google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
USA

From Silicon Valley to DC, tech world obsessed with AI distillation

Jeff Dean, head of artificial intelligence at Google LLC, speaks at the Google AI event on Tuesday, January 28, 2020 in San Francisco, California, United States.

David Paul Morris | Bloomberg | Getty Images

Earlier this year, Google AI leader Jeff Dean said on a podcastHe discussed a concept that wasn’t much talked about outside risky tech circles at the time: distillation.

Discussing the development of Google’s AI models, Dean said he and his colleagues explored AI distillation techniques because Google aimed to improve performance on its systems without relying on a single large image recognition model.

“Through distillation, which is an important technique for making smaller models more capable, you have to have the boundary model to then distill it into your smaller model,” Dean said in February.

Five months later, distillation has suddenly become a hot topic from Silicon Valley to Washington, D.C., as tech experts and lawmakers debate whether the app has become a national security threat and allows China to catch up with the United States in the high-stakes AI race. Concerns rose last week after Chinese lab Moonshot AI released Kimi K3, and users quickly noticed this was happening. competitive With the best AI available on the market from Anthropic and OpenAI.

Unlike leading U.S. AI companies that sell access to proprietary models, Moonshot and other Chinese labs offer vulnerability-heavy models that allow users to download the technology, tweak it, and run it wherever they want.

Some government officials attribute Moonshot’s ability to catch up so quickly to distillation and describe it as theft of American intellectual property, particularly by incorporating Anthropic’s frontier Fable model.

“We have information that Moonshot AI utilized Anthropic’s Fable for the development of the K3 model,” said White House advisor Michael Kratsios. Published on X on Wednesday. “To do this, they developed an advanced internal platform that would perform large-scale distillation against US models and allow them to quickly switch between multiple access methods to avoid detection.”

At a high level, distillation means using responses from work product from a chatbot or an advanced AI model to train another model. The practice is controversial because, depending on how it is used, it can allow a model developer to create a competitive offering using the output of companies that have invested millions or billions of dollars to develop state-of-the-art educational technology.

“It’s as if someone went to classes, read the textbook, and did all the hard work of doing their homework,” said Pukar Hamal, founder of AI security firm SecurityPal. “Then another student said: ‘Hey, I didn’t do that. Can I copy your work?'”

Whether it was Kratsios’ post or something else, the biggest tech heavyweights on the planet came together in an unprecedented way on Friday to clarify their positions. Following a series of social media posts throughout the week, tech giants Nvidia, Microsoft, Meta and Palantir joined more than 20 companies in publishing a letter urging policymakers to avoid “premature restrictions” on vulnerability-heavy AI models that would “stifle competition or encourage innovation abroad.”

“Distillation, or the practice of using the outputs of one model to help train or improve another, is a widely used technique for model refinement, development, and validation,” they wrote.

We’re complicating the China problem

The emergence of distillation presents a conundrum for U.S. policymakers, who have long been concerned about Chinese technology for both IP theft and national security issues.

Colin Shea-Blymyer, a research fellow at the Georgetown Center for Security and Emerging Technology, said the U.S. government is trying to understand its position.

Shea-Blymyer said the government could argue that Chinese and Russian companies “are using the output of hard-working American models to make themselves more performant and therefore have an unfair advantage there.”

Box CEO Aaron Levie was one of the signatories of Friday’s letter. To remain competitive, U.S. companies must have access to the best technology, regardless of where it was developed, Levie said in an interview.

“In general, no matter how much innovation there is from the U.S., China, or any other country, you should expect more AI advancements, and generally over time, it will trend toward becoming even more cost-effective and more efficient,” Levie said.

Shashi Bellamkonda, research director at Info-Tech Research Group, said that although much of the current discourse focuses on Chinese vulnerability-heavy AI models such as Kimi K3, many companies are incorporating the distillation technique when creating their own models. For example, Nvidia used distillation as part of the training process for its Llama Nemotron series models. accompanying research paper.

“Training a smaller, cheaper model on the outputs of a larger model is a legitimate and very valuable technique and is practiced all the time,” Bellamkonda said.

Dario Amodei, co-founder and chief executive officer of Anthropic, during an interview on “The Circuit with Emily Chang” on Thursday, April 30, 2026, at Anthropic’s headquarters in San Francisco, California, United States.

Jason Henry | Bloomberg | Getty Images

But Anthropic has a different view because the company sees how its models are being used and has a thriving business that needs to be protected. company in february in question Claude capabilities were filtered “on an industrial scale” by China’s DeepSeek, Moonshot and MiniMax, which used approximately 24,000 fake accounts and created 16 million exchanges.

Anthropic, which is valued at close to $1 trillion and plans to go public in the near future, said stopping illegal distilling is a matter of national security.

“Anthropic and other U.S. companies are building systems that prevent state and non-state actors from using AI to, for example, develop biological weapons or conduct malicious cyber activities,” the company said in a February post. And stopping this will require “rapid, coordinated action between industry players, policymakers and the global AI community.”

OpenAI and Anthropic prohibit distillation in their terms of service. Bellamkonda said they essentially argue that using their larger models without permission represents potential IP theft.

However, as the costs of artificial intelligence are rapidly increasing, companies will do whatever it takes to increase efficiency.

Hamal said he would not have any problems using China’s vulnerability-heavy models, such as Kimi K3, in SecurityPal, which automates security assessments using artificial intelligence. He says it could save them a lot of money.

“We will make sure there are no malicious backdoors in the code,” Hamal said. “But after making an assessment, we host it in our own infrastructure, why not?”

One of the big problems for Anthropic and OpenAI trying to make their case about IP theft is that both companies rely on other content sources to build their models and lawsuit filed for doing this.

Max Pritt, an attorney at Boies Schiller Flexner who represents book authors in a copyright lawsuit against artificial intelligence companies, said the government is in the same boat.

“The administration, at least publicly, has focused its efforts on protecting the intellectual property rights of technology companies while remaining largely silent on the unauthorized use of the intellectual property rights of creators and individuals,” Pritt said. he said.

WRISTWATCH: China’s AI firms are finding ways to make money even if their models remain open

Goldman Sachs: China's AI firms are finding ways to make money even if their models remain open
Select CNBC as your preferred source on Google and never miss a beat from the most trusted name in business news.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Check Also
Close
Back to top button