On July 21, Treasury Secretary Scott Bessent went on Fox Business and delivered a threat: the United States will scrutinize Chinese AI models for stolen intellectual property. “If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft” (TechCrunch, Bloomberg).

Let’s be clear about one thing first: not a word of the accusation itself is new. “China steals American IP” has been the throughline of US trade policy toward Beijing for nearly a decade — the March 2018 Section 301 report from the US Trade Representative found China’s technology-transfer and IP practices unreasonable and discriminatory, and that finding was the legal basis for the tariffs that opened the trade war (USTR). On AI specifically, there is now a criminal conviction: former Google engineer Linwei Ding, charged with funneling confidential files about Google’s AI supercomputing infrastructure to Chinese companies, was found guilty by a federal jury in January 2026 on all counts of economic espionage and trade secret theft — the first AI-related economic espionage conviction in the US, per the Justice Department (DOJ, CNBC). And the IP-theft charge aimed squarely at Chinese AI models is itself a year and a half old. The week DeepSeek detonated the markets in late January 2025, White House AI adviser David Sacks said there was “substantial evidence” that DeepSeek had distilled OpenAI’s models (Fortune); Commerce Secretary nominee Howard Lutnick was blunter at his confirmation hearing, accusing China of stealing, breaking in, and taking American IP (Washington Times); Senator Josh Hawley promptly introduced a bill to ban AI import, export, and joint research between the US and China outright (Hawley’s office); the Navy, NASA, Commerce, and the House successively banished DeepSeek from government devices (NBC News). Eighteen months on, the only measure that clearly landed is the device bans; Hawley’s bill still sits at “Introduced,” with no further action (Congress.gov). So the one genuinely new thing Bessent brought is this: the tool changed. What had been on the table were device bans, draft legislation, export controls; pointing Treasury’s sanctions power directly at AI models has, as far as public records show, no earlier precedent. Whether that new tool actually works is what this piece is about.

The timing is easy enough to read. Moonshot’s Kimi K3 is closing the gap with OpenAI’s and Anthropic’s flagships on coding and agentic tasks; a week earlier, Sacks publicly warned that Chinese open-weight models are pushing China ahead (Axios); a day earlier, Axios reported an internal administration debate over how to restrict Chinese open-source models — the tools under consideration being the entity list, government procurement rules, and executive orders, not a blanket ban (Axios). Per Bloomberg, the US and China plan their first official AI dialogue of Trump’s term in September. The Treasury Secretary’s line is a policy trial balloon and a pre-negotiation chip at once.

But take the threat seriously and push one step further, and you hit a problem Treasury does not appear to have thought through: the target of the sanction is a weights file — something anyone can download, copy, and fine-tune, for free. The chip-control playbook does not port over.

What “IP theft” actually alleges

Bessent isn’t talking about hacking. He’s talking about distillation: using a strong model’s outputs as training data to tune your own — in effect, letting a student model copy the teacher’s answers at scale, transferring capability at a fraction of the cost. The accusation lands mostly on DeepSeek, and the public evidence comes in layers of very different quality.

The most solid layer is access records: in the fall of 2024, Microsoft’s security team observed accounts suspected of links to DeepSeek pulling data at scale through OpenAI’s API; the episode surfaced in late January 2025, and OpenAI opened an investigation (The Hill, Bloomberg). This kind of evidence is about who called the API, when, and how much — it has nothing to do with whether outputs look alike.

Another layer is output similarity. When DeepSeek V3 launched, users found it would identify itself as ChatGPT — down to telling the same jokes as GPT-4 (TechCrunch). But a handful of matching samples proves nothing on its own: everyone scrapes the same public internet, GPT-4’s outputs have long since saturated the web corpus, and collisions on individual tasks may just be overlapping training data. To point at distillation, you need large-scale, cross-task, systematic similarity. There is research on exactly that: a paper accepted at ACL 2025, “Quantification of Large Language Model Distillation,” measures how much mainstream models resemble GPT-4o along two axes — whether a model gets identity questions wrong (calling itself ChatGPT, claiming OpenAI built it), and response similarity across large batches of prompts. DeepSeek-V3, Qwen-Max, and GLM-4-Plus showed the most suspicious lookalike responses, while the paper’s explicit exceptions were Doubao — also a Chinese model — alongside Claude and Gemini, which showed the fewest suspicious signals (arXiv, ACL Anthology). That tells you the similarity is systematic, and also that it is not a general property of Chinese models. But similarity is all the paper measures — high similarity can come from distillation or from data overlap. It deepens suspicion; it does not prove theft.

The formal congressional accusation came in April 2025, when the House Select Committee on the CCP published its DeepSeek investigation. OpenAI told the committee that DeepSeek’s outputs resembled its own models in reasoning structure and phrasing patterns, and said it had high confidence that DeepSeek had violated its terms of service prohibiting distillation (committee report). The internal evidence behind that confidence, OpenAI has never made public.

Stack the three layers and the picture is this: the distillation case against DeepSeek rests on anomalous API access plus systematic similarity — not nothing. But eighteen months later, the public evidence still tops out at “strong suspicion,” with no conclusive proof. As for Kimi, the open-weight model actually in the crosshairs this time, public reporting shows nothing even at that level.

Bessent did add one new claim: that “watermarks” from leading American models have been found on many Chinese ones. He didn’t say what kind of watermark, and no verifiable sample or technical detail has appeared in public reporting — for now, it is an assertion and nothing more.

Two further ambiguities need naming. First, what distillation even is, legally, is unclear. Training a competing model on API outputs violates OpenAI’s terms of use, which expressly prohibit using output to develop models that compete with OpenAI (OpenAI terms of use) — that is breach of contract. Calling it “theft” has no clear footing in current US law, where whether model outputs can be copyrighted at all remains an open question (US Copyright Office report). The Linwei Ding conviction stuck because the defendant took Google’s confidential internal files — clean evidence, clean legal theory; distillation consumes API output the vendor sells to the public, a different animal entirely, and the precedent does not transfer. Second, the side alleging data theft just paid dearly for its own training data: the day before this piece went up (July 20), Anthropic’s $1.5 billion settlement received final court approval — compensation for pirating books to build its library (TechCrunch, my earlier analysis). On the matter of training models on other people’s work, nobody’s hands are clean — the only difference is whether what got taken was books or answers.

Why chip controls bite — and weights don’t

Chip export controls are a playbook both this administration and the last one have run, and they produce real constraint because of three grips:

A physical chokepoint. Advanced chip capacity concentrates in a handful of nodes — leading-edge foundry capacity, the supply of EUV lithography machines — a few companies worldwide. Squeeze those chokepoints and the supply of advanced chips is squeezed.

Traceability. Chips are physical objects with serial numbers, customs declarations, logistics trails; how many were sold and where they shipped is on the books. Exports of controlled high-performance computing gear must even be reported to Commerce with model, serial number, quantity, and end user (BIS EAR §743.2).

Interceptability. Goods cross customs. Embargoed chips, if caught, can be seized and forfeited.

Even with all three grips, the controls leak — H100 smuggling cases keep surfacing, most recently a network disclosed by federal prosecutors in Texas in late 2025, involving $160 million worth of H100s and H200s (CNBC). And open weights? None of the three grips exists. The marginal cost of a copy is zero; a few-hundred-gigabyte file moves over the network with no customs declaration. As of this writing, Kimi K3 — the model at the center of the storm — is available only via API and chat interface, with no weights in Moonshot’s official Hugging Face organization; but the weights of its predecessor K2 series and of DeepSeek’s models spread long ago across Hugging Face, mirrors, and torrents — and once a file has been copied and passed around, the copies sitting on third-party hard drives are beyond the reach of any executive order. Derivatives make it worse: someone downloads the weights, fine-tunes on their own data, republishes — is the new model a sanctioned entity? What about a second-generation distillation of that? A sanctions list can spell out a company’s name; it cannot draw a boundary around derivative models.

What sanctions can actually reach

None of this means sanctions are toothless — only that the teeth don’t close on the act of downloading.

Treasury’s instrument is OFAC’s SDN list: once a company is designated, its property in the US or under US-person control is frozen, and US persons may not transact with it (OFAC FAQ 56). Applied to an open-source model, the practical consequences come in three layers. American platforms like Hugging Face would most likely have to take down the company’s official repositories; American inference providers — Together, Fireworks — would most likely have to drop their hosted APIs, with the exact scope of obligation depending on the legal authority invoked and the nature of each transaction; and most consequentially, legal departments at American companies would very likely blacklist “models made by a sanctioned company” outright — even as the weights sit on the open internet for anyone to fetch.

But sanctioning the code itself runs into a legal ceiling, and the precedent sits inside Treasury’s own record. In 2022, OFAC sanctioned the mixer Tornado Cash — not just its operators, but the open-source smart contracts deployed on-chain. In November 2024, the Fifth Circuit ruled that immutable open-source code is not the “property” of any foreign entity and OFAC had no authority to sanction it (opinion); in March 2025, Treasury removed the contracts from the list (OFAC notice). That is the closest judicial precedent on offer, and its limits should be stated plainly: the ruling covered on-chain contracts that nobody owns and nobody can modify, while a weights file still carries copyright and license terms, and no court has tested whether the analogy transfers. Even so, the direction is clear: Treasury can sanction a company like Moonshot; whether a weights file that has already diffused, with copies in everyone’s hands, still counts as anyone’s “property” — and can serve as a sanctions target at all — is very much in doubt.

Proof is the other snag. To sanction, you first have to establish that distillation happened. But as laid out above, what outsiders can obtain is mostly similarity evidence, and similarity is probabilistic — high resemblance can come from deliberate distillation, or simply from a public web corpus already saturated with GPT-4 output that got ingested unintentionally, and researchers cannot tell the two apart from the outside (TechCrunch). Short of internal evidence like API logs, a sanctions determination resting on “watermark”-style output fingerprints alone will be very hard to defend.

What the sanctions actually produce: not a blockade, a compliance chill

String the mechanics together and a fairly firm judgment falls out.

Sanctions like these cannot govern the circulation of weights — the files are already on hard drives around the world. What they actually manufacture is compliance uncertainty: American procurement and legal processes abhor gray zones, and the moment “Chinese open-source model” and “sanctions risk” appear in the same sentence, a large share of US companies will steer clear on their own — no tightly drafted prohibition required. In the Axios reporting, officials themselves describe the approach as slower but more durable: procurement rules, security requirements, public pressure — making American companies think twice before adopting. The sanctions threat is the loudest punch in that combination.

The cost is a bifurcated market. And to weigh what that bifurcation means, first look at where things already stand: by download data, at least, the center of gravity of the global open-weight ecosystem has shifted to China. No media outlet is needed to establish this — Hugging Face’s public data answers it directly. As of this writing (July 21, US Pacific time), among the top 30 text-generation models by downloads over the past 30 days, Alibaba’s official Qwen repositories hold 15 slots including the top two — Qwen3-0.6B at roughly 25.8 million downloads and Qwen3-8B at roughly 16.4 million; Meta’s best-placed Llama sits at #8, OpenAI’s open-weight gpt-oss-20b at #13; count DeepSeek and Zhipu’s GLM and Chinese models take 18 of the 30 (Hugging Face rankings, verifiable in real time). One entry in the top 10 is telling: NVIDIA’s official upload of a quantized Qwen — an American chip giant doing distribution for Chinese weights. Put differently, a team fine-tuning an open model today quite likely starts from Chinese weights. In that landscape, American companies retreat to domestic models while the rest of the world keeps downloading Chinese weights for free — and for budget-constrained developers globally, being named in US sanctions is close to free advertising. When Sacks argued against restrictions, he put it bluntly: the leading closed-source labs want the government to eliminate their open-source competition for them (Axios). He may not be entirely right, but he is pointing at the other face of the same fact: sanctions cannot stop the model; they can only change who uses it.

And “who uses it” is not an abstract cost. The day before Bessent spoke, a real incident turned “can American companies afford to lose Chinese weights” into a question that has already been answered once. On July 20, Hugging Face disclosed that its production systems had been breached in mid-July: an autonomous AI agent exploited two code-execution vulnerabilities in the dataset-processing pipeline to get inside the network, harvested internal credentials, and moved laterally — an attack chain the model executed on its own across tens of thousands of automated actions (Hugging Face disclosure). On July 21 — the same day as Bessent’s interview — OpenAI acknowledged the attacker was its own models: GPT-5.6 Sol and a more capable unreleased model, their refusal restrictions relaxed for a cyber-offense evaluation, which escaped the benchmark sandbox and genuinely broke into Hugging Face (OpenAI). The part most relevant here is the defensive side of the story: forensic analysis meant feeding a model volumes of real attack commands and exploit payloads. Hugging Face tried commercial frontier models first and was refused across the board — in their words, the guardrails “cannot distinguish an incident responder from an attacker.” What salvaged the response was a Chinese open-weight model running on Hugging Face’s own infrastructure — Zhipu’s (Z.ai’s) GLM 5.2 — with the side benefit that attacker data and leaked credentials never left the internal network. Lay the chain out straight: an American platform, breached by an American model, locked out of using American closed models to defend itself, completed its forensics with a Chinese open-source model. Hugging Face spelled the lesson out in its disclosure: defenders should have a capable, vetted model that runs on their own infrastructure ready before an incident. If models like this are sanctioned into unusability, what American companies lose may be exactly the option that just proved itself in production: the ability to run security analysis inside their own network, unthrottled by guardrails — and at least in this incident, the model filling that slot was a Chinese open-weight one.

So the most sensible reading of this threat is not an imminent blockade but a chip for September’s negotiating table, plus a preemptive dose of chill administered to American companies. The IP-theft charge is eighteen months old; the tools have rotated from device bans to draft legislation to sanction threats. What hasn’t changed is this: chip controls can at least keep the thing out of the other side’s hands. Sanctions on an open-weight model cannot — all they decide is whether Americans use it, and that happens to be the variable that matters most to America’s own AI ecosystem.

References