Disclaimer: This is all speculation. All of it. If I'm close to how this actually plays out; kings to me. The people who do know how it'll play out are, based on what I've seen so far, very statue-lipped about it. That's a good thing. It also gives me room to have some fun and make predictions based on information made publicly available via the EOS Telegram group chat and everything else presently available via OSINT channels.
In this write-up I'll speculate how I think the "very robust and fair distribution system" may occur during the EOS initial token distribution, as well as provide thoughts on how, imho, such a feat could be pulled off securely in defense of a sophisticated power grab. This submission is pretty much a rewording of a rant I threw down in the Telegram community, which I recommend joining if you haven't.
First, let's borrow some help from @trogdor and ask: What is EOS?
The EOS team uses many reputable exchanges as a buffer between them and the early adopters. This would imply that the exchanges would allow the buying of the EOS token but restrict the ability to sell it for a set amount of time. A "read only" type of setup. This is also useful in preventing a power grab by spreading acquisition options across various platforms as opposed to one specific funding source.
Now, this in itself wouldn't prevent a billion dollar institution from staging a power grab. Only the implementation of IP and exchange account associated rate-limiting on daily buying spread out over a considerable period of time, and a reCAPTCHA2 clone impervious to OCR implemented across each individual exchange would fully eliminate the threat of an instantaneous power grab via exchange API; be they publicly available APIs or reverse engineered.
I say a reCAPTCHA 2clone and not reCAPTCHA2 itself because OCR services such as http://zennolab.com/en/products/capmonster/ boast a > 55% success rate on breaking reCAPTCHA2.
Edit: Welp