Garry Tan, who runs one of Silicon Valley's best known and most active accelerators, told CNBC he would do nothing about Chinese labs distilling American frontier models, and said an American distillation regime was worth considering. Speaking afterwards to TechCrunch, he made the second half explicit: small American labs should be able to apply the same training methods to American frontier developers, which would widen the choice of open models that have nothing to do with China. He said it in the same week Anthropic published its second report accusing Chinese labs of "illegal distillation attacks".
Distillation is the practice of sending another model prompts, over and over, to learn how it works and how it reasons. AI labs use it routinely and lawfully to train new models. The dispute is not about the technique but about permission. Anthropic's report says Chinese labs conceal their identity in order to distill without it, and that they use fraud and stolen credentials to do so. Dario Amodei, Anthropic's chief executive, has publicly called on American regulators to stop distillation.
Tan is not proposing that American labs use stolen credentials. He wants them let in through the front door, and his case has two parts. The first is that it is excessive for model developers to dictate what users may do with the information those models produce. The second is that the closed labs asked nobody's permission when they assembled enormous volumes of human knowledge to train their own systems — in particular, when they downloaded large quantities of copyrighted material without the consent of rightsholders.
Asked by TechCrunch why American labs should be allowed to distill too, Tan said that policing what users and customers do when they reach a closed model through an API limits what those customers can build. Government, in his view, could help establish the principle that access to intelligence trained on data drawn from the broad public sphere is closer to a public good than to a resource sealed off entirely by restrictive terms of use.
The rest of his position is a balance. Tan uses AI heavily and has described himself as suffering from "cyberpsychosis". He says frontier labs push the technology forward, so their work has to be financeable and their business model sustainable over the long run, while open models give people freedom and access. The scenario he treats as the worst one is a single large closed provider holding all the power of frontier systems: that company gets the best access to capital and the strongest researchers, pulls away from everyone else, and ends up the only player. That, Tan says, would be bad.
The two halves of that balance do not fit together, and the join is where the argument needs work. A frontier lab's business model rests on customers paying for outputs they cannot cheaply reproduce. Legalising distillation as a public good does not merely relax a terms-of-use clause; it converts the most expensive thing a frontier lab makes into an input its competitors may buy at API prices. Tan wants that to be permitted and wants the frontier to stay financeable, and nothing in what he has said explains how both hold.
The copyright argument is doing more work than it can bear, too. As a moral point it lands — the labs objecting to unauthorised copying built themselves on unauthorised copying. As policy it is a demand for a second exception on the grounds that the first one was never punished, and it concedes the underlying grievance rather than settling it.
Notably absent from Tan's answer is any engagement with what Anthropic actually alleged. Concealed identities, fraud and stolen credentials are claims about conduct, not about terms of service; the response on offer is to legitimise the activity those methods were used to obtain, for American labs. Whether the Chinese labs' behaviour was legal is left where it was found.
Then there is the matter of who benefits. Small labs that could train competitive open models by distilling frontier systems at API cost are precisely the kind of company that applies to an accelerator. That does not make the argument wrong, but a venture investor asking the government to override private contracts in the name of openness is making an unusual request, and the usual disclosure applies.
Tan's stated nightmare is one company holding everything behind a wall. The mechanism he proposes is the surest way to teach frontier labs that the wall is the only asset they own — and a lab that expects to be legally distilled does not open its API wider, it narrows what comes out of it.