🔮 Copy that: The curious case of AI distillation #594
Plus: A prophet of terror & AI doomers; bioweapons, orcas & the Amazon success
Hi,
Welcome to the latest Sunday briefing! I am off on holiday for a couple of weeks. The team will continue to tend to Exponential View while I’m gone, so you won’t miss a beat.
Azeem
Distillation grey zone
On 1st September 1789, Samuel Slater set sail from England for New York. He’d learned that the Pennsylvania legislature had recently passed an act awarding £100 to a British textile worker who smuggled high-end machinery into the state. America was going to great lengths to acquire industrial know-how, by any means possible.
Britain had made it illegal to export textile machinery and technical drawings. The ban extended to prevent textile workers from emigrating. Slater had worked in mechanized textile mills and saw his chance.
He committed the entirety of Richard Arkwright’s system – the first factory method for spinning cotton – to memory. He disguised himself as a farm laborer and broke the laws of his nation as he carried himself across the Atlantic, valuable know-how secretly distilled into his brain.
By 1790, Slater was a partner in a cotton mill in Pawtucket, Rhode Island, built from the plans he memorized. President Jackson called him the “Father of American Manufactures.” He died in 1835 worth around a billion dollars in today’s terms.1

Today’s question is to what extent are Chinese AI labs distilling the outputs of American AI models – and is it really a problem? The easy answer is the hawkish one: hugely and yes, it is. But it’s not the only answer.
First of all, distillation is a decades-old machine learning technique in which a larger model can train a smaller, more efficient model. A lab running distillation internally is not an issue. But it is possible to distill a model from the outside (even without the provider’s permission). This is the accusation against Kimi and other Chinese labs.
Diogo Almeida, a four-year veteran of OpenAI, explains that effective distillation is much harder today than a few years ago, when AI models helpfully provided their reasoning traces. What Almeida calls “behavior parroting” is to learn from final answers, the least powerful approach but might still work well to help bootstrap another model.
There is substantial evidence that both Chinese and American researchers have trained models on the outputs of frontier systems. Stanford’s Alpaca project has admitted as much. Anthropic has alleged that DeepSeek, Moonshot and MiniMax have used more than 16 million Claude chats via 24,000 fake accounts. Michael Kratsios, Trump’s science chief, says he now has evidence of how Moonshot ran distillation attacks.
Anastasios Angelopoulos, the CEO of Arena, a benchmarking company, makes the case that Kimi K3 is exceeding the performance of some of the top US models, something distillation alone doesn’t allow, and he predicts that “American labs will start distilling Chinese intelligence.”
It isn’t clear that distillation is illegal yet. Nathan Lambert points out that “[t]here’s no legal precedent that model outputs are IP.” The US Copyright Office’s 2023 statement on AI confirms as much:
When an AI technology determines the expressive elements of its output, the generated material is not the product of human authorship. As a result, that material is not protected by copyright.
Unlike the case of Samuel Slater, who knew he was breaking British law, the problem here is a case of the exponential gap: the technology has stepped ahead of the law.2 If labs have IP in outputs of their models, they will essentially have IP in every future economic activity of all their users.
It also weakens the labs’ own position – why should AI models be prevented from consuming Anthropic’s IP when Anthropic is allowed to consume yours and mine?
Bahrad Sokhansanj has some other sensible suggestions, summed up as follows. Address distillation but scope it narrowly, only focusing on the real harm done, with the right instruments. Is it about national security? Or something else? Regulate more broadly, and this will play into the labs’ desire to skew the regulatory field in their favor.
Again, there is precedent: in 1824, once he was settled as a prominent American industrialist, Samuel Slater lobbied for protectionist tariffs to stifle foreign competition. By then, he was also known as “Slater the Traitor” back in his hometown.
See also:
Satya Nadella was one of many tech leaders to force the case for open-weight models to quieten rumors that the American administration was considering limiting them. Jensen agrees:
A MESSAGE FROM OUR SPONSOR, OKTA
To get AI security right, take care of identity
When you and your team deploy AI agents, identity becomes your strategic infrastructure. An agent is an actor that reads your data, calls APIs, and does things on your behalf. You need to give it clear permissions and to audit its trails.
Okta’s AI Identity Readiness assessment will score the security of your AI agents and show exactly what you need to fix to go to production with peace of mind.
Run Okta’s 5-minute survey to evaluate your agents.
Want to sponsor Exponential View? Get in touch.
China’s chip chase
In 2015, Made in China set a target of 70% self-sufficiency in semiconductors within a decade. It was often mocked as fanciful and missed wildly. Data from Morgan Stanley now shows that domestic suppliers will have met about 41% of China’s AI chip demand in 2026, up from 20% in 2023. Beijing may hit its 70% threshold five years late.
Compute-weighted, the 41% figure delivers less compute compared to Nvidia, but for the purposes of strategic autonomy, the quality gap is increasingly a non-issue.
The spark was Washington’s export restrictions. “If the U.S. hadn’t forced our country, our company and our industry into a corner, we would never have done something like this”, says Huawei’s deputy chairman. It has become an “all-out push” according to this excellent reporting.
A leaked conversation between DeepSeek’s boss, Liang WenFeng, and several investors supports this. Liang says:
What’s the gap with the U.S.? Only one thing: resources. We don’t have enough GPUs – our count is still small. […] Domestic chips now have a historic opportunity. Previously, adaptation was hindered by poor ecosystem… But that’s changing. NVIDIA CUDA’s moat is eroding rapidly.
Full transcript and context at Grace Shao’s blog.
We the people
Peter McCrory, Anthropic’s Head of Economics, points out that the US labor market has shrugged at AI. Unemployment is at 4.2%, and Anthropic’s data finds no worsening unemployment even in the most exposed occupations.
AI augments rather than replaces, for now. Not a single profession has been 100% handed over to machines yet. Every job still needs human effort. It is changing how work gets done, and if workers get more productive, value shifts inside existing roles, and those who use the technology best stand to benefit.
The final hard-to-automate tasks, the “weak links”, as Professor Chad Jones calls them, are the things only a human can do. Companies will need people to get them done, and this protects employment, keeping a decent share of income in human paychecks
Here is another take. People still matter and will continue to matter. Europe creates far fewer successful innovative companies than the US. One reason I’ve often argued is the simple cost of changing the workforce. I think of startups as exercises in making mistakes and learning from them. Every additional cost to making a mistake means an opportunity to learn not taken. Yoram Wijngaarde finds a simple relationship (correlation is not causation) that shows that the more expensive it is to let go of staff, the lower the rate of unicorns per capita.
Prophet motive
A new biography of Jean-Paul Marat, one of the leaders of the French Revolution, reviewed in the current LRB, is worth reading for anyone trying to make sense of today’s AI debate.
Stanford historian Keith Baker3 has a new biography of the journalist and politician. He argues that Marat hates mediation of any type, from Newtonian formulas to parliamentary assemblies and calm discussion- anything that stands between the people and the truth. He tried to write a daily pamphlet, shouted rather than argued and manufactured intimacy. “By making his journal ‘more interactive, more dynamic, more personal’, he fashioned an intimacy that allowed him to speak for the people.”
In amongst this, his paranoia did help him identify real corruption and institutional betrayal. Baker calls him the first modern populist.
High-frequency publishing, paranoia as analysis, a parasocial closeness and the constant insistency that any complexity is just conspiracy in disguise… Well, AI discourse is now selecting for exactly this Marat-like temperament.
While today’s keyboard warriors carry none of the physical violence of Marat’s Terror, there is a similar underlying logic against nuance and complexity. Doomers and accelerationists share patterns – purge rhetoric, aggressive polemics, and the framing of every whiff of nuance as corrupt. What is left are the extremes. Call to mind imminent economic disaster; catastrophic fraud; utopian abundance… or, simply, the transformation of the human condition.
What can get lost in these extremes is the reasoned position that admits and examines evidence. A position that balances probabilities and accepts answers might be complex, incomplete and – contingent.
See also:
💪🏼 Really stoked that AMD’s CEO Dr. Lisa Su opened her keynote with Exponential View data. You can get the same data here.
Become a member to receive our Sunday briefing every week in your inbox or the app.
Short morsels to appear smart at dinner parties
Why AI-assisted bioweapons won’t kill us. via EV member Abi Olvera
🏋🏼♀️ The share of UK businesses using AI has nearly tripled since 2023, but most firms are still dabbling.
Arsenal FC is building AI models for football (soccer).
Young people are more likely to gamble in financial markets when important life goals (like buying a house) feel out of reach.
Global air and sea surface temperatures are headed for a new record.
Good news from the Amazon: wildfires are at a record low this year and deforestation is at a 10-year low. h/t EV member Angus Hervey
Vintage LLM 😎Training AI models only on pre-1931 texts help researchers study what AI can do without contamination from the modern web.
👀 Stripe is in talks to buy OpenRouter.
Intel is shipping the first chips with layers printed on ASML’s $380 million High-NA EUV machines.
Know thy maths. Michael Liebreich breaks down why the EU’s 46% electrification target by 2040 is mathematically unachievable. Relevant for anyone working in policy, really.
🐳 Orcas preparing food for their young? Amazing.
Thanks for reading!
His estate was worth $1 million. On a CPI basis, that is $40 million; on a relative income/wage equivalence, it is about $1 billion; on a share of the US economy, it is about $1.7 billion.
It is obviously unseemly to many people that the labs trained on other people’s outputs (like books and essays) en masse. But the courts haven’t yet decided that the training is a breach of copyright law. In Anthropic’s case, despite the settlement, they have decided it wasn’t.
Baker is a super historian whose work I have gotten to know over the past few years. His two sons run one of the world’s most successful (and least well-known) hedge funds.










