The US Treasury Secretary said on Tuesday that Washington is already finding what he called the "watermarks" of American AI systems inside Chinese open-source models, and that sanctions are a real option if IP theft is confirmed. The statement moves this from a general trade argument into something more specific: a claim that there is traceable evidence.
To understand what that means, you need to know how this kind of copying works. The technique is called distillation. A company builds a weaker AI system by feeding it millions of questions and answers from a stronger, more expensive one. The new model learns to behave like the original without ever seeing its actual code. It is legal when done with permission. It becomes contested territory when done at scale without it.
The most serious documented case involves Anthropic, the company behind the Claude AI. In a letter to the US Senate Banking Committee last month, Anthropic alleged that operators connected to Alibaba ran nearly 29 million conversations with Claude through about 25,000 fake accounts over a 44-day window. The stated goal, according to Anthropic, was to copy Claude's advanced capabilities in coding and cybersecurity into a rival Chinese model. Alibaba denies the allegations.
That was not the first disclosure. In February, Anthropic named three other Chinese AI labs: DeepSeek, Moonshot AI, and MiniMax, with a combined total of over 16 million Claude interactions through fraudulent accounts. The scale has been growing with each new disclosure.
This week's sanction warning lands in the same week that Chinese startup Moonshot AI released a new model called Kimi K3. It is now the largest open-source AI model in the world by size, and in several independent tests it performs close to the top American systems, at a significantly lower price. Bank of America analysts noted that Moonshot achieved this despite having limited access to the most advanced chips, which suggests strong underlying research capability.
That is where the argument gets more complicated. The Hugging Face CEO said recently that distillation is a small factor in building good AI and that Chinese labs have genuinely strong research teams. Microsoft's CEO made a related point: it is inconsistent for AI labs to claim broad rights to train on public data while simultaneously treating the same technique as theft when others do it to them.
Washington is also aware that OpenAI and Anthropic have their own unresolved legal exposure. Anthropic recently agreed to pay authors 1.5 billion dollars to settle a lawsuit over books used to train its AI. OpenAI is still in litigation with the New York Times over a similar dispute. The moral authority the US government claims on IP is not without its complications.
The timing of Tuesday's statement is worth noting. On the same day Bessent made the sanction threat, Reuters reported that the US and China are planning formal government-to-government AI talks in September, to be led by Bessent himself. The talks grew out of the Trump-Xi summit in May. China's priority going into those talks includes questions about US restrictions on Chinese AI models. So Washington is threatening sanctions and scheduling negotiations simultaneously, with the same official at the table for both.
For businesses that use or are considering using AI tools, the practical takeaway is not about who is right in the IP dispute. It is about direction of travel. Access to certain Chinese AI models may become restricted for US-connected companies. Regulatory pressure on which AI tools companies can use is building on both sides, and the September talks will give a clearer picture of where rules are actually heading.