An AI company is accusing another AI company of improperly learning from its AI. If your first reaction is that learning from other people’s work sounds suspiciously like the entire business, you have already found the reason this argument is attracting attention.
Unfortunately, the headlines tend to skip several important steps. They jump from “distillation” to “stealing intelligence,” then add national security concerns before most readers have figured out what was supposedly taken. Somewhere in that journey, a fairly understandable dispute becomes a vocabulary exam.
So let’s start with a monkey, a tutor, and a pile of bananas. The monkey needs no background in machine learning. Neither do you.
Meet the Two Companies Fighting Over the Bananas
OpenAI is the company behind ChatGPT. Moonshot AI is a Chinese developer behind Kimi, another family of AI models and an AI assistant. For this story, imagine two companies selling tutoring services. Both want their tutor to give useful answers, attract customers, and justify the money spent building it.
In a September 30, 2026 disclosure, OpenAI alleged that people associated with Moonshot participated in a coordinated attempt to extract protected reasoning from its models. It attributed a core cluster of activity to those individuals, while acknowledging that it could not establish whether every operator belonged to the same actor. That is a more specific, limited accusation than “Moonshot stole ChatGPT.” [1]
To understand the complaint, we need to separate the answers an AI gives you from the additional material it may generate while producing those answers.
Could be related: Human vs AI: How Embracing GenAI is Evolving Us into Better Humans
How Can One AI Learn From Another?
Suppose a monkey wants to learn how to divide twelve bananas between three friends. A tutor gives it the answer: four each. The monkey then studies thousands of similar examples until it becomes better at solving new problems.
In AI development, something broadly comparable can happen. Developers collect answers from an existing model and use them as examples to train another model. This is called distillation. The second model is learning patterns from examples, rather than receiving a downloaded copy of the first model’s machinery.
Think of the difference between learning to cook by studying meals and being handed the restaurant’s entire kitchen. You may learn something useful from the meals, but you still need your own ingredients, equipment, and practice.
Distillation is not inherently scandalous. OpenAI itself introduced an API feature for it in 2024, helping developers use outputs from larger models to improve smaller ones. An API is simply a way for software to request an AI’s services directly, rather than having a person type into a chat window. [2]
The dispute, therefore, cannot be explained as “learning from another AI is bad.” The important questions are what material was obtained, how it was obtained, and what the provider permitted.
What Was Allegedly Taken?
Return to the banana problem. The final answer is four bananas each. A worked explanation might show that twelve divided by three equals four, or describe dealing out one banana at a time until the pile is empty.
Some AI models generate intermediate text while working through a task. This is often called a reasoning trace or chain of thought. It can contain more information than the final answer, making it potentially useful as training material. However, it is generated text, not a perfect window into a humanlike mind. An explanation can be helpful without faithfully describing every process that produced it.
OpenAI’s complaint concerns attempts to recover reasoning it intended to keep protected. It says operators manipulated interactions to expose that material. It also says they did not break its encryption, compromise a database, or directly access stored user conversations. Its reported request counts describe attempts, not necessarily successful extractions. [1]
The simple distinction is between studying explanations the tutor willingly hands out and allegedly finding a way to recover notes the service was designed to withhold. Whether that boundary is fair is another question, but we first need to understand which boundary is being disputed.
Is This Just OpenAI’s Word Against Moonshot’s?
There is independent research supporting the existence of a relevant technical weakness. An August 2026 paper describes how protected reasoning could be recovered from systems operated by OpenAI, Anthropic, and Google. [3]
The researchers examined systems that send encrypted reasoning blocks back to the software using the AI. Imagine receiving a sealed envelope that you cannot read, but must return to the tutor during the next lesson so it can continue from where it stopped.
The problem arose when those envelopes could be moved between compatible sessions or models. The researchers found ways to get a different model within the same provider’s system to expose their contents. The protection around the information could fail even though nobody had mathematically cracked the encryption. [3]
That supports the technical possibility of extraction. It does not independently identify Moonshot as the operator behind OpenAI’s campaign. Knowing a window can be opened does not tell us who climbed through it.
Nor does discovering an extraction attempt establish how much it helped a rival. Someone could obtain useful training examples, poor examples, or almost nothing. Even useful material would not tell us what proportion of a model’s abilities came from it.
Moonshot previously rejected suggestions that Kimi K3’s performance came from distillation, saying its gains reflected original architectural changes, according to July reporting by Reuters. That response concerned earlier allegations, not this September disclosure. The Register reported receiving no immediate Moonshot response to the new complaint. [4][5]
A company can also develop original technology and learn from competitors. Those possibilities are not mutually exclusive. The public information reviewed here does not let us reduce Kimi’s development to one explanation.
Why Are People Calling OpenAI Hypocritical?
The criticism is easy to understand. AI developers learn from enormous collections of human-created material. When they complain about competitors learning from their products, people naturally ask why their own work deserves a protective fence while everyone else’s becomes educational scenery.
OpenAI has publicly argued that training AI on copyrighted material can qualify as fair use. That is its legal position, not a universal ruling that every use of every work is permitted. [6]
Still, the moral question has force. If learning from existing work is essential to progress, why should that principle suddenly become narrower when the learner is a rival company?
There is also a meaningful response. Accessing material through a service with restrictions, and allegedly bypassing controls to recover withheld information, can differ from studying publicly accessible material. A library book, a paid lesson, and a locked filing cabinet are all sources of knowledge, but access to one does not automatically grant access to the others.
That distinction deserves examination rather than automatic acceptance. Calling information proprietary does not settle every question about how it may be used. Equally, accusing a company of hypocrisy does not prove that bypassing its restrictions was acceptable. The monkey can question the fence without pretending the fence never existed.
Might be related: Why Does AI Hallucinate? Because It Was Trained to Always Have an Answer
Why Does This Become a Safety Argument?
OpenAI argues that extracting reasoning could transfer capabilities without preserving the safeguards surrounding the original service. [1] In everyday terms, a tutor might know how to solve a dangerous problem but refuse to provide the instructions. Training another system on material behind that refusal could potentially pass along information the public answer withheld.
That possibility should be investigated. It should also remain a possibility unless evidence shows the consequence actually occurred. The September disclosure does not demonstrate that a particular Kimi model became unsafe because of this campaign.
There is a commercial interest here too. A developer that spends heavily on a model has an incentive to stop rivals obtaining valuable training material cheaply. Safety concerns and business interests can coexist; finding one does not automatically cancel the other.
For readers, the useful habit is to ask what a claim demonstrates. Evidence of an extraction weakness supports a security concern. Establishing a particular company’s responsibility requires attribution evidence. Establishing resulting harm requires evidence of that harm. Adding “national security” to a sentence does not complete those missing steps.
What Should Ordinary People Take Away?
The argument involves more than two companies accusing each other of copying. It concerns where the industry draws the boundary between learning, authorized reuse, and extracting information against a provider’s restrictions.
There is a reasonable case for protecting costly development work. There is also a reasonable concern that powerful companies could define “improper learning” so broadly that it becomes a convenient barrier to competition. We should judge the specific conduct and the proposed rules, rather than assuming that either the expensive incumbent or the cheaper challenger must be right.
For now, the clearest account is that OpenAI has alleged a protected-reasoning extraction campaign and linked part of it to people associated with Moonshot. Independent research supports the existence of the underlying weakness, while important questions about responsibility, successful extraction, and benefits to Kimi remain unresolved.
The monkey does not need to pick a team yet. It needs to know which bananas were offered, which were allegedly taken, and whether anyone has shown the receipts.
