cnbc.com web signal

Bessent Threatens China Sanctions Over 'Watermarks' in AI Models

TL;DR

  • Treasury Secretary Scott Bessent told Fox Business the U.S. is finding watermarks of American large language models on many Chinese models.
  • Bessent said Washington can sanction overseas firms for AI 'theft' and will look at action 'in the coming days or weeks.'
  • Comments follow Anthropic's Senate letter alleging Alibaba ran 'the largest known distillation attack' with 25,000 fake accounts and 28.8 million interactions.

Treasury Secretary Scott Bessent went on Fox Business on Tuesday and said something that, if it turns into policy, will reshape how American companies use Chinese open-weight AI. CNBC reported his line straight: "We are finding watermarks of our U.S. large language models on many of the Chinese models, and that's unacceptable." He added the administration has the ability to sanction offenders and will be looking at it "in the coming days or weeks."

The technical hook is distillation, which Bessent himself defined on air as an AI training method where a smaller, weaker model is built using the outputs of a stronger one. That framing lines up with Anthropic's letter to the Senate Committee on Banking, Housing, and Urban Affairs last month, which alleged Alibaba ran "the largest known distillation attack" against Claude, roughly 28.8 million interactions between April 22 and June 5 using about 25,000 fraudulent accounts. Bessent added that Chinese operators have "hundreds of millions of hits against the large language models here in the U.S." trying to reconstruct their behavior.

Why this matters for anyone who is not a policymaker: the fastest-moving tier of Chinese open-weight models, including Moonshot's newly released Kimi K3, is now sitting inside a potential sanctions perimeter. Any U.S. team building on those weights, or reselling them through a hosted API, could end up on the wrong side of a Treasury designation with very little warning. Procurement and vendor lists are worth a look before, not after.

The honest caveat is what the reporting does not give you. There is no named legal authority, no list of specific Chinese firms in scope beyond the Alibaba allegation, and no description of how a watermark claim gets proven to a court's standard. Bessent also said he will represent the U.S. in AI talks with China in September, so "days or weeks" may end up being negotiating leverage rather than a fired shot. Either way, the direction is set. The open-weight arms race has just acquired a sanctions dimension, and the U.S. labs that have been quietly logging abuse now have a Treasury Secretary reading from their script.

Shared on Bluesky by 1 AI expert