Y Combinator CEO Garry Tan backs an American regime allowing open-weight labs to distill frontier models, challenging restrictions and raising policy questions.

Y Combinator CEO Garry Tan is calling for U.S. open-weight AI companies to be allowed to distill proprietary frontier models, arguing that broader access could prevent advanced AI from becoming controlled by a single provider.
Tan told CNBC that he would prefer regulators not intervene in the current dispute over model distillation. He later told TechCrunch that smaller American labs should be able to use the technique openly on U.S. frontier systems, creating more domestic alternatives to Chinese open-weight models.
The position puts the head of one of Silicon Valley’s most influential startup accelerators at odds with calls from some frontier-model companies for tighter controls on how customers use their systems. It also opens a wider debate over whether knowledge obtained through paid model access should be treated as proprietary output, public infrastructure, or something between the two.
Model distillation generally involves querying a larger model extensively and using its responses to train another system. The process can help a smaller model learn patterns in language, reasoning, or task performance without reproducing the larger model’s underlying weights. AI labs commonly use distillation as part of legitimate training and evaluation work.
Tan’s proposal is not for American companies to use stolen credentials or impersonate customers. TechCrunch reported that he wants U.S. labs to be allowed to access frontier models “through the front door,” using ordinary model access rather than deception or unauthorized accounts.
His argument has two parts. First, Tan believes frontier companies may be overreaching when they dictate what customers can do with information returned through their AI APIs. Second, he argues that proprietary AI companies themselves built their systems by absorbing vast amounts of publicly accessible human knowledge, including copyrighted material whose owners did not necessarily grant permission.
From Tan’s perspective, allowing open-weight AI companies to learn from commercial systems could create a counterweight to the concentration of computing, capital, and research talent among a small number of frontier AI labs. He said the worst-case scenario would be one company gaining an overwhelming lead and becoming a “monolithic” provider.
The comments arrive after Anthropic published a second report alleging that Chinese AI companies carried out what it calls “illicit distillation attacks.” According to the report as described by TechCrunch, the companies concealed their identities, used fraud, and relied on stolen credentials to extract capabilities from other models without permission.
Anthropic CEO Dario Amodei has previously urged U.S. regulators to respond to such activity. That position treats unauthorized distillation as a security and intellectual-property problem rather than an ordinary consequence of offering a model through an API.
The distinction between permitted and prohibited distillation is therefore central. Tan is not endorsing the credential theft and deception described in Anthropic’s allegations. He is arguing that American open-weight labs should have a legitimate path to conduct similar training work under transparent access conditions.
That proposal still leaves difficult questions unanswered. A model provider may permit customers to generate outputs while restricting the use of those outputs to train a competing system. It may also impose technical limits, monitoring, or contractual terms designed to prevent systematic extraction. Tan’s comments challenge whether those restrictions should be enforceable as broadly as they are today, but they do not establish a legal framework for replacing them.
The central news is Tan’s public policy position, reported by TechCrunch after comments to CNBC and follow-up remarks to the publication. There is no evidence in the supplied reporting that the U.S. government is preparing an “American distillation regime,” nor that Tan’s proposal has been adopted by Y Combinator as a formal policy platform.
Likewise, the reporting does not provide independent measurements showing that distillation would reliably produce competitive open-weight models, lower training costs, or reduce dependence on Chinese systems. Those outcomes are part of the argument for the proposal, not demonstrated results in this account.
Anthropic’s claims about Chinese labs are also presented as allegations from the company’s own report. The available evidence does not include an independent investigation or response from the named companies. That matters because the same technical activity can look very different depending on authorization, contractual terms, the scale of querying, and whether credentials were obtained legitimately.
For builders, the practical takeaway is that distillation remains technically established but politically unsettled. Model developers can use the method in authorized settings, yet access agreements and provider policies may determine whether a particular training workflow is permitted.
If Tan’s view gained policy support, smaller American labs could gain a more direct route to improving open-weight models. They might use frontier systems for synthetic data generation, reasoning demonstrations, evaluation, or specialized fine-tuning rather than relying only on public datasets and internally generated examples.
That could increase competition for model developers and give product teams more options when they need local deployment, greater control over weights, or reduced dependence on a single hosted provider. It could also create new commercial services around licensed teacher-model access and carefully documented distillation pipelines.
The risks would be substantial. Frontier companies could respond by raising prices, restricting high-volume access, adding stronger output filters, or limiting accounts that appear to be training competitors. More aggressive extraction could also make it harder for providers to protect proprietary capabilities and recover the cost of developing large models.
Enterprise buyers would face a related governance issue. A company using a distilled model would need to understand not only the model’s benchmark performance, but also the provenance of its training data, the permissions attached to teacher-model outputs, and the possibility that the resulting system reproduces protected or sensitive material. In regulated environments, those questions could matter as much as model quality.
The debate also touches AI safety. Open-weight distribution can improve auditability and user control, but it can make powerful capabilities easier to deploy without a central provider’s monitoring or refusal systems. Tan’s competition argument addresses concentration risk; it does not by itself resolve misuse, privacy, or accountability concerns.
The first signal will be whether U.S. policymakers distinguish between authorized distillation and the covert activity alleged by Anthropic, rather than treating all model-to-model training as one category. Any proposed rules concerning AI APIs, synthetic data, or model output ownership would clarify whether Tan’s idea is gaining traction.
The market should also watch for frontier providers to revise terms governing high-volume queries, model imitation, and competitor training. New licensing programs could offer a middle ground: allowing distillation under explicit contracts while preserving provider controls over access and attribution.
On the technical side, independent evaluations will be important. Claims that distilled models can match or approach frontier systems should be tested across reliability, safety, factuality, and cost—not just selected benchmark tasks. Evidence of real adoption by American open-weight labs would also be stronger than general arguments about national competitiveness.
Tan’s proposal is best understood as a competition argument, not a settled answer to the intellectual-property or security questions surrounding distillation. He is warning that restrictions imposed by frontier providers could reinforce the very concentration of power that many policymakers are trying to avoid.
But an open regime would need clear boundaries. Authorized access, transparent training records, and enforceable safeguards could support a healthier model ecosystem; tolerating fraud or indiscriminate extraction would risk undermining the commercial incentives that finance frontier research. For AI builders and enterprise buyers, the near-term issue is less whether distillation exists than whether providers, regulators, and courts can define when it is legitimate.