Ban the thieves, not the technique: the AI fight turns on a legal distinction

The American debate over Chinese artificial intelligence has reached a fork in the road. One would punish Chinese AI labs caught stealing American trade secrets. The other would restrict the technique those labs use, a method called distillation that is also used by every serious AI company in the world, including the Americans. The two policies look similar from a distance. They are not.

A prominent argument for the first approach comes from Ryan Fedasiuk, a former State Department adviser now at the American Enterprise Institute, writing for War on the Rocks. His case, in short: Washington should stand ready to sanction Chinese AI labs that commit industrial-scale fraud, without outlawing distillation itself, because distillation is a standard industry practice, because banning it would not work, and because punishing it would hand American frontier labs an artificial moat at the expense of everyone else who builds AI.

The technique and the fraud

Distillation is how a smaller model learns from a stronger one: a developer trains a student model on the outputs of a teacher model, which is how many of the most popular AI products are built. Every major lab does it, including the American frontier labs, and there is no way to ban it without cutting off legitimate access to model outputs entirely. Anyone who can use a model, including a paying customer, can rearrange its outputs into training data. The technique is not enforceable out of existence.

What is enforceable is fraud. The distinction is between using a model you have lawful access to and obtaining access to a competitor’s product through deception to copy it. The hallmarks of fraud under trade secret law are recognizable: invented identities, infrastructure built to dodge detection, and the deliberate bypassing of security systems. Those elements carry legal liability under American statutes, from the Computer Fraud and Abuse Act to federal wire fraud law.

If you value careful, fact-driven reporting, consider supporting 1ban.news.

Help us grow

The evidence of fraud is specific. Anthropic counts more than 3.4 million conversations with its models as the work of Moonshot AI, routed through hundreds of fake accounts on a platform built for evasion. In testimony to the Senate Banking Committee in June, Anthropic identified Alibaba’s Qwen lab as the source of the largest distillation attack it had seen to date. DeepSeek, Moonshot, and MiniMax have all been accused by Anthropic of industrial-scale extraction through tens of thousands of fraudulent accounts.

Why the distinction matters

The distinction matters because the two policies lead to different outcomes. Sanctions on proven fraud would hit specific companies for specific conduct, leaving the legitimate open-model ecosystem alone. A ban on distillation would effectively freeze the competitive field around two or three American frontier labs, protect them from price competition, and try to enforce something that cannot be enforced. It would also, critics note, protect those labs from the consequences of their own pricing, which is a market problem, not a security one.

There is also a question of whether banning the technique would even slow China down. The argument that Chinese progress is mostly copied is weaker than it looks. DeepSeek’s January 2025 leap forward owed more to a fresh reinforcement learning design than to copying, and Moonshot’s recent focus on agent swarming appears to be a homegrown capability. Stopping distillation attacks would slow Chinese labs. It would not stop them.

The legal theory gets tricky

The law here is less settled than the rhetoric suggests. Raw model outputs cannot be copyrighted in the United States, because they lack human authorship, which makes the popular framing of this as intellectual property theft legally shaky. Trade secret law fits better: the secret is not any single response but the underlying model behavior encoded across millions of conversations, which is only extractable systematically at scale. Frontier models are not open to the public: access requires credentials, payment, rate limits, and acceptance of terms of service. That is a trade secret regime, not a copyright regime.

The asymmetry problem cuts both ways. Anthropic itself settled a suit over training on pirated books for $1.5 billion, the largest copyright payout in history. Fedasiuk’s point: Anthropic answered in an American court and wrote the check, and no court, American or otherwise, will ever make Moonshot pay for what it took. Sanctions are the closest thing to a forum that exists.

The politics of the moment point toward escalation. Treasury Secretary Scott Bessent has said Washington is finding watermarks of American large language models on many Chinese models, and has threatened sanctions against labs that built models on theft. The White House has accused Moonshot of building a platform to copy Anthropic’s leading model while evading detection. Nvidia’s Jensen Huang, meanwhile, urges American firms to make full use of Chinese models that beat US rivals on price, and investor Bill Gurley has argued that containing open models violates free-market principles.

The debate is not really about distillation. It is about whether the United States treats Chinese AI as a security threat to be contained or a competitor to be beaten in the open market. Banning the technique is the containment answer. Sanctioning the fraud is the competitive answer. The administration is being asked to choose, and the choice will define the AI relationship with China for years.

Source

Scroll to Top