Garry Tan told CNBC on Thursday 10 September 2026 that he would “do nothing” about Chinese labs distilling American frontier models, and told TechCrunch the following day that smaller American open-weight labs should be free to do the same thing to American frontier labs. The Y Combinator chief executive called this “an American distillation regime”. He said it two days after three US agencies published an advisory naming six Chinese companies, and in the same week Anthropic published its second report on what it calls illicit distillation.
We read both interviews, the terms of service of OpenAI, Anthropic and Google, the July open-weights letter that Y Combinator signed, Dario Amodei’s July response to it, Anthropic’s February and September reports, the CISA advisory, Elon Musk’s April testimony, Hugging Face’s August state-of-open-models report and OpenRouter’s June roundup. We wanted to know whether the door Garry Tan wants opened exists, who has already walked through it, and what the people he disagrees with have actually asked for.
Three things stood out. The “front door” already exists in Anthropic’s usage policy, as “prior authorization”, but none of Anthropic’s 531 sitemap pages explains how to obtain it. Y Combinator signed a letter 48 days before Demo Day making the same argument, which Amodei answered in its own words. And the regime Garry Tan describes already runs both ways: a US open-weight model was built with a Chinese one, and xAI has admitted in court to distilling OpenAI. The machine learning startups he presented are the customers in the middle. Our reports cover Anthropic’s distillation campaigns and the AI distillation advisory.
Table of contents
- What Garry Tan Actually Said, and Where
- The Front Door Garry Tan Wants Is Already Written Into the Terms
- Y Combinator Signed the Letter That Makes the Same Argument
- The American Distillation Regime Already Runs, in Both Directions
- What the Accusers Have Counted Since February
- Garry Tan’s Tightrope: The Price Premium Condition
- Who the Smaller American Open-Weight Labs Are
- Three Nightmares: Garry Tan, Dario Amodei and the Letter
- What an American Distillation Regime Would Have to Decide
- Frequently Asked Questions About Garry Tan and Distillation
- References
What Garry Tan Actually Said, and Where
The remarks come from two outlets and one event. CNBC’s Kate Rooney interviewed Garry Tan at Y Combinator’s Summer 2026 Demo Day, which YC’s own calendar placed on Thursday 10 September. CNBC posted a 22-minute-35-second video that afternoon, and Rooney and Isabel O’Brien published the written story at 01:37 UTC on 11 September, which is Thursday evening in California. TechCrunch’s Julie Bort published her story at 20:59 UTC on 11 September, adding quotes from her own follow-up.
The two accounts side by side
| Item | CNBC | TechCrunch |
|---|---|---|
| Bylines | Kate Rooney, Isabel O’Brien | Julie Bort |
| Published | 11 Sep, 01:37 UTC | 11 Sep, 20:59 UTC (revised 22:44) |
| Setting | Demo Day interview, 10 Sep | CNBC quotes plus written follow-up |
| Body length | About 560 words | About 500 words |
| Headline claim | “Do nothing” about distillation | US open-weight labs should distill too |
| Condition attached | Frontier models keep “a price premium” | Labs “come in the front door”, no stolen credentials |
| Nightmare named | Not stated | “There’s just one company” |
| Batch figure | 149 of 196 startups are ML or AI | Not stated |
The quotes, in the order they were given
To CNBC, Garry Tan said: “I would do nothing” about distillation, then “We could argue that there should be an American distillation regime.” On open weights he said: “This is actually the ideal case. You want open weight models to give people freedom and access. If I were a regulator, that’s what I would go after.” He called the balance between open and frontier models “a tightrope” that “could result in the best possible outcome.”
To TechCrunch he explained the regime: “Controlling what users and customers do with API calls to closed weight models feels constraining, and there’s a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service.” Bort adds that Garry Tan is not asking American labs to use stolen credentials, and wants them “free to come in the front door”.
The sentence CNBC has that TechCrunch does not
CNBC records a condition. Garry Tan wants an equilibrium between open-weight and frontier models “as long as frontier models retain a price premium that allows their business model to remain feasible.” He told TechCrunch the same thing in different words: “They are at the frontier and driving it forward. We want that to be fundable, and be a great business model ongoing.” No number is attached to the premium in either account, and we return to that gap later.
CNBC also gives the batch composition. Of the 196 startups presenting at Demo Day, 149 were categorised as machine learning and artificial intelligence ventures. That is 76.0 percent, so three in four of the companies Garry Tan was on stage to present are customers of the frontier labs whose terms he wants loosened.
The Front Door Garry Tan Wants Is Already Written Into the Terms
The complaint is about “restrictive terms of service”, so we read them. Every frontier lab we checked prohibits using its outputs to build competing AI models, and two of Anthropic’s three documents describe an exception. The exception is the front door. What is missing is any description of how a lab would walk through it.
The clauses, verbatim, with their effective dates
| Document | Effective | What it says |
|---|---|---|
| OpenAI Terms of Use | 1 Jan 2026 | You may not “use Output to develop models that compete with OpenAI” |
| Anthropic Commercial Terms, D.4 | 17 Jun 2025 | No access “to build a competing product or service, including to train competing AI models … except as expressly approved by Anthropic” |
| Anthropic Consumer Terms | 8 Oct 2025 | Not “to develop any products or services that compete with our Services, including to develop or train any artificial intelligence or machine learning algorithms or models” |
| Anthropic Usage Policy | 15 Sep 2025 | No “utilization of inputs and outputs to train an AI model (e.g., ‘model scraping’ or ‘model distillation’) without prior authorization from Anthropic” |
| Google Gemini API Additional Terms | 23 Mar 2026 (updated 28 Apr) | “You may not use the Services to develop models that compete with the Services (e.g., Gemini API or Google AI Studio)” |
| xAI consumer terms | 1 Sep 2026 | Every sentence containing “train” is about xAI’s own use of user content; we found no clause restricting training on Grok output |
Anthropic describes the door Garry Tan wants but publishes no path to it
“Except as expressly approved by Anthropic” and “without prior authorization from Anthropic” are two phrasings of the same idea: distillation is permitted if Anthropic says yes. That is precisely what Garry Tan says he wants, a legitimate route rather than stolen credentials. So we looked for the route. Anthropic’s sitemap lists 531 URLs. One of them contains the word “distill”, and it is the February post accusing three labs. The help centre’s search for “distillation” returns general onboarding articles.
There is no page that says who may apply, what it costs, or what safeguards an approved student model must carry. The exception exists on paper and nowhere else that we could find. That is a narrower complaint than “restrictive terms of service”, but it is a checkable one, and it is the one Garry Tan could have made.
OpenAI’s front door opens inward only
OpenAI does sell distillation. Its Model Distillation product, launched on 1 October 2024, lets developers “use the outputs of frontier models like o1-preview and GPT-4o to fine-tune and improve the performance of more cost-efficient models like GPT-4o mini”, with Stored Completions and Evals to run the whole pipeline “all on the OpenAI platform”. The teacher is OpenAI’s and so is the student.
That is the technique Garry Tan wants normalised, packaged as a product, with one condition: the student never leaves the building. An open-weight lab cannot use it, because the point of open weights is that the student does leave.
Y Combinator Signed the Letter That Makes the Same Argument
Garry Tan’s Demo Day answer was not improvised. On 24 July 2026 a group of companies published “Open Weights and American AI Leadership”, a letter to policymakers. The PDF hosted on Nvidia’s site, generated on 30 July, lists 235 signatories. Y Combinator is one of them, alphabetically between xpander.ai and Zendesk. OpenAI, Google, Meta, Microsoft, Nvidia, Hugging Face and Andreessen Horowitz are on it. Anthropic, xAI and Thinking Machines Lab are not.
What the letter says about distillation
The letter’s distillation paragraph reads: “Policymakers should be careful not to conflate legitimate model-development techniques with misappropriation. Distillation, or the practice of using one model’s outputs to help train or improve another, is a widely used technique for model improvement, evaluation, and validation.” It continues: “By contrast, unlawful efforts to extract value from closed models raise legitimate concerns. Those concerns should be addressed through targeted legal and commercial frameworks rather than sweeping restrictions.”
The letter never mentions China. It does not mention terms of service either. Its remedy for concentration is a “plural” frontier, and its warning is that closed models create “a small number of single points of failure”. Read in that light, what Garry Tan said on 10 September is the letter’s paragraph delivered in the first person, 48 days later, with one addition the letter does not make: that the government should push the frontier labs’ terms open.
Three positions, one table
| Question | The letter (24 Jul) | Dario Amodei (27 Jul) | Garry Tan (10 to 11 Sep) |
|---|---|---|---|
| Is distillation legitimate? | “Widely used”, “a long tradition” | Yes; the problem is “industrial-scale distillation operations” | Yes; labs should be free to do it |
| What is the problem? | “Unlawful efforts to extract value from closed models” | Operations “backed by an authoritarian state” | “Restrictive terms of service” |
| Remedy | “Targeted legal and commercial frameworks” | The same phrase, verbatim, plus chip controls and mandatory testing | “Do nothing”; government should “normalize” access |
| Public good | Not used | Open-weights models without dangerous capabilities | Access to intelligence trained on public data |
| Mentions China | 0 times | Repeatedly; the CCP is “the most capable threat” | Only as the source of the models to be matched |
| Nightmare | “Single points of failure” behind few closed models | Authoritarian states with stronger models; cyber and bio misuse | “There’s just one company” |
The phrase both sides share
Amodei’s 27 July post, headed “Our position on open-weights models”, says: “Concerns about distillation should be addressed through targeted legal and commercial frameworks, the same measure I described above.” That is the letter’s sentence, quoted back at it. Amodei also wrote that “Open-weights models that don’t have dangerous capabilities are a public good” and that “Anthropic has never advocated for a ban on open-weights models.”
So the disagreement is smaller than the headlines suggest. The letter, Amodei and Garry Tan all call distillation legitimate. The letter and Amodei both want targeted frameworks. Where Garry Tan departs from both is in naming the frontier labs’ contracts, rather than Chinese state backing or unlawful extraction, as the thing to fix. Amodei’s post was published 45 days before the Demo Day interview, and TechCrunch notes that “Anthropic CEO Dario Amodei had previously publicly called on U.S. regulators to crack down on distillation.” That call is the sentence “We should have policy interventions to deter this behavior.”
The American Distillation Regime Already Runs, in Both Directions
Garry Tan presented distillation by American labs as something the government should make possible. The record shows it happening already, sometimes through the front door, sometimes not, and in one direction he did not mention.
Five cases on the record
| Case | Teacher and student | What the record says |
|---|---|---|
| Stanford Alpaca, 13 Mar 2023 | OpenAI text-davinci-003 into LLaMA 7B | 52,000 demonstrations for under $500 of API spend, under $600 all in; Stanford wrote that OpenAI’s terms “prohibit developing models that compete with OpenAI” and barred commercial use |
| xAI Grok, testimony 30 Apr 2026 | Models from OpenAI into Grok | Asked in federal court whether xAI distilled models from OpenAI, Elon Musk answered “Partly” and called it a general practice |
| Thinking Machines Inkling, 15 Jul 2026 | Moonshot Kimi 2.5 into a US open-weight model | Replit’s Amjad Masad told TechCrunch it “was trained with the help of Moonshot’s Kimi 2.5”; Hugging Face says some US releases above 100B “are built on top of Chinese models” |
| OpenAI Model Distillation, 1 Oct 2024 | GPT-4o or o1-preview into GPT-4o mini | A paid product; both models stay on OpenAI’s platform |
| Seven China-based labs, Anthropic Sep 2026 | Claude into their models | “Typically enabled by fraud: sophisticated networks of fake accounts created with stolen credit cards, login credentials, and API keys” |
The direction Garry Tan did not mention
Inkling matters because it is the mirror image of the regime Garry Tan proposed. Thinking Machines Lab, a US company, released an open-weight model that TechCrunch put at 975 billion total parameters and Hugging Face’s August report put at 952 billion. Both agree it drew on a Chinese open model. That is legal by construction, because Chinese labs release under permissive licences. OpenRouter notes that DeepSeek V4 Flash, the open model it rates first for agentic work, is MIT-licensed.
Arcee’s chief technology officer Lucas Atkins told TechCrunch in July that his lab “benefits from those models being good because we can learn what they did. We can build on top of them.” The American labs Garry Tan wants to protect are already distilling. They are distilling Chinese weights, because those come with permission, and not Claude or GPT, because those do not. An American distillation regime, on his definition, would add the second source to the first.
Two chief executives who said it before Garry Tan
Microsoft’s Satya Nadella made the same point in July, as quoted by TechCrunch: “I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation.” Hugging Face’s Clem Delangue called distillation “a practice that everyone is doing, including companies in the U.S.” Musk’s “Partly” came 133 days before Demo Day. Garry Tan is the first accelerator head to say it, but the third or fourth chief executive.
What the Accusers Have Counted Since February
The “do nothing” answer was given to a question about two documents. It helps to know what they count, and what they ask for.
Anthropic’s February and September figures
Anthropic’s first disclosure, on 23 February 2026, named DeepSeek, Moonshot and MiniMax. It said the three labs “generated over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts”. DeepSeek’s share was over 150,000 exchanges, Moonshot’s over 3.4 million and MiniMax’s over 13 million. One DeepSeek target was rubric grading that made Claude act as a reward model for reinforcement learning.
The September report, which CNBC dated to Thursday 10 September, says Anthropic has since “identified and disrupted additional distillation attacks against Claude from seven labs based in China”. It defines illicit distillation as “an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization”. Its per-lab floors, which we tallied in our earlier report, are 151 million for Alibaba, 23 million for Moonshot, 12.1 million for DeepSeek, 3.4 million for Zhipu and 400,000 for Xiaomi. The report prints no total. Those five floors sum to 189.9 million.
| Measure | February disclosure | September report |
|---|---|---|
| Labs named | 3 | 7 |
| Exchanges (sum of stated floors) | 16.55 million | 189.9 million |
| Largest single lab | MiniMax, over 13 million | Alibaba, over 151 million |
| Accounts | About 24,000 | Per lab; 3,500-plus for Alibaba |
| Models targeted | Claude | Generally available Claude; none against Mythos 5 or Mythos Preview |
| Uses of “policymakers” | 2 | 0 in the distillation section |
The September floors are 11.5 times the February ones, across 199 days. That growth is the reason the question was put to Garry Tan at all.
The bars below share the September floors out of that 189.9 million sum. Alibaba’s 151 million is 79.5 percent of it.
The advisory that came two days earlier
On Tuesday 8 September, CISA, the NSA and the FBI issued advisory AA26-251A, naming six China-based companies. As we found when we read it, the document never uses the words theft, illegal or crime. Its whole legal characterisation is that the companies route requests “to gain unauthorized access, consequently violating U.S. AI companies’ terms of use.” Every remedy it lists is an action for a private company.
That is worth holding next to Garry Tan’s answer. The advisory’s own framing makes distillation a contract matter, which is the framing he uses too. Where he differs is on whose contract should give way.
What none of the three documents asks a regulator to do
The distillation section of Anthropic’s September report uses “policymakers” zero times, “legislation” zero times and “export control” zero times. The February post uses “policymakers” twice, both in calls for “coordinated action among industry players, policymakers, and the global AI community”. The advisory addresses companies. The regulatory ask lives in Amodei’s July post (“We should crack down on industrial-scale distillation operations”) and in Treasury Secretary Scott Bessent’s July statements that “sanctions and Entity List designations will be on the table” and that “Open source is not open season on American IP.”
So Garry Tan’s “I would do nothing” is an answer to Amodei and Bessent, not to the reports. The reports mostly describe what the labs are already doing themselves: banning accounts, downgrading responses and sharing indicators. Nobody in the documents has asked a regulator to stop an American lab from distilling an American model, because no American lab has publicly tried to through the front door.
Garry Tan's Tightrope: The Price Premium Condition
Garry Tan’s one condition is that frontier labs keep “a price premium that allows their business model to remain feasible.” He gave no figure. The figures that exist come from the people measuring open-weight models against closed ones.
How wide the gap is, according to two sources that disagree on the cause
OpenRouter’s June roundup says open-weight models “have been maintaining a consistent 3-6 month gap for over 18 months” behind US frontier labs, and that “the frontier labs do not (at this moment, anyway) appear to be accelerating away.” Amodei’s July post says distillation “can bring the Chinese frontier to within a few months of the US frontier.” The two agree on the size of the gap. OpenRouter attributes it to the pace of open research. Amodei attributes it to extraction. Garry Tan’s proposal would make the second explanation moot by making extraction lawful.
On price, OpenRouter lists DeepSeek V4 Flash at $0.14 per million input tokens and $0.28 per million output tokens on its first-party API, and calls that “roughly 150x cheaper than GPT-5.5’s output costs.” A premium of 150 times on output tokens is the premium that currently exists for that pair. Whether it “allows their business model to remain feasible” is the question Garry Tan left open. We looked at what the DeepSeek V4.1 Flash release does to that arithmetic when it shipped on Hugging Face.
The size gap that matters more than the price gap
Hugging Face’s “State of Open Models: Summer 2026”, published 14 August, says that “in almost every month of 2026, the largest and most performant open model from a Chinese lab was larger than any model an American lab released.” China’s monthly ceiling ran from 754 billion to 2.78 trillion parameters. US models stayed under 130 billion “in five of seven months”, the exceptions being Nvidia’s Nemotron 3 Ultra at 561 billion and Inkling. Meanwhile Qwen’s family drew 2,045 million downloads across the period against Moonshot’s 37 million, about 55 times more.
The bars below put those two download counts on one scale, with Qwen at 100 percent.
This is the gap Garry Tan’s regime is meant to close. A “more robust set of open-weight options that aren’t Chinese”, in Bort’s summary of his position, would need American open models that are both large and adopted. Hugging Face’s numbers say the US has one large original model and the adoption is elsewhere.
The batch he was presenting
The 149 AI companies in the Summer 2026 batch are the demand side of the tightrope. They buy frontier tokens today and would buy cheaper open-weight tokens if the quality held. Three in four is the share of Garry Tan’s own portfolio that the premium is charged to.
Who the Smaller American Open-Weight Labs Are
Garry Tan did not name a lab. The letter’s signatory list and Hugging Face’s report between them do.
The US open-weight releases of 2026 with a stated size
| Model | Lab | Size | Date and source |
|---|---|---|---|
| Nemotron 3 Ultra | Nvidia | 561B | May and June ceiling, Hugging Face |
| Nemotron 3 Super | Nvidia | 124B | Hugging Face |
| Trinity-Large | Arcee AI | 399B | Hugging Face, “original American” |
| Inkling | Thinking Machines Lab | 975B (TechCrunch) or 952B (Hugging Face) | 15 Jul; built with Kimi 2.5 |
| Muse Glimmer | Meta | Not stated | 10 Aug, CNBC |
| Nemotron 3.5 Lightning | Nvidia | Not stated | 11 Aug, CNBC |
Of those five labs, Nvidia, Arcee and Meta signed the letter and Thinking Machines did not. Smaller signatories that publish weights include Nous Research, Prime Intellect, Liquid AI, EleutherAI, Ai2 and Reflection. Hugging Face ranks Liquid AI third in the US by new model repositories this year, at around 100, behind AMD and Nvidia at more than 200 each. That is the pool of “smaller, American open-weight AI labs” that Garry Tan’s regime would license.
Who is not on the list
Anthropic, the lab whose door Garry Tan’s regime would most need to open, has never released open weights and did not sign the letter. OpenAI signed it, which puts it on both sides of the argument: its terms forbid distilling its models, and its signature endorses “targeted legal and commercial frameworks” for the concern. Nvidia’s purchase of Hugging Face put the largest US open-weight publisher and the largest distribution platform under one owner, which changes who would negotiate any American regime.
What Y Combinator’s own request list says
We read YC’s Requests for Startups page, about 3,100 words. It uses “open source” zero times, “open weight” zero times and “distill” zero times. The only “frontier” is a line about “founders building on the frontier”. Its novelty this batch is a request from the sitting US Secretary of the Army. So the accelerator that signed the letter has not, in its public wish list, asked anyone to build the open-weight lab its chief executive says the country needs.
Three Nightmares: Garry Tan, Dario Amodei and the Letter
Each of the three positions ends with a worst case. They are not the same worst case, and the difference explains the disagreement better than the word “distillation” does.
The three worst cases side by side
| Who | The nightmare | What distillation does to it |
|---|---|---|
| Garry Tan | “There’s just one company … It has the best access to capital. It has the best AI researchers. It runs away with it” | Prevents it, by spreading capability |
| Dario Amodei | Authoritarian governments build stronger models and use them for “permanent military superiority” or repression; misuse for cyber or biological attacks | Causes the first, by letting China “partially evade chip bans” |
| The letter | “A small number of single points of failure” that “leaves critical technology in the hands of a few providers” | Prevents it, as “a widely used technique” |
Garry Tan and the letter fear the same thing, concentration. Amodei fears the wrong state winning, and wrote that protecting US labs from competition “has never been my goal.” A regime that lets American labs distill American models addresses the first fear directly and the second not at all, because the models it would license are not the ones Amodei is worried about. Our report on why AI labs press ahead despite insider warnings counted six proposed brakes and found none that binds a lab.
Garry Tan on science fact and science fiction
In the same interview Garry Tan said “We need to be focused on science fact, not science fiction” and named the risk he considers imminent: “If there was a breach and a coordinated attempt by agents to take over our infrastructure, what do we do about it?” He put job loss decades out: “It will take decades for this to actually percolate into society, and that’s not a bad thing.”
That places him alongside the critic in our report on the claim that doom talk is meant to distract, and against the survey respondents in our piece on why so many AI researchers think the machines could kill everyone. The cyber risk he names is the first section of the same Anthropic report whose distillation section he is dismissing.
What an American Distillation Regime Would Have to Decide
“Regime” implies rules. Garry Tan supplied one verb, “normalize”, and one condition, the price premium. The documents we read supply the rest of the questions, and mostly no answers.
The open questions and who has spoken to each
| Decision | Garry Tan | Anthropic | Others |
|---|---|---|---|
| Who authorises | Government should “normalize” access | “Prior authorization from Anthropic”, no process published | OpenAI: itself, for its own students only |
| Price | A premium that keeps frontier labs “fundable” | Not addressed | OpenRouter: 150x on one output-token pair today |
| Safeguards | Not addressed | Distilled models “lack necessary safeguards” (Feb); test all capable models (Jul) | The letter: openness “may be one of the most important paths to AI safety” |
| Geography | American labs only | Seven labs “based in China” named | The advisory: six China-based companies; the letter: no country named |
| Enforcement | “Do nothing” | Bans, downgrades, indicator sharing | Bessent: sanctions and Entity List “on the table” |
The precedent already on the table
The US government has already said which direction it will enforce. On 21 July Bessent said “This administration supports open source models, but what we do not support is IP theft.” On 22 July, after White House science adviser Michael Kratsios accused Moonshot of distilling Anthropic’s Fable model, Bessent posted that sanctions would be on the table for “covert, industrial-scale distillation attacks that cross the line into IP theft.” The Carolina Principles the same administration is pressing on the G20 describe light-touch rules for everything else.
Garry Tan’s regime would need that same government to lean the other way on American labs, telling frontier providers to accept what it threatens to sanction Chinese labs for. Nothing in the record suggests it is considering that. The one word the administration and Garry Tan share is “supports”, as in open source models.
What we could not verify
We could not find a mechanism proposed by Garry Tan beyond the word “normalize”, and TechCrunch’s follow-up did not report one. We could not establish whether Y Combinator’s signature on the July letter was his decision, although he is its chief executive. And we found no public record of any American lab applying for the “prior authorization” that Anthropic’s usage policy names, so we cannot say whether the front door has ever been tried.
Frequently Asked Questions About Garry Tan and Distillation
What exactly did Garry Tan say about distillation?
To CNBC on 10 September 2026 he said “I would do nothing” and “We could argue that there should be an American distillation regime.” To TechCrunch he said controlling API customers “feels constraining” and that access to intelligence trained on public data should be “more a form of a public good than something locked away behind restrictive terms of service.”
Is Garry Tan asking American labs to break the frontier labs’ terms?
No. TechCrunch reports that he is not advocating the use of stolen credentials and wants labs “free to come in the front door.” His argument is that the terms themselves should change, with government help.
Did Y Combinator take this position before Demo Day?
Yes. Y Combinator is one of 235 signatories in the 30 July version of the “Open Weights and American AI Leadership” letter, which calls distillation “a widely used technique” and asks for “targeted legal and commercial frameworks rather than sweeping restrictions.”
Does any frontier lab allow distillation with permission?
Anthropic’s usage policy prohibits distillation “without prior authorization from Anthropic” and its commercial terms say “except as expressly approved by Anthropic”, but we found no published route to that approval. OpenAI sells a Model Distillation product that only works between its own models.
Has any American company admitted distilling another American lab’s model?
Yes. On 30 April 2026 Elon Musk, asked in court whether xAI had used distillation on models from OpenAI to train Grok, answered “Partly”. Stanford’s Alpaca project did the same with text-davinci-003 in 2023 and said so.
How does Garry Tan’s position differ from Dario Amodei’s?
Both call distillation legitimate and both want targeted frameworks. Amodei wants a crackdown on “industrial-scale distillation operations” backed by an authoritarian state; Garry Tan wants “restrictive terms of service” loosened for American labs. Their nightmares differ: one company for Tan, a rival state for Amodei.
References
Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too (TechCrunch)
Garry Tan urges separating ‘science fact from science fiction’ amid AI doomsday fears (CNBC video)
Open Weights and American AI Leadership, July 24, 2026 (PDF)
Our position on open-weights models (Anthropic)
Detecting and preventing distillation attacks (Anthropic)
Threat Intelligence Report: September 2026 (Anthropic)
Cybersecurity Advisory AA26-251A (CISA)
Model Distillation in the API (OpenAI)
Commercial Terms of Service (Anthropic)
Gemini API Additional Terms of Service (Google)
US threatens sanctions against Chinese AI models over IP theft (TechCrunch)
Elon Musk testifies that xAI trained Grok on OpenAI models (TechCrunch)
Arcee, a US open source AI lab, says Chinese models are not inherently dangerous (TechCrunch)
Meta and Nvidia plant ‘very firm flag’ in open-weight AI race led by Chinese Labs (CNBC)
State of Open Models: Summer 2026 Observations (Hugging Face)
The Open Weight Models that Matter: June 2026 (OpenRouter)
Alpaca: A Strong, Replicable Instruction-Following Model (Stanford CRFM)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.