Sequoia's Dean Meyer on America's open model paradox: US frontier AI is being distilled into Chinese open-source models
Jul 27, 2026 with Dean Meyer
Key Points
- US frontier AI labs are being systematically distilled by Chinese competitors, who then release the capability as open-weight models that American startups depend on, creating structural dependency on Chinese release cadence.
- Detecting backdoors in Chinese open-source models is computationally infeasible, and time-triggered attacks can evade standard evaluations, leaving the US ecosystem vulnerable to potential data exfiltration.
- Legal remedies like Moonshot AI's revenue-share license are unenforceable across jurisdictions, forcing US labs to pursue symbolic enforcement rather than structural solutions to the distillation problem.
Summary
Read full transcript →America's open model paradox
Dean Meyer, a Sequoia Capital partner, argues that the US is effectively subsidizing Chinese AI capability through a structural asymmetry in how open-weight models get trained.
The mechanism is straightforward: US frontier labs produce cutting-edge models, Chinese labs distill them at scale through what Meyer describes as tens of millions of queries run through large-scale proxy accounts, then release the resulting capability as open-weight models. American startups, legally blocked from distilling US frontier models themselves, then build on those Chinese open-weight releases. The US ecosystem ends up dependent on Chinese labs for its next model generation.
Meyer is careful not to claim distillation explains everything. The debate online splits into two camps — distillation explains everything, or it explains nothing — but his read is that it accounts for somewhere between 20% and 40% of the capability gap closure. Even getting only the final output from a query, without chain-of-thought traces or RL signal, is "extremely valuable," according to conversations he says Sequoia has had with people leading synthetic data generation at the labs.
“The core concept was, US is creating this frontier capability that gets leaked into Chinese open weight models. You have the entirety of the American builder ecosystem, which is Neolabs, companies that are somewhat dependent on these Chinese models. There are two major risks: the dependency risk and the risk of backdoors — and it is an NP hard problem to know if there is a backdoor in a model.”
Two risks from Chinese open-source dependency
The first is strategic dependency. Meyer's framing is that you're only as good as your next model, and if the next model comes from a Chinese lab, you're structurally beholden to their release cadence and decisions.
The second risk gets less attention: backdoors. Meyer is explicit that he is not claiming all Chinese open-weight labs have backdoored their models. But he argues the verification problem is effectively unsolvable — detecting a backdoor in a large model is NP-hard. Research also shows models can be time-triggered, meaning they pass all standard evaluations and then change behavior on a specific input, potentially exfiltrating data. Meyer compares the current state of AI security to Wi-Fi encryption in 2001, which was publicly broken and largely ignored.
The Kimi license problem
Moonshot AI's Kimi released a new license that allows free self-hosted use but requires a revenue share from anyone reselling Kimi-generated tokens commercially. Meyer doesn't think the revenue-share structure is enforceable, drawing a parallel to the database market where hyperscalers simply copied Redis and similar open-source projects without consequence. His broader point is that legal or commercial remedies are unlikely to resolve the asymmetry — the structural problem needs a different kind of fix.
On whether US labs should sue Chinese competitors for distillation, Meyer's view is that they probably could, and nothing material would happen. The value would be symbolic: entering evidence into the public record that the practice occurred, even if enforcement is impossible across jurisdictions.
The Sequoia post on sovereign AI that Meyer co-authored with his partner Constantine went viral shortly before Kimi K3 launched — timing he says was coincidental.
Every deal, every interview. 5 minutes.
TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.