Y Combinator CEO Garry Tan said U.S. regulators should not intervene to stop AI model distillation and instead consider an "American distillation regime" that lets smaller domestic open-weight labs train on outputs from American frontier models. In interviews with TechCrunch and CNBC this week, Tan argued that open-weight labs should be free to use legitimate API access to frontier systems, giving the United States a more robust set of open-weight options that are not Chinese.

Distillation is the practice of extensively prompting a more capable model to learn its reasoning patterns and then using those outputs to train a smaller model. Anthropic this week released a report alleging that seven Chinese laboratories — including Moonshot AI, DeepSeek, and MiniMax — conducted "illicit distillation attacks" using fake identities, stolen credentials, and proxy accounts. Anthropic CEO Dario Amodei has called on regulators to crack down on the practice. Tan disagrees with that approach, telling, "I would do nothing" about distillation and that regulators should focus on creating equilibrium between open-weight and frontier models.

Confirmed

  • Tan wants U.S. open-weight labs to distill American frontier models under legitimate API access, not stolen credentials.
  • He frames the issue as a balance: frontier labs need sustainable business models, while open-weight models should give developers freedom and choice.
  • Anthropic's latest report names seven Chinese labs allegedly engaged in unauthorized distillation via fraud and credential theft.
  • OpenAI believes DeepSeek's V3 and R1 architectures were distilled from GPT-4 and GPT-4o.
  • U.S. agencies (NSA, CISA, FBI) issued a joint cybersecurity advisory on distillation risks this week.

Unknown

  • Whether any U.S. open-weight lab has begun distilling frontier models under Tan's proposed framework.
  • How regulators would define "legitimate API access" versus unauthorized distillation in practice.
  • Whether frontier labs would voluntarily offer distillation-friendly terms of service or require legislative action.
  • Independent verification of Anthropic's claims about the seven Chinese labs.
  • What specific safety mitigations would apply to distilled open-weight models once weights are released.

Our take

Tan's position reframes distillation from a security threat into a competitive necessity: if Chinese labs are already distilling frontier models, U.S. open-weight labs need the same capability to keep pace. The tension he highlights is real — frontier labs trained on vast public and copyrighted data now seek to restrict what customers can do with model outputs. But the "American distillation regime" he envisions requires frontier labs to cooperate, and none have signaled willingness to open their APIs for that purpose. Until they do, the proposal remains a policy argument without a technical path.

Sources