OpenAI has accused China's Moonshot AI of playing a key role in a distillation campaign to extract protected reasoning from its models.

In a blog post published Wednesday, OpenAI wrote that it identified thousands of user attempts to extract information that could help others reproduce the model's capabilities.

Knowledge distillation is a machine learning technique involving training a smaller AI model using output from more capable ones.

The coordinated campaign began at a low volume on July 1 and peaked on July 24 and 25, when OpenAI detected about 16,000 requests that used a relevant extraction pattern from more than 4,000 users. The company said it disrupted the campaign by July 28 after identifying related patterns deployed by over 15,000 users.

OpenAI said it is unclear whether all the operators originated from a single actor, but attributed a core cluster of the activity to individuals associated with Moonshot, a major Chinese AI company.

The American AI company said the operators attempted to uncover protected reasoning in novel ways, including transferring outputs between conversations and prompting another model to decrypt and transcribe the hidden reasoning content.

"The activity evolved over time, reinforcing that adversarial distillation is a broader security challenge that requires layered, adaptive defenses," the team said.

The Latent has reached out to Moonshot for comment.

Frontier Model Releases per Month by Lab

Frontier Model Releases per Month by Lab

  • OpenAI
  • Google
  • Anthropic
  • xAI
  • Meta AI
  • NVIDIA
  • Z.ai
  • Other
SOURCE: Epoch AI — Frontier AI Models

Shared security challenge

OpenAI said such distillation campaigns pose safety and national security risks, as extracted reasoning could be used to train other models without preserving appropriate safeguards.

"This risk is not unique to OpenAI," the company said, adding that similar techniques may affect other advanced AI systems, "making this a shared security challenge that requires coordination across the industry."

The allegations come amid a wider dispute over how Chinese labs use American models. Last month, Anthropic accused Moonshot and DeepSeek of silently routing user requests to Claude models and displaying the responses to users as their own. Anthropic also accused Alibaba and Xiaomi of running distillation campaigns targeting its models.

U.S. federal agencies have raised similar concerns, alleging last month that Chinese AI companies systematically extracted capabilities from American AI models through distillation.

Meanwhile, The Information reported last week that China's internet watchdog was investigating Moonshot and DeepSeek for potential data leaks to Anthropic.