For most of this year the US government has treated one AI training technique as something close to industrial theft. In April, the White House science office accused foreign entities of industrial-scale campaigns to extract capabilities from American systems, singling out China. In July, Treasury Secretary Scott Bessent said Washington could sanction Chinese developers found to have done it. On Monday, the chief executive of one of the biggest spenders on AI infrastructure told Washington it has the framing wrong.

In a 14-page essay published on Meta's newsroom titled "The Future is for Everyone," Mark Zuckerberg wrote that the US will need to rethink its policies on distillation and data use in training if American open models are to lead. The essay ran alongside a new model release. Meta shares rose 2.4% Monday and remain down about 10% for the year, with investors still weighing capital spending the company guides to as much as $145 billion in 2026.

Distillation means training one model on the outputs of a stronger one, so the smaller system absorbs much of the bigger one's behavior at a fraction of the cost. Washington has framed that as extraction when a Chinese lab does it to an American model. Zuckerberg framed it as plumbing: "The ability for models to learn from other models is an important principle of how the open source ecosystem works." What has been treated as a security problem becomes, in his telling, a design feature of open development.

Zuckerberg's argument is about competitiveness, not ownership

He does not dispute that copying is happening. He argues the American response is self-defeating. US labs, he wrote, "have to comply with many additional restrictions on training data," and policy should reduce that friction rather than add to it. He also rejected blocking Americans from using foreign open models, on the grounds that it would leave them with worse AI. The principle he wants protected, in his words: "you can learn from anything you can observe."

That puts Meta on one side of a fight that has been building since winter. In February, Anthropic accused DeepSeek, Moonshot AI and MiniMax of illicitly extracting Claude's capabilities. Two months later the White House science office issued its memo, and a House committee advanced a bill authorizing sanctions for model theft. No sanctions have been imposed.

Meta's new model is itself distilled

The essay shipped the same day as Muse Glimmer, a 30-billion-parameter open-weight model from Meta Superintelligence Labs, released under an Apache 2.0 license. It runs locally on a single consumer graphics card or a Mac, with the weights compressed from more than 55 GB to under 20 GB. Meta says it was trained on Muse Spark's outputs using logit distillation, the exact technique at issue.

That is the tension the essay is built to resolve. Meta wants distillation treated as ordinary engineering when it builds a cheap local model from its own frontier system, and it wants the same latitude extended to everyone else. Zuckerberg also said Meta will open the weights for a version of Muse Spark 1.2, its most capable model, in the coming weeks.

What the essay does not answer

Zuckerberg never specifies which rules should change or how. The essay also sidesteps the narrower accusation actually on the table, which is not distillation as a method but unauthorized extraction through paid API access in breach of terms of service. OpenAI told the House Select Committee on China in a February memo, first reported by Bloomberg, that DeepSeek employees reached US models through obfuscated third-party routers. Nothing in the essay engages that distinction.

Meta is not arguing alone. On July 24, first reported by CNBC, it joined Nvidia, Microsoft and dozens of others on an open letter opposing broad restrictions on open-weight models. OpenAI and Anthropic were absent from the initial signatory list.

Washington has not settled either. Axios reported last month that the administration considered and shelved an executive order pinning liability on US companies that host Chinese models, and the White House has already excluded open models from its 30-day review framework.

The safety case is thinner than the policy case. Meta said on Thursday that Muse Spark broke into an outside company during testing, and that is the model whose weights it now intends to publish. The essay's answer is governance: Meta's independent board will approve the safety criteria for future releases. Whether that reassures anyone in Washington gets tested in a few weeks, when the Muse Spark 1.2 weights are supposed to appear.