Nvidia CEO Jensen Huang has publicly broken with the White House over one of the most charged questions in the US-China AI rivalry: whether Chinese labs training models on American models' outputs amounts to legitimate competition or theft. Asked on CNBC's Squawk Box on Monday whether distillation was "not robbery," Huang replied: "That's called competition."

His remarks put the head of the world's most valuable chipmaker at odds with the administration's official framing. Treasury Secretary Scott Bessent described the practice as "theft" in July and threatened sanctions against overseas companies that use it to extract capability from US-built models, according to CNBC. For more context on this story, see our ongoing AI trends.

What Distillation Is — and Why It Became a Flashpoint

Distillation, in the AI industry's usage, refers to training one model on the outputs of another — typically a smaller, cheaper student model learning to imitate a larger, more capable teacher. It is a standard, widely practiced technique, and US AI companies use it extensively on their own models.

The controversy stems from who is doing the distilling. US officials have accused Chinese AI companies of using the technique to squeeze advanced capability out of American frontier models, and distillation has become a key flashpoint in the race between Washington and Beijing for AI supremacy, CNBC reported.

The accusations have grown sharper in recent weeks. Earlier this month, the US Cybersecurity and Infrastructure Security Agency accused China's AI companies of conducting "industrial-scale knowledge distillation campaigns" that violated US companies' terms of use. Anthropic separately said this month that it had found Alibaba, the company behind the Qwen family of models, and DeepSeek both engaging in what it called illicit distillation.

How Distillation Works, and Why It Is Hard to Police

The technique itself is straightforward. A developer prompts a powerful model millions of times, harvests its responses, and trains a smaller model to reproduce them — compressing the teacher's capability into something cheap enough to run at scale. Because the training data is text rather than code or weights, there is usually no technical fingerprint proving which teacher produced it.

That is what makes enforcement so contentious. The alleged "violation" in most distillation disputes is contractual rather than technical: terms of use generally forbid using a model's outputs to train a competing model, but a company that obtains outputs through an ordinary API subscription is difficult to distinguish from any other customer. Detection typically depends on statistical evidence — distinctive phrasing, errors, or benchmark behavior patterns — rather than a smoking gun.

Huang's "know your customers, and disable the service" comment speaks directly to that reality: in his framing, the party best positioned to prevent unwanted emulation is the company selling access, not a regulator reviewing training data after the fact.

Huang: 'Competition Makes Everything Better'

Huang did not dispute that the practice happens to Nvidia's own products. "You're allowed to test somebody else's products all you want," he told CNBC, adding that Nvidia's products are sometimes stripped "down to bones" as companies try to learn how they work.

"I'd really prefer they didn't," he said. "I'd really prefer that nobody learns from our products, and we have the benefit of just cruising along. But, you know, frankly, competition makes everything better."

He also suggested the remedy for companies worried about being studied is commercial, not legal: "If you don't like that, if you don't like people to use your products, all you [have to do is] know your customers, and disable the service."

The White House did not immediately respond to a request for comment from CNBC.

Why the Distinction Matters

The gap between "competition" and "theft" is not merely rhetorical. If distillation is treated as ordinary market rivalry, the response is product strategy — tighter terms of service, usage detection, restricting access to frontier outputs. If it is treated as theft, the response is sanctions, export controls and legal exposure for overseas companies, the path Bessent's July threat pointed toward.

That distinction has direct consequences for the AI supply chain. Nvidia sells the accelerators on which frontier models on both sides of the Pacific are trained, and any sanctions regime aimed at companies that distill from US models could reshape who is allowed to buy what. Huang's framing — that buyers will study what they buy, and sellers should account for it — is, in effect, an argument against treating model emulation as an enforcement problem.

It also lands in the middle of a widening public split over how the US should compete with Chinese AI. Government agencies have spent the month escalating accusations, while one of the industry's most prominent figures has just argued, on camera, that the accused behavior is how markets work.

For now, the two positions coexist uneasily: Anthropic's allegations against Alibaba and DeepSeek remain unresolved, CISA's accusations have not led to announced sanctions, and Huang — whose chips remain in demand everywhere — has made the case that the industry's openness is inseparable from its speed.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →