I don't expect Tan's position to be based on any kind of real moral high ground, but his conclusion is correct.
I love the "illicit distillation attacks" framing from the incumbents. There's nothing illicit. There's no attack. You just don't like it because it threatens your market position and business model.
Obviously it's not possible to run a company whose value is predicated on its IP that uploads said IP to a third party which might get access to it.
This could mean every potential serious customer would have no option but to seek alternatives to these online services.
I don't mean this as rhetoric, I did not think many people (except possibly those operating under government contracts, and 'normies' who don't know about these things) were under the belief that their IP was kept secret when they use these services.
https://privacy.claude.com/en/articles/10023548-how-long-do-... (see the additional info section)
You pay more for it, but if you care that much, use it.
AWS and Azure give you the same thing for Claude and ChatGPT, no need to be stuck with open weights. They might sometimes store some of it for other purposes (I don't know the specifics), but it is emphatically not being fed back to OpenAI or Anthropic.
The services have toggles to allow prompts to be used in the training set. There is a conspiracy theory that the toggle is a false distraction and they’re actually keeping everything, and that none of the employees involved will ever whistleblow this fact.
Outside of Internet comment sections, I think most people assume these US-based companies are doing what they say.
For enterprise use there are services like AWS Bedrock which have strict isolation guarantees. There are some people who still believe those guarantees are a lie, but once someone has reached that point I don’t think they trust anything that isn’t running entirely within their house. People in that category are a very small minority, but a very vocal minority.
You have access to all the frontier models, but...your inputs are not shared with the model vendors...neither are used to train the next model.
Why am I even doing the Amazon board job for them!??
I think this is being misunderstood. Codex has a toggle to allow your prompts to be included in training data. They’re saying they can’t be sure if the person had it on or off while using Codex to discuss the work.
They’re not saying that some prompts are mysteriously jumping into training data.
Also, there is a large market for AI services which don’t retain anything under any circumstances for enterprise customers.
If you are big enough to be able to withstand that, you’re already running (or trying to run) your own/open-weight models.
Besides, true ZDR is usually offered by third-parties with deals to host OpenAI models, such as Amazon (AWS Bedrock) and Microsoft (Azure).
2023:
"The approach also aligned with the company’s broader deployment strategy, to gradually release technologies into the world for people to get used to them. Some executives, including Altman, started to parrot the same line: OpenAI needed to get the “data flywheel” going."
https://www.theatlantic.com/technology/archive/2023/11/sam-a... https://archive.is/NmO5P#selection-979.907-979.1177
I don't think this has been a big secret.
So why is their own ToS so special? :)
LLMs should just pay a flat fee to use a specific book and thats it. Fees should be reasonable (not a million dollars per book), so long as the model doesnt spit out the entire book.
By your phrasing, it sounds like you still intend the possibility of companies owning copyrights; but how does that happen (other than copyrights already owned by companies grandfathered in)?
Copyright always starts off in the hands of individual human beings; it only ends up in the hands of companies when those human beings transfer ownership to a company. That ownership transfer can be automatic as a term of a contract, e.g. as part of a work-for-hire agreement. But no contract can cause the copyright to come into existence already held by the company instead of the individual. So if you abolish ownership transfer, you effectively make work-for-hire IP assignment invalid. What replaces it?
And, if "nothing"... then how do people pool the IP rights of their own small contributions to a large-scale work, into an IP pool that can be legally defended by a coherent legal entity, so that the large-scale work itself can have market value (i.e. so that sales of polished commercial bootlegs don't drive sales of the "authentic" work to zero)?
Keep in mind that, no matter how much we might want "mass distributed" media to have more-reasonable IP terms, the ability to sue for infringement is still critical to the existence of some forms of media. Especially "location-based" media, with no equivalent licensed broadcast right: movies still in theatre; concerts; live performances of plays and musicals; etc. If there's no legal team that can sue a movie theatre that shows an unlicensed copy of a given movie, then no movie theatre will ever bother with licensing movies again; "box office" goes to zero (from the movie company's perspective); and the incentive to create movies in the first place declines massively.
(You can see what this alternate world looks like from the few cases where movies screwed up the steps required to assert copyright, back before copyright was automatic. Night of the Living Dead (1968) is a good example: theatres — even upstanding large-chain theatres! — did indeed leap at the opportunity to show the movie unlicensed, and so Romero et al made effectively zero revenue off the work.)
I'm not saying this is an impossible problem. There are ways to accomplish this besides the way it's done now. (For example, individual-contributor IP could be retained by the original owners, but cross-licensed between individuals through a collaboration structure to form a coherent defensible IP pool, in exactly the same way that IP for e.g. video codecs is cross-licensed between corporations to form a coherent defensible IP pool today.) I'm just pointing out that the problem does need to be solved.
Daily reminder that piracy is the only enduring archive mechanism.
Or they could abide by the precedents they set and learn to compete. They shouldn't be allowed to have it both ways.
Weird, weird weird take. How does any of this work. Like you cant influence the first decision but you can magically influence the second?
Vote (well-informed of the candidate's policies) in every election you can, even the local ones that seem of little consequence.
Convince others to vote.
Make demands of your elected representatives. You can mail them, call them, etc.
The government is the people.
The Reagan-era and beyond successful convincing of people that the government is an unchangeable black box made up of shady actors out to destroy everything (see: Republicans still going on about the 'deep state' when they run literally everything) is a big part of how we got to this place. It was a self-fulfilling lie, now coming true as the people who sold the lie start grasping for unending power.
But we still have the ability to vote our way out of it. If we continue to fail to do so, then at an evolutionary level we have to consider that we collectively deserve all the bad that comes from it.
However the frontier labs don’t have to serve customers who are farming the service for distillation purposes. That’s their choice and they’re free to make it if they detect distillation happening.
The only way US maintains dominance over Chinese models is by having an ecosystem of models. Relying on a small set of frontier labs will only let you get ahead temporarily. I agree with Gary Tan on this one.
I don't think a correct remedy is to require companies to provide services even if they want to. A simple example: you drop a client because their asks / ways-of-working / etc is more headache and costs than it's worth. I've done that before, multiple times, in my freelancing life.
There is sooo much irony here.
I also think if Anthropic and OpenAI had been releasing Open models along the way, people wouldn't be nearly as suspicious of them.
By copying their programming style, you'll move the model towards that way of writing, which will move the model towards the values expressed in those documents.
I feel that Deepseek v4 got so claudified at the end that it was like Claude.
I’m sure the labs claim that their real innovation is in the RLHF, training and architecture. Keep that and just share the raw data somewhere.
> He also notes that the proprietary AI labs didn’t ask permission when they vacuumed up as much human knowledge as they could to train their models. They famously ingested plenty of copyrighted material without the permission of those intellectual property holders.
And many people's shared opinion (B):
>> I don't expect Tan's position to be based on any kind of real moral high ground, but his conclusion is correct.
...
It is very difficult to actually say NO to the fact that (A) was done, which then leads logically to conclusions as (B). But also we should remember that if these two hold (and (A) is an axiom more or less now), then it comes as no surprise that then also all opensource licensing is immediately rendered void and null, as keeping it would contradict (A) and would go against the very common and consequential logic in (B).
Copyright is so dead. And it was not me killing it with a cynical post on HN. Dunno why so many people still fail to face it. There is no way it can exist in its current form, because then immediately (A) happens and (B) follows.
Figure we’ll have to reckon with this next year in any case, guess we’ll see.
Someone with that lab could almost certainly figure out how do something stupid or destructive on their own, or bypass model safeguards somehow.
With what knowledge are you claiming this? If it turns out companies are using IP proxy networks would you change your mind?
What if the IP Proxy networks were used by criminals for similar attacks like DDoS or plain cyber attacks?
What if the source of the IP proxy networks were residential addresses to avoid detection?
What if the way these IPs were acquired were through pwned devices?
What if the credit cards used do not identify the company that carries the attack? What if they use the employee's personal credit cards? What if it's family members of employees? What if it's a network of personal credit cards where cc owners get a payment for making a purchase on their name? What if they are stolen ccs?
Not just a hypothetical btw, I believe almost all of these are true.
I think this should desactivate the moral high ground from which Anthropic is trying to speak. That they would want to make distillation orderly IMHO is fair, but to make it illegal is very rich from any AI frontier lab, really.
The moniker gives them an air of scientific, knowledgeable, tranquil, pro-social, pro bono work.-
Of course they are entitled to kill off a few mice, or pillage the commons to forward their "lab" work.-
The Atlantic argued this (rather well, IMO) a week or so ago - "There’s No Such Thing as an AI ‘Lab’" - https://www.theatlantic.com/technology/2026/09/stop-calling-...
But it's a black box! Nobody knows whats going on inside! It's all transformative! Sure...
But I get your meaning. What should they be called instead? AI Sausage Factories maybe (cue Upton Sinclair?)?
That's actually great? Slaughterhouses killing off the collective genius of humanity and grinding it into a bland paste for mass consumption.
Their open-weights competitors like Facebook can at least claim some kind of public benefit, but it's still just running a well-understood algorithm on dubiously obtained data with longer and longer runs, give or take some inconsequential architectural tweaks.
Anthropic's mechanistic interpretability work is the most "lab-like" of these, but it's still just secondary to selling subscriptions and fear-mongering for regulatory capture/investment/publicity.
> Ownership of content. As between you and OpenAI, and to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output. We hereby assign to you all our right, title, and interest, if any, in and to Output.
https://openai.com/policies/terms-of-use/
> As between the parties and to the extent permitted by applicable law, Anthropic agrees that Customer (a) retains all rights to its Inputs, and (b) owns its Outputs. Anthropic disclaims any rights it receives to the Customer Content under these Terms. Subject to Customer’s compliance with these Terms, Anthropic hereby assigns to Customer its right, title and interest (if any) in and to Outputs.
https://www.anthropic.com/legal/commercial-terms
Obviously there is some bad behavior going on in the distillation scene with gray-market token resellers but that is "just" normal fraud.
> to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output
If the argument is that the model itself is under copyright protection then "as permitted by applicable law" would be doing some heavy lifting. Assuming that were true, given that locally-run LLMs exist, what would be illegal: the distillation itself or the provision of service of the distilled model?
ahem.. it happens even today, you can use open weight models directly and even fine tune
It's also clear that, as Tan indicates, open-weight models will be (and basically already are) just as good as frontier models. It's all about the harness, baby. We will have two main forks in the road, and two new industries created:
- AI hardware (NVidia/Cerebras/etc.), the equivalent of Intel/AMD
- AI software (harnesses, assistants, etc.) the equivalent of Microsoft/Apple
We already saw a glimmer of this with popularity of OpenClaw—the problem is that it's janky, hard to set up, inconsistent, and very hacker-esque. Imo "AI labs" will be a dying breed because there's no real money in the actual models if they get commoditized, which they already kind of are.Inference is not being subsidized and in fact has pretty high margins.
Similar-sized open weight models on openrouter are 15x cheaper per token than the big labs. This should reflect the isolated cost of inference, since 3rd party hosts have no reason to subsidize and no training costs to amortize.
Only datacenter buildout costs are being subsidized.
If it were true that Anthropic and OpenAI were profitable on all inference they wouldn’t need to constantly raise so much money. Anthropic regularly announce huge investments in infrastructure but it is all smoke and mirrors, data center build out costs aren’t being paid by OpenAI and Anthropic, they’re financed externally. Google, for example, are backstopping tens of billions of datacenter build outs that are being financed based on commitments but not investment from Anthropic.
You are underestimating the insanity of subscription subsidization. Being profitable on API inference is meaningless when it is such a small proportion of usage and is only going to fall off a cliff as cheap open weight models become more capable.
https://hraness.com/writing/my-girlfriend-asked-me-why-i-hav...
The absolute majority of tokens are being subsidized and as soon as the subsidies end usage will fall off a cliff, rendering all the data center buildout a terrible waste of money.
Do we know that? As I understand it, enterprise customers pay more. Do we know the usage breakdown between monthly subscribers vs enterprise accounts? I agree that it's inevitable that subsidized subscriptions are unlikely to last forever, but that's not the only assumption in your argument.
Edit: I think "enterprise customers pay more" was poorly phrased. I mean that enterprise customers are charged per token, presumably with a profit margin, and thus are not subsidized. While personal accounts are (thought to be) highly subsidized if you consistently max out the quotas. We also don't know what proportion of personal accounts do that though, which is another big question mark.
I know people that have the most expensive plan on all the platforms... because
The other side to that is, what is 'cost'? Is cost just inference or are expenses also being taken into account? Because the expenses of these companies are huge to build the models.
1. Companies are trying to decrease costs, not increase it, and are looking at alternatives
2. Competitors are catching up, and even if the frontier labs are "better" at some things (like writing plans or complicated analysis), the competitors can take a lot of the inference on routine tasks like implementing a well-defined plan
3. The frontier labs don't just need to have high margins right now. They have to pay back their massive liabilities.
I was referring to the "AI labs" here. Sam Altman himself conceded that OpenAI is losing money on the $200 subscription. Using open-weight/open-source models is indeed cheaper (and no reason for inference to be subsidized).
>Sam Altman himself conceded that OpenAI is losing money on the $200 subscription.
They have since stopped offering the $200 subscription, probably for this reason.
Subscription margins are harder to judge because it depends on usage; token costs are a better comparison.
The US can no longer keep global trade secure on the high seas. What if the supply chains for GPUs get disrupted for months, a year? Then what?
I fear Google will win in the longer run.
Maybe it is “sunked cost” or maybe it is “I will do it myself dammit”.
Well yes, as I think I said in a previous comment, on the current trajectory OpenAI and Anthropic will really stop releasing models due to distillation and regulatory pressures. Then, they would eat all knowledge work themselves, which would be the end of YC.
I do not agree with this man all that often, but that is very concisely put.
Same thing as Cliff Notes imo. In every other area of manufacturering and tech I can use a machine to build a new machine that competes with the original machine. Should Milwaukee be able to prevent DeWalt from using their drill to make a competing drill? Should Jetbrains ban Eclipse contributors from using their IDE?
Preventing token-consumers from developing competing products should be litigated as anti-competitive behavior.
I think that software execs should not incentivize users or other execs to break Terms of Services, or contracts of any kind.
An executive or manager of a company that breaks contracts is worth 0, there's no incentive to do business with them, if you know they will agree to doing or not doing something and then breaking that promise.
The word of a businessman is their most valuable asset, Tan is signalling that he is either misinformed on what Chinese distillation consists of, or that it's ok to do it.
FAQ:
- "But the frontier models do bad things too"
- An argument worthy of a 5 year old, one civil issue doesn't negate the other, bring it to a court if you have an actual claim against OAI or Claude, etc...
- "Companies have the right to reverse engineer"
- Ok, do it, but the moment you are creating 10K accounts in a Distributed fashion (Distributed as in the first D of DDoS), using IP proxies and stolen credit cards or your employees and employee family credit cards, you are not doing it because you believe you have a right, you are doing it despite not having a right to it.
EDIT:
Re(actually)reading the article, Tan's take is a bit more nuanced, he seems to be advocating for regulation to restrict the capacity of Foundation models to restrict usage, on the basis (or to the extent) that it was trained on public data, and therefore it belongs or attributes its success to a wealth of the commons.
My pre-existing quip is against those that want to solve this as-is by breaking the ToS. I think that's a weak version of Free Software position, it's very weak to complain that some software is proprietary and want to use it anyway, the strong FS position is that you don't even want to use it if it's proprietary, you won't catch a FS activist pirating proprietary software, they just don't use it and develop alternatives. Similarly it's not a FS position to distill a proprietary model (where you still wouldn't have source code at any rate).
Isn't this exactly what Dario wanted? He thought he knew what's best for the humanity...
Back when people made arguments for software privacy, the argument was usually "big business will still pay and consumers wouldn't have paid anyways so it's ok for us to pirate" - I actually think that was fine for business software but terrible for indie games, whose market was 0% businesses.
But in the AI case, it's not like they get to keep some of the value of their investment - it all gets cloned into models that businesses and consumers alike are happy to use. If someone knows how labs could continue to fund data creation and acquisition in this model, please do share!
Not sure you get to count breaking the law and getting in trouble in your cost-of-doing-business. That's a little too on the nose.
You're basically arguing that a criminal syndicate must be allowed to continue and we're required to make their business model make sense?
This is how Uber worked. They didn't just break the law in different countries, in several they actively misled government/law enforcement investigations. Google "Greyball".
I suspect the top labs will come up with a business model that doesn't involve handing out their secret sauce for everyone else to reverse engineer. Perhaps restricting their top models to select high paying government/enterprise contracts. Or maybe a bespoke "describe the problem and we'll solve it for you" type service.
Following news of companies and projects increasingly moving to open weights models.
As AI gets more central to society, we really need to know how the weights were determined.
Open weights isn't just "free as in beer"; it can be "free as in the mystery drug that creepy guy chatting you up at the bar offered you". And maybe even he doesn't even know everything that went into the tablets, since he too was being worked, by an organ-theft ring who will be harvesting both of you tonight.
That's an analogy to get your attention. Your LLM probably isn't going to steal your organs. But in the current environment, it does and will have ideological biases determined by those with direct and indirect influence over it. And there will be a massive market for commercial influence biases (look at how previous generations of adtech invaded almost all technology companies). And there's incentive for military and spying capabilities to be buried in the models, perhaps as long-term sleepers. Maybe some organized crime trojans, too, depending which model you pick up.
In this low-trust environment of the current real world, we need genuine open source models, not closed "open weights", and not mindlessly distilling black boxes gifted by sketchy powerful interests.
Ban data brokers before you ban distillation.
At the end of the day they were built from data that did not belong to them. So it would be fair that humanity REQUIRES to give back the output of that.
It's a bit like the free software thing: you can still make money from it and providing service to it, but if you build it based on another free stuff the derivative should be free.
Why not do the same for intelligence ?
Similarly, AI companies should be required to allow distillation at a fair price. Fair Use doesn’t make sense as a social contract if it only cuts one way!
Garry Tan and Sam Altman recently did this interview together. They seemed pretty friendly with each other during it. Wonder what Sam Altman would say about Tan advocating for OpenAI’s models to be distilled.
Then again this is the same OpenAI that has gotten into legal trouble recently regarding Apple’s IP so who knows
Genuinely fucking crazy we pay money for fast access to autocomplete of stolen human remains.
I would love for a US lab to be at or near the frontier with an open weight model, but it’s going to take some serious elbow grease, and yes some distillation (which btw OAI, anthropic et al, also use distillation of other’s outputs in their training)
They know it won't happen, so arguing for it is 'effectively free' and purely personal marketing.
A bullshit game played by politicians and wannabes.
I think the only way forward is wealth tax. Rich accumulated so much wealth already, that they don't need to put it to profitable businesses.
it works for RE already without liquidation
> . I would opt for a tax on loans instead (you have to prepay tax on loans that use investments as collateral and no more step up in basis on death).
rich just will move from this scheme to something else, and nothing changes.
Maybe if we had a world government or something.
Also, I think it is equilibrium of interests of all involved parties: rich pay 0.5%/y of wealth tax, population is healthier, country is stronger and protects interests and safety of rich. The problem is mostly to make them realize this.