Y Combinator CEO Garry Tan said he would do nothing about AI model distillation.

He wants regulators to focus on creating an equilibrium between open-weight and frontier models, as long as frontier models retain a price premium that allows their business model to remain feasible.

The position landed Thursday, days after the NSA, FBI and Cybersecurity and Infrastructure Security Agency named six Chinese companies in a joint advisory alleging industrial-scale distillation of American models.

“I would do nothing” about distillation, Tan told CNBC at YC’s annual Demo Day. Distillation uses outputs from a more capable AI system to train another model, a common research method that can violate a provider’s rules when access is unauthorized.

Key Takeaways

AI-generated summary, reviewed by an editor. More on our AI guidelines.

A different regulatory target

On the equilibrium between open-weight and frontier models, Tan said, “This is actually the ideal case. You want open weight models to give people freedom and access,” adding, “If I were a regulator, that’s what I would go after.”

He called that balance “a tightrope” that “could result in the best possible outcome.” Tan said, “We could argue that there should be an American distillation regime.” He did not explain what such a regime would permit or who would administer it.

Critics have pushed back on Anthropic’s and OpenAI’s distillation complaints because much of the data used to train these AI models may be covered under copyright law, a point Tan highlighted. The New York Times sued OpenAI and Microsoft over its articles in 2023, and book authors settled a related case with Anthropic in 2025.

Washington makes its case

The Sept. 8 advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It alleged that campaigns had operated since at least late 2024, likely with Chinese government awareness, using fraudulent accounts and proxy “transfer stations” in violation of American providers’ terms.

The agencies described distillation as “the core, not merely a supplement” of the companies’ development. They said DeepSeek’s widely cited $5.6 million training cost did not include the cost of data allegedly acquired through distillation.

Recommended defenses include subtly altering answers or quietly moving suspected distillers to a less capable model without notifying them.

Anthropic puts numbers on the claims

Anthropic said in a Sept. 10 threat report that it had detected attacks from seven China-based labs. Operators linked to Alibaba generated more than 151 million exchanges from May through July 2026, peaking at nearly 3 million a day through more than 3,500 fraudulent accounts, the largest campaign Anthropic said it had measured.

The company attributed more than 23 million exchanges in that period to Moonshot and more than 12.1 million over 14 days in July 2026 to DeepSeek.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

“The robust safeguards that prevent Claude from being misused by bad actors do not transfer when our models are distilled by an unauthorized lab,” Anthropic said. The company said its own research showed that a model distilled from a frontier model can help achieve dangerous capabilities, including those in the biological or cyber domains, even when the collected exchanges contain little material about those subjects.

Those counts are Anthropic’s own findings, while the company-level attributions in the advisory belong to the agencies. Neither China’s foreign ministry nor, as far as is publicly known, any of the six companies has rebutted the advisory’s company-by-company allegations.

YC’s stake and Beijing’s answer

Of the 196 startups presenting at Thursday’s Demo Day, 149 were classified as machine-learning and AI ventures. The accelerator funds hundreds of companies building on frontier systems, including Scale AI, Legora and Emergent, and was an early OpenAI supporter. Sam Altman led YC from 2014 to 2019.

China rejected the accusations Wednesday. “China’s AI development is the result of high-level technological self-reliance and strength,” foreign ministry spokesperson Mao Ning said. The Ministry of Foreign Affairs urged the United States to “refrain from making unfounded accusations or smears.”

President Donald Trump and Chinese leader Xi Jinping are due to meet Sept. 24, with AI governance expected to be part of the talks.

Frequently Asked Questions

What did Garry Tan say about distillation?

At Y Combinator's annual Demo Day, Tan said he would "do nothing" about it. He wants regulators to focus on an equilibrium between open-weight and frontier models, as long as frontier models retain a price premium that keeps their business model feasible.

What is AI model distillation?

Distillation uses outputs from a more capable AI system to train another model. It is a common research method, but it can violate a provider's rules when access is unauthorized.

Which companies did the US advisory name?

The Sept. 8 advisory from the NSA, FBI and CISA named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It alleged campaigns since at least late 2024, likely with Chinese government awareness.

What did Anthropic report?

Anthropic said it detected attacks from seven China-based labs. It attributed more than 151 million exchanges from May through July 2026 to Alibaba-linked operators, more than 23 million to Moonshot, and more than 12.1 million over 14 days in July to DeepSeek.

How did China respond?

Foreign ministry spokesperson Mao Ning said China's AI development "is the result of high-level technological self-reliance and strength." The ministry urged the United States to "refrain from making unfounded accusations or smears."

AI-generated summary, reviewed by an editor. More on our AI guidelines.

Moonshot Releases Kimi K3 Weights as Amodei Rejects Open-Weight Ban
Moonshot AI released the weights for its Kimi K3 model on Monday, a system with 2.8 trillion parameters. Developers can now download, modify and self-host K3, which the report described as the world's
Meta Releases 30B Open-Weight Muse Glimmer and Promises Spark 1.2 Weights
Meta released Muse Glimmer, a 30-billion-parameter open-weight model, Monday. Glimmer distills Muse Spark to run local agents on a single high-end Mac or PC. Meta promised Muse Spark 1.2 weights in co
White House Accuses Moonshot of Distilling Fable and Using Banned Nvidia Chips
Michael Kratsios, director of the White House Office of Science and Technology Policy, accused Moonshot AI on Wednesday of distilling Anthropic’s Fable to develop Kimi K3, the 2.8-trillion-parameter m
AI News

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai