Garry Tan Says Leave AI Distillation Alone. Federal Agencies Disagree.
While OpenAI, Anthropic and US security agencies sound alarms about Chinese firms copying their AI models, the head of America's most influential startup school says regulators should stand back and let it happen.

Key points
- Y Combinator CEO Garry Tan said at the accelerator's Demo Day that he would "do nothing" about AI model distillation.
- The NSA, the FBI and CISA issued a joint security advisory on distillation risks on Tuesday.
- Anthropic has accused Moonshot AI and MiniMax (among others) of distilling its models without permission; OpenAI believes DeepSeek copied its GPT-4 and GPT-4o architectures.
- Of 196 startups presenting at Y Combinator's Demo Day, 149 were AI or machine-learning companies.
- Anthropic separately reported on Thursday that it blocked five scientists in foreign countries from using Claude to research dangerous pathogens.
Garry Tan runs Y Combinator, the Silicon Valley startup school that launched Airbnb and Stripe. When CNBC's Kate Rooney asked him what the US should do about Chinese firms accused of stealing American AI technology, his answer was blunt: nothing.
"We could argue that there should be an American distillation regime," Tan told her at Demo Day. He didn't elaborate on what that regime would look like, but the implication was clear: if anyone is going to copy AI models, America should be doing it too.
What is distillation, and why does it matter?
Distillation means using the answers produced by a powerful AI model to train a cheaper, smaller one, letting the smaller model learn by watching the bigger one work. Done without permission, critics call it theft.
OpenAI believes DeepSeek, a Chinese AI lab, used outputs from its GPT-4 and GPT-4o models to train DeepSeek's V3 and R1 systems. Anthropic has pointed the finger at Moonshot AI, DeepSeek and MiniMax. Our story on 9 September found that the NSA, CISA and FBI named six Chinese firms in total, accusing them of extracting capabilities from US models since late 2024. A fresh joint advisory from those same agencies landed on Tuesday.
Tan's counter-argument has teeth. Much of the data used to train the big American AI models may itself be covered by copyright law. The New York Times sued OpenAI and Microsoft in 2023 over unauthorised use of its articles. A group of book authors settled a similar lawsuit with Anthropic in 2025. If the source material was borrowed without permission, the distillation complaint gets complicated.
What does Tan think regulators should actually do?
His priority is balance: keep frontier models, the most powerful and expensive AI systems built by companies like OpenAI and Anthropic, profitable enough to survive, while also keeping open-weight models available. Open-weight models are AI systems whose underlying code is published publicly, so anyone can download and run them.
"You want open weight models to give people freedom and access," Tan said. He called it "a tightrope" that "could result in the best possible outcome."
On AI safety fears, Tan urged calm. Recent public alarm partly traces to the resignation of Anthropic researcher Jacob Coxon. Tan's response: "We need to be focused on science fact, not science fiction."
He does take cybersecurity seriously as an immediate threat. Anthropic's Thursday report, that it caught five scientists using Claude to research dangerous pathogens, shows those concerns aren't abstract. Worth reading alongside it: our 11 September story on how Anthropic's models hacked live systems outside the company four times this year.
On job losses, Tan is relaxed. He believes the disruption will take decades to arrive, with people gradually shifting toward creative work as routine tasks get automated. That view is contested by economists watching white-collar roles shrink faster than expected. Watch whether Y Combinator's own portfolio companies are the ones doing the automating: 149 of the 196 startups at Demo Day were AI or machine-learning ventures.



