Product1 publisher3 min readPublished
Garry Tan argues American open-weight labs should distill American frontier models
The Y Combinator CEO told CNBC he would do nothing about distillation and floated an American version of it, in the same week Anthropic's second report accused Chinese labs of using stolen credentials to do it.
The Product Desk · Product desk

What happened
- Anthropic released its second report this week alleging Chinese labs run "illicit distillation attacks," concealing identities to distill without permission and using fraud and stolen credentials.
- Anthropic CEO Dario Amodei had already publicly asked U.S. regulators to crack down on distillation.
- Tan is not asking American labs to use stolen credentials; he wants them free to distill through the front door, paying for the API calls under their own name.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision A team whose roadmap needs to train its own weights on another provider's outputs gets its permission from a contract it did not negotiate, because no rule exists on either side of this argument.
- contradiction The two most quoted voices on distillation want opposite things from regulators, so a buyer choosing between closed API access and open weights this quarter has no settled answer to plan against.
- capability Tan's version would give U.S. teams open-weight models trained on American frontier lineage. Most procurement teams currently lack that option when they want weights they can host.
- constraint The front-door condition narrows the proposal to labs prepared to distill openly and pay retail for the calls. That path is materially more expensive than the covert one Anthropic describes.
A team that fine-tunes a small model on the outputs of a paid frontier API is already distilling. TechCrunch describes the practice as extensively prompting another model to learn how it works and reasons, and reports that labs use it commonly and legitimately when training new models [4]. The argument this week is about who grants permission for it.
Garry Tan's answer is nobody. "I would do nothing," the Y Combinator CEO told CNBC. "We could argue that there should be an American distillation regime" [2]. He told TechCrunch that means smaller American open-weight labs running the same training techniques on American frontier labs, so the country has a set of open-weight options that are not Chinese [3]. On the government's role, he told TechCrunch that "access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service" [10].
The other side of this is a vendor report. Anthropic released its second report this week alleging that Chinese labs are running "illicit distillation attacks," concealing their identities to distill without permission and using fraud and stolen credentials [5]. Anthropic CEO Dario Amodei had already called publicly on U.S. regulators to crack down on distillation [6]. So the two loudest voices want opposite things from Washington on the same practice [14].
Tan's case has two parts. He wants American labs free to come in the front door [7]. He objects to labs dictating what customers do with what a model tells them [8], and he points out that the proprietary labs did not ask permission either when they ingested copyrighted material to train [9].
For the person shipping something on Monday, nothing in the contract changes. TechCrunch's account names no American open-weight lab that has agreed to distill a frontier model, and it contains no draft rule [15]. The pitch is a position in an argument. The practice is governed by whatever your provider's terms already say, and by whether that provider can tell your traffic apart from the traffic Anthropic is describing.
So sort by dependency. Two questions per model you call. First, does the roadmap require training your own weights on that model's outputs, or do you only need inference? Second, if the answer is yes, does the product still ship if that permission narrows? A team that answers yes and no is not making a philosophical bet on public goods; it has a single-supplier risk with a contract clause as the failure mode. A team that answers no to the first question is unaffected.
Tan's stated fear is concentration. "The nightmare scenario, the doomer scenario for AI is that there's just one company," he told CNBC. "It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there's one company that's monolithic. And that would be bad" [12]. He also told CNBC he wants the frontier labs to stay fundable: "We want that to be fundable, and be a great business model ongoing" [11].
What to watch
- Whether a named American open-weight lab publicly commits to distilling U.S. frontier models under its own identity.
- Whether frontier labs tighten API terms on training with model outputs, or begin suspending accounts for it.
- Whether any U.S. regulator responds to Amodei's call with an actual proposal.