
🔮 Exponential View #594:Copy that: The curious case of AI distillation|AI 蒸馏的奇特案例|英文原文 + 中文翻译
完整呈现 Exponential View #594 的英文原文与中文翻译,讨论 AI 蒸馏的法律灰区、中国芯片自给率、美国劳动力市场与 AI 话语中的极端化,并保留原文引语、数据和外部链接。
English original
🔮 Exponential View #594: Copy that: The curious case of AI distillation
Plus: A prophet of terror & AI doomers; bioweapons, orcas & the Amazon success
Azeem Azhar
Jul 26, 2026
Intro
Hi,
Welcome to the latest Sunday briefing! I am off on holiday for a couple of weeks. The team will continue to tend to Exponential View while I’m gone, so you won’t miss a beat.
Azeem
Distillation grey zone
On 1st September 1789, Samuel Slater set sail from England for New York. He’d learned that the Pennsylvania legislature had recently passed an act awarding £100 to a British textile worker who smuggled high-end machinery into the state. America was going to great lengths to acquire industrial know-how, by any means possible.
Britain had made it illegal to export textile machinery and technical drawings. The ban extended to prevent textile workers from emigrating. Slater had worked in mechanized textile mills and saw his chance.
He committed the entirety of Richard Arkwright’s system – the first factory method for spinning cotton – to memory. He disguised himself as a farm laborer and broke the laws of his nation as he carried himself across the Atlantic, valuable know-how secretly distilled into his brain.
By 1790, Slater was a partner in a cotton mill in Pawtucket, Rhode Island, built from the plans he memorized. President Jackson called him the "Father of American Manufactures." He died in 1835 worth around a billion dollars in today’s terms.1
Today’s question is to what extent are Chinese AI labs distilling the outputs of American AI models – and is it really a problem? The easy answer is the hawkish one: hugely and yes, it is. But it’s not the only answer.
First of all, distillation is a decades-old machine learning technique in which a larger model can train a smaller, more efficient model. A lab running distillation internally is not an issue. But it is possible to distill a model from the outside (even without the provider’s permission). This is the accusation against Kimi and other Chinese labs.
Diogo Almeida, a four-year veteran of OpenAI, explains that effective distillation is much harder today than a few years ago, when AI models helpfully provided their reasoning traces. What Almeida calls "behavior parroting" is to learn from final answers, the least powerful approach but might still work well to help bootstrap another model.
There is substantial evidence that both Chinese and American researchers have trained models on the outputs of frontier systems. Stanford’s Alpaca project has admitted as much. Anthropic has alleged that DeepSeek, Moonshot and MiniMax have used more than 16 million Claude chats via 24,000 fake accounts. Michael Kratsios, Trump’s science chief, says he now has evidence of how Moonshot ran distillation attacks.
Anastasios Angelopoulos, the CEO of Arena, a benchmarking company, makes the case that Kimi K3 is exceeding the performance of some of the top US models, something distillation alone doesn’t allow, and he predicts that "American labs will start distilling Chinese intelligence."
It isn’t clear that distillation is illegal yet. Nathan Lambert points out that "[t]here’s no legal precedent that model outputs are IP." The US Copyright Office’s 2023 statement on AI confirms as much:
When an AI technology determines the expressive elements of its output, the generated material is not the product of human authorship. As a result, that material is not protected by copyright.
Unlike the case of Samuel Slater, who knew he was breaking British law, the problem here is a case of the exponential gap: the technology has stepped ahead of the law.2 If labs have IP in outputs of their models, they will essentially have IP in every future economic activity of all their users.
It also weakens the labs’ own position – why should AI models be prevented from consuming Anthropic’s IP when Anthropic is allowed to consume yours and mine?
Bahrad Sokhansanj has some other sensible suggestions, summed up as follows. Address distillation but scope it narrowly, only focusing on the real harm done, with the right instruments. Is it about national security? Or something else? Regulate more broadly, and this will play into the labs’ desire to skew the regulatory field in their favor.
Again, there is precedent: in 1824, once he was settled as a prominent American industrialist, Samuel Slater lobbied for protectionist tariffs to stifle foreign competition. By then, he was also known as "Slater the Traitor" back in his hometown.
See also:
- Will Kimi K3 change the economics of AI? Our analysis.
- Satya Nadella was one of many tech leaders to force the case for open-weight models to quieten rumors that the American administration was considering limiting them. Jensen agrees:
For my first post, I’m sharing a letter @JensenHuang signed on why open models matter. AI will transform every industry, power every company, and be built by every country. Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.
A MESSAGE FROM OUR SPONSOR, OKTA
To get AI security right, take care of identity
When you and your team deploy AI agents, identity becomes your strategic infrastructure. An agent is an actor that reads your data, calls APIs, and does things on your behalf. You need to give it clear permissions and to audit its trails.
Okta’s AI Identity Readiness assessment will score the security of your AI agents and show exactly what you need to fix to go to production with peace of mind.
Run Okta’s 5-minute survey to evaluate your agents.
China’s chip chase
In 2015, Made in China set a target of 70% self-sufficiency in semiconductors within a decade. It was often mocked as fanciful and missed wildly. Data from Morgan Stanley now shows that domestic suppliers will have met about 41% of China’s AI chip demand in 2026, up from 20% in 2023. Beijing may hit its 70% threshold five years late.
Compute-weighted, the 41% figure delivers less compute compared to Nvidia, but for the purposes of strategic autonomy, the quality gap is increasingly a non-issue.
The spark was Washington’s export restrictions. "If the U.S. hadn’t forced our country, our company and our industry into a corner, we would never have done something like this", says Huawei’s deputy chairman. It has become an "all-out push" according to this excellent reporting.
A leaked conversation between DeepSeek’s boss, Liang WenFeng, and several investors supports this. Liang says:
What’s the gap with the U.S.? Only one thing: resources. We don’t have enough GPUs – our count is still small. […] Domestic chips now have a historic opportunity. Previously, adaptation was hindered by poor ecosystem… But that’s changing. NVIDIA CUDA’s moat is eroding rapidly.
Full transcript and context at Grace Shao’s blog.
We the people
Peter McCrory, Anthropic’s Head of Economics, points out that the US labor market has shrugged at AI. Unemployment is at 4.2%, and Anthropic’s data finds no worsening unemployment even in the most exposed occupations.
AI augments rather than replaces, for now. Not a single profession has been 100% handed over to machines yet. Every job still needs human effort. It is changing how work gets done, and if workers get more productive, value shifts inside existing roles, and those who use the technology best stand to benefit.
The final hard-to-automate tasks, the "weak links", as Professor Chad Jones calls them, are the things only a human can do. Companies will need people to get them done, and this protects employment, keeping a decent share of income in human paychecks.
Here is another take. People still matter and will continue to matter. Europe creates far fewer successful innovative companies than the US. One reason I’ve often argued is the simple cost of changing the workforce. I think of startups as exercises in making mistakes and learning from them. Every additional cost to making a mistake means an opportunity to learn not taken. Yoram Wijngaarde finds a simple relationship (correlation is not causation) that shows that the more expensive it is to let go of staff, the lower the rate of unicorns per capita.

Prophet motive

A new biography of Jean-Paul Marat, one of the leaders of the French Revolution, reviewed in the current LRB, is worth reading for anyone trying to make sense of today’s AI debate.
Stanford historian Keith Baker3 has a new biography of the journalist and politician. He argues that Marat hates mediation of any type, from Newtonian formulas to parliamentary assemblies and calm discussion, anything that stands between the people and the truth. He tried to write a daily pamphlet, shouted rather than argued and manufactured intimacy. "By making his journal ‘more interactive, more dynamic, more personal’, he fashioned an intimacy that allowed him to speak for the people."
In amongst this, his paranoia did help him identify real corruption and institutional betrayal. Baker calls him the first modern populist.
High-frequency publishing, paranoia as analysis, a parasocial closeness and the constant insistency that any complexity is just conspiracy in disguise… Well, AI discourse is now selecting for exactly this Marat-like temperament.
While today’s keyboard warriors carry none of the physical violence of Marat’s Terror, there is a similar underlying logic against nuance and complexity. Doomers and accelerationists share patterns – purge rhetoric, aggressive polemics, and the framing of every whiff of nuance as corrupt. What is left are the extremes. Call to mind imminent economic disaster; catastrophic fraud; utopian abundance… or, simply, the transformation of the human condition.
What can get lost in these extremes is the reasoned position that admits and examines evidence. A position that balances probabilities and accepts answers might be complex, incomplete and contingent.
See also:
- 💪🏼 Really stoked that AMD’s CEO Dr. Lisa Su opened her keynote with Exponential View data. You can get the same data here.
Short morsels to appear smart at dinner parties
- Why AI-assisted bioweapons won’t kill us. Via EV member Abi Olvera
- 🏋🏼♀️ The share of UK businesses using AI has nearly tripled since 2023, but most firms are still dabbling.
- Arsenal FC is building AI models for football (soccer).
- Young people are more likely to gamble in financial markets when important life goals, like buying a house, feel out of reach.
- Global air and sea surface temperatures are headed for a new record.
- Good news from the Amazon: wildfires are at a record low this year and deforestation is at a 10-year low. H/t EV member Angus Hervey
- Vintage LLM 😎 Training AI models only on pre-1931 texts helps researchers study what AI can do without contamination from the modern web.
- Stripe is in talks to buy OpenRouter.
- Intel is shipping the first chips with layers printed on ASML’s $380 million High-NA EUV machines.
- Know thy maths. Michael Liebreich breaks down why the EU’s 46% electrification target by 2040 is mathematically unachievable. Relevant for anyone working in policy, really.
- 🐳 Orcas preparing food for their young? Amazing.
Thanks for reading!
中文翻译
🔮 Exponential View 第 594 期:复制那一份:AI 蒸馏的奇特案例
另有: 一位恐怖主义预言家与 AI 末日论者;生物武器、虎鲸和亚马逊的好消息
Azeem Azhar
2026 年 7 月 26 日
开场
你好,
欢迎阅读最新一期周日简报!接下来几周我会去度假。虽然我不在,团队仍会继续打理 Exponential View,所以你不会错过任何内容。
Azeem
蒸馏灰色地带
1789 年 9 月 1 日,Samuel Slater 从英国启程前往纽约。他得知,宾夕法尼亚州议会最近通过了一项法案:向把高端机器偷偷带入该州的英国纺织工人奖励 100 英镑。为了获得工业知识,美国当时几乎不惜一切手段。
英国法律禁止出口纺织机械和技术图纸,禁令甚至扩展到禁止纺织工人移民。Slater 曾在机械化纺织厂工作,看到了机会。
他把 Richard Arkwright 的整套系统,也就是第一套棉纺工厂生产方法,全部记在脑中。他把自己伪装成农场劳工,带着这份偷偷蒸馏进脑中的宝贵知识横渡大西洋,也因此触犯了本国法律。
到 1790 年,Slater 已成为罗德岛州 Pawtucket 一家棉纺厂的合伙人,那家工厂就是按他记住的图纸建成的。总统 Jackson 称他为「美国制造业之父」。他于 1835 年去世,按今天的价值计算,身家约 10 亿美元。1
今天的问题是:中国 AI 实验室在多大程度上蒸馏美国 AI 模型的输出?这真的有问题吗?强硬派的答案很简单:蒸馏规模巨大,而且当然有问题。但这不是唯一的答案。
先说定义。蒸馏是一种已有数十年历史的机器学习技术,大模型可以用来训练更小、更高效的模型。实验室在内部运行蒸馏并没有问题。但也有人可能在模型提供方不知情、甚至未获许可的情况下,从外部蒸馏一个模型。这正是针对 Kimi 和其他中国实验室的指控。
OpenAI 四年资历的员工 Diogo Almeida 解释说,如今要有效蒸馏,比几年前困难得多。那时 AI 模型还会提供推理轨迹。Almeida 把从最终答案中学习称为「行为模仿」,这是能力最弱的一种做法,但仍可能有助于另一模型完成初始训练。
有相当多的证据表明,中国和美国的研究人员都曾用前沿系统的输出训练模型。Stanford 的 Alpaca 项目已经承认过这一点。Anthropic 指称,DeepSeek、Moonshot 和 MiniMax 通过 24,000 个虚假账号使用了超过 1,600 万条 Claude 对话。特朗普政府的科学事务负责人 Michael Kratsios 表示,他现在已经掌握了 Moonshot 如何实施蒸馏攻击的证据。1
基准测试公司 Arena 的 CEO Anastasios Angelopoulos 认为,Kimi K3 的表现已经超过部分顶尖美国模型,仅靠蒸馏无法做到这一点。他还预测:「美国实验室将开始蒸馏中国的智能。」
当 AI 技术决定了输出中的表达性元素时,生成的材料就不是人类作者创作的成果。因此,这些材料不受版权保护。
Samuel Slater 明知自己违反了英国法律,而这里的问题属于指数差距:技术已经跑在法律前面。1 如果实验室拥有其模型输出的知识产权,那它们实际上就会拥有所有用户未来每一项经济活动中的知识产权。
这也削弱了实验室自己的立场:既然 Anthropic 可以吸收你我的内容,为什么 AI 模型就不应被允许吸收 Anthropic 的知识产权?
Bahrad Sokhansanj 提出了一些其他建议,可以概括为:应当处理蒸馏问题,但范围要窄,只针对真正造成的伤害,并使用恰当的工具。问题究竟与国家安全有关,还是与别的事情有关?如果监管范围过宽,就会顺着实验室的意愿,把监管领域塑造成有利于它们的样子。
延伸阅读:
- Kimi K3 会改变 AI 的经济学吗?我们的分析。
- Satya Nadella 是众多科技领袖之一,他公开支持开放权重模型,以平息美国政府可能限制这类模型的传闻。Jensen Huang 也持同样观点:
在我的第一篇帖子中,我分享了 NVIDIA 签署的一封说明开放模型为何重要的信。AI 将改变每个行业,为每家公司提供动力,并由每个国家来建设。开放模型能增强安全与网络安全,加速创新与扩散,并让各国拥有自主权。
赞助商信息:OKTA
要做好 AI 安全,先照顾好身份
当你和团队部署 AI agent 时,身份就成了战略基础设施。agent 是一种行动者,它会读取你的数据、调用 API,并代表你完成操作。你需要为它设置清晰的权限,并审计它留下的轨迹。
Okta 的 AI 身份准备度评估会为你的 AI agent 的安全性打分,并明确告诉你要修复哪些问题,帮助你更有把握地将 agent 投入生产环境。
用 Okta 的 5 分钟问卷评估你的 agent。
以上为页面中的赞助内容,不属于作者正文。
中国的芯片追赶
2015 年,「中国制造」提出了在十年内实现半导体 70% 自给的目标。这个目标经常被嘲笑过于异想天开,实际进度也大幅落后。Morgan Stanley 的数据显示,2026 年中国本土供应商将满足约 41% 的 AI 芯片需求,高于 2023 年的 20%。北京或许会晚五年达到 70% 的门槛。
按算力加权后,这 41% 所提供的算力仍低于 NVIDIA。但如果从战略自主的角度看,质量差距正越来越不构成问题。
转折点来自华盛顿的出口限制。华为副董事长说:「如果美国没有把我们的国家、公司和产业逼到墙角,我们永远不会做出这样的事情。」据这篇报道,这已经变成一场「全力推进」。
DeepSeek 创始人 Liang WenFeng 与几名投资人的一段对话被泄露,也支持这一判断。Liang 说:
我们和美国的差距是什么?只有一样:资源。我们没有足够的 GPU,手里的数量仍然很少。[…] 国产芯片现在迎来了历史性机会。过去,生态系统不完善阻碍了适配……但这种情况正在改变。NVIDIA CUDA 的护城河正在迅速侵蚀。
Grace Shao 的博客提供了完整对话文本和背景。1
我们这些人
Anthropic 经济学负责人 Peter McCrory 指出,美国劳动力市场对 AI 的反应相当平静。失业率为 4.2%,Anthropic 的数据也显示,即便是受 AI 影响最深的职业,失业情况也没有恶化。
目前,AI 更像是在增强工作,而不是取代工作。还没有任何一个职业被 100% 交给机器。每项工作仍然需要人来完成。AI 正在改变工作的做法;如果劳动者因此提高生产率,价值就会在现有岗位内部重新分配,最善于使用这项技术的人会从中受益。
最后那些难以自动化的任务,也就是 Chad Jones 教授所说的「薄弱环节」,是只有人类才能完成的事情。企业仍然需要人来完成这些任务,这会保护就业,并让相当一部分收入继续进入人们的工资收入。1
还有另一种看法。人仍然重要,而且今后也会继续重要。欧洲成功的创新企业远少于美国。我经常提出的一个原因,是改变劳动力的成本很高。我把创业看作不断犯错、从错误中学习的过程。每增加一项犯错成本,就意味着少了一次学习机会。Yoram Wijngaarde 发现了一种简单的关系,但相关不等于因果:解雇员工越昂贵,人均独角兽企业数量就越低。
先知式动机
原文配图:Anonymous,《让-保罗·马拉肖像(1743–1793)》,巴黎卡纳瓦莱博物馆 / Paris Musées。
法国大革命领导人之一 Jean-Paul Marat 的一部新传记最近在 LRB 上受到评论,对于任何试图理解今天 AI 争论的人来说,都值得一读。
斯坦福历史学家 Keith Baker3 为这位记者和政治家写了一部新传记。他认为,Marat 厌恶一切形式的中介,从牛顿公式到议会集会,再到平静的讨论,凡是挡在人们与真相之间的东西都在此列。他试图每天撰写小册子,靠喊叫而不是论证来说服人,并制造亲密感。「他让自己的报纸『更互动、更动态、更个人化』,从而塑造了一种亲密感,让自己能够代表人民发声。」
在这些特征之中,他的偏执确实帮助他识别出真实的腐败和制度背叛。Baker 称他为第一位现代民粹主义者。
高频发布,把偏执当成分析,制造拟社会亲密感,还不断坚持认为一切复杂性都只是伪装起来的阴谋……现在的 AI 话语,正好在筛选出这种 Marat 式气质。
今天的键盘斗士没有 Marat 的恐怖统治所包含的肉体暴力,但其反对细微差别和复杂性的底层逻辑相似。末日论者和加速主义者共享一些模式:清洗式言论、咄咄逼人的论战,以及把每一点细微差别都说成腐败。最后留下的只有极端立场。你可以想到迫在眉睫的经济灾难、灾难性的欺诈、乌托邦式的富足,或者干脆是人类处境的彻底改变。
在这些极端立场中,容易被丢掉的是一种有理有据的态度:承认证据,也检验证据。这种态度会衡量概率,接受答案可能复杂、不完整,而且取决于具体条件。1
延伸阅读:
- 💪🏼 AMD CEO Lisa Su 博士在主题演讲中以 Exponential View 的数据开场,作者对此感到非常兴奋。你也可以在这里获取同一份数据。
晚宴上显得见多识广的短讯
- AI 辅助的生物武器不会杀死我们。经 EV 会员 Abi Olvera 推荐。
- 🏋🏼♀️ 自 2023 年以来,使用 AI 的英国企业比例接近增长三倍,但大多数企业仍在试水。
- Arsenal FC 正在构建足球 AI 模型。
- 当买房等重要人生目标变得遥不可及时,年轻人更可能在金融市场上投机。
- 全球陆地和海洋表面温度正走向新纪录。
- 亚马逊传来好消息:今年的野火数量处于历史低位,毁林面积也处于十年来低位。感谢 EV 会员 Angus Hervey 提供线索。
- 复古 LLM 😎:只用 1931 年以前的文本训练 AI 模型,可以帮助研究人员了解 AI 能做什么,同时避免现代互联网造成的污染。
- Stripe 正在谈判收购 OpenRouter。
- Intel 正在出货首批芯片,其内部层使用 ASML 价值 3.8 亿美元的 High-NA EUV 设备进行光刻。
- 先算清楚。Michael Liebreich 拆解了为什么欧盟到 2040 年实现 46% 电气化的目标在数学上无法完成。这对从事政策工作的人尤其相关。
- 🐳 虎鲸正在为幼崽准备食物?太神奇了。
感谢阅读!
脚注
他的遗产价值 100 万美元。按消费者价格指数换算约为 4,000 万美元;按相对收入 / 工资等价关系计算约为 10 亿美元;按其占美国经济的比例计算约为 17 亿美元。
许多人显然认为,实验室大规模使用他人的输出,例如书籍和文章,来训练模型并不体面。但法院尚未裁定这种训练违反版权法。就 Anthropic 的案件而言,尽管双方达成了和解,法院的判断并不是这样。
Baker 是一位非常出色的历史学家。过去几年里,我逐渐熟悉了他的作品。他的两个儿子经营着世界上最成功、也最不为人知的对冲基金之一。
本期正文依据 Exponential View 官方页面与 RSS 返回的公开内容整理;赞助区块已单独标注,原文中可见的外部链接、引语、数据和图片均保留。
数据和图片均保留。*
References
Related content
- Sign in to comment.
More from this channel›
- 🔮 Exponential View #595 公开部分:AI 采用的决策陷阱与 Leopold 基金的崩解|英文原文 + 中文翻译
- 📚 My non-obvious summer reading list|Azeem Azhar 的偏旧、偏冷门夏日书单|英文原文 + 中文翻译
- 🔮 For AI adopters, success and failure look identical — at first|对 AI 采用者来说,成功与失败起初看起来一模一样|英文原文 + 中文翻译
- 📈 Exponential View e72:Open models volume ↑、AI & productivity ↑、Kids in cities ↓|开放模型、生产率与城市儿童|英文原文 + 中文翻译
- 🔮 Will Kimi K3 change the economics of AI?|Kimi K3 会改变 AI 的经济学吗?|英文原文 + 中文翻译
- 📈 Data to start your week|Kimi-K3 编码、DeepSeek 收入与 AI 安全测试|英文原文 + 中文翻译
- Exponential View #593:Kimi K3、AI 经济与太阳能悖论|英文原文 + 中文翻译