" after it declined to release a Chinese-distillation rebuttal; Pentagon official Emil Michael insulted an OpenAI hire over the same episode. The MIT Technology Review deep-dive from July 20 documents the infighting as the trigger for the current inter-agency push, and the language is now spilling into public X posts. Read the three camps together and the disagreement is the policy: escalators at Treasury, hedgers behind Huang, ideologues in the Trump-era AI orbit.
This is a fight with a real operational floor. Chinese models are no longer a future threat: they are running inside Western products. MIT Technology Review's July 23 newsletter notes that Hugging Face reportedly turned to Moonshot's Kimi model to recover from a separate OpenAI-related incident, a single example of a Western infrastructure provider falling back on a Chinese open-source model in production. When the model is already inside the stack, the question of who gets to sanction whom changes shape. A sanction on Moonshot does not pull Kimi out of Hugging Face the way a chip sanction pulls accelerators out of a data center.
The Bessent threat is also a claim, not a finding. Treasury is asserting that Moonshot's training of Kimi amounted to "industrial-scale distillation" of Anthropic's Fable. Anthropic and the White House have not published a technical exhibit, and the Bessent X post is a statement of intent, not an adjudication. If the Entity Listing goes through, it will be the first US action against a foreign AI lab over a training method, and it will happen before the underlying allegation has been litigated.
The next decision points are concrete. Treasury will name a second Chinese lab, or it won't. Allied regulators in Brussels, London, and Tokyo will follow Treasury's lead on distillation, or they will treat it as an American theory of harm. And the White House will either bind the three camps together or let the infighting settle the question. The disagreement is already the story; whether it becomes policy is the next 60 days.