Nvidia’s Huang Calls AI Model Distillation Competition, Not Theft

The Nvidia CEO says providers can cut off customers they do not want using their products. Officials and Anthropic allege some labs broke access rules.

By 2 min read
Nvidia’s Huang Calls AI Model Distillation Competition, Not Theft
Nvidia’s Huang Calls AI Model Distillation Competition, Not Theft

Listen to this story

The audio brief

About 1:22
0:001:22
Read transcript
Nvidia CEO Jensen Huang says model distillation is competition, not theft—a direct rebuttal to Treasury Secretary Scott Bessent, who has threatened sanctions over the practice. The disagreement matters because distillation is a standard way to train a smaller AI model using answers from a larger one. Anthropic described it in February as widely used and legitimate, including for making smaller versions of a lab’s own systems. But Anthropic says DeepSeek, Moonshot and MiniMax crossed a different line. It alleges they used about 24,000 fraudulent accounts and proxy services to send Claude more than 16 million exchanges, with prompts aimed at specific capabilities. Those are Anthropic’s findings, not independently established figures in the report. Huang’s argument is that companies can test competitors’ products, and providers should control access: know who the customers are, then cut off service when necessary. He did not directly address Anthropic’s account-fraud allegations. That distinction is central: Bessent has called capability extraction theft, while Huang treats learning from a rival as competition and puts the practical burden on the provider. There is still no announced sanction, and the trigger remains unclear. The question ahead is whether penalties would target distillation itself, or conduct such as breaking a provider’s access rules.

Story brief

3 key points

Nvidia CEO Jensen Huang says providers should treat model distillation as competition and manage unwanted use by controlling customer access, rather than treating the method itself as theft. The dispute has policy consequences: Treasury Secretary Scott Bessent has threatened sanctions, but has not announced them, and the conduct that would trigger penalties remains undefined. Anthropic alleges DeepSeek, Moonshot and...

  1. 01

    Anthropic’s February disclosure called distillation widely used and legitimate, including for creating smaller versions of a lab’s own models.

  2. 02

    Anthropic said the labs used proxy services and targeted prompts; the account and exchange totals are its findings, not independently established figures in the article.

  3. 03

    Bessent’s threatened sanctions have not been announced; the unresolved policy question is whether penalties would target distillation itself or violations of access rules.

A training method has become a fight over what counts as fair competition in AI. In a CNBC interview Monday, Nvidia CEO Jensen Huang called model distillation “competition,” pushing back on Treasury Secretary Scott Bessent’s description of it as “theft.” U.S. officials and Anthropic have accused Chinese AI labs of violating access rules while using the technique.

From training method to sanctions threat

Distillation means training one AI model on answers produced by another. It is not inherently illicit: in a February disclosure, Anthropic called it a widely used, legitimate way to build models, including smaller versions of a lab’s own systems. The company also warned that competitors could use it to acquire another lab’s capabilities illicitly.

In that disclosure, Anthropic alleged that DeepSeek, Moonshot and MiniMax generated more than 16 million exchanges with its Claude model through about 24,000 fraudulent accounts. It said the labs used proxy services to access Claude at scale while evading detection, and aimed repeated prompts at particular capabilities. Those figures and accusations are Anthropic’s findings.

Bessent raised the stakes in July, calling distillation “theft” and threatening sanctions against overseas companies using it to extract capabilities from U.S.-built models. Earlier this month, the Cybersecurity and Infrastructure Security Agency accused Chinese AI companies of industrial-scale campaigns that violated U.S. companies’ terms of use. Anthropic separately accused Alibaba and DeepSeek of illicit distillation; China rejected the claims.

Huang puts the choice with providers

Asked on CNBC whether distillation was “not robbery,” Huang replied, “That’s called competition.” Companies are allowed to test one another’s products, he argued. He said companies sometimes take apart Nvidia’s products to learn how they work. He would prefer they did not, but said competition makes products better.

Huang’s answer to unwanted use was to know your customers and disable the service. That places responsibility for controlling access with the provider. His remarks in the CNBC interview did not specifically address Anthropic’s allegations about fraudulent accounts.

Two ways of drawing the line

01Competition

Huang

Huang says companies may test competitors’ products and calls learning from them competition.

02Theft

Bessent

Bessent used the theft label while threatening sanctions over extracting capabilities from U.S. models.

The next policy decision

Bessent has threatened sanctions, not announced them. Any such action would force a sharper question than whether distillation is good or bad: which conduct would trigger a penalty? Huang has defended testing rival products; the agency and Anthropic have alleged violations of access rules. His interview leaves that gap between the positions unresolved.

Sources

  1. anthropic.comDetecting and preventing distillation attacks
  2. cnbc.comJensen Huang says AI distillation is 'competition.' Scott Bessent has called it 'theft'

Loading discussion...

YOUR READING SPACE

Notifications