Model distillation, the practice of training new AI systems on the outputs of existing models, has become a focal point in the escalating competition between the United States and China for artificial-intelligence leadership. The technique allows developers to extract capabilities from larger, often proprietary, models, raising concerns about intellectual-property protection and national security as both sides vie for technological advantage.
In July, Treasury Secretary Scott Bessent characterized the practice as theft and warned that the United States could impose sanctions on foreign entities that leverage American-origin models to build competitive products. His remarks signaled a willingness to use economic pressure to deter what Washington views as unauthorized exploitation of U.S. AI innovations.
During an interview on CNBC’s Squawk Box, Nvidia chief executive Jensen Huang countered the theft narrative, describing distillation as a form of competition. He argued that testing competitors’ offerings is permissible and noted that Nvidia’s technologies are sometimes reduced to their core components by other firms seeking to understand their operation.
Huang added that, while he would prefer others not to dissect Nvidia’s products, competition ultimately benefits the industry. He suggested that companies uncomfortable with such scrutiny could mitigate risk by closely monitoring their customers and disabling services when necessary, placing the onus on providers rather than on the technology itself.
Earlier this month, the U.S. Cybersecurity and Infrastructure Security Agency accused Chinese artificial-intelligence firms of conducting industrial-scale knowledge-distillation campaigns that breach the terms of use set by American companies. The agency’s statement highlighted concerns that systematic extraction of model capabilities could undermine the protective frameworks governing U.S. AI assets.
Anthropic, an independent AI research organization, reported that it identified illicit distillation activities involving Alibaba’s Qwen model series and the startup DeepSeek. The findings reinforce the broader narrative of cross-border model copying and add weight to calls for stricter enforcement of intellectual-property rules in the rapidly evolving AI landscape.