Every accusation made during the first half of 2026 concerned a single transfer: a frontier model queried, a competing model trained. Research published during the same period argued that framing understates the problem, because distillation is not an event. It is a chain.
Three stages, not one
The chain runs roughly as follows. A frontier model is distilled by a first recipient. That recipient releases a model, often openly. A third party then builds on the recipient’s work, inheriting capability that originated two steps back, without ever touching the original model or violating anyone’s terms of service.
By the second hop there is no fraudulent account to point at, no API traffic to analyse and no contract to have breached. The capability has become ambient.
A worked example
Reporting on Zhipu AI’s GLM-5 noted that the model claimed frontier-comparable performance across eight benchmarks, and that its technical report described substantial reliance on DeepSeek’s architecture, DeepSeek being the lab that both OpenAI and Anthropic had separately accused of systematic distillation earlier in the year.
Whatever one concludes about the original accusations, the structural point stands: capability that enters the open ecosystem does not stay with its first recipient. Open weights accelerate this considerably, which is why the July release mattered more than the accusation that preceded it.
Why this breaks the enforcement model
Every instrument discussed during 2026, Entity List designation, sanctions, export controls, terms-of-service enforcement, operates on a party. Each requires identifying who did the thing and imposing a cost on them.
A cascade has no such party at the far end. The third-hop builder has done nothing actionable. They downloaded a public model and fine-tuned it, which is the ordinary practice of the entire open-weights ecosystem and is not something any serious proposal suggests prohibiting.
Where that leaves the argument
This is the strongest version of the frontier labs’ concern, and it is considerably more coherent than the individual accusations that have been made. It is also the version least amenable to the remedies being proposed. Sanctioning a first recipient does not recall capability that has already moved twice.
Six months of dispute have produced no enforcement action, no published attribution method, and one openly released frontier-class model. The chain described in the research has not been interrupted at any point.