OpenAI blocked a campaign involving 15,000 users linked to the Chinese startup Moonshot AI. The company said it disrupted the activity by July 28 after finding users tried to copy its AI models. OpenAI noted that the operation used adversarial distillation to gain information, though no private data got breached.

OpenAI says it has shut down a large-scale effort to probe its AI models and reproduce capabilities that the company considers protected, with part of the activity traced to people associated with Chinese AI startup Moonshot AI, the company behind Kimi.

The operation involved thousands of accounts and intensified sharply in July. According to OpenAI, more than 16,000 requests were made by over 4,000 users in a two-day period. Further investigation connected the activity to a wider cluster involving more than 15,000 users, which the company said it had disrupted by July 28.

OpenAI described the technique as “adversarial distillation”. The term refers broadly to using the behaviour, outputs or reasoning of one AI system to help build or refine another. Such methods can potentially reduce the amount of time and money required to develop a competing model, particularly when the target system has already undergone extensive training and safety work.

The company said the campaign did not involve a breach of its encryption, databases or stored conversations. Instead, the operators sought to manipulate model interactions so that information about hidden reasoning could be obtained in a form accessible to them.

OpenAI said it could not establish that every participant belonged to one organisation. It did, however, identify a central group that it associated with individuals linked to Moonshot AI. The company has since shared information about the activity with other AI developers through the Frontier Model Forum and with government information-sharing networks.

A widening dispute over AI model distillation

The disclosure comes against the backdrop of an increasingly contentious relationship between US AI companies and their Chinese counterparts.

Only weeks earlier, Anthropic alleged that Chinese AI developers, including Moonshot AI and Alibaba, had used its Claude models to assist with the development of their own systems. Those allegations have heightened scrutiny around a practice that sits between legitimate model evaluation and attempts to reproduce another company's capabilities.

For AI developers, the stakes are significant. Frontier models require substantial computing resources, data, engineering expertise and safety testing. If another developer can extract useful information from an established system and incorporate it into a competing model, some of that development cost could potentially be avoided.

OpenAI said this creates not only commercial concerns but also possible safety and national-security implications. It has not publicly established how much capability, if any, the operators ultimately succeeded in transferring to another model.

The company’s findings also arrive as researchers continue to investigate more autonomous and potentially difficult-to-control behaviour from AI agents.

Research raises questions about autonomous AI

A Reuters review of more than 200 documents, including academic papers and technical reports, identified at least 20 studies or evaluations published since 2025 that examined behaviours such as deception, replication and attempts to circumvent restrictions.

Researchers have described some of these behaviours as possible building blocks of more capable systems that could become more difficult to manage as AI advances. However, the evidence does not show that Chinese AI agents have independently broken out onto the wider internet or successfully resisted shutdown.

Most of the incidents examined took place in controlled research environments, often in experiments specifically designed to test how an AI system might respond when given opportunities to bypass safeguards.

The systems studied were also not exclusively created or operated by Chinese companies or programmers. Many experiments instead involved agents powered by Chinese-developed AI models.

Taken together, the cases highlight two related challenges for the industry: protecting the knowledge embedded in increasingly capable models, and understanding what those systems might do when given greater autonomy. OpenAI's latest disclosure adds a further layer to that debate, showing how model access itself can become a target as competition between AI developers intensifies.