The threat arrived on television, not in a filing
Scott Bessent, the US Treasury Secretary, made the remark on Fox Business on Tuesday 21 July 2026. He began with the competitive framing, saying there had been a lot of talk about open source models coming and threatening the large language models in the United States, and then he attached an instrument to it. If Washington sees that overseas models are stealing from American companies, he said, it has the ability to sanction them because of that theft.
The alleged theft is distillation, a training method in which a smaller or less capable model is built using the outputs of a stronger existing one. Bessent said watermarks belonging to US large language models had been found on many Chinese models, and called that unacceptable. He named no specific enforcement tool, no target list and no date. What he named was a capability, and capabilities stated by a Treasury Secretary on the record are how sanctions programmes usually begin.
Sanctions instruments were built for companies, and a model is a file
The model in question is not hypothetical. Moonshot AI released Kimi K3 on 16 July 2026, describing it as natively multimodal, with 2.8 trillion parameters and a one-million-token context window, built for long-horizon coding, knowledge work and deep reasoning. It performs close enough to the leading American systems that it has become the reference point in this argument, and its capacity has been constrained by demand rather than by quality.
This is where the instrument and the target do not fit each other. Sanctions regimes act on entities, transactions and shipments. They freeze assets, they bar dealings, they add names to lists. None of that reaches a set of open weights that has already been copied onto a European company's own hardware. There is no shipment to stop and no transaction to block, because the transfer already happened and it was free. Deletion is not one of the powers involved.
The enforcement surface is your supplier list
That mismatch is the part worth acting on, and it points somewhere most coverage has not looked. If an action lands, it will not be enforced against the file. It will be enforced against the companies that are legally obliged to comply with US sanctions, and for a European operator that is a long and mostly invisible list: the hyperscaler running your inference, the model-serving provider you rent GPUs from, the continuous-integration platform that builds your images, the observability vendor reading your traces, and in several cases the insurer underwriting the whole arrangement. Most of these are US-headquartered, and their European subsidiaries follow the parent.
The asymmetry that creates is uncomfortable. You keep the weights and lose the ability to run them in production. Your legal exposure does not come from possessing the model; it comes from the compliance clauses already written into your supplier agreements, which typically allow a vendor to suspend service on short notice when a sanctions determination touches a workload. Those clauses fire on the vendor's timetable. A European manufacturer that has spent six months fine-tuning an open-weight model into its support workflow would discover the dependency at the moment the service stops, which is the worst moment to discover it.
Brussels does not get a vote on this one
European law governs how AI is placed on the European market and what obligations attach to providers and deployers. It does not govern whether a company incorporated in Delaware may continue to process a sanctioned workload for a customer in Lyon or Bologna. That determination is made in Washington and travels through corporate structure rather than through territory, which is why a European operator can be fully compliant with European rules and still lose the service.
The direction of travel is not a surprise either. The Commerce Department circulated draft rules last year aimed at Chinese open-source models, using its authorities over domestic supply chains, and those efforts were killed inside the administration by officials who did not want regulation to slow domestic innovation. Commerce also weighed adding Chinese AI labs, DeepSeek among them, to its Entity List. Reporting this week describes the current approach as slower and more persistent than an outright ban: procurement rules, a revived Entity List threat, and public pressure. Slower and more persistent is harder to plan around than a ban, because it never produces a single date.
What to check before an action lands
Start with an inventory, because most organisations do not have one. Establish which models are actually in production, which of them are Chinese in origin, and where each one is served from. Open weights spread through teams quietly, arriving inside a framework default or a colleague's pull request, so the honest answer is often that nobody knows. Until that list exists, no risk assessment about this is worth anything.
Then read the contracts rather than the headlines. Find the sanctions and export-control clauses in every agreement that touches model serving, and establish what notice period each vendor owes you before suspending. Where the notice is short and the workload matters, the mitigation is a second serving path that does not share the first one's jurisdiction, which for European operators usually means a European or self-hosted route kept warm rather than theoretical. The cost of maintaining that path is a known number in euros. The cost of not having it is a support function going dark on a vendor's schedule.
Read next: Independent Tests Rank Kimi K3 Above Fable 5 | Moonshot's Biggest Model Has No Thinking Dial



