The Information Machine
Following·Day 121·first covered 2 Jun 2026·5 sources

OpenAI Disrupts Chinese-Linked Model Distillation Campaign

The gist

OpenAI's public attribution of a specific extraction campaign to a Chinese-linked lab, combined with a White House directive and proposed legislation, shows government and industry moving from general concern to named enforcement actions. The gap between Huang's framing of distillation as ordinary competition and OpenAI's enforcement framing reflects a live disagreement over how to characterize the practice.

The full picture

OpenAI on September 30 disclosed it disrupted a coordinated campaign by a Chinese-linked AI lab to extract protected reasoning outputs through adversarial distillation. The attackers, unable to break encryption directly, copied encrypted reasoning outputs from one conversation and asked a separate model to decrypt and transcribe them. The campaign began July 1 at low volume, then spiked July 24-25 with 16,000 requests from over 4,000 users; related activity spanned a cluster of more than 15,000 users. OpenAI said it fully disrupted the activity by July 28, closing the replay pathway, adding output-holding checks for streamed reasoning, banning involved accounts, and coordinating with third-party services used by the operators.

The September disclosure fits into a longer policy arc. In February 2026, OpenAI sent a memo to US lawmakers alleging that DeepSeek used distillation to transfer learnings from OpenAI's systems and accused Chinese large language models of cutting corners on safe training and deployment practices. The White House OSTP followed in April 2026, with Director Michael Kratsios signing NSTM-4 directing federal agencies to share intelligence with AI companies and explore accountability measures. A CNAS paper from June 2026 noted that the Deterring American AI Model Theft Act of 2026 (H.R. 8283) had been introduced to target actors linked to countries of concern.

Nvidia CEO Jensen Huang, in a CNBC interview published September 28, took a contrasting position, characterizing distillation as routine competitive behavior.

How it developed
30 September 2026

OpenAI publicly discloses the disruption and attributes it to a Chinese-linked AI lab

28 September 2026

Jensen Huang characterizes model distillation as routine competitive behavior in CNBC interview

2 June 2026

CNAS publishes analysis of adversarial distillation and emerging legislative and industry responses

Sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free