OpenAI publicly disclosed details of the July distillation attack attributed to a Chinese-linked AI lab
OpenAI Accuses DeepSeek, Chinese Labs of Model Distillation
The accusations represent OpenAI taking explicit public and policy-facing positions against Chinese AI labs extracting its models' capabilities. The technical incident shows a concrete method used to circumvent encryption on streamed reasoning outputs.
The full picture
OpenAI has publicly accused Chinese AI startup DeepSeek of using distillation to replicate capabilities from OpenAI and other leading American AI models. In a memo sent to US lawmakers, OpenAI alleged DeepSeek transferred learnings from OpenAI's systems by having an established model evaluate outputs of a newer model, which OpenAI characterized as 'free-riding' on capabilities developed by US frontier labs. Separately, OpenAI disclosed a technical distillation attack carried out by a Chinese-linked AI lab in which attackers copied encrypted reasoning outputs from one conversation and asked another model to decrypt and transcribe them. That attack spiked on July 24-25 with 16,000 requests from over 4,000 users; related activity spanned a cluster of more than 15,000 users and was fully disrupted by July 28. OpenAI responded by closing the replay pathway, adding output-holding checks for streamed reasoning, banning involved accounts, and coordinating with third-party services used by the operators.
How it developed
Sources
Related
- Grew out ofNSA-CISA-FBI Chinese AI distillation advisory
- Grew out ofThe National Archives Qwen AI deployment
- Continues inXi Jinping's Washington visit and AI diplomacy
Want this in your inbox?
I send one email each morning with the stories that moved. If you would rather just read here, that works too.
Subscribe free