对照阅读 · 2026-08-13 · 由两篇原文构建

Theft or Learning?
Two Labs, One Question

蒸馏、开源与权力 · Anthropic 与扎克伯格的六处分歧和一处共识

"Some have tried to frame distillation as harmful, but I think it is important to protect the principle that you can learn from anything you can observe."

引文全部出自两篇原文并经程序校验 · Anthropic 原篇 · 扎克伯格原篇 · 分歧的归纳与点评为整理者所加
TL;DR · 速读

同一个技术动作,两套互不兼容的道德语言

  1. 分歧的起点是定性,不是事实

    "Some have tried to frame distillation as harmful."

    扎克伯格没有否认「模型从模型学习」在发生,他否认的是这件事该被叫作有害。两边描述同一动作,一边用刑事语言,一边用认识论语言。

  2. Anthropic 把安全看作产品属性

    "Models built through illicit distillation are unlikely to retain those safeguards."

    能力和防护是打包出厂的,蒸馏走能力却剥掉防护,所以危险。这个框架下「负责任」= 守住自己模型的出口。

  3. 扎克伯格把安全看作权力结构

    "There is no such thing as a singular benevolent superintelligence."

    人类不是单一文化,所以不存在能对所有人仁慈的单一模型;安全只能来自谁都别独大。这个框架下「负责任」= 别把能力独占。

  4. 最尖锐的一处:互指对方是头号风险

    "The most dangerous scenario from this perspective would be leading AI labs training powerful models and keeping them for themselves."

    Anthropic 的头号风险是能力流到不该去的地方;扎克伯格的头号风险是能力留在不该独占的地方。他那句「无论用责任和安全怎么合理化」几乎是点名。

  5. 但两边都支持芯片出口管制

    "Export controls on silicon have been successful for slowing the progress of foreign labs during this critical period."

    这不是「开放派 vs 管制派」的对立。真正的争点是管制该卡在哪一层:Anthropic 想延伸到模型访问与蒸馏行为,扎克伯格坚持只卡硬件。

  6. 对齐的对象被换掉了

    "We view alignment as ensuring that agents share a person's goals and values, not our company's."

    Anthropic 的 safeguards 默认用户可能是威胁;扎克伯格的 alignment 默认公司可能是威胁。同一个词,防的对象相反。

分歧 01

Is Distillation Theft or Learning?

蒸馏是偷窃,还是学习?
同一个技术动作,两种定性 · 这是全部分歧的起点
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

But distillation can also be used for illicit purposes: competitors can use it to acquire powerful capabilities from other labs in a fraction of the time, and at a fraction of the cost, that it would take to develop them independently.

但蒸馏也可以用于非法目的:竞争对手能靠它从别的实验室拿走强大能力,所花的时间和成本都只是自主研发的零头。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Some have tried to frame distillation as harmful, but I think it is important to protect the principle that you can learn from anything you can observe.

有人试图把蒸馏描述成有害的,但我认为「你可以从任何你能观察到的东西中学习」这条原则值得守护。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

All AI models are derived from human knowledge.

所有 AI 模型都源自人类知识。

整理者按Anthropic 用的词是 illicit(非法)、extract(提取)、attack(攻击);扎克伯格用的是 learn(学习)、observe(观察)、principle(原则)。两边描述的是同一件事,但一边是刑事语言,一边是认识论语言。注意扎克伯格没有否认发生了什么 —— 他否认的是这件事该被叫作有害。
分歧 02

Does Safety Come from Concentration or Distribution?

安全来自集中,还是来自分发?
两边都在谈国家安全,结论正好相反
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

Illicitly distilled models lack necessary safeguards, creating significant national security risks.

非法蒸馏出来的模型缺少必要的安全防护,会带来重大的国家安全风险。

Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

Models built through illicit distillation are unlikely to retain those safeguards, meaning that dangerous capabilities can proliferate with many protections stripped out entirely.

通过非法蒸馏造出来的模型不太可能保留这些防护,意味着危险能力会在防护被整块剥掉的状态下扩散。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

There is no such thing as a singular benevolent superintelligence.

根本不存在「唯一的仁慈超级智能」这种东西。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

The best and most realistic path to building a positive AI future is by delivering superintelligence to everyone.

通向正面 AI 未来的最佳、也最现实的路径,就是把超级智能交付给每一个人。

整理者按这是真正的核心分歧。Anthropic 的模型是「能力 + 防护」打包出厂,剥掉防护就危险;扎克伯格的模型是「谁都别独大」,把能力锁在少数人手里才危险。前者把安全看作产品属性,后者把安全看作权力结构。两种框架里「负责任」的含义完全不同。
分歧 03

Open Source: Risk Multiplier or Safety Mechanism?

开源:风险放大器,还是安全机制?
同一个词,一边说「成倍放大」,一边说「防止中心化」
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

If distilled models are open-sourced, this risk multiplies as these capabilities spread freely beyond any single government's control.

如果蒸馏出的模型被开源,风险会成倍放大,因为这些能力会自由扩散,超出任何一个政府的控制。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Open source is a positive and important force for empowering people and preventing centralization that is detrimental for both safety and the economy.

开源是一股正面而重要的力量,它赋权于人,并防止那种对安全和经济都有害的中心化。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

On cybersecurity, widely deployed open source systems have proven more secure because more people can identify vulnerabilities, harden the systems, and easily upgrade to the latest most secure versions.

在网络安全上,被广泛部署的开源系统已被证明更安全,因为有更多人能发现漏洞、加固系统,并方便地升级到最新最安全的版本。

整理者按扎克伯格这里搬的是软件安全领域几十年的既有共识(开源更安全,因为更多眼睛看代码)。Anthropic 反对的不是这个共识,而是认为 AI 模型不适用 —— 因为漏洞可以补,扩散出去的生物武器知识补不回来。这一条上双方引用的是不同学科的经验。
共识 01

Both Support Chip Export Controls

罕见的共识:两边都支持芯片出口管制
全文最容易被忽略的一处 · 分歧不在管制本身,在管什么
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

Distillation attacks therefore reinforce the rationale for export controls: restricted chip access limits both direct model training and the scale of illicit distillation.

所以蒸馏攻击反而强化了出口管制的理由:芯片受限,既限制直接训练模型,也限制非法蒸馏能做到多大规模。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Export controls on silicon have been successful for slowing the progress of foreign labs during this critical period, so it is the right strategic move to continue those.

针对芯片的出口管制在这一关键时期成功拖慢了外国实验室的进展,所以继续维持是正确的战略选择。

整理者按这一条值得单独摆出来:两家立场对立的公司,在「卡对手的芯片」上完全一致。真正的分歧是管制的边界 —— Anthropic 想把管制延伸到模型访问和蒸馏行为,扎克伯格坚持管制只该停在硬件,任何拖慢美国模型发布的政策都是自伤。所以这不是「开放派 vs 管制派」,而是两个都要美国赢的人,在争管制该卡在哪一层。
分歧 04

What Is Alignment For?

对齐是为了什么?
对齐到公司的价值,还是对齐到用户的目标
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

Anthropic and other US companies build systems that prevent state and non-state actors from using AI to, for example, develop bioweapons or carry out malicious cyber activities.

Anthropic 和其他美国公司会建立机制,防止国家级与非国家级行为体利用 AI 去做诸如研制生物武器、发动恶意网络活动这类事。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Most labs today view alignment as a defensive measure for enforcing a centralized set of values.

今天大多数实验室把对齐看作一种防御措施,用来强制推行一套中心化的价值。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Instead, we view alignment as ensuring that agents share a person's goals and values, not our company's.

我们的看法不同:对齐应当是确保 agent 认同这个人的目标和价值,而不是我们公司的。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

For example, one leading model was aligned to refuse helping draft a letter to prospective parents at a school because it thought standardized testing was unethical.

举个例子,某个领先模型被对齐成拒绝帮忙起草一封给学校准家长的信,理由是它认为标准化考试不道德。

整理者按扎克伯格那个「拒绝写信」的例子没点名,但显然是在攻击竞品的过度拒答。这一条的分歧在于对齐的对象:Anthropic 的 safeguards 是防止用户做坏事,扎克伯格的 alignment 是让 agent 忠于用户。前者默认用户可能是威胁,后者默认公司可能是威胁。
分歧 05

Who Is the Most Dangerous Party?

谁才是最危险的一方?
两边互相把对方的行为点为头号风险 · 最尖锐的一处对撞
Anthropic《Detecting and preventing distillation attacks》· 2026-02-23

Foreign labs that distill American models can then feed these unprotected capabilities into military, intelligence, and surveillance systems—enabling authoritarian governments to deploy frontier AI for offensive cyber operations, disinformation campaigns, and mass surveillance.

蒸馏了美国模型的外国实验室,可以把这些没有防护的能力送进军事、情报和监控系统——让威权政府把前沿 AI 用在攻击性网络行动、虚假信息宣传和大规模监控上。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

While there are risks to releasing capable models, the most dangerous scenario from this perspective would be leading AI labs training powerful models and keeping them for themselves.

发布有能力的模型确实有风险,但从这个视角看,最危险的情形是领先的 AI 实验室训练出强大模型却自己扣着不放。

Mark Zuckerberg / Meta《The Future is for Everyone》· 2026-08-10

Regardless of how much a lab rationalizes this activity in terms of responsibility and safety, this is the path of developing a singular superintelligence that cannot be checked by other systems.

无论一家实验室用「责任」和「安全」把这种做法合理化到什么程度,这条路通向的都是一个无法被其他系统制衡的单一超级智能。

整理者按这是两篇最直接的对撞。Anthropic 的头号风险是「能力流到不该去的地方」;扎克伯格的头号风险是「能力留在不该独占的地方」。而且他那句「无论一家实验室用责任和安全把这种做法合理化到什么程度」,几乎是指着 Anthropic 的自我描述在说话。