
Distillation—a technique that uses outputs from advanced AI models to train smaller, cheaper models—has become a flashpoint in U.S.-China AI competition after Chinese lab Moonshot AI released a competitive model that the White House says distilled Anthropic's proprietary technology. Over 20 major tech companies have now urged policymakers not to restrict open-weight models, arguing distillation is a standard and valuable training practice; however, Anthropic and OpenAI view unauthorized distillation as intellectual property theft and national security risk.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Chinese AI lab Moonshot AI released Kimi K3, which users found competitive with Anthropic and OpenAI models. White House advisor Michael Kratsios alleged that Moonshot distilled Anthropic's Fable model to build K3, describing it as theft of American intellectual property. In response, over 20 major tech companies—including Nvidia, Microsoft, Meta, and Palantir—jointly urged policymakers to avoid "premature restrictions" on open-weight AI models.
Why it matters
Distillation lets developers train smaller, cheaper models using outputs from expensive frontier models, potentially allowing competitors to catch up without investing billions in their own development. Anthropic reported that Chinese companies used its Claude model on an "industrial scale" via about 24,000 fake accounts generating 16 million exchanges. The practice sits at the heart of a broader debate over whether the U.S. can protect its AI advantage while staying competitive globally.
What to watch
The U.S. government is trying to determine its position on distillation—balancing concerns about Chinese IP theft and national security against the risk that restricting the practice could drive innovation overseas. OpenAI and Anthropic have banned distillation in their terms of service, treating unauthorized use as potential IP theft; however, both companies have themselves relied on other sources of content to build their models and have faced lawsuits for doing so.
The distillation debate has escalated rapidly from academic circles to the highest levels of U.S. policy. In February, Google AI lead Jeff Dean discussed the concept on a podcast, explaining that he and colleagues had developed distillation techniques to improve performance on systems without relying on a single large image recognition model. He noted that "through distillation, which is a key technique for making the smaller models more capable, you have to have the frontier model in order to then distill it into your smaller model."
Five months later, the release of Kimi K3 by Chinese lab Moonshot AI triggered alarm. Users found the model competitive with the best commercially available AI from Anthropic and OpenAI, despite Moonshot being a Chinese company that has not invested billions in proprietary model development. Unlike leading U.S. companies, which sell access to proprietary models, Moonshot offers an open-weight model that users can download, tweak, and run wherever they want.
On Wednesday, White House advisor Michael Kratsios posted on X that Moonshot had distilled Anthropic's Fable model for K3 development. He stated: "To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection." This allegation resonated with Anthropic's February disclosure that Chinese companies—including DeepSeek, Moonshot, and MiniMax—distilled its Claude capabilities on an "industrial scale" using about 24,000 fake accounts that generated 16 million exchanges.
On Friday, the tech industry responded with an unprecedented show of unity. Nvidia, Microsoft, Meta, Palantir, and more than 20 other companies released a joint letter urging policymakers to avoid "premature restrictions" on open-weight AI models that would "stifle competition or drive innovation overseas." In the letter, they wrote: "Distillation, or the practice of using one model's outputs to help train or improve another, is a widely used technique for model improvement, evolution, and validation." Box CEO Aaron Levie, a signatory, argued that "the more innovation that there is, whether that's from the U.S. or China or otherwise, you should expect more AI progress, and generally it'll bend toward being even lower cost and more efficient over time."
Anthropichas taken a harder line. Valued at close to $1 trillion(約160兆円) and with aspirations of going public in the near future, the company framed stopping illicit distillation as a matter of national security, writing that "Anthropic and other US companies build systems that prevent state and non-state actors from using AI to, for example, develop bioweapons or carry out malicious cyber activities." Both OpenAI and Anthropic have banned distillation in their terms of service, effectively treating unauthorized use of their model outputs as potential IP theft. Shashi Bellamkonda, research director at Info-Tech Research Group, noted that distillation is legitimate: Nvidia, for instance, used it as part of the training process for its Llama Nemotron series of models.
The debate is complicated by a historical irony. Both OpenAI and Anthropic have relied on other sources of content to build their models and have been sued for doing so. Max Pritt, an attorney for Boies Schiller Flexner representing book authors in copyright litigation against AI firms, observed: "The administration, at least publicly, has focused its efforts on the protection of technology companies' intellectual property, while remaining silent in large part about creators and individuals' intellectual property that was used without authorization." Meanwhile, companies facing high AI costs see practical incentives to use open-weight models. Pukar Hamal, founder of security firm SecurityPal, said he would have no problem using Kimi K3 at his company—which automates security assessments using AI—if he could verify there were no malicious backdoors: "hosting it on our own infrastructure after we've done an assessment, why not?"
Distillation is not a new technique—Jeff Dean, Google's AI lead, discussed it on a podcast in February as a method for making smaller models more capable without relying on a single large model. What has changed is the scale and geopolitical stakes. The revelation that Chinese labs used distillation to rapidly develop competitive open-weight models has shifted the conversation from a technical practice to a national security and IP theft debate. Anthropic's February disclosure that Chinese companies distilled its Claude model at an "industrial scale" using 24,000 fake accounts and 16 million exchanges crystallized the concern.
The response from major tech companies signals deep disagreement over how to handle distillation. OpenAI and Anthropic have banned it in their terms of service, framing unauthorized use as IP theft. However, the tech giants' joint letter reflects a different calculus: they argue that distillation is a "widely used technique for model improvement, evolution, and validation" and that restricting it risks driving innovation overseas and stifling competition. This tension reveals a fault line in how the U.S. technology industry views its own interests—whether protection of proprietary models outweighs the competitive benefits of access to open-weight AI.
A complicating factor is that both OpenAI and Anthropic have themselves built models using content from other sources and have faced lawsuits for doing so. This historical reliance on external data weakens their argument that distillation by others constitutes unprecedented IP theft, even as government officials frame Chinese use of American model outputs as a national security threat.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion


Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime