Through late June 2026 the framing of model distillation changed in the press. Coverage stopped treating it primarily as a question of research ethics or platform rules and began treating it as a trade and national-security question, the mechanism by which frontier AI capability might cross a border without any controlled item crossing with it.
The structural argument
Export controls on advanced semiconductors are designed to slow the training of frontier models by restricting the compute required. Distillation sidesteps that logic entirely. A student model does not need the compute its teacher needed; it needs access to the teacher’s outputs and a far smaller training run. If capability can be acquired that way, controls on hardware constrain who can build a frontier model but not who can end up with one.
That is the argument that moved distillation from the engineering pages to the policy pages, and it is a serious one irrespective of any particular allegation.
The counter-argument
The difficulty is that the legal foundation is thin. Model outputs are not clearly copyrightable. Training on publicly available text, including text generated by another model, does not map neatly onto existing theories of misappropriation. Commentators through this period repeatedly noted that the strongest available claims were contractual: violation of terms of service, and the fraudulent account creation used to obtain access at scale.
Those are real claims, but they are claims about how access was obtained rather than about the value of what was taken, and they carry correspondingly modest remedies.
Where it left the field
By the end of June the dispute had acquired the shape it kept for the rest of the summer: a serious structural concern about capability transfer, supported by allegations that were difficult to prove, resting on legal theories that were narrower than the political language surrounding them.