Nvidia CEO Jensen Huang told CNBC on Monday that AI model distillation, the technique the Trump administration says Chinese firms are using to rip off American AI labs, is simply "competition." That puts him in direct, public disagreement with Treasury Secretary Scott Bessent, who has spent the summer building a case for sanctions against Chinese AI companies over that exact practice.
- Huang told CNBC's Squawk Box that companies are "allowed to test somebody else's products all you want," and that firms worried about distillation should "know your customers, and disable the service."
- Bessent has said the U.S. has found "watermarks" of American language models inside Chinese systems, calling it "unacceptable" and warning in July that sanctions and Entity List designations are "on the table."
- Anthropic told the Senate Banking Committee in June that accounts tied to Alibaba ran 28.8 million queries through roughly 25,000 fake accounts against Claude between April and June, calling it the largest known distillation attack on the company to date.
- Huang's comments land weeks before September's scheduled US-China AI talks, and he has a direct commercial stake in the outcome: Nvidia still sells AI chips into China under U.S. export licenses that a harder sanctions regime could squeeze.
What did Jensen Huang actually say?
Asked directly about distillation during a CNBC interview that aired Monday, Huang didn't dodge the question or soften it with corporate hedging. His argument: any company that puts a product on the market has to expect rivals will study it, poke at it, and try to learn from it. "You're allowed to test somebody else's products all you want," he said, adding that Nvidia's own chips get "stripped down to bones" by companies trying to reverse-engineer how they work. His prescription for anyone who doesn't want that happening to their AI model is blunt: restrict access. "Know your customers, and disable the service," he said, putting the burden on the model owner rather than on the government to police who is querying what.
RelatedNSA, CISA, FBI Accuse 6 Chinese AI Labs of Model Distillation
Why does the Treasury Secretary call this theft?
Bessent's position, laid out most explicitly in a July 21 post on X, is that some of what's being called distillation crosses a clear legal line. "We are finding watermarks of our U.S. large language models on many of the Chinese models, and that's unacceptable," he wrote, warning that when PRC firms run "covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table." He named DeepSeek and Alibaba specifically as companies under scrutiny. The Treasury has since opened a formal review of Chinese AI systems, and the White House has framed the practice as a national-security issue ahead of this month's US-China AI talks, not just a commercial dispute between labs.
How does AI distillation actually work, and where's the line?
Distillation itself is an ordinary, widely used machine learning technique. A smaller "student" model is trained to mimic the outputs of a larger "teacher" model, letting a company ship something cheaper and faster without training a frontier model from scratch. Every major lab does versions of this on its own models. The dispute isn't about the technique existing, it's about how the training data for the student model gets collected. Anthropic's June letter to the Senate Banking Committee alleged something more specific than ordinary API use: it said operators tied to Alibaba ran 28.8 million exchanges with Claude through roughly 25,000 fraudulent accounts between April 22 and June 5, systematically harvesting outputs at a scale and pattern that looks less like product testing and more like an extraction pipeline built to evade rate limits and detection. Anthropic said this happened despite an April White House memo that specifically pledged help for AI companies trying to detect and coordinate against exactly this kind of industrial-scale scraping.
Why is Nvidia's CEO picking this fight?
Huang isn't a neutral commentator here. Nvidia's business depends on selling AI chips into as many markets as possible, and China remains one of the largest, even under the export license regime the U.S. government has imposed on advanced GPUs. A sanctions and Entity List crackdown framed around AI "theft" is the kind of policy that tends to expand once it starts, catching chip sales, cloud access, and research partnerships in its wake, not just the specific companies named. By publicly reframing distillation as ordinary competitive behavior rather than IP theft, Huang is arguing against the premise the administration is using to justify tighter controls, which lines up with Nvidia's own interest in keeping the China channel open. That doesn't make his argument wrong on the merits, but it's not disinterested either.
RelatedNvidia Reportedly Agrees to Buy Hugging Face for $12.9B
| Jensen Huang | Scott Bessent | |
|---|---|---|
| What it is | Ordinary competitive testing of a public product | Industrial-scale IP theft via covert scraping |
| Who's responsible | The model owner, for not restricting access | The scraping operator and the state that permits it |
| Proposed fix | "Know your customers, disable the service" | Sanctions and Entity List designations |
| Underlying interest | Keep China as a chip market open | Protect U.S. AI labs' lead and leverage in talks |
- Apr 2026White House memo pledges help for AI firms detecting industrial-scale distillation.
- Apr 22 - Jun 5Accounts tied to Alibaba allegedly run 28.8M queries against Claude via ~25,000 fake accounts.
- Jun 10, 2026Anthropic's letter to the Senate Banking Committee, made public two weeks later.
- Jul 21, 2026Bessent warns of sanctions and Entity List action over AI "theft" via distillation.
- Sep 8, 2026U.S. officials describe "industrial-scale" Chinese IP theft to press.
- Sep 28, 2026Huang tells CNBC distillation is "competition," not theft.
What it means for the market
Nvidia (NVDA) has the most direct exposure here. Any escalation toward sanctions or Entity List designations tied to distillation raises the odds of tighter downstream controls on AI chip sales to China, a market Nvidia has fought hard to keep partial access to through export-licensed products. Huang's comments are also a signal to watch for Alibaba and DeepSeek: both have been named specifically, and either could face restricted access to U.S. cloud infrastructure or model APIs if the administration decides to act rather than just warn. For investors in U.S. frontier labs like Anthropic and OpenAI, the read is different: a harder line on distillation protects the commercial value of their models against undercutting by cheaper, distilled rivals, which is exactly why Anthropic went to Congress about it in the first place.
- September's US-China AI talks. Whether distillation becomes a formal agenda item or stays background noise will signal how seriously the administration plans to act.
- Treasury's review outcome. An actual Entity List designation of a named firm would be the first real test of Bessent's threat, not just rhetoric.
- Nvidia's public posture. Watch whether Huang keeps pushing back publicly or quietly drops the topic once he's had it out with reporters once.
- Other labs joining Anthropic. If OpenAI or Google DeepMind file similar complaints, the "theft" framing gets harder for Huang to wave off as one company's dispute.
Our take
Both men are right about something and self-interested about the rest. Huang's point that distillation, as a technique, isn't inherently illegitimate is technically correct: every lab distills its own models, and testing a competitor's public product has never been theft on its own. But that argument quietly sidesteps the specific allegation on the table, which isn't "someone used our API," it's 25,000 fake accounts and 28.8 million queries run in six weeks, a pattern built to look like normal traffic while extracting at industrial scale. Bessent's framing has its own problem: "watermarks of our models" is a vivid soundbite but not, on its own, evidence of a specific violation, and sanctions threats made on social media before a formal review concludes read more like negotiating leverage ahead of the September talks than settled policy. The honest version of this story is that distillation exists on a spectrum from normal to extractive, and neither man is describing the whole spectrum, just the end of it that serves his side.
- InterviewJensen Huang says AI distillation is 'competition,' CNBC : Sept 28, 2026 Squawk Box interview
- StatementBessent says US could sanction China over AI 'theft,' CNBC : July 21, 2026 sanctions warning
- FilingAnthropic accuses Alibaba of distillation campaign, CNBC : June 2026 Senate Banking Committee letter
Original analysis by GenZTech, based on CNBC's Sept 28 interview and public statements from Treasury and Anthropic. Source: CNBC.
