Jeff Dean, head of artificial intelligence at Google LLC, speaks during a Google AI event in San Francisco, California, USA, on Tuesday, January 28, 2020.
David Paul Morris | Bloomberg | Getty Images
Earlier this year, Google AI boss Jeff Dean discussed on a podcast a concept that was rarely talked about outside of weird tech circles at the time: distillation.
Speaking about the development of Google’s AI models, Dean said that he and his colleagues discovered artificial intelligence distillation techniques because Google wanted to improve the performance of its systems without relying on a large image recognition model.
“Through distillation, which is a key technique to make the smaller models more powerful, you have to have the frontier model and then distill it into your smaller model,” Dean said in February.
Five months later, distillation has suddenly become a hot topic from Silicon Valley to Washington, D.C., as techies and lawmakers debate whether the practice is becoming a national security threat and allowing China to catch up with the U.S. in the high-risk AI race. Concern grew late last week after Chinese lab Moonshot AI released Kimi K3, and users quickly discovered that it was competitive with the best commercially available AI from Anthropic and OpenAI.
Unlike leading U.S. AI companies that sell access to proprietary models, Moonshot and other Chinese labs offer so-called open-weight models that allow users to download, tweak and run the technology wherever they want.
Some government officials attribute Moonshot’s ability to catch up so quickly to distillation and describe it as theft of American intellectual property, particularly through its incorporation of Anthropic’s Frontier Fable model.
“We have information that Moonshot AI distilled Anthropics Fable for the development of its K3 model,” White House adviser Michael Kratsios posted on
![]()
At a higher level, distillation refers to using responses from a chatbot or work product from an advanced AI model to train another model. The practice is controversial because, depending on the application, it can allow a model developer to create a competitive offering simply by leveraging the results of companies that have invested many millions or billions of dollars in developing the most sophisticated training technology.
“It’s almost as if someone went to the lectures, read the textbook and did all the hard work of doing the homework,” said Pukar Hamal, founder of AI security firm SecurityPal. “Then another student says, ‘Hey, I didn’t do that. Can I just copy your work?'”
Whether it was Kratsios’ contribution or something else, the world’s biggest tech heavyweights came together in perhaps unprecedented fashion on Friday to clearly state their position. After a series of social media posts throughout the week, tech giants Nvidia, Microsoft, Meta and Palantir, along with more than 20 other companies, released a letter urging policymakers to avoid “premature restrictions” on open AI models that would “stifle competition or spur innovation abroad.”
“Distillation, or the practice of using the results of one model to train or improve another, is a widely used technique for model improvement, development, and validation,” they wrote.
Table of Contents
The China problem is becoming more complicated
The emergence of distillation poses a conundrum for U.S. policymakers, who have long worried about Chinese technology, both in terms of intellectual property theft and national security issues.
Colin Shea-Blymyer, a research fellow at Georgetown’s Center for Security and Emerging Technology, said the U.S. government is trying to figure out its position.
The government could argue that Chinese and Russian companies “have used the results of hard-working American models to make themselves more powerful and that they have an unfair advantage there,” Shea-Blymyer said.
Crate CEO Aaron Levie was one of the signatories of Friday’s letter. Levie said in an interview that U.S. companies must have access to the best technology to remain competitive, regardless of where it is developed.
“The general idea is that the more innovation there is, be it from the U.S., China or elsewhere, you should expect more AI advances, and generally it will be even more cost-effective and efficient over time,” Levie said.
Although much of the current discourse focuses on Chinese open-weight AI models like Kimi K3, many companies have incorporated the distillation technique when creating their own models, said Shashi Bellamkonda, research director at Info-Tech Research Group. Nvidia, for example, used distillation as part of the training process for its Llama Nemotron model line, as described in an accompanying research paper.
“Training a smaller, cheaper model on the output of a larger model is a legitimate and very valuable technique and is practiced all the time,” Bellamkonda said.
Dario Amodei, co-founder and CEO of Anthropic, during an interview on “The Circuit with Emily Chang” at Anthropic’s headquarters in San Francisco, California, USA, on Thursday, April 30, 2026.
Jason Henry | Bloomberg | Getty Images
However, Anthropic disagrees, as the company sees how its models are being used and needs to protect a burgeoning business. In February, the company said its Claude capabilities were being distilled on an “industrial scale” by Chinese companies DeepSeek, Moonshot and MiniMax, which used about 24,000 fake accounts and generated 16 million exchanges.
Anthropic, which is valued at nearly $1 trillion and plans to go public in the near future, said stopping illegal distillation was a matter of national security.
“Anthropic and other U.S. companies are building systems that prevent state and non-state actors from using AI to, for example, develop bioweapons or conduct malicious cyber activities,” the company said in its February post. And preventing this will require “quick, coordinated action between industry stakeholders, policymakers and the global AI community.”
OpenAI and Anthropic prohibit distilling in their terms of service. Bellamkonda said that they are essentially suggesting that unauthorized use of their larger models constitutes potential IP theft.
However, as the cost of AI skyrockets, companies will do everything they can to increase efficiency.
Hamal said he would have no problem using Chinese open-weight models like Kimi K3 at SecurityPal, which automates security assessments using AI. He says this could save them a lot of money.
“We would ensure that there are no nefarious backdoors in the code,” Hamal said. “But why not host it on our own infrastructure after we do an assessment?”
A big problem for Anthropic and OpenAI in their argument against IP theft is that both companies relied on other content sources to build their models and were sued for it.
Max Pritt, an attorney at Boies Schiller Flexner who represents book authors in copyright lawsuits against AI companies, said the government is in the same boat.
“The government has focused its efforts, at least publicly, on protecting the intellectual property of technology companies, while remaining largely silent when the intellectual property has been used by creators and individuals without authorization,” Pritt said.
REGARD: China’s AI companies are finding ways to monetize even as their models remain open
Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.
https://www.cnbc.com/2026/07/25/hat-is-distillation-and-why-is-everyone-so-obsessed-with-it-this-week.html
