24 comments

  • kelnos 2 hours ago
    I agree. The frontier models are based on training data from tons of copyrighted work. Some of that work was obtained illegally, even. They could not exist without strip-mining the commons. The labs have no moral or ethical ownership to the end result, and others should feel free to treat any company-imposed restrictions on their use as invalid.

    I don't expect Tan's position to be based on any kind of real moral high ground, but his conclusion is correct.

    I love the "illicit distillation attacks" framing from the incumbents. There's nothing illicit. There's no attack. You just don't like it because it threatens your market position and business model.

    • torginus 1 hour ago
      With the recent Navier-Stokes controversy, I think there's a credible suspicion that all your IP you run through these models will end up in these companies' possession. OpenAI themselves has admitted a weak version of this (that prompts might inadvertedly end up improving the model). We don't know the extent of this.

      Obviously it's not possible to run a company whose value is predicated on its IP that uploads said IP to a third party which might get access to it.

      This could mean every potential serious customer would have no option but to seek alternatives to these online services.

      • lynndotpy 24 minutes ago
        I thought this was commonly accepted to be the case that companies which sell access to LLMs are also storing and training on the inputs?

        I don't mean this as rhetoric, I did not think many people (except possibly those operating under government contracts, and 'normies' who don't know about these things) were under the belief that their IP was kept secret when they use these services.

        • zdragnar 0 minutes ago
          Some offer zero data retention policies, but there can be weasel words. For example, on the individual pro plan, you can turn off the setting that lets them train models on your data, but they still have a section in their terms that allows them to evaluate your anonymized data for statistical and "research" purposes. You have to actually get a signed contract along with an enterprise plan that spells out exactly what they're going to use, and what settings enable what retention.

          https://privacy.claude.com/en/articles/10023548-how-long-do-... (see the additional info section)

        • Gud 9 minutes ago
          No, that is not "common knowledge". You are supposed to be able to disable that unwanted feature.
      • Aurornis 45 minutes ago
        > OpenAI themselves has admitted a weak version of this (that prompts might inadvertedly end up improving the model). We don't know the extent of this.

        I think this is being misunderstood. Codex has a toggle to allow your prompts to be included in training data. They’re saying they can’t be sure if the person had it on or off while using Codex to discuss the work.

        They’re not saying that some prompts are mysteriously jumping into training data.

        Also, there is a large market for AI services which don’t retain anything under any circumstances for enterprise customers.

      • ronsor 1 hour ago
        Almost every serious customer is already using ZDR where nothing is retained at all, instead of "anonymized" data.
        • steveBK123 1 hour ago
          They already trained on pirated content, what makes you think they are going to honor ZDR?
          • GrinningFool 5 minutes ago
            Contractual obligations carry teeth. Scraping the internet is relatively risk-free.
        • torginus 51 minutes ago
          Just a thought experiment: considering training seems to be 'fair use', I wonder if they trained a tiny model to retain key info from your prompts, would mean that this would still constitute fair use, and allow them to legally claim they don't retain your data.
          • ronsor 48 minutes ago
            ZDR is shorthand for a more specified agreement of "we don't do anything other than generate your output tokens", so no.

            Besides, true ZDR is usually offered by third-parties with deals to host OpenAI models, such as Amazon (AWS Bedrock) and Microsoft (Azure).

        • applfanboysbgon 1 hour ago
          ZDR is based on the exact same pinky-promise as training opt-outs. There is no technical barrier to OpenAI, or whoever is running your compute, retaining your prompt after they run inference on their servers. If you don't control the hardware the model is being inferenced on, you don't control your data.
        • nrmitchi 1 hour ago
          The guarantee on this is a (contractual) “trust me bro”, and a right to try to sue a multi-trillion-dollar company who will absolutely drive you into the ground with legal red tape.

          If you are big enough to be able to withstand that, you’re already running (or trying to run) your own/open-weight models.

          • enugu 50 minutes ago
            Doesn't Amazon Bedrock change this, since OpenAI does not have access to the data?
            • nrmitchi 47 minutes ago
              Well that is a different thing and an entirely different provider than OpenAI/Anthropics ZDR promise.
        • pennomi 1 hour ago
          Where nothing is retained at all, allegedly.
    • stymaar 1 hour ago
      This. Distillation “attacks” are a made up concept. It's as if I claimed that Anthropic made a “training attack” when training on my internet writing.
    • giancarlostoro 1 hour ago
      Abolish copyright and make it less ridiculous. Sampling music was never a thing that required royalties until the 1990s when I guess someone got angry that rappers were making money off their sampled music. Its insane to me. Make it illegal to transfer ownership of copyrighted work too, only the spouse or one single inheritor who isnt a company can have the rights transferred, after both die, the work enters public domain.

      LLMs should just pay a flat fee to use a specific book and thats it. Fees should be reasonable (not a million dollars per book), so long as the model doesnt spit out the entire book.

      • TFNA 1 hour ago
        One of the most infamous legal challenges to sampled music was MARRS "Pump Up the Volume" in the 1980s, and that was preceded by other famous cases. Not sure why you think that started in the 1990s.
      • derefr 20 minutes ago
        > Make it illegal to transfer ownership of copyrighted work too, only the spouse or one single inheritor who isnt a company can have the rights transferred, after both die, the work enters public domain.

        By your phrasing, it sounds like you still intend the possibility of companies owning copyrights; but how does that happen (other than copyrights already owned by companies grandfathered in)?

        Copyright always starts off in the hands of individual human beings; it only ends up in the hands of companies when those human beings transfer ownership to a company. That ownership transfer can be automatic as a term of a contract, e.g. as part of a work-for-hire agreement. But no contract can cause the copyright to come into existence already held by the company instead of the individual. So if you abolish ownership transfer, you effectively make work-for-hire IP assignment invalid. What replaces it?

        And, if "nothing"... then how do people pool the IP rights of their own small contributions to a large-scale work, into an IP pool that can be legally defended by a coherent legal entity, so that the large-scale work itself can have market value (i.e. so that sales of polished commercial bootlegs don't drive sales of the "authentic" work to zero)?

        Keep in mind that, no matter how much we might want "mass distributed" media to have more-reasonable IP terms, the ability to sue for infringement is still critical to the existence of some forms of media. Especially "location-based" media, with no equivalent licensed broadcast right: movies still in theatre; concerts; live performances of plays and musicals; etc. If there's no legal team that can sue a movie theatre that shows an unlicensed copy of a given movie, then no movie theatre will ever bother with licensing movies again; "box office" goes to zero (from the movie company's perspective); and the incentive to create movies in the first place declines massively.

        (You can see what this alternate world looks like from the few cases where movies screwed up the steps required to assert copyright, back before copyright was automatic. Night of the Living Dead (1968) is a good example: theatres — even upstanding large-chain theatres! — did indeed leap at the opportunity to show the movie unlicensed, and so Romero et al made effectively zero revenue off the work.)

        I'm not saying this is an impossible problem. There are ways to accomplish this besides the way it's done now. (For example, individual-contributor IP could be retained by the original owners, but cross-licensed between individuals through a collaboration structure to form a coherent defensible IP pool, in exactly the same way that IP for e.g. video codecs is cross-licensed between corporations to form a coherent defensible IP pool today.) I'm just pointing out that the problem does need to be solved.

    • godwinson__4-8 1 hour ago
      If the leading private labs attempt to use the government to pull up the ladder under the pretense of "safety" then the response of the people should be to take such questions out of private hands and nationalize the leading labs.

      Or they could abide by the precedents they set and learn to compete. They shouldn't be allowed to have it both ways.

    • Aurornis 50 minutes ago
      There is nothing illegal about training on traces from frontier models.

      However the frontier labs don’t have to serve customers who are farming the service for distillation purposes. That’s their choice and they’re free to make it if they detect distillation happening.

      • darth_avocado 40 minutes ago
        I would argue they should have to. They scraped data off others, a lot of whom did not want that data to be used for AI training, and still had to share it with the frontier labs. It’s only fair they should have to hand it back.

        The only way US maintains dominance over Chinese models is by having an ecosystem of models. Relying on a small set of frontier labs will only let you get ahead temporarily. I agree with Gary Tan on this one.

      • hlynurd 46 minutes ago
        That's fine, they just gotta tone down the victim rhetoric.
        • ronsor 42 minutes ago
          Yes, I think this is the main issue. I don't care what policies the AI labs have or enforce, but they need to stop acting like ToS violations are an international crisis demanding intervention instead of a boring civil dispute at most.
    • Barbing 1 hour ago
      All correct, just help me get over the idea of an open-weight Mythos where one or a dozen of us eight billion does something stupid on the bioweapon front. Smart people who’ve exhausted possibilities for what they can do with books and web search and today’s Kimi/GLM.

      Figure we’ll have to reckon with this next year in any case, guess we’ll see.

      • ronsor 1 hour ago
        "Bioweapon" information is not useful without a lab for synthesis.

        Someone with that lab could almost certainly figure out how do something stupid or destructive on their own, or bypass model safeguards somehow.

        • a34729t 49 minutes ago
          You dont need an LLM to figure out to make anthrax. Anybody who can figure out how to make a home lab can make all sorts of dangerous stuff pretty easily. Same with college grad from a respectable chemistry program. This all FUD.
    • mobelkh 1 hour ago
      why can't I use the tokens i paid for anyway?
    • knollimar 1 hour ago
      I'm sure they put some BS in their TOS
      • stymaar 1 hour ago
        I'm also certain that they violated countless ToS when they scrapped the internet for training purpose.
        • knollimar 54 minutes ago
          Ethically sure but that doesn't mean taking from them is nothing "illicit".
  • TheJCDenton 2 hours ago
    > He also notes that the proprietary AI labs didn’t ask permission when they vacuumed up as much human knowledge as they could to train their models.

    I think this should desactivate the moral high ground from which Anthropic is trying to speak. That they would want to make distillation orderly IMHO is fair, but to make it illegal is very rich from any AI frontier lab, really.

    • Bluestein 1 hour ago
      Also, as said elsewhere: "Lab" is rich here, for outfits that, facing these giant, energy swallowing black boxes have really no clue what's going on inside.-

      The moniker gives them an air of scientific, knowledgeable, tranquil, pro-social, pro bono work.-

      Of course they are entitled to kill off a few mice, or pillage the commons to forward their "lab" work.-

      • samizdis 1 hour ago
        > The moniker gives them an air of scientific, knowledgeable, tranquil, pro-social, pro bono work.

        The Atlantic argued this (rather well, IMO) a week or so ago - "There’s No Such Thing as an AI ‘Lab’" - https://www.theatlantic.com/technology/2026/09/stop-calling-...

      • Den_VR 1 hour ago
        “We don’t know what’s going on” is essentially marketing. Sure we don’t _know_ but we have intuitions about why, where, and how to make certain changes…
      • pona-a 30 minutes ago
        It used to be OpenAI was a real research organization that wrote real open-access papers that aren't marketing brochures, and when they did large training runs, they released all artifacts including model weights. Now certainly they are anything but. We haven't learned learned anything meaningful about ML from OpenAI since GPT-3 was released.

        Their open-weights competitors like Facebook can at least claim some kind of public benefit, but it's still just running a well-understood algorithm on dubiously obtained data with longer and longer runs, give or take some inconsequential architectural tweaks.

        Anthropic's mechanistic interpretability work is the most "lab-like" of these, but it's still just secondary to selling subscriptions and fear-mongering for regulatory capture/investment/publicity.

      • travisgriggs 1 hour ago
        We also associate laboratories with evil scientists and Frankenstein and the like. I can just hear Boris Karloff (er Bobby Picket) uttering “I was working in the lab late one night. When my eyes beheld an eerie sight… … … …the monster mash”. If anything, I associate _uncertainty_ with labs. The result is never known up front, they’re a place of discovery.

        But I get your meaning. What should they be called instead? AI Sausage Factories maybe (cue Upton Sinclair?)?

        • Avicebron 1 hour ago
          > What should they be called instead? AI Sausage Factories maybe (cue Upton Sinclair?)?

          That's actually great? Slaughterhouses killing off the collective genius of humanity and grinding it into a bland paste for mass consumption.

    • sobellian 2 hours ago
      I reflected on this myself recently. Model distillation seems to be at least as fair a use as distilling a book.
      • causal 2 hours ago
        More than fair if you consider that the tokens are paid for.
        • dathery 2 hours ago
          Both labs even explicitly promise the customer owns the outputs. It feels like they want to have their cake (ensure enterprises don't get spooked away from using as many LLMs as possible) while eating it too (still arguing some level of control over the outputs).

          > Ownership of content. As between you and OpenAI, and to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output. We hereby assign to you all our right, title, and interest, if any, in and to Output.

          https://openai.com/policies/terms-of-use/

          > As between the parties and to the extent permitted by applicable law, Anthropic agrees that Customer (a) retains all rights to its Inputs, and (b) owns its Outputs. Anthropic disclaims any rights it receives to the Customer Content under these Terms. Subject to Customer’s compliance with these Terms, Anthropic hereby assigns to Customer its right, title and interest (if any) in and to Outputs.

          https://www.anthropic.com/legal/commercial-terms

          Obviously there is some bad behavior going on in the distillation scene with gray-market token resellers but that is "just" normal fraud.

          • zenoprax 1 hour ago
            > Both labs even explicitly promise the customer owns the outputs.

            > to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output

            If the argument is that the model itself is under copyright protection then "as permitted by applicable law" would be doing some heavy lifting. Assuming that were true, given that locally-run LLMs exist, what would be illegal: the distillation itself or the provision of service of the distilled model?

        • visarga 3 minutes ago
          Distilled content can also sever the direct link to infringement if the new models never saw the original texts.
    • toomuchtodo 2 hours ago
      YC does better if its startups get open weight frontier benefits. Garry’s just advocating for his book, which is his job. Consider how much capital YC portfolio companies would have to burn until liquidity if they have to pay OpenAI and Anthropic, versus relying on open weight frontier capabilities.
      • visarga 2 minutes ago
        > versus relying on open weight frontier capabilities

        ahem.. it happens even today, you can use open weight models directly and even fine tune

      • SOLAR_FIELDS 2 hours ago
        If someone proposes the right thing for selfish reasons, do we call that bad? Or do we call it proper incentive alignment?
        • dofm 42 minutes ago
          We used to call it enlightened self-interest.
  • dvt 1 hour ago
    I think OpenAI and Anthropic will go bust, or at least be scrapped for parts in the next 5 years or so. It's clear that the extreme cost used up for training is impossible to recoup, as inference is already being subsidized.

    It's also clear that, as Tan indicates, open-weight models will be (and basically already are) just as good as frontier models. It's all about the harness, baby. We will have two main forks in the road, and two new industries created:

        - AI hardware (NVidia/Cerebras/etc.), the equivalent of Intel/AMD
        - AI software (harnesses, assistants, etc.) the equivalent of Microsoft/Apple
    
    We already saw a glimmer of this with popularity of OpenClaw—the problem is that it's janky, hard to set up, inconsistent, and very hacker-esque. Imo "AI labs" will be a dying breed because there's no real money in the actual models if they get commoditized, which they already kind of are.
    • Legend2440 10 minutes ago
      >inference is already being subsidized.

      Inference is not being subsidized and in fact has pretty high margins.

      Similar-sized open weight models on openrouter are 15x cheaper per token than the big labs. This should reflect the isolated cost of inference, since 3rd party hosts have no reason to subsidize and no training costs to amortize.

      Only datacenter buildout costs are being subsidized.

    • FanaHOVA 36 minutes ago
      If harness is all that matters, a co-developed harness + model stack + large compute availability advantage + massive distribution advantage with data for post training will win the market.
  • consumer451 40 minutes ago
    > To him, the true AI doomer scenario is for all the immense power of frontier AI to wind up in the hands of a single powerful, proprietary provider. “The nightmare scenario, the doomer scenario for AI is that there’s just one company,” he said. “It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there’s one company that’s monolithic. And that would be bad.

    Well yes, as I think I said in a previous comment, on the current trajectory OpenAI and Anthropic will really stop releasing models due to distillation and regulatory pressures. Then, they would eat all knowledge work themselves, which would be the end of YC.

  • gr_norm 1 hour ago
    Society as a whole has paid into this technology: through the theft of its intellectual property, through having to deal with the pillaging of so many commons (digital or otherwise) by it, through skyrocketing energy and computing device prices, and even just through ordinary investment. Democratize the technology! At the very least, don't step in legally to prevent this from happening.
  • dofm 44 minutes ago
    Controlling what users and customers do with API calls to closed weight models feels constraining, and there’s a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service

    I do not agree with this man all that often, but that is very concisely put.

  • amelius 16 minutes ago
    Governments should be more concerned about the _people's_ personal data instead.

    Ban data brokers before you ban distillation.

    • Legend2440 5 minutes ago
      Unfortunately, the government doesn't want to ban data brokers because the government wants to buy from data brokers.
  • sick_of_slop 35 minutes ago
    Frontier labs trained their models on the entirety of human knowledge and didn't ask permission. It's a "want" or "should" it's a moral imperative to distill their models.
  • neilv 35 minutes ago
    Given the short-term pragmatic, conflicted way that AI tech adoption is happening... won't encouraging distillation effectively taint the entire space of open weights models, with the undisclosed biases of a few models that are under the influence of parties (certain billionaires and politicians) known for aggression and duplicity, and not for admirable ethics?

    Following news of companies and projects increasingly moving to open weights models.

    As AI gets more central to society, we really need to know how the weights were determined.

    Open weights isn't just "free as in beer"; it can be "free as in the mystery drug that creepy guy chatting you up at the bar offered you". And maybe even he doesn't even know everything that went into the tablets, since he too was being worked, by an organ-theft ring who will be harvesting both of you tonight.

    That's an analogy to get your attention. Your LLM probably isn't going to steal your organs. But in the current environment, it does and will have ideological biases determined by those with direct and indirect influence over it. And there will be a massive market for commercial influence biases (look at how previous generations of adtech invaded almost all technology companies). And there's incentive for military and spying capabilities to be buried in the models, perhaps as long-term sleepers. Maybe some organized crime trojans, too, depending which model you pick up.

    In this low-trust environment of the current real world, we need genuine open source models, not closed "open weights", and not mindlessly distilling black boxes gifted by sketchy powerful interests.

  • pton_xd 1 hour ago
    Agreed! Allow US companies to innovate by creating an ecosystem of smaller, more efficient open weight models and it will be a net benefit for everyone. Distillation is a good thing.

    Preventing token-consumers from developing competing products should be litigated as anti-competitive behavior.

  • layer8 1 hour ago
  • fmnxl 1 hour ago
    If it were so easy why aren't the frontier labs doing it themselves?
    • layer8 1 hour ago
      Distilled models are worse than the original, so you can’t fully compete. Also, if all frontier labs did that, there would be nothing left to distill from.
  • quicklywilliam 1 hour ago
    I see it as analogous to companies building fiber in the public ROW during the last big infrastructure bubble. Under the Telecoms Act, these companies had to allow competitors to use their fiber at a fair price.

    Similarly, AI companies should be required to allow distillation at a fair price. Fair Use doesn’t make sense as a social contract if it only cuts one way!

    • jimnotgym 1 hour ago
      But if they tried to set a fair price they would have to report how much money they are losing on each token sold. This might be bad for the real business of ai firms, hoovering up as much capital as they can
  • ViktorRay 1 hour ago
    https://youtu.be/ZIaOBAjvc38

    Garry Tan and Sam Altman recently did this interview together. They seemed pretty friendly with each other during it. Wonder what Sam Altman would say about Tan advocating for OpenAI’s models to be distilled.

    Then again this is the same OpenAI that has gotten into legal trouble recently regarding Apple’s IP so who knows

  • re-thc 1 hour ago
    There were comparisons and Muse Spark is so very similar to Fable / Opus... so...
  • etdznots 1 hour ago
    This is all based on the delusion that Chinese labs are mindlessly distilling the frontier.

    I would love for a US lab to be at or near the frontier with an open weight model, but it’s going to take some serious elbow grease, and yes some distillation (which btw OAI, anthropic et al, also use distillation of other’s outputs in their training)

  • Edwinat23 1 hour ago
    Freefire
  • okasaki 1 hour ago
    Like Gates saying there should be UBI, or Musk saying... well, whatever.

    They know it won't happen, so arguing for it is 'effectively free' and purely personal marketing.

    A bullshit game played by politicians and wannabes.

    • seanmcdirmid 1 hour ago
      Gates probably honestly believes in UBI; the guy is practical to a fault but evil misleading genius he is not. I actually don’t see any better options than UBI long term.
      • wannabe44 42 minutes ago
        Only ways to rise in a UBI society where AI is supposed to replace intellectual work is crime and prostitution. Smart people who want better lives than the average will have to get into crime.
        • seanmcdirmid 36 minutes ago
          A UBI society doesn't mean jobs aren’t available. There most certainly will be jobs. But with UBI and universal healthcare, the jobs can pay whatever the market really demands. People always complain about the government subsidizing low Walmart wages for example, but with UBI that argument is moot. Liberalizing the labor market wouldn’t mean less jobs, it would mean more (we would also have to lean more on corporate and consumption taxes rather than taxes around employment which would also make employment easier).
  • Hikikomori 1 hour ago
    Garry also goes to Thiels silicon valley church.
  • zombiwoof 1 hour ago
    [dead]
  • 9865322689965 1 hour ago
    [dead]
  • brcmthrowaway 1 hour ago
    [flagged]
  • zetazzed 1 hour ago
    Ok, but how do the economics of this work? Based on its settlement, Anthropic paid an average of $3000 per work they scanned based on their settlement (https://tech-insider.org/au/anthropic-copyright-settlement-2...). They and OpenAI pay billions per year for a mix of experts and normal people to label or create data. Why would they continue doing this if the value of this is immediately copied by open models? If your goal is to end the economics of generating and buying data for AI (and I recognize for some people this is really the goal) then sure, but if you want AI for various subfields of interest to continue improving then it's not workable.

    Back when people made arguments for software privacy, the argument was usually "big business will still pay and consumers wouldn't have paid anyways so it's ok for us to pirate" - I actually think that was fine for business software but terrible for indie games, whose market was 0% businesses.

    But in the AI case, it's not like they get to keep some of the value of their investment - it all gets cloned into models that businesses and consumers alike are happy to use. If someone knows how labs could continue to fund data creation and acquisition in this model, please do share!

    • etdznots 1 hour ago
      They can’t they’re literally fucked, and it’s not society’s problem! The whole world doesn't have to bend over to make sure a couple of lunatics who believe they are building a doomsday weapon also have a viable business model
      • dofm 41 minutes ago
        This made me laugh out loud but ain't it the truth.
    • kadoban 1 hour ago
      > Anthropic paid an average of $3000 per work they scanned based on their settlement

      Not sure you get to count breaking the law and getting in trouble in your cost-of-doing-business. That's a little too on the nose.

      You're basically arguing that a criminal syndicate must be allowed to continue and we're required to make their business model make sense?

    • kingleopold 1 hour ago
      %99 of the startups fail, they are venture backed. Nobody or no market forced them to spend like that. It's all their decisions
    • wonnage 1 hour ago
      Surely if you hoover up every book in existence to feed into an ai model you must be extracting more than 1.5B in value. If not then it’s not a viable business.