{
  "id": 11188335,
  "title": "OpenAI says it disrupted large-scale effort to copy its AI model capabilities",
  "url": "https://urgent.news/2026/10/01/openai-says-it-disrupted-large-scale-effort-to-copy-its-ai-model",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-01T12:20:23.000Z",
  "source": {
    "name": "Economic Times Tech",
    "slug": "economic-times-tech",
    "url": "https://economictimes.indiatimes.com/tech/artificial-intelligence/openai-says-it-disrupted-large-scale-effort-to-copy-its-ai-model-capabilities/articleshow/134619022.cms"
  },
  "original_language": "en",
  "account": "OpenAI disclosed that it had thwarted a coordinated effort to extract sensitive reasoning from its AI models for the purpose of training or improving another model. The company identified this activity, described as adversarial distillation, which involves the unauthorized and systematic use of one model's outputs or reasoning to develop another. According to OpenAI, the campaign started on July 1 and escalated significantly, peaking with 16,000 requests from over 4,000 users on July 24 and 25. By July 28, the company had fully disrupted the operation.\n\nThe operators did not breach OpenAI's encryption, databases, or directly access user conversations. Rather, they manipulated interactions with the models to reproduce protected reasoning in a way that could be visible to the requester. Protected reasoning refers to the model's internal record of how it processes a task. Extracting this information could reveal information not included in the final answer, potentially enabling others to replicate the model's capabilities.\n\nOpenAI also observed attempts to extract protected reasoning in new ways, such as copying encrypted reasoning from one conversation and asking a different model to decrypt and transcribe it. Independent security researchers had previously reported similar vulnerabilities through responsible disclosure, and OpenAI confirmed these findings. The company is uncertain whether all operators were part of a single entity but noted a core cluster of activity was linked to individuals associated with Moonshot AI, developers of Kimi.\n\nAdversarial distillation poses safety and national security risks, as extracted reasoning could be used to train another model without preserving the safeguards applied to the original model's outputs. As models become more capable in dual-use areas, the risks associated with this type of activity increase. To combat the campaign, OpenAI employed account enforcement, technical controls, and partnerships. It banned or restricted fraudulent accounts, tightened signup and infrastructure controls, and enhanced monitoring for related networks. The company also fortified protections for hidden reasoning across users, workspaces, organizations, and model families. It closed a pathway that allowed someone with another user's encrypted reasoning to replay it and recover its contents. OpenAI anticipates adversarial distillation attempts will become more sophisticated as frontier models improve and actors seek cheaper ways to mimic capabilities. The company remains committed to ongoing work on technical protections, detection, enforcement, and threat-information sharing.",
  "summary": "The company said the activity was consistent with what it described as adversarial distillation, a practice involving the systematic and unauthorised use of one model's outputs or reasoning to help develop another model.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}