Key takeaways
- Y Combinator CEO Garry Tan argues U.S. regulators should not restrict AI model distillation and should instead allow American open-weight labs to freely distill from frontier models.
- Anthropic this week released a second report alleging Chinese labs are conducting illicit distillation attacks with stolen credentials, contrasting with Tan's view that distillation should be permitted.
- Tan contends proprietary AI labs that trained on copyrighted material without permission should not be able to restrict how customers use their models through API calls.
- Tan's concern is that restricting distillation could entrench a monopoly where one company controls the most powerful AI, making a diverse ecosystem of competing models impossible.
Y Combinator Chief Executive Garry Tan is pushing back against industry calls to restrict how AI models can be copied, positioning himself against Anthropic and its push for regulatory intervention. In interviews this week with CNBC and TechCrunch, Tan argued that the U.S. government should take a hands-off approach to a training technique called distillation—and that American AI labs should actually embrace it as a way to build alternatives to proprietary models dominated by a few giants.
This stance puts Tan at direct odds with Anthropic, which released a second report this week alleging that Chinese laboratories are conducting “illicit distillation attacks,” using fraudulent credentials and stolen access to extract knowledge from proprietary models without permission. Anthropic CEO Dario Amodei previously made public calls for U.S. regulators to impose restrictions on the practice. Tan’s response: regulators should do nothing.
Understanding distillation and the Chinese challenge
What the technique actually involves
Distillation is the process of extracting knowledge from one AI model by extensively prompting another model in order to learn how it works and reasons. It is a standard and legitimate training technique already used across the AI industry—a method for researchers to transfer capabilities from larger models to smaller, more efficient ones. The practice itself is not inherently unauthorized or problematic.
Anthropic’s escalating warnings
Anthropic’s latest report details what it describes as “illicit distillation attacks” conducted by Chinese AI laboratories. According to the findings, these labs hide their identities to conduct distillation without permission, relying on fraud and stolen credentials to gain unauthorized access to proprietary models. This second report follows Amodei’s earlier public calls for U.S. regulators to crack down on the practice in response to these unauthorized attempts.
Tan’s contrarian position
As head of Y Combinator—Silicon Valley’s prominent startup accelerator—Tan has staked out a position that directly contradicts the regulatory path Anthropic is advocating. He not only opposes government intervention against distillation but suggests the opposite approach: American AI labs should establish what he terms an “American distillation regime.” When asked by CNBC what he would do about Chinese distillation, he replied simply: “I would do nothing.”

The argument for unrestricted distillation
Proprietary labs shouldn’t control downstream use
Tan’s case distinguishes between the illicit techniques Anthropic describes—stolen credentials, hidden identities—and legitimate distillation conducted transparently. His core argument is that proprietary AI labs should not have the power to dictate what customers and users do with information their models share through API calls. “Controlling what users and customers do with API calls to closed weight models feels constraining, and there’s a role government can play here,” he told TechCrunch. That role, in his view, is to establish that access to intelligence trained on broadly available public data should function as a form of public good, not as a restricted product locked behind proprietary terms of service.
The hypocrisy of training restrictions
Tan also draws attention to how proprietary AI labs built their own models. These companies vacuumed up as much human knowledge as possible during training—ingesting copyrighted material without permission from intellectual property holders. Given this history of unrestricted data consumption, Tan argues it is inconsistent for these same labs to impose restrictions on downstream use through distillation. The laboratories that incorporated public knowledge without seeking approval, he suggests, should not now claim the authority to prevent others from learning from the outputs they created.
Public goods versus proprietary control
Tan frames the issue as a question of what should count as a public good in AI. When companies train on data that was created and published by the broader public, the resulting intelligence should not, in his view, be treated as purely proprietary output. Open access to that intelligence should be treated similarly to how we treat access to other forms of human knowledge.
Building American open-weight alternatives
Creating a domestic ecosystem
Tan elaborated to TechCrunch that his vision for an “American distillation regime” means smaller, American open-weight AI labs should be free to use the same training techniques on American frontier labs that Chinese laboratories are already attempting. The goal is to establish a more robust set of domestically developed open-weight options rather than allowing the open-source AI space to be dominated by Chinese alternatives built through distillation.
Supporting both frontier and open labs
Tan acknowledged that proprietary frontier AI labs deserve continued support. “They are at the frontier and driving it forward. We want that to be fundable, and be a great business model ongoing,” he told CNBC. Yet he simultaneously advocates for open-weight models to provide people with “freedom and access.” His framing suggests that a healthy AI ecosystem requires both: labs that push the technical frontier and competing labs that can freely adapt and build on those advances.
The concentration of power risk
The nightmare scenario Tan fears
Underlying Tan’s position is a deeper concern about the concentration of AI power in too few hands. He described his worst-case scenario: one company accumulates all the structural advantages—the best access to capital, the most talented researchers, the most powerful models. “The nightmare scenario, the doomer scenario for AI is that there’s just one company,” he said. “It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there’s one company that’s monolithic. And that would be bad.” His argument treats restrictions on distillation as a mechanism that could strengthen that monopolistic outcome rather than prevent it.
The stakes of the regulatory choice
Tan’s intervention highlights a fundamental tension in the regulatory debate. If policymakers restrict distillation to shut down Chinese unauthorized extraction, they may simultaneously prevent American labs from building alternatives to the few proprietary models that dominate the market. Conversely, if American labs are given latitude to distill frontier models, the result could be a thriving ecosystem of open-weight competitors—or it could accelerate capabilities races that raise other safety concerns. Tan’s position stakes out a libertarian approach: regulators should ensure that models trained on public data produce outputs users are free to use, even when that use takes the form of distillation.
Frequently Asked Questions
What is AI model distillation?
Distillation is the process of extracting knowledge from one AI model by extensively prompting another model to learn how it works and reasons. It is a legitimate training technique used across the AI industry to transfer capabilities from larger models to smaller ones.
Why does Anthropic want distillation restricted?
Anthropic released a second report this week alleging that Chinese labs are conducting illicit distillation attacks using fraudulent identities and stolen credentials to extract knowledge from proprietary models without permission. CEO Dario Amodei has called for U.S. regulators to crack down on the practice.
Why does Garry Tan oppose restrictions on distillation?
Tan argues that proprietary labs should not control what customers do with API calls to their models, especially since these labs trained their own models on copyrighted material without permission. He believes American open-weight labs should be free to distill frontier models to build alternatives and prevent a single company from dominating AI.