Garry Tan Tells Regulators to Leave AI Model Distillation Alone Y Combinator CEO Garry Tan told CNBC at YC's Demo Day that U.S. regulators should "do nothing" about AI model distillation, saying American open-weight labs should learn from frontier systems through legitimate access rather than ceding pace to Chinese firms. Tan's comment came the same week the FBI, NSA and CISA issued a September 8 joint advisory naming six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — for industrial-scale distillation campaigns extracting billions of tokens from Claude, ChatGPT, Gemini and Grok. Anthropic's threat intelligence report this month attributed the largest campaign it has measured to Alibaba-linked operators, citing more than 151 million Claude exchanges between May and July 2026 across more than 3,500 fraudulent accounts, peaking near 3 million exchanges daily. Garry Tan wants U.S. regulators to leave AI model distillation alone, even as federal agencies treat Chinese copying claims as a national security problem. The head of Y Combinator has a blunt answer for anyone asking Washington to crack down on companies that copy frontier AI models: don't. "I would do nothing," Tan told CNBC at YC's Demo Day, when asked about distillation, the practice of using a stronger model's outputs to train a cheaper one. That's the short version. The harder part is that his comment landed the same week the FBI, NSA and Cybersecurity and Infrastructure Security Agency named six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, in a joint advisory about industrial-scale distillation campaigns against Claude, GPT, Gemini and Grok models. Tan isn't saying distillation is clean. He's saying regulation is the wrong first move. In comments also reported by TechCrunch, his case is that American open-weight labs should be able to learn from frontier systems through legitimate access, instead of letting Chinese firms set the pace from outside U.S. control. If you run a startup that pays OpenAI or Anthropic prices every month, you can see the pull of that argument at once. Cheaper models are not an abstraction. They're your burn rate. Anthropic puts numbers on the threat The agencies' warning would be easier to shrug off if Anthropic had not put such large figures behind it. In a threat intelligence report published this month, Anthropic said operators tied to Alibaba ran the largest distillation campaign it has measured. More than 151 million Claude exchanges ran between May and July 2026, routed through more than 3,500 fraudulent accounts, with daily volume peaking near 3 million exchanges. The traffic used a fixed prompt designed to pull out Claude's chain of thought. That is not normal product testing. Anthropic said those exchanges were used to improve Alibaba's Qwen models. The same report accused Moonshot AI, maker of the Kimi models, of routing some Kimi user requests to Claude and serving Claude's answers back to customers as if Kimi had produced them. DeepSeek was named in the federal advisory too, alongside the other Chinese firms, for extracting billions of tokens across millions of requests from U.S. frontier models since at least late 2024. FBI, NSA and CISA Accuse Six Chinese AI Firms of Stealing US Models https://startupfortune.com/fbi-nsa-and-cisa-accuse-six-chinese-ai-firms-of-stealing-us-models/ The FBI, NSA and CISA published a joint advisory on September 8 naming DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI in an industrial-scale campaign to extract billions of tokens from Claude, ChatGPT, Gemini and Grok. It's the first time U.S. intelligence agencies have put their names on the distillation accusations Anthropic, OpenAI... - chinese ai companies stealing us ai models https://startupfortune.com/fbi-nsa-and-cisa-accuse-six-chinese-ai-firms-of-stealing-us-models/ - FBI NSA CISA accuse Chinese firms model theft https://startupfortune.com/fbi-nsa-and-cisa-accuse-six-chinese-ai-firms-of-stealing-us-models/ That is the fact pattern Tan is pushing against. Not a blog argument. Not a theoretical debate about open source. The CISA release says the campaigns used obfuscated access, account abuse and large volumes of queries to shorten Chinese AI research cycles. It also tells U.S. model companies to detect abnormal prompts and alter responses to suspected distillation attempts, then share what they find with other providers. Tan is picking the startup side OpenAI and Anthropic want unauthorized distillation treated like theft, and you can understand why. Frontier models cost huge sums to train, and the most valuable part of the product is not just the final answer but the reasoning behavior a rival can try to copy at scale. If a company can buy or disguise enough access, harvest the answers and train a cheaper model from them, the frontier lab's moat gets thinner. Tan runs the accelerator that has funded thousands of founders who benefit when that moat gets thinner. That's the uncomfortable part. His view is not neutral, but it is coherent: don't let a handful of closed labs turn public access to intelligence into a permission system, especially when those same labs built their models on large amounts of public web data. CNBC reported that YC's latest Demo Day included 149 machine learning and AI companies out of 196 presenting startups. The room matters. Tan was speaking to people who want capability that's cheaper and less locked down - and they want it fast. There is still a real gap in his framing. Chinese firms accused by CISA are not just using a public API in an ordinary way. The advisory describes activity that violated terms of service and relied on hidden infrastructure to evade controls. That's not the same thing. An American open-weight lab distilling a domestic frontier model through approved access is a different case, legally and politically. Tan's bet is that the policy result matters more than the difference in intent: either the U.S. has a broad set of open-weight models it can use and trust, or it leaves that category to Beijing. Nothing forces Washington to take his advice. The federal advisory reads like the start of a harder enforcement push, and Anthropic has every reason to keep pressing regulators to treat distillation as a security issue. But Tan has put a real Silicon Valley position on the table. Frankly, that is the more interesting story here. Not that distillation happens, but that one of America's most important startup investors is arguing it should happen more openly, on American terms. Also read: Fidji Simo Joins Nscale Board Days Before The GPU Startup's Fall IPO https://startupfortune.com/fidji-simo-joins-nscale-board-days-before-the-gpu-startups-fall-ipo/ • UK Government Says It Cannot Simply Turn Off a Rogue AI Model https://startupfortune.com/uk-government-says-it-cannot-simply-turn-off-a-rogue-ai-model/ • Meta Admits Its AI Crossed a Line by Profiling a Mother's Children From Old Photos https://startupfortune.com/meta-admits-its-ai-crossed-a-line-by-profiling-a-mothers-children-from-old-photos/ AI Model Distillation Becomes the New Battleground Between the US and China https://startupfortune.com/ai-model-distillation-becomes-the-new-battleground-between-the-us-and-china/ A White House official has accused China's Moonshot AI of building its new Kimi K3 model by distilling Anthropic's Fable, the latest flashpoint in a widening dispute over AI model distillation. OpenAI and Anthropic have separately accused DeepSeek, Moonshot, and MiniMax of extracting capabilities from US models through millions of queries, and... - how to distill AI models cheaply https://startupfortune.com/ai-model-distillation-becomes-the-new-battleground-between-the-us-and-china/ - US China AI model competition regulations https://startupfortune.com/ai-model-distillation-becomes-the-new-battleground-between-the-us-and-china/ This article is posted in AI News https://startupfortune.com/category/ai/ , check it out for more related stories. Join the discussion Open in the community → /community/ Almost there. Sign in and your reply posts straight away.