GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
← Back to feed

Garry Tan Wants an American Distillation Regime — While Anthropic Calls Chinese Attacks 'Illicit'

Y Combinator CEO Garry Tan told CNBC this week that when it comes to Chinese AI labs distilling knowledge from US frontier models, his policy position is simple: do nothing. His preferred alternative is not enforcement — it is an American counter-programme.

“We could argue that there should be an American distillation regime,” he told CNBC. He subsequently elaborated to TechCrunch that the goal is a more robust US open-weight stack that does not depend on Chinese-built models. The argument is that US open-weight labs should be free to use distillation on American frontier models, giving the country a more robust stack of open-weight options that are not Chinese-built.

The Context

Anthropic’s second threat intelligence report of September 2026 describes Chinese labs conducting what it calls “illicit distillation attacks” — systematically prompting Claude at scale using stolen credentials and fraudulent accounts to extract training signal. Anthropic CEO Dario Amodei has separately called on US regulators to crack down on distillation as a form of IP theft.

Tan’s position cuts directly against Amodei’s. He does not dispute that Chinese labs are doing this. He disputes whether stopping them is the right goal — and whether AI labs have standing to demand it.

His reasoning: the proprietary labs themselves ingested copyrighted human work without permission to train their frontier models. They have since faced significant litigation over this. Anthropic settled for $1.5B in a landmark copyright case. The moral authority to police what others extract from their outputs is, in Tan’s framing, compromised.

What Tan Is Actually Proposing

He is not advocating for stolen-credential attacks. He is arguing that legitimate distillation — openly prompting a model, using its outputs to train another, paying for the access — should remain legal and be actively encouraged for American labs. The distinction is fraud versus inference.

His secondary point is about market structure. Amodei’s “pace the frontier” framing and the push to restrict distillation both, in effect, protect the position of the two biggest closed-API labs. A world where distillation is banned is a world where Anthropic and OpenAI face less open-weight competition.

The Policy Split

The US government currently has no settled position on distillation. David Sacks, Chair of the President’s Council of Advisors on Science and Technology, has separately argued that frontier labs do not need regulatory authority to pace their own releases — they can choose not to ship without asking Congress for permission.

The rough coalition forming is: Anthropic and OpenAI want regulatory tools to control distillation and slow development of dangerous capabilities. Tan, Sacks, and a significant part of Silicon Valley want the market — and open-weight competition — to remain unrestricted.

The September Anthropic threat report frames distillation attacks as a national security issue. Tan frames the response to those attacks as a national competitiveness issue. Both positions invoke the same threat. They reach opposite conclusions.