Ordering the Dish Until You Can Cook It

Nobody broke into a server room. Picture instead a group of diners who order the same dish from the same restaurant thousands of times, take notes on every plate, and go home to reproduce it in their own kitchen. That is the whole of what OpenAI described on 30 September, when it said it had disrupted an adversarial distillation campaign and attributed a core cluster of it to “individuals associated with Moonshot AI”, the company behind Kimi. The recipe was never copied. The answers were.

Hold the contradiction before judging it. The same company that OpenAI points at is the one that, in the same month, put its own flagship model, Kimi K3, on the internet for anyone to download. One hand is accused of taking; the other is giving weights away. Whether that is hypocrisy, strategy, or two unrelated facts that landed in one news cycle is the question this piece is about, and the honest answer is that the public record does not settle it yet.

Why Did Distillation Become a Fight Now?

Closed frontier labs keep their best capability behind an API and a subscription. You can ask the model anything; you cannot have the model. Anyone who wants to catch up has two routes: spend enormous sums training from scratch, or learn from the leader’s answers. The second route is cheaper by orders of magnitude, which is why it was always going to be contested.

Distillation itself is ordinary engineering. Every lab does it: a large model answers, a small model is trained on those answers, and the small one inherits the big one’s habits at a fraction of the cost. What separates normal from adversarial is scale, whether limits are being evaded, whether the terms of the service being queried forbid it, and whose commercial output is being turned into whose training set.

Then there is the structural pressure. Chinese labs have released a run of strong open-weight models this year, and the gap to the closed American leaders has narrowed. The closer you get, the more tempting it is to let the leader’s answers cover the last stretch. That describes incentives in general and says nothing about any one company’s choices. We wrote about the economics of that open-weight push in our piece on China’s open-source AI strategy.

Finally, an open-weight release and a distillation accusation landing close together will be read as cause and effect. In this case they did not even land together: the campaign OpenAI describes ran in July, around K3’s launch, and OpenAI disclosed it two months later. Proximity on a timeline is not proof of a causal chain.

What Did OpenAI Say Happened, and When?

These three events are usually reported as separate stories. On a calendar they are one summer.

One summer, in order

Dates are from OpenAI’s post, Moonshot’s announcements, and press coverage named in the text.

  1. 1 July 2026OpenAI says the extraction activity began at low volume.
  2. 16 JulyMoonshot announces Kimi K3, “the world’s first open 3T-class model”.
  3. 22 JulyWhite House officials say Moonshot distilled Anthropic’s Fable for K3 and threaten sanctions; Moonshot denies it.
  4. 24 to 25 JulyOpenAI’s spike: about 16,000 attempted requests from more than 4,000 users.
  5. 27 JulyK3 weights published on Hugging Face.
  6. 28 JulyOpenAI says the campaign was fully disrupted.
  7. 8 to 10 SeptemberUS agencies issue an advisory naming six Chinese labs for distillation; Anthropic says Kimi traffic was relayed to Claude through fraudulent accounts; Beijing calls the accusations a pretext.
  8. 30 SeptemberOpenAI publishes its account of the July campaign.

What OpenAI says it found

OpenAI’s post , as The Hacker News and The Register reproduce it, defines adversarial distillation as “the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model”. The target was the model’s hidden reasoning, which OpenAI encrypts, rather than its visible answers. Operators, it says, “copied encrypted reasoning from one conversation and asked a model in another conversation to decrypt and transcribe it”. OpenAI is explicit that they “did not break our encryption, compromise a database, or gain direct access to stored user conversations”. The activity “violated our terms of service”. Everything here is OpenAI’s account; The Hacker News notes that no technical evidence for the Moonshot attribution was published.

Sealed envelope held against a desk lamp, the folded letter inside showing as a faint shadow.

What “15,000 users” does and does not mean

The number everyone repeats is the one OpenAI reported as “related prompt-pattern activity across a cluster of more than 15,000 users”. The noun is users whose accounts showed the pattern. It is not a count of bans, which OpenAI did not publish, and it is not a finding that 15,000 people took part. An account can sit in such a cluster as an operator, as a relay someone else routed traffic through, or as a bystander whose prompts happened to match. The public statement does not split the figure, so this article will not either.

What Moonshot did: Kimi K3 and its license

Moonshot announced Kimi K3 on 16 July as “the world’s first open 3T-class model”, aimed at “long-horizon coding, knowledge work, and reasoning”, and said in the same post that its performance “still trails the most powerful proprietary models”, according to its announcement. The weights went up on Hugging Face on 27 July under a modified MIT license. That is a product route: scale, openness, lower cost, aimed at people who run models themselves. It is not evidence that the company distilled anyone, and it is not evidence that it did not.

Moonshot has not responded to OpenAI’s 30 September post, as far as Decrypt and The Register could find. It did deny the earlier White House claim: its business head, Huang Zhenxin, said K3’s gains came from its own data filtering and architecture work, per Asia Times. Beijing’s commerce ministry called the US distillation campaign “a pretext to achieve industrial monopoly”, AFP reported in September.

So, what is settled. OpenAI made an accusation and says it acted on it: accounts banned, a pathway closed, findings shared with other labs. Kimi K3 is open-weight. What is not settled: the legal character of “individuals associated with”, the roles of the accounts in the 15,000 figure, and whether anything improper is in K3’s training data. Nobody outside the companies can currently check that last one.

What Sits Under the Adversarial Distillation Fight?

Technical: an answer carries the model with it

A model sold through an interface leaks behaviour by design. Every answer carries the model’s habits, knowledge and shortcuts, and at enough volume a collection of answers is close to the model in effect while being nothing like it in method. The defences are the ones OpenAI listed: rate limits, detecting abnormal prompt patterns, banning accounts, holding streamed output that might expose reasoning. All of them raise the cost of extraction. None of them makes an answer stop containing capability.

Terms, copyright and criminal law are three rulers

OpenAI’s terms of use say customers may not “use Output to develop models that compete with OpenAI”. Breaking that is a contract matter between OpenAI and the account holder. Copyright is a different ruler, and whether model outputs are protected at all is unsettled; experts quoted by the South China Morning Post said they are not. Trade-secret and computer-misuse law are a third ruler, and nobody has brought a case under them. A terms violation is real; it is also a long way from a conviction.

Business: the moat is “you can only ask here”

Part of a closed lab’s moat is that the capability lives in one place. If distillation at scale works, a rival has trained a cheaper substitute on your inference bill and then comes for your customers. That is why OpenAI has to say this out loud. Silence would turn the API into a free textbook. The post is as much a notice to every other large customer as it is a complaint about one.

Library with an open shelf of books beside a locked glass cabinet of similar books.

Open weights are a different competition, with a different exposure

Giving the weights away is a strategy too. K3 competes for the developer who wants to run a model privately, change it, and control cost, a market where beating a closed subscription on raw capability is not required. Open weights buy ecosystem and mindshare. They also put the question “where did this model learn that” under a spotlight, because the artefact is in everyone’s hands to probe. Our Xiaomi MiMo piece has the current gap between open and closed models, where K3 sits near the top of the open side.

Geopolitics flattens evidence into camps

US and Chinese officials have already turned this into a bloc story. In July the White House said it had “information” that Moonshot distilled Anthropic’s Fable and threatened sanctions, according to Bloomberg Law; no designation has followed as of this week. In September a joint NSA, CISA and FBI advisory named six Chinese labs for “systematic” distillation, as AFP reported , and Beijing’s commerce ministry called it “a pretext to achieve industrial monopoly”. Both sides gain from exaggeration: one can be painted as locking a market in the name of safety, the other as a state actor before any evidence is public. What a reader should track is the evidence level: a company blog, a wave of bans, a named association, or reproducible traces in training data. The same flattening happened to the chip story we covered in the Huawei Ascend piece .

Ordinary developers and users

The 15,000 figure frightens people who just use an account for work. The difference between normal use and organised extraction is scale, automation and purpose, not whether you asked it to write code one afternoon. The practical warning runs the other way: if you are harvesting large volumes of any commercial model’s output to train your own, read the terms first; the clause is explicit.

Wall of identical apartment mailboxes with a few doors marked by red tags.

What Should You Do About It, by Who You Are?

If you just use ChatGPT or Kimi to get work done: nothing here asks you to pick a side. Keep using them. Know that if your account is ever borrowed by abnormal traffic, it may be banned; that is a platform cutting a channel, and it says nothing about you.

If you are building a model or a product on one: distillation comes in three grades, and they are not the same act.

  • Using a teacher model you are licensed to use, within its terms, to train a smaller one. Ordinary engineering; we do it for clients in our AI agent work when a task does not need the frontier.
  • Bulk-querying someone else’s API to train a competitor. This is the act OpenAI has now said, publicly, it will detect and ban.
  • Taking open weights such as K3 and following the license. A third road, unrelated to the first two, and the license itself says nothing about distillation either way.

If you are choosing a model: open weights suit teams that need private deployment, modification and cost control; closed APIs suit teams that want the top capability without running anything. Add one question to the usual list: is this provider’s capability built on extraction that the other side can cut off? A single disruption can shrink an advantage that was stacked on someone else’s answers.

If you are reading the news: when you see “associated individuals”, “accounts involved” and “campaign disrupted”, ask three things. Who is saying it? Does “associated” mean employed, contracted, or merely in the same cluster? Has any one of the people counted been shown to have done it? If any of the three has no answer, do not forward it as a verdict.

Greg Brockman, OpenAI’s president, called K3 “a pretty good model” in July and said it was “too early” to know whether it was distilled, per Bloomberg Law. Two months later his company published its accusation naming “the developer of Kimi” and not K3. That gap is the honest state of the record, and it leaves the question that matters. When the most valuable thing a model produces is its answers, can a company sell those answers and also stop the world from learning from them? Every closed lab is betting yes. Every open-weight release is a bet that the question will stop mattering.

Further reading, by search term: OpenAI coordinated model distillation campaign Moonshot; adversarial distillation definition; Kimi K3 license Hugging Face; NSA CISA FBI advisory distillation September 2026; Anthropic Moonshot Claude relay.

FAQ: OpenAI, Moonshot and Kimi K3

What did OpenAI accuse Moonshot AI of?

In a 30 September 2026 post, OpenAI said it had disrupted a coordinated model distillation campaign that ran from 1 July to 28 July 2026, and that it attributed a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi. It said operators copied encrypted reasoning from one conversation and asked a model in another conversation to decrypt and transcribe it, which violated its terms of service. OpenAI banned the accounts and closed the pathway; it did not announce legal action, and Moonshot had not responded as of early October.

What is adversarial distillation?

Distillation is a normal technique: a stronger model’s answers are used to train a smaller or cheaper one. OpenAI uses adversarial distillation to mean the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce or improve another model, in other words large-scale, organised querying of a commercial model to extract its capability against the provider’s terms. Nobody copies the model’s weights; the capability is pulled out through the question-and-answer interface.

Did OpenAI say 15,000 Moonshot users took part?

No, that is not what OpenAI said. It reported a spike on 24 and 25 July of about 16,000 attempted requests using the extraction pattern from more than 4,000 users, and related prompt-pattern activity across a cluster of more than 15,000 users. The number counts accounts that showed the pattern, not people proven to be part of the operation and not a count of bans, which OpenAI did not publish. Accounts can appear in such a cluster as operators, as relays, or as bystanders whose usage happened to match.

What is Kimi K3?

Kimi K3 is Moonshot AI’s flagship model, announced on 16 July 2026 and released as open weights on Hugging Face on 27 July 2026. Moonshot calls it the world’s first open 3T-class model, built for long-horizon coding, knowledge work and reasoning, and says its performance still trails the strongest proprietary models. It is available through Kimi’s app and API and can be downloaded and run under the Kimi K3 License.

Is Kimi K3 open source, and what does its license allow?

Kimi K3 is open-weight: Moonshot announced it on 16 July 2026 and published the weights on Hugging Face on 27 July under the Kimi K3 License, a modified MIT license. Anyone can download, run and modify it. The license asks for a separate agreement once a model-as-a-service business built on it passes $20 million in revenue over 12 months, and for attribution at very large scale. It says nothing about training other models from K3’s outputs. Moonshot calls K3 the world’s first open 3T-class model and concedes it still trails the strongest proprietary models.