Huang's remedy for AI distillation: know your customers, cut them off
Nvidia's CEO told CNBC that training on rivals' model outputs is "competition," not theft — and that the fix is access control, not sanctions.
A CEO and a Treasury Secretary, describing the same act
Asked on CNBC's Squawk Box on Monday whether AI model distillation was "not robbery," Nvidia CEO Jensen Huang answered: "That's called competition." In July, Treasury Secretary Scott Bessent had described the same practice as "theft" and threatened sanctions against overseas companies using it to extract capability from U.S.-built models. The White House did not immediately respond to CNBC's request for comment.
The gap between those two words — competition, theft — is not rhetorical. It determines whether this becomes an export-control problem, a contract dispute, or nothing at all.
What distillation actually is
Distillation, in its original and entirely legitimate form, is a compression technique. You have a large, expensive model. You run huge volumes of prompts through it, capture its answers, and use those answers as training data for a smaller model. The small model learns to imitate the large one's behaviour without ever seeing the large one's weights or training data. Engineers call the big model the teacher and the small one the student.
The technique is old and uncontroversial when a lab distils its own model. What is contested is doing it to someone else's model, through their public API, at scale.
Here is why that matters. The expensive part of building a frontier model is not the architecture — those are broadly published. It is the training run, the data curation, and above all the post-training work that makes a model helpful, safe and well-behaved. That last layer is the accumulated product of enormous human feedback effort. A model's outputs encode it. If you can buy API access and generate millions of high-quality responses, you are capturing a compressed version of that investment for the price of inference tokens.
Crucially, nothing is copied in the conventional sense. No weights are exfiltrated. No code is stolen. The student model is trained on text that the teacher model was paid to produce.
Why "theft" is the harder word to defend
This is where Huang's position has legal gravity, whatever his commercial motives. "You're allowed to test somebody else's products all you want," he said, noting that Nvidia's own hardware gets stripped "down to bones" by competitors trying to understand it. "I'd really prefer they didn't," he added. "I'd really prefer that nobody learns from our products... But, frankly, competition makes everything better."
Note what the accusations actually allege. The Cybersecurity and Infrastructure Security Agency, earlier this month, accused Chinese AI companies of "industrial-scale knowledge distillation campaigns" that violated U.S. companies' terms of use. Anthropic said it found Alibaba, developer of the Qwen models, and DeepSeek engaging in "illicit distillation." China has rejected the claims.
Terms of use are a contract between a provider and its account holder. Breaching one is not the same as theft, and enforcing one against a foreign company with no U.S. presence is difficult — which is precisely why the conversation has drifted toward sanctions.
Huang's counter-proposal is the genuinely new part of this exchange, and it is unglamorous: "If you don't like people to use your products, all you have to do is know your customers, and disable the service." That places the burden on the model providers' own identity verification and abuse detection rather than on federal trade policy. It is also, conveniently, a framing in which nobody needs to restrict chip sales.
Questions You Should Be Asking
- If distillation is only a terms-of-use violation, what legal instrument actually supports sanctions — and has anyone named it?
- Can any provider prove a specific model was distilled from theirs, or is the evidence statistical similarity that a competitor could dispute?
- What does your own API contract say about using outputs to train models — and have you checked whether your vendors' contracts allow them to train on yours?
- Nvidia sells the hardware that trains models on both sides of this dispute. How should that shape the weight given to its CEO's definition of fair competition?
- If "know your customers" is the answer, who verifies identity at inference scale, and what happens to open access when they do?
What To Watch Next
Watch whether the U.S. moves from accusation to instrument. Bessent's July threat of sanctions remains a threat; CISA's finding rests on terms-of-use breaches, not statute. The signal that this is real is a named designation against a specific company, or a formal rule defining distillation as a controlled activity. Absent that, Huang's framing — that this is ordinary competition, policed by vendors' own access controls — becomes the default by attrition.
- 1Write anti-distillation clauses into your model API terms of service now, since contract law is your fastest remedy when export controls don't apply.
- 2Monitor API usage for distillation signatures — high-volume, diverse, systematic querying patterns — and cut off suspicious accounts immediately.
- 3Run KYC verification on enterprise API customers so you know who's behind each key before capability extraction becomes irreversible.
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
