Garry Tan, CEO of Y Combinator, believes that the United States may need to allow smaller AI labs to distill knowledge from advanced American models, with the aim of building a stronger set of open-weight models that do not depend on Chinese labs. This position comes at a time when Anthropic is accusing Chinese labs of carrying out illicit distillation attacks on advanced models.
In an interview with CNBC, Tan said he would not intervene through regulation in Chinese labs’ use of distillation techniques, but instead raised the possibility of creating an “American distillation system.” He explained to TechCrunch that this would mean allowing American labs developing open-weight models to use these techniques, with access to the targeted models obtained “through the front door” and under clear access conditions—not through impersonation, fraud, or the theft of credentials.
What Is Model Distillation?
Model distillation is the process of training a new model by leveraging the outputs of another model, often by sending it a large number of prompts and analyzing its answers and reasoning process. AI labs use this technique legitimately in some training and model-improvement scenarios, but the boundaries of its use become contentious when the targeted model is accessed without authorization or when the identity of the party using it is concealed.
According to the article, Anthropic released its second report this week accusing Chinese labs of carrying out “illicit distillation attacks.” The company says those operations involved concealing identities and relying on fraud and stolen credentials to access the models. Dario Amodei, Anthropic’s CEO, had publicly called on U.S. regulators to take stricter action against this type of distillation.
Why Is Tan Taking a Different Position?
Tan’s argument is not limited to competition between the United States and China. He believes AI labs should not have broad authority to control what customers do with information they obtain through application programming interfaces. In his view, imposing severe restrictions on the use of closed-model outputs could limit researchers’ and developers’ ability to build open alternatives.
Tan also connects this position to the history of training commercial models themselves. He points out that closed-model labs collected vast amounts of widely available human knowledge to train their systems, including copyrighted material, without always obtaining permission from intellectual property rights holders. From this perspective, he argues that access to intelligence trained on extensive public data should be closer to a public benefit, rather than being governed entirely by terms of service imposed by private companies.
What Changes in Practice?
If this idea became policy, the battle would concern access conditions, usage limits, and proof that the targeted model had consented, rather than legalizing any type of model copying. The distinction Tan draws between authorized distillation and distillation based on credential theft is important: he is not defending the operations Anthropic attributes to Chinese labs, but advocating for giving smaller American labs a legal opportunity to use the outputs of advanced models.
For open-weight model developers, this approach could reduce the resource gap between them and labs that possess the capital, researchers, and infrastructure needed to develop Frontier models from scratch. Advanced commercial labs, however, may view it as a threat to the value of their closed models and to their ability to control the use of their interfaces and outputs.
Opinion Versus Facts
Tan presents his position as a way to preserve pluralism in the AI market. He warns of a scenario in which a single company, possessing the best access to capital and the best researchers, becomes the owner of the most powerful model and the sole gateway to advanced capabilities. He believes that open-weight models give users greater freedom and access, while advanced labs ensure continued investment in developing new capabilities.
However, the article provides no evidence of a U.S. regulatory agreement on an “American distillation system” of this kind, nor does it resolve questions concerning intellectual property rights, contractual terms, or how authorized use would be verified. Tan’s proposal therefore remains a political and intellectual position in a debate where economic security intersects with corporate rights, researchers’ interests, and the risks of model misuse—not an announcement of an effective policy.