Leading U.S. developers of artificial intelligence models have repeatedly accused Chinese rivals of refining their products, with OpenAI recently filing a complaint against China’s Moonshot, accusing the company of extracting large amounts of data to train the startup’s models. OpenAI noticed corresponding suspicious activity in early July.
Image source: Moonshot AI
The creator of GPT said that the data extracted by Chinese developers can be used to reproduce the capabilities of OpenAI artificial intelligence models in aspects such as reasoning. OpenAI said that since early July, the company has seen thousands of attempts to obtain hidden information about how its own AI models solve problems that require inference and reasoning. These attempts were made by users of its AI models and were allegedly related to China’s moon landing AI. Coordination to extract the required data began in July, with the number of requests peaking at 16,000 that month. At the same time, OpenAI is not sure that all Chinese players are acting in the interests of Moonshot, but it is this new startup that has played a key role in these attempts.
Rapid advances in the capabilities of Moonshot’s Chinese artificial intelligence model, Kimi K3, have raised questions among U.S. officials about the conditions that will ensure its success. The Chinese startup is suspected of actively extracting advanced artificial intelligence models from OpenAI, Anthropic and Google. A representative of OpenAI said that such actions by China violated the U.S. company’s rules for using artificial intelligence models. OpenAI itself supports an ecosystem of open weighted artificial intelligence models supported by many Chinese developers, and hopes that the United States can maintain its global leadership in this field.
OpenAI is working to protect its artificial intelligence models from being refined by third-party developers by hiding the chains of logic that provide users with the answers they need. As the US startup points out, operators acting in the interests of Moonshot managed to circumvent these restrictions by copying encrypted information about these chains from a conversation and asking the AI model to decrypt it in a separate request. The Chinese tried to obtain information about a version of the inference algorithm used only on the OpenAI server, but it could not be cracked. Representatives of the startup said the evolving nature of these attacks demonstrated the need for data needed to train Chinese artificial intelligence models after OpenAI tightened its protection measures.
According to an Anthropic report from August this year, Moonshot ranked second behind Alibaba in terms of activity trying to refine the U.S. startup’s artificial intelligence model, and China’s DeepSeek ranked third. Chinese developers are also trying to gain access to the advanced computing power of Nvidia chips located abroad. The supply of many U.S.-origin artificial intelligence accelerators to China is restricted by U.S. export controls. Chinese developers are cooperating with each other. Alibaba, for example, agreed to give Moonshot AI access to some 20,000 Nvidia chips in its computing infrastructure.
Last month, Anthropic also accused Moonshot of simply directing thousands of user requests to the U.S. startup’s model and passing off the results as its own. At the same time, Moonshot uses the responses of the Claude series AI models to train its own Kimi model. The Chinese requests number in the millions, presumably related to the refinement of their own models. Early detection of such activity allows the creators of US models to block it, thereby reducing the amount of information extracted by Chinese developers. Chinese officials have repeatedly denied accusations of anti-competitive behavior against state developers of artificial intelligence systems.
OpenAI is trying to develop standards for sharing security and threat information for its artificial intelligence models, and it hopes proponents of open source weight models, including many Chinese rivals, will join the process. The company has shared information about such threats with other market participants and U.S. government agencies. In order to establish a permanent exchange of such information, U.S. antitrust laws must be changed because notes Bloomberg.
This week, U.S. technology giants also signed an artificial intelligence industry self-regulation agreement, which means creating conditions for independent review of artificial intelligence models produced for public safety. The move comes in response to the developers’ own statements about the need to focus on the security of decentralized AI models, rather than just pursuing their regular updates and improvements.
If you find an error, select it with your mouse and press CTRL+ENTER.









