Leadership2 publishers3 min readPublished
Garry Tan points regulators away from distillation days after agencies named six Chinese labs
Y Combinator's chief said he would do nothing about model distillation, two days after the NSA, FBI and CISA accused six Chinese firms of doing it at scale. Every defence the agencies recommend is the providers' own work.
The Board Room · Leadership desk

What happened
- Y Combinator CEO Garry Tan said he would do nothing about AI model distillation, and told CNBC that regulators should work instead on an equilibrium between open-weight and frontier models.
- A Sept. 8 joint advisory from the NSA, FBI and CISA named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging industrial-scale distillation of American models since at least late 2024.
- Anthropic said in a Sept. 10 threat report that it had detected attacks from seven China-based labs, attributing more than 23 million exchanges to Moonshot and more than 12.1 million over 14 days in July to DeepSeek.
- The agencies called distillation "the core, not merely a supplement" of the named companies' development, and said DeepSeek's cited $5.6 million training cost excluded data allegedly acquired that way.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction The ask and the exemption pull against each other. Cheaper distilled models are one route by which a frontier price premium erodes, and the American distillation regime Tan floated has no stated administrator or scope.
- constraint The remedies on offer all run through the provider's own stack, so a lab that wants distillation stopped funds the detection itself and absorbs the cost of degrading service to accounts it has misjudged.
- exposure If safeguards do not survive distillation, as Anthropic says, a buyer picking a distilled model inherits capability without the refusal behaviour the original vendor tested.
- precedent With the federal response so far limited to advice, the escalation with a constituency behind it is the chip-import action advocacy groups have asked the White House for.
Distillation is used to reduce the time and money needed to create a new model [20]. Tan's ask of regulators is that frontier models keep a price premium large enough to leave the frontier business model feasible [3]. The practice he would leave alone is the one that narrows the distance between a cheap model and an expensive one. On the open-weight balance he said, "This is actually the ideal case. You want open weight models to give people freedom and access" [4], and added, "If I were a regulator, that's what I would go after" [5]. He floated a middle position, saying "We could argue that there should be an American distillation regime" [7]. He did not say what it would permit or who would administer it [7].
He was speaking at YC's annual Demo Day, where 149 of the 196 startups presenting were classified as machine-learning and AI ventures [30], about three quarters of the batch [1].
Anthropic said Alibaba-linked operators generated more than 151 million exchanges from May through July 2026 through more than 3,500 fraudulent accounts, peaking at nearly 3 million a day [22]. Spread across those accounts and the 92 days in that window, the average account ran about 470 exchanges a day [2]. That is not a conspicuous number for one account. The advisory says the operators "deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection" [17], routing through native APIs, cloud providers and third-party aggregators that obfuscate user metadata [16]. Detection depends on aggregating across accounts and across companies. The third of the agencies' three recommendations to US developers is exactly that: cross-organization intelligence sharing [15].
The other two cost the provider something. The agencies suggest subtly altering answers, or quietly moving a suspected distiller to a less capable model without notifying them [14]. Both work by degrading service to an account the provider has classified, and a misclassification is paid by a paying customer who never learns the model got worse. Neither agency account reports a fine, a licence condition or a new restriction; advocacy groups have separately asked the White House to act on Chinese imports of advanced semiconductor chips [32].
Tan raised the copyright objection, the one critics have used against Anthropic's and OpenAI's distillation complaints: much of the data used to train those models may itself be covered by copyright [28]. That record is real. The New York Times sued OpenAI and Microsoft over its articles in 2023, and book authors settled a related case with Anthropic in 2025 [29]. Anthropic's stated concern is a different one. "The robust safeguards that prevent Claude from being misused by bad actors do not transfer when our models are distilled by an unauthorized lab," the company said [25]. It also said its research showed a distilled model can help achieve dangerous capabilities, including biological and cyber ones, even when the collected exchanges contain little material on those subjects [26]. The exchange counts are Anthropic's own findings, while the company-level attributions in the advisory belong to the agencies [27].
The accusations did not start this week. Michael Kratsios, who directs the White House Office of Science and Technology, said in July that Moonshot AI's distillation efforts sought to steal proprietary functions from Anthropic's Fable model, and Anthropic made the same accusations in February [31]. Seven months of that [3] have produced an advisory whose remedies are engineering tasks inside the providers [15]. For this quarter it sets a budget line: whoever sells access to a capable model pays for the rate limits and the account forensics, and carries the false positives.
What to watch
- Whether any enforcement action, fine or licence condition follows the Sept. 8 advisory, which so far carries recommendations to developers only.
- Whether Tan or YC puts detail on an "American distillation regime": what it would permit, and which body would administer it.
- Whether OpenAI, Google or others publish exchange counts of their own, since the volume evidence currently rests on Anthropic's telemetry plus the agencies' attributions.