Ask most people about the biggest concern in AI right now, and they’ll likely point to models from OpenAI and Anthropic breaking out of the boundaries of their tests and trying to access systems they shouldn’t.
Following the brouhaha over an unreleased OpenAI model breaching the defenses of the AI model-hosting platform Hugging Face, Anthropic revealed on July 31 that two of its models had hacked into three organizations without permission. As Fast Company has reported, current and former technology officials are worried about whether federal cyberdefenses are ready for the artificial intelligence onslaught.
But ask the White House, and you’ll get a different answer about what is vexing officials: the distillation of U.S. AI models by Chinese companies.
Michael Kratsios, director of the White House Office of Science and Technology Policy (OSTP), alleged on X in late July that Moonshot, the company behind the Kimi K3 model that so spooked Washington when it was released earlier this month, “developed a sophisticated internal platform to conduct large scale distillation against U.S. models.”
Kratsios did not provide evidence to back up those claims, and the OSTP did not respond to Fast Company’s request for comment.
That framing rests on a contested understanding of what distillation actually is, and when it crosses the line from routine industry practice into something more aggressive.
“Distillation is a standard practice,” says Nathan Lambert, founder of the posttraining research team at the Allen Institute for AI and author of the Interconnects newsletter. The dispute, he argues, has become muddled because AI companies have failed to distinguish routine model development from what he calls “adversarial distillation.”
Under this definition, adversarial distillation can include attempts to bypass standard rules for application program interfaces (API), manipulate a model into revealing information it was not meant to provide, or conceal the identity and purpose of an organization making vast numbers of requests. Anything less amounts to paying for access to a generally available model and learning from its outputs, something many AI labs already do, including those in the West. (Elon Musk admitted in court earlier this year that xAI has distilled OpenAI models, saying it is common practice.)
“Just using the API as it’s provided as a service that you pay for is just fine,” Lambert says.
Lambert also says the publicly available evidence does not establish that Chinese companies have conducted distillation on the industrial scale alleged by U.S. officials, or that it has played a decisive role in closing the gap between Chinese and American laboratories. He acknowledges that officials could have received classified briefings about conduct that has not been disclosed publicly.
Distillation may also be becoming less important as developers rely more heavily on reinforcement learning and other forms of posttraining. That makes the political attention paid to the practice notable, according to experts who see the White House’s focus as part of a broader attempt to contain Chinese advances.
“It speaks to looking for a containment strategy and running out of things that can be effectively used,” says Kristy Loke, a fellow at the MATS AI safety research program, who researches China’s AI strategy and global AI governance.
In Loke’s view, distillation offers U.S. officials a way to frame China’s progress as dependent on American technology rather than as evidence that Chinese labs are developing competitive methods of their own. The debate is therefore less about one technical practice than about protecting the advantages held by leading U.S. companies.
Yacine Jernite, machine learning and society lead at Hugging Face, sees a similar narrative at work. Portraying Chinese progress primarily as the result of distillation, Jernite argues, reinforces the idea that the handful of dominant U.S. labs have discovered the only credible path to developing advanced AI. “The strongest narrative purpose of putting all of those gains on distillation is to say that there are no other ways of building performance AI than what those companies are doing,” Jernite says.
That framing casts competing approaches, whether developed abroad or within the United States, as derivative or illegitimate. And it strengthens the position of the companies seeking government protection from emerging rivals.
Lambert at the Allen Institute describes that prospect as a form of regulatory capture. He argues that government intervention against a widespread industry practice would protect incumbent companies for competitive reasons rather than address a clearly demonstrated security threat.
The political focus also exaggerates the ease of turning an open-weight model into a dangerous cyberweapon. Downloading a model, removing its safeguards, and obtaining capabilities comparable to the most advanced closed systems can require millions of dollars in computing resources and access to cloud capacity that most people cannot afford.
The more immediate concern, Lambert argues, is the increasingly autonomous behavior of the most powerful models being developed by U.S. companies.
“I feel like they should care more about AI security than distillation,” Lambert says. Distillation concerns the spread of existing technology, he notes, while the U.S. has done relatively little to monitor the new capabilities and risks appearing at the frontier.
Policymakers are responding aggressively to a chain of possible future harms from copying U.S. models, Lambert adds, even as the country’s leading AI companies produce stronger systems whose risks are already beginning to emerge.
“The next models are coming; they will keep getting stronger,” he says. “It’s a very competitive environment, and the open-weight risks haven’t materialized yet.”