Y Combinator's President Says Washington Should Do Nothing About Chinese Distillation

Three days after the NSA, the FBI and CISA jointly accused six Chinese companies of running industrial-scale extraction campaigns against American frontier models, the man who writes first checks into more American AI startups than almost anyone else told CNBC what he thinks regulators should do about it.

“I would do nothing” about distillation, said Garry Tan, president and chief executive of Y Combinator, speaking at the accelerator's annual Demo Day on Thursday, September 10. “We could argue that there should be an American distillation regime.”

Distillation means prompting a more capable model at scale and using its outputs to train a cheaper one — routine when a lab does it to its own models, and a violation of essentially every frontier provider's terms of service when done to someone else's API without permission. That gap, between research method and contractual breach, is the entire fight.

His alternative target is market structure: less policing of extraction, more attention to balancing open-weight and frontier models, provided the frontier keeps enough of a price premium to stay a business. “This is actually the ideal case. You want open weight models to give people freedom and access,” he told CNBC. “If I were a regulator, that's what I would go after.” He conceded the balance is “a tightrope,” but said it “could result in the best possible outcome.”

Asked by TechCrunch why American open-weight labs should be free to distill American frontier labs, Tan argued that outputs from systems trained on the open internet should not be locked down by contract. “Controlling what users and customers do with API calls to closed weight models feels constraining, and there's a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service,” he said. He is not endorsing the methods in the federal advisory — he wants American labs coming in the front door, not through stolen credentials — but he cited the copyright fights, including the $1.5 billion authors' settlement Anthropic closed in July, as the reason the labs' complaints land awkwardly.

To Tan, the real tail risk is concentration, not catastrophe. “The nightmare scenario, the doomer scenario for AI is that there's just one company,” he said. “It runs away with it and suddenly there's one company that's monolithic.”

What the government and the labs allege

The September 8 advisory named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, describing campaigns running since at least late 2024, likely with Chinese government awareness, that pulled billions of tokens from Claude, GPT, Gemini and Grok via fraudulent accounts, bulk premium subscriptions and proxy services the agencies call transfer stations. They called distillation “the core, not merely a supplement” of those companies' development, and noted DeepSeek's widely cited $5.6 million training figure excludes data allegedly obtained this way. Suggested countermeasures include subtly altering responses or quietly downgrading suspected distillers.

Anthropic's September 10 threat report added numbers: more than 151 million exchanges from May to July 2026 attributed to Alibaba-linked operators, peaking near 3 million a day across 3,500-plus fraudulent accounts, plus 23 million to Moonshot and 12.1 million over 14 days in July to DeepSeek. Its safety argument is one Tan does not address: “The robust safeguards that prevent Claude from being misused by bad actors do not transfer when our models are distilled by an unauthorized lab,” the company wrote.

Anthropic CEO Dario Amodei staked out the lab's position in July, and it is narrower than Tan's framing suggests. “Anthropic has never advocated for a ban on open-weights models,” he wrote, calling open models without dangerous capabilities “a public good.” What he wants is a crackdown on industrial-scale distillation specifically, because it “allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans,” closing the gap to within a few months of the US frontier. Beijing rejects the premise: China's AI development “is the result of high-level technological self-reliance and strength,” foreign ministry spokesperson Mao Ning said.

Why this matters

Strip away the geopolitics and the disagreement is about who pays for the next training run. Frontier pretraining is funded on the expectation that the capability can be rented at a margin; distillation converts it into a cheap open artifact at a fraction of the compute. Tan does not dispute those economics — his equilibrium explicitly preserves a frontier price premium. He disputes that terms-of-service enforcement is the right instrument, and implicitly that it is an enforceable one, given outputs can be laundered through any intermediary willing to resell API access.

Whether that makes distillation theft is genuinely contested, not just rhetorically. Frontier labs assert a property interest in outputs while defending their own ingestion of copyrighted text as fair use — a tension the authors' settlement priced rather than resolved. Amodei's answer is that the security case does not turn on the property question at all.

Tan is also not a neutral observer. Of the 196 startups at Thursday's Demo Day, 149 were classified as machine-learning or AI ventures, nearly all building on models they rent. Cheap, capable open weights mean leverage over suppliers and less margin drag for that portfolio. YC was also an early OpenAI backer, and Sam Altman ran it from 2014 to 2019 — the interests cut both ways.

What to watch: whether any American open-weight lab takes Tan up on an above-board distillation program, and how providers respond if one does; whether degrading responses to suspected distillers becomes standard practice, and what that does to trust in paid API access; and September 24, when Trump and Xi Jinping are scheduled to meet with AI governance on the agenda. Tan wants no rules. The agencies have written recommendations. Whether anything binding follows is the open question.

“We could argue that there should be an American distillation regime.”
— Garry Tan, President and CEO, Y Combinator
151M
Claude exchanges attributed to distillation operators
6
Chinese AI firms named in the Sept 8 advisory
$5.6M
DeepSeek's cited training cost
149 of 196
YC Demo Day startups classified as AI ventures