Political risk / Jul 21, 2026 / 4 min
Treasury Just Turned Watermarks Into a Weapon
On July 21, Treasury Secretary Scott Bessent threatened sanctions against Chinese AI labs if U.S. officials confirm American model watermarks inside their weights — escalating Washington's Kimi K3 panic from procurement FUD into a Treasury enforcement track days before Moonshot's July 27 open-weight drop.
Treasury Secretary Scott Bessent just gave Washington a faster weapon than banning open weights: sanctions. On July 21, he told Fox Business the administration is finding U.S. large language model watermarks inside Chinese AI systems — and will deploy Treasury's sanctioning power if it confirms intellectual property theft through distillation.
What Bessent said:
- "We've seen a lot of talk about open source models coming and threatening the large language models in the US," Bessent said on Fox Business. "This administration supports open source models, but what we do not support is IP theft."
- "If we see, especially, that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft."
- "We are finding watermarks of our U.S. large language models on many of the Chinese models, and that's unacceptable," he added. "We're going to be looking at that in the coming days or weeks."
- Bloomberg first reported the remarks; CNBC and TechCrunch confirmed them Tuesday morning.
Why this is different from yesterday's ban talk:
- Axios reported July 20 that Commerce, the NSA, and the White House are weighing procurement walls, Entity List designations, and liability rules to chill Chinese open-weight adoption — a slow-motion pressure campaign, not a statute.
- Bessent's threat routes through Treasury's sanctions toolkit — the same lever used on chips, banks, and energy — and ties enforcement to forensic evidence inside model weights.
- That matters because open weights cannot be recalled once published. Kimi K3's full drop is scheduled for July 27.
The evidence file:
- On June 10, Anthropic told the Senate Banking Committee that operators affiliated with Alibaba and its Qwen lab ran roughly 25,000 fraudulent accounts through Claude between April 22 and June 5 — generating 28.8 million exchanges in what Anthropic called "the largest known distillation attack on Anthropic to date."
- Anthropic said the campaign targeted agentic reasoning and software engineering — Claude's most commercially valuable skills — and continued after the White House Office of Science and Technology Policy warned against industrial-scale distillation in April.
- Alibaba has not publicly responded. No court has verified Anthropic's claims.
- In February, Anthropic also accused DeepSeek, Moonshot AI, and MiniMax of industrial-scale distillation campaigns totaling more than 16 million exchanges through about 24,000 fake accounts.
The irony nobody in D.C. wants to say aloud:
- Microsoft CEO Satya Nadella wrote in July: "While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation."
- Hugging Face CEO Clem Delangue told TechCrunch this week: "We know distillation to be a very small factor in the ability to create good models, and it's a practice that everyone is doing, including companies in the U.S."
- On July 20, a federal judge gave final approval to Anthropic's $1.5 billion copyright settlement — after ruling training on books is fair use, but before a jury could rule on seven million pirated downloads.
- Washington is now threatening to sanction foreign labs for a training technique U.S. labs both practice and litigate over.
What's on the calendar:
- CNBC reported the U.S. and China expect AI-related talks in September — the same window Bessent gave for completing the watermark review.
- Congress is not waiting: Sens. Bill Hagerty (R-TN) and Andy Kim (D-NJ) are drafting an NDAA amendment to blacklist Chinese firms found harvesting U.S. model outputs at scale; H.R. 8283 would create a public sanctions list for AI extraction actors.
- Moonshot is separately racing toward a reported $30 billion Hong Kong IPO — the same company whose K3 launch erased more than $3 trillion in global chip market value last week.
What enterprises should price in:
- Sanctions risk attaches to vendors, not just downloads. Any U.S. firm routing production traffic through a sanctioned Chinese lab faces the same compliance exposure as a bank clearing a blocked transaction.
- Watermark claims — even unproven in court — are enough for procurement teams to freeze pilots while legal reviews the vendor stack.
- The cheaper the model, the higher the geopolitical discount rate just became.
Convina's view: Bessent did not need a ban Congress cannot pass or a court cannot enforce. He needed fingerprints and a Treasury pen. Whether the watermarks prove theft or merely shared training patterns, the threat alone re-prices Chinese open weights from a margin hack into a sanctions-adjacent bet — and exposes the frontier labs cheering Washington on as companies that want distillation outlawed for rivals after arguing fair use for themselves. Enterprises should assume Treasury's review outruns Kimi K3's July 27 ZIP file.