White House: Moonshot AI Accessed Banned Nvidia GB300 Chips to Build Kimi K3
White House OSTP Director Michael Kratsios publicly accused Moonshot AI of routing around U.S. export controls via Thailand and covertly extracting Anthropic's Fable model. Kimi K3 is already out. The weights can't be recalled.

U.S. export controls on frontier AI chips are already a sieve, and the White House's own top science official just said so on the record.
Key takeaways
- OSTP Director Michael Kratsios publicly stated Moonshot AI accessed banned Nvidia Blackwell GB300 chips through servers in Thailand and distilled Anthropic's Fable model to build Kimi K3.
- Kimi K3 is open-weight and already globally distributed. Sanctions against Moonshot cannot recall the model weights.
- The circumvention playbook (third-country GPU access plus mass covert distillation) is now documented. Every sanctioned-jurisdiction AI lab just received a working blueprint.
Michael Kratsios, Director of the White House Office of Science and Technology Policy, posted a public accusation on July 22, 2026, stating that Moonshot AI acquired servers equipped with Nvidia's banned Blackwell GB300 chips and accessed those chips through facilities in Thailand, likely to train its Kimi K3 model. The post also accused Moonshot of conducting industrial-scale covert distillation against Anthropic's Fable model, using a purpose-built internal platform designed to rotate access methods and evade detection.
Kratsios wrote: "We have information that Moonshot AI distilled Anthropic's Fable for the development of its K3 model," adding that Moonshot "developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection." On the hardware side: "Moonshot AI has also acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models."
The Hardware and the Playbook
The GB300 is part of Nvidia's Blackwell generation, explicitly banned from sale to Chinese companies under U.S. export controls. The Trump administration permits H200 exports but has maintained the Blackwell ban. A Bureau of Industry and Security memo issued May 31, 2026, affirmed that U.S. export licenses are required to ship advanced AI chips to any entity headquartered in, or with an ultimate parent in, Country Group D:5 (China), even when the purchasing entity sits outside China. Thailand is the documented workaround.
This is not the first time Washington flagged the distillation vector. An OSTP memorandum issued April 23, 2026, warned that foreign entities, principally in China, were running "deliberate, industrial-scale campaigns to distill U.S. frontier AI systems." That memo called for intelligence sharing. The Kratsios post names a specific company and a specific model.
Kimi K3 was released on July 16, 2026, with model weights published publicly. The model is open-weight. The weights are already downloaded, mirrored, and running on hardware that U.S. sanctions cannot reach.
What Export Controls Actually Bought
This is a live demonstration of why centralized chokepoints fail. The U.S. government controlled a single vendor (Nvidia), a single chip generation (Blackwell), and a set of geographic export rules. Moonshot routed around all three: third-country server access for compute, fraudulent API access for model knowledge, and open-weight release to make the result uncontainable.
The export controls regime has now produced a documented case where restricting access to U.S. models appears to have driven a Chinese lab to extract those models covertly at industrial scale rather than license them. The controls may have slowed Moonshot. They did not stop it.
At Computex 2025 in Taipei, Nvidia CEO Jensen Huang told reporters on the sidelines that "the export control was a failure," arguing restrictions handed Chinese firms the motivation to accelerate domestic alternatives. Kimi K3 arriving at near-frontier capability is that argument made concrete. Meanwhile, Z.AI completed a 1-gigawatt data center running on all-Chinese chips. The hardware workaround and the software workaround are both on the board.
The decentralization parallel is direct. Open-weight models behave like Bitcoin: once the weights exist on enough nodes, there is no issuer to compel, no server to shut down, no jurisdiction that covers the whole network. Mira Murati's open-weights release earlier this year pointed in the same direction. The pattern is consistent. Every attempt to lock capability behind a centralized chokepoint accelerates the market toward distribution.
Kratsios called the behavior "unacceptable" and Treasury Secretary Scott Bessent, speaking on Fox Business on July 21, 2026, stated: "If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft." That threat is real. Its practical effect on Kimi K3 is close to zero.
What Comes Next
The credible response to a demonstrated, working circumvention playbook is not tighter controls on the same chokepoints. The thesis breaks only if the U.S. government sanctions Moonshot in a way that materially degrades Kimi K3's global distribution and deployment, and no comparable open-weight model emerges from China within the next 12 months. Given that the weights are already out, that outcome is unlikely. Watch whether the administration moves toward positive-sum responses: investment in open-weight domestic models, distributed inference infrastructure, and compute that doesn't route through politically controlled nodes. That would be the durable play. Naming Moonshot on X is not.
Sources
Frequently Asked Questions
AI distillation is a standard technique: train a smaller, faster model to replicate the outputs of a larger one. Widely practiced and entirely lawful when done with models you have rights to. What Kratsios alleges is different: covert, industrial-scale extraction targeting a closed commercial model (Anthropic's Fable) through fraudulent account access and automated evasion of detection. That is a terms-of-service violation at minimum, and potentially an export-law violation depending on whether the model outputs are classified as controlled technology.
The GB300 is part of Nvidia's Blackwell generation, the current frontier for AI training throughput. The U.S. restricts Blackwell exports to Chinese entities entirely. China can legally import H200s under current Trump administration policy, and a further-restricted H20 chip exists for that market. Blackwell is the line Washington has drawn because the training performance gap between H200 and GB300 is large enough to matter at frontier scale.
Treasury has sanction authority and Bessent signaled it is on the table. Sanctions could restrict Moonshot's access to U.S. cloud infrastructure, payment systems, and partnerships. What sanctions cannot do is pull weights that are already public, remove mirrors already distributed globally, or prevent anyone from running inference on hardware outside U.S. jurisdiction. The capability is out. The sanctions debate is about deterrence for future behavior, not containment of the current model.



