Garry Tan Pushes for U.S. Open-Weight AI Labs to Legally Distill Frontier Models

At the center of today’s AI governance debate, Y Combinator CEO Garry Tan argues that American open-weight AI labs should have the freedom to employ distillation techniques on frontier models, much like their Chinese counterparts. He believes U.S. regulators should allow smaller labs to extract knowledge from high-end models without fear of overregulation or legal backlash. The distinction he draws is clear: permission through official channels, no illicit credentials or hidden identities.

What Does “Distillation” Mean?

Distillation refers to a method where one model is probed using another—that is, the “student” model learns from the “teacher” model’s responses. It’s a common strategy in AI development, often used to train more efficient models by observing how frontier models reason. Tan says this practice isn’t about reverse engineering with bad intent; it’s about enabling smaller labs to build upon the foundational knowledge embedded in cutting-edge models.

This debate gains urgency in light of recent claims by Anthropic, alleging that Chinese AI labs have conducted “illicit distillation attacks,” using fraud or stolen credentials to train open-weight models without authorization. Anthropic has called on U.S. regulators to clamp down on these practices. Tan’s position takes a different tack: rather than strict enforcement, he favors transparency and equal opportunity for domestic labs. He believes the current proprietary AI environment—where large models are locked behind restrictive terms—neglects the fact that much of their training data comes from public sources.

The Frontier vs. Open-weight Divide

Frontier AI labs are those developing the very highest-capability models—think large language models or specialized systems pushing the edge of what’s technically possible. Open-weight labs, by contrast, build or distribute models with freely readable or modifiable weights, often encouraging collaboration, scrutiny, and innovation. Tan argues both have roles: frontier entities drive capability, while open-weight players deliver accessibility and accountability. He warns that letting a single proprietary provider dominate would stifle competition and centralize too much power.

He points out that many proprietary models used data drawn from publicly accessible sources—books, websites, academic articles—often without direct permission. Thus, he says, it would be hypocritical to permit blanket controls on how clients use models via APIs. According to Tan, access to the intelligence distilled from public data should itself retain some of the public-good qualities of its inputs.

Importantly, Tan isn’t advocating for illicit behavior. He expects labs that distill frontier models to follow legal routes—no stolen credentials or surreptitious access. He calls for what he dubs an “American distillation regime,” one that allows open-weight labs to compete, offers users more freedom in how they build applications, and prevents monopoly over both model weights and AI development.

In his view, the genuinely dangerous future of AI isn’t malicious agents—it’s an imbalance of power. If every breakthrough falls into the coffers of one or two proprietary giants with deep pockets, that concentration could distort innovation, hinder safety oversight, and limit who shapes AI’s trajectory.

What this push means in practical terms is that U.S. policymakers will need to balance concerns about intellectual property, safety, and national security with innovation and openness. Regulations around model use—especially those dictating what users can do with closed-model APIs—must be crafted with careful consideration so they don’t bind open-weight labs out of existence.

As AI continues its rapid evolution, questions around who owns what models, who may extract what kinds of intelligence, and how governments should regulate all of it are only growing more pressing. What we’re watching now is whether U.S. policy will protect both innovation and competition—or lock in advantages for already dominant players.

Analysis: Tan’s argument reflects a broader tension in AI governance—how to ensure frontier labs’ breakthroughs don’t become black boxes, while still safeguarding intellectual property and safety. If U.S. policy aligns with Tan’s vision, we could see a stronger ecosystem of open-weight tools and labs, more scrutiny of frontier models, and a more competitive field. But risks remain: IP litigation, model misuse, and regulatory overreach could all complicate the path forward.