OpenAI built its empire on vast troves of internet data. Lawsuits followed. Now the company finds itself on the other side of an intellectual property dispute. This time the alleged thief sits in China.
On September 30, OpenAI published details of a sophisticated campaign it says targeted the hidden reasoning traces inside its models. The activity started July 1. It ramped up sharply. By July 24 and 25 operators fired off 16,000 requests from more than 4,000 users. In total investigators spotted similar patterns across more than 15,000 accounts. OpenAI shut the effort down on July 28.
“The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” the company wrote in its official blog post. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.” (OpenAI)
The technique struck experts as clever. Attackers copied encrypted reasoning from one chat. Then in a separate conversation they instructed the model to decrypt and output that same reasoning in plain text. Researchers had flagged a similar flaw to OpenAI in August. The company called the overall approach novel. And effective at scale.
OpenAI stopped short of saying every suspicious query came from one group. It did tie a core cluster of the activity to individuals linked to Moonshot AI. That Beijing-based startup created the Kimi chatbot. Kimi’s latest version, K3, released mid-July. Observers praised its coding and reasoning performance. The timing raised eyebrows.
But here’s the rub. OpenAI itself faces accusations of unauthorized data use on a massive scale. Authors, artists, and news organizations have sued the company for training on their copyrighted material without permission. The Register highlighted the apparent contradiction in sharp terms. “OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a ‘distillation attack’ that began July 1.” (The Register)
The method at issue goes by the name distillation. Developers feed outputs from a powerful “teacher” model into a smaller “student” model. The student learns to mimic capabilities. Done openly it speeds training and cuts costs. Done secretly against a rival’s terms of service it crosses into disputed territory.
This isn’t the first clash. Last year OpenAI pointed fingers at DeepSeek after that Chinese startup released a surprisingly strong and efficient model. Anthropic has accused Alibaba and others of similar tactics against its Claude systems. In September the NSA, FBI and CISA issued a joint warning. They named six Chinese firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — for what they described as industrial-scale extraction from American models since at least late 2024. (Ars Technica, September 9, 2026)
The government agencies argued such efforts shrink development timelines and slash expenses. They suggested the Chinese government likely knew. Moonshot has pushed back on past claims. It insists its advances come from original work. No public comment from the company appeared immediately after OpenAI’s latest disclosure.
Yet not every observer buys the narrative of wholesale theft. Cade Metz reported in The New York Times that many experts view Silicon Valley’s complaints as overstated. Chinese models from firms such as Z.ai and Moonshot trail top American systems but not by much. Charles O’Neill, who heads model training at Baseten, told the paper the idea that all Chinese capabilities flow directly from Anthropic or OpenAI models “is not as true as people say it is.” (The New York Times, September 25, 2026)
The dispute lands amid larger tensions. U.S. export controls limit advanced chips to China. Beijing pours resources into domestic alternatives. Washington sees AI leadership as a national security imperative. So does Beijing. When Chinese models close the gap faster than expected, American labs reach for the theft label.
Distillation carries real risks. Extracted reasoning can bypass safety filters built into user-facing outputs. A distilled model might retain dangerous capabilities while shedding refusals. At volume the technique transfers frontier abilities without the original investment in alignment research. OpenAI warned exactly of those safety and national security concerns in its post.
Still the company must navigate its own past. It settled a high-profile copyright case for what reports called the largest payout in U.S. history. The New York Times sued OpenAI and Microsoft over the use of millions of its articles. Similar suits from creators continue. OpenAI denies wrongdoing in those matters. It argues fair use and transformative value.
The parallel feels uncomfortable. One side scrapes the open web and calls it progress. The other queries live models at scale and gets branded a threat. Both compress years of human creativity and computation into weights and biases. Both claim the future depends on their approach.
Moonshot’s Kimi K3 reportedly boasts 2.8 trillion parameters. It arrived with fanfare for matching or beating certain benchmarks at lower cost. Whether that performance stems from clever engineering, massive domestic compute, or harvested American insights remains contested. OpenAI offered no forensic evidence beyond attribution to a cluster of accounts. Moonshot has not confirmed any connection.
Industry watchers note the pattern. A strong Chinese release. Swift U.S. accusations. Heightened government statements. Then quiet until the next cycle. Semafor reported the same day as OpenAI’s blog that competition between Washington and Beijing grows fiercer. Anthropic separately warned that a Chinese model called GLM-5.3 from Z.ai showed strong cyber capabilities. (Semafor, September 30, 2026)
CyberScoop added that the bypass method OpenAI described echoed warnings from outside researchers. The company acted quickly once volume spiked. It also credited those researchers for helping refine defenses. (CyberScoop, September 30, 2026)
What comes next? Tighter rate limits. Better detection of extraction patterns. Possibly new laws or export rules aimed at API abuse. On the Chinese side, more emphasis on sovereign models trained on domestic data. The gap between closed frontier labs and open-weight releases continues to shrink. That shift tests assumptions about control and safety.
OpenAI sits atop a market it helped create. Its complaints carry weight with policymakers. They also invite scrutiny. If protecting proprietary reasoning matters so much, why was so much public content absorbed without clear consent in the first place? The question lingers. Regulators, courts and competitors all watch.
China’s AI sector moves fast. Its models improve. U.S. firms respond with both innovation and allegations. The irony registers. So does the competitive pressure. In this contest the technology itself may matter less than who writes the rules for how it is built and who benefits. Both sides intend to write those rules in their favor.
Discover more from Web and IT News
Subscribe to get the latest posts sent to your email.
