Chinese Military Taps US AI Models via Distillation, Escalating US-China Technology Battle

7 Sources

Share

Chinese military researchers leveraged US AI models from OpenAI and Anthropic to train defence systems through model distillation, according to a Reuters review of over 80 academic papers. The findings expose how China's People's Liberation Army systematically extracts capabilities from proprietary models despite US export controls, intensifying the US-China flashpoint over AI governance.

Chinese Military Researchers Extract Capabilities from US AI Models

Chinese military researchers have systematically used outputs from leading US AI models developed by OpenAI and Anthropic to train domestic defence systems, according to a Reuters investigation of more than 80 Chinese academic papers and patents

2

3

. The previously unreported findings reveal how military and security-linked institutions in China are leveraging cutting-edge US AI models as a shortcut to developing specialised systems, despite Washington's efforts to restrict Beijing's access to advanced chips and strategic technologies. The documents show widespread use of AI model distillation, a technique where outputs from a powerful AI system train smaller, specialised models that can be deployed locally without enormous computing requirements needed to build frontier AI systems from scratch

1

2

.

Understanding AI Model Distillation and Its Strategic Value

AI model distillation uses a large teacher model to train a smaller student model by generating examples such as answers and computer code as training material

1

4

. The student model does not inherit the teacher's weights, architecture or full capabilities. Instead, it learns selected behaviours enabling it to perform specific tasks more efficiently

1

5

. The appeal of distillation is that it makes AI cheaper and easier to deploy. A frontier model may require large data centres and expensive chips to operate, while distilled models can run on less powerful hardware and be tailored for specific tasks

1

4

. This makes them appealing to companies and governments looking to deploy AI more widely, from devices and factories to vehicles and private networks

1

.

Recent AI systems have increased interest in transferring not only final answers but also reasoning traces—the steps used to reach them

1

4

. Florian Tramèr, an assistant professor at ETH Zurich who researches machine-learning security, compared the process to human learning: "If I give you a book of complicated math problems with final solutions, you will have a much harder time learning how to solve problems than if I gave you detailed solutions that describe all steps to take"

1

5

. As reasoning traces have become more valuable, access to AI outputs has become more sensitive because they may expose methods advanced systems use to tackle complex problems

1

4

.

Military Applications Across Surveillance and Cyber Warfare

Reuters' review, which included research compiled by the Washington-based Jamestown Foundation, showed distillation is widely used by researchers linked to the People's Liberation Army and other military institutions

2

3

. Sunny Cheung, a Jamestown fellow who analysed over 60 of the papers, said Chinese military scientists are systematically capturing the reasoning steps of Western models to adapt them for surveillance, cyber warfare and tactical decision-making

2

3

. "Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder. These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally," Cheung stated

2

3

.

One paper published last year by researchers in PLA Unit 96941, a military intelligence and cyber-warfare unit in Beijing, described using OpenAI's GPT-3.5 to process sensitive military source code

2

3

. The researchers said third-party models were unsuitable for handling classified information. To overcome that limitation, they used GPT-3.5 to summarize software code and trained a domestic model on those summaries to run entirely within Chinese military networks

2

3

. A 2024 paper from the PLA's National University of Defense Technology described using distillation to shrink an image-processing model for deployment on unmanned aerial vehicles, allowing drones to analyse live video and support drone navigation and targeting decisions in real time even when communications are cut

2

3

.

Unauthorised Extraction Emerges as US-China Flashpoint

The dispute centres on unauthorised extraction, not distillation itself, which is a widely used industry practice

2

3

. The issue has emerged as a major flashpoint ahead of US-China talks on AI governance and safety

2

3

. US officials have accused some Chinese entities of using distillation to extract capabilities from American AI models, potentially undermining export controls and infringing intellectual property rights

2

3

. Anthropic has accused Chinese entities including DeepSeek, Moonshot and MiniMax of conducting large-scale campaigns to obtain capabilities from Claude models, targeting capabilities including software engineering and advanced reasoning

1

4

. OpenAI has also detected attempts by Chinese actors to use its models for distillation-related purposes

1

4

.

China has rejected the accusations, saying Washington is pursuing AI hegemonism while arguing that US firms have engaged in similar practices

2

3

. Chinese developers have disputed claims that their AI advances rely on foreign models. AI startup Moonshot last week denied allegations by the Trump administration that its Kimi K3 model was built using distillation, saying it was driven by proprietary innovations

2

3

. Anthropic said it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations

2

3

. The company added that distilled models may lose the original systems' safety safeguards, potentially allowing sensitive capabilities to be transferred to models beyond its control

2

3

.

Implications for Geopolitical Tensions and Technology Leadership

The papers suggest Chinese defence institutions see leading US AI models as both a source of technical insight and a way to close the gap with American rivals

2

3

. At the North University of China, which has close links to the country's weapons industry, researchers used Anthropic's Claude 3 Haiku to generate synthetic training data for a text classification model for social media monitoring and content moderation

2

3

. Researchers at China's Academy of Military Sciences used distillation to run a target recognition model on tactical hardware during simulated maritime operations involving drones, ships and unmanned submarines, a study published earlier this year showed

2

3

. The White House, Pentagon, China's foreign ministry, the People's Liberation Army and OpenAI did not respond to requests for comment

2

3

. Watch for escalating regulatory measures from Washington, potential restrictions on API access, and how this controversy shapes upcoming US-China technology battle negotiations on AI governance.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved