The definitional fight over AI distillation now has two ends of Pennsylvania Avenue pointing in opposite directions. Jensen Huang, NVIDIA's co-founder and CEO, said in a CNBC Squawk Box interview last week that using the outputs of other companies' models to train new ones — the practice Washington has spent the past two months labeling industrial-scale theft — is simply how competition works. Asked whether distillation amounts to plunder, he replied: "That's called competition."
Huang's argument, as reported across the interview coverage, ran on three points. Anyone can freely test a rival's products, he said. Companies routinely take competing hardware apart to learn from it — he noted that some have stripped NVIDIA's own products down to nearly the skeleton to understand how they work. And if a vendor truly objects to being studied, the remedy is commercial, not legal: "If you don't like it, if you don't want people using your product, all you have to do is understand your customers and turn off the service," he said, adding that he obviously prefers nobody reverse-engineers NVIDIA's products, "but honestly, competition makes everything better."
The question he was answering did not come from nowhere. Treasury Secretary Scott Bessent, in an Axios interview aired Saturday, described the "large-scale industrial distillation" behind China's open-source models as "a euphemism for stealing from American models." Bessent claimed one strong Chinese model, Moonshot AI's Kimi, sometimes identifies itself as Anthropic's Claude — "Kimi thinks it's Claude; Kimi will tell you it's Claude" — and asserted that Kimi sessions had even forwarded Chinese military weapons-program materials back to Anthropic. His office has previously weighed adding Moonshot AI to a trade blacklist and imposing sanctions.
The administration's tech policy chief made the same argument in July. Michael Kratsios, the White House OSTP director, said at the time that the US had information Moonshot had distilled Anthropic's frontier Fable model to build its Kimi K3 release — a 2.8-trillion-parameter open-weight system — calling "large-scale, covert industrial distillation aimed at stealing proprietary US technology" unacceptable. Anthropic, for its part, said in February that three Chinese companies — DeepSeek, Moonshot and MiniMax — had extracted Claude outputs through roughly 24,000 fake accounts and more than 16 million interactions, in violation of its terms of service.
China rejects the framing wholesale. A Ministry of Commerce spokesperson said in September that the accusations were groundless and without basis in law, and accused Washington of politicizing what it called a normal technical and commercial practice while applying double standards. Chinese embassy spokespeople have made the same point in Washington. Distillation itself is uncontroversial as a technique: introduced by Turing Award winner Geoffrey Hinton's group in 2015, it trains smaller, cheaper models on the outputs of larger ones and underpins much of the industry's cost curve — including at American startups.
Huang has an obvious vantage point in this argument, and it is not a neutral one. NVIDIA sells the accelerators that everyone's models run on, and cheap, plentiful open-weight models increase token consumption — which increases demand for NVIDIA's systems. A policy regime that locks frontier capability behind a handful of closed labs shrinks the surface area NVIDIA can sell into. His "turn off the service" logic mirrors, almost verbatim, the argument open-weight advocates have been making in Washington all year: that distillation is a legitimate model-improvement technique that should be separated from outright misappropriation, with the latter handled through targeted legal and commercial frameworks rather than restrictions on the technique itself.
It is worth noting what Huang is not saying. NVIDIA signed the White House's voluntary superintelligence safety accord this week alongside Alphabet and Meta, and the company has its own reasons to stay inside the administration's good graces as export-control policy tightens. His objection is narrower: not that China steals nothing, but that "distillation" is the wrong word for what competitors do in the open — and that the harm narrative is doing commercial work. Anthropic's founder Dario Amodei, the most prominent advocate of the theft framing, benefits from the same framing in reverse, since it entrenches the moat of whoever already has the biggest model.
Where this lands is now a policy question rather than a technical one. Bessent confirmed the US and China have established a bilateral AI-focused communications channel for handling emergencies, even as he kept sanctions on the table. The distinction both sides are groping toward is behavioral: learning from a model's publicly visible outputs is different from covertly extracting them through fake accounts. If Washington writes that boundary into law, it will land on exactly the gray zone Huang described — and the company with the most to lose from either extreme is the one selling shovels to both sides.
Comments (0)
Log in to join the discussion
Log InNo comments yet