Garry Tan Advocates U.S. Open-Weight Labs Be Allowed to Distill Frontier Models
Preface
Context: This article summarizes Y Combinator CEO Garry Tan's stance on so-called distillation techniques and how they should apply in the United States. Recent concerns about labs—particularly in China—using distillation to extract knowledge from leading models have prompted calls for regulatory action. Tan counters that heavy-handed regulation could be counterproductive and that American open-weight labs should be able to use similar methods to foster competition and resilience in the AI ecosystem. The purpose here is to present Tan's arguments, the technical practice of distillation, and the competing viewpoints so readers can understand the trade-offs and implications.
Lazy bag
Garry Tan says: don’t rush to ban distillation. Instead, allow U.S. open-weight AI labs to distill frontier models openly. He argues that permitting lawful, front-door distillation would strengthen American options, promote innovation, and help prevent monopolization by single proprietary firms. Tan emphasizes that this is about legal, transparent use—not theft or credential fraud—and frames access to model knowledge as important for competition and public benefit.
Main Body
Distillation refers to the practice of querying a powerful model extensively to learn how it reasons and to capture its behavior in a new model. It can be an ordinary, legitimate training method used by researchers and smaller labs to accelerate development and increase the range of available models. Recently, some companies have raised alarms, alleging that certain actors use deceptive means—such as hiding identities or using stolen credentials—to mount "illicit distillation attacks." Those allegations have prompted calls for regulatory intervention, particularly from companies concerned about unauthorized extraction of their models' capabilities.
Garry Tan offers a contrasting view. He argues that regulators should be cautious about forbidding distillation outright. In interviews, Tan suggested that U.S. policymakers might instead permit and even encourage an American distillation regime that allows domestic open-weight labs to distill frontier models through proper, legitimate channels. His reasoning has two main strands.
First, Tan sees limits on how model creators can control downstream uses of their systems as potentially overreaching. If a model exposes information through ordinary interactions or API responses, he questions whether creators should fully dictate what customers do with that information. In Tan’s view, once intelligence has been generated by models trained on broad public data, restricting access to the resulting knowledge via heavy contractual or technical controls risks concentrating power rather than democratizing it.
Second, Tan highlights an asymmetry in historical behavior. Many prominent proprietary models were trained by ingesting vast quantities of publicly available human-created content—often without explicit permission from individual rights holders. Given that dynamic, Tan argues it is inconsistent to allow wide-ranging data ingestion in the development phase while tightly restricting downstream access to the intelligence those models produce. Instead, he frames responsibly conducted distillation by open-weight American labs as a way to broaden the ecosystem of available models and reduce dependence on any single provider or foreign-dominated set of models.
He is careful to distinguish his position from support for illicit practices. Tan does not endorse fraud, credential theft, or covert attacks to extract model behavior. Rather, he envisions an open and lawful path: allow smaller American labs to interact with frontier models via ordinary access methods and to use those interactions as training data for their own open-weight models. He believes that approach would expand trustworthy, accessible options that are not tied to foreign providers.
Tan also frames the debate in terms of long-term market structure and public good. He worries about a scenario in which one proprietary company accumulates disproportionate capital, talent, and infrastructure, resulting in a monolithic provider that controls the most capable AI systems. That, he suggests, is the real "doomer" outcome—concentration of technical and economic power that limits access, choice, and innovation. Open-weight labs that can distill legitimately, he argues, contribute to a more pluralistic landscape where multiple actors can iterate, audit, and build on top of advanced capabilities.
Critics—including executives at some frontier firms—have urged regulators to step in, arguing that unrestricted distillation could facilitate intellectual property theft or enable actors to replicate dangerous capabilities without accountability. These concerns are not trivial: if distillation is performed covertly or with stolen access, it can subvert existing protections and create pathways for misuse. It is also true that smaller labs may lack the safety engineering resources that larger labs invest in. That creates a tension between enabling competition and ensuring responsible development and deployment.
Tan’s proposal invites a middle path: protect against illicit activity while permitting transparent, legal distillation practices that sustain a diverse model ecosystem. Under such a regime, governments could clarify acceptable conduct, require transparency or attribution, and discourage fraudulent access, while still allowing legitimate reverse-engineering-style techniques to be used for innovation and redundancy. Proponents of this view argue that clarity from regulators would reduce covert behavior and foster an environment in which open-weight models can coexist with frontier, closed-weight providers.
Adopting a U.S.-centric distillation policy would also have geopolitical implications. Advocates contend it could ensure that alternatives to foreign-dominated models remain available, supporting national technological independence and academic research. Opponents counter that permissive policies could accelerate proliferation of high-risk capabilities or weaken incentives for frontier labs to invest in stewarding their models responsibly.
In the end, Tan’s perspective is consistent with a broader debate about governance, innovation, and competition in AI. He emphasizes legality, openness, and balance: support frontier labs as fundable engines of progress, while allowing open-weight models to provide freedom and access. Whether policymakers adopt his approach will depend on how they weigh the trade-offs between competition, safety, intellectual property, and national interest.
Key Insights Table
| Aspect | Description |
|---|---|
| Tan’s stance | He favors permitting lawful distillation by U.S. open-weight AI labs to promote competition and alternatives to foreign models. |
| Distillation defined | The process of extensively querying a powerful model to capture its behavior and use that data to train new models. |
| Concerns raised | Allegations of illicit distillation (deceptive access, stolen credentials) and risks of reproducing dangerous capabilities without oversight. |
| Tan’s caveat | He explicitly opposes illicit methods; his recommendation is for transparent, front-door access and legal practices. |
| Policy implication | A regulated U.S. distillation regime could balance competition, public access, and protections against fraud and misuse. |
| Broader goal | Avoid concentration of AI power in a single proprietary firm and preserve pluralism in model development. |