Chinese Military Taps OpenAI and Anthropic Models to Train Defence Systems via AI Model Distillation

Reviewed byNidhi Govil

10 Sources

Share

A Reuters investigation uncovered that Chinese military researchers have systematically used outputs from leading US AI models developed by OpenAI and Anthropic to train domestic defence systems. The review of over 80 academic papers and patents reveals widespread use of AI model distillation by People's Liberation Army-linked institutions, exposing a critical gap in US export controls and escalating US-China geopolitical tensions ahead of AI governance talks.

News article

Chinese Military Exploits US AI Models Through Distillation

Chinese military researchers have systematically leveraged outputs from frontier AI models developed by OpenAI and Anthropic to train domestic defence systems, according to a Reuters investigation examining more than 80 Chinese academic papers and patents

1

2

. The findings, compiled with research from the Washington-based Jamestown Foundation, reveal how People's Liberation Army-linked institutions are using AI model distillation as a shortcut to develop specialized military applications despite US export controls restricting access to advanced chips

1

.

The investigation offers rare insight into how Chinese defence institutions view US AI models as both a source of technical knowledge and a mechanism to close the capability gap with American rivals

5

. Reuters independently verified the academic literature and identified an additional two dozen military-linked case studies beyond the Jamestown Foundation's initial analysis

2

.

Understanding AI Model Distillation and Its Strategic Value

AI model distillation involves using outputs from a powerful teacher model to train a smaller student model that can perform specific tasks with significantly fewer computing resources

1

. The technique has become particularly valuable because it transfers not just final answers but reasoning traces—the step-by-step problem-solving approaches that advanced systems use to tackle complex challenges

1

.

Florian Tramèr, an assistant professor at ETH Zurich specializing in machine-learning security, explained the distinction: "If I give you a book of complicated math problems with final solutions, you will have a much harder time learning how to solve problems than if I gave you detailed solutions that describe all steps to take"

1

. This capability to transfer reasoning rather than just outputs makes distillation particularly powerful for military applications

2

.

Sunny Cheung, the Jamestown fellow who analyzed over 60 papers, emphasized that Chinese military scientists are systematically capturing reasoning steps from Western models to adapt them for surveillance, cyber warfare and tactical decision-making

5

. "Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," Cheung noted, adding that the papers show researchers transferring expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally

2

.

Military Applications Span Cyberwarfare to Drone Navigation

The Reuters review documented specific military applications across multiple Chinese defence institutions. PLA Unit 96941, a military intelligence and cyber-warfare unit in Beijing, published a paper describing how researchers used OpenAI GPT-3.5 to process sensitive military source code

2

5

. The researchers acknowledged that third-party models were unsuitable for classified information, so they used GPT-3.5 to summarize software code and trained a domestic model on those summaries to run entirely within Chinese military networks

1

.

At the North University of China, which maintains close links to the country's weapons industry, researchers used Anthropic Claude 3 Haiku to generate synthetic training data for a text classification model designed for social media monitoring and content moderation

5

. Anthropic responded by stating it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations

1

.

A 2024 paper from the PLA's National University of Defense Technology detailed using distillation to shrink an image-processing model for deployment on unmanned aerial vehicles, enabling drone navigation and target recognition in real time even when communications are severed

5

. Similarly, researchers at China's Academy of Military Sciences used distillation to run a target-recognition model on tactical hardware during simulated maritime operations involving drones, ships and unmanned submarines

1

.

How Distillation Circumvents US Export Controls

The strategic significance of AI model distillation lies in how it sidesteps the logic of US export controls, which restrict the advanced chips needed to train frontier AI models but cannot restrict the text outputs those models produce

3

. Washington's export controls regulate physical objects—chips, tools and hardware that cross borders—but the outputs being transferred through distillation are text that a model produced, which crosses no border in any customs sense

3

.

This represents a fundamental gap in the US regulatory framework. Export controls are built to deny China the chips needed to train frontier models, but distillation eliminates that requirement because the expensive computational work has already been completed by American companies

3

. The technique allows Chinese researchers to create smaller models that inherit selected behaviors at a fraction of the compute cost and can run on modest local hardware

4

.

Escalating US-China Geopolitical Tensions Over AI Governance

The distillation controversy has emerged as a major flashpoint ahead of US-China talks on AI governance and safety

1

5

. US officials and leading AI firms have accused Chinese entities including DeepSeek, MiniMax and Moonshot of conducting large-scale campaigns to obtain capabilities from proprietary models

1

. Anthropic specifically accused these entities of targeting capabilities including software engineering and advanced reasoning from its Claude models

1

.

China has rejected the accusations, characterizing Washington's position as pursuing AI hegemonism while arguing that US firms have engaged in similar practices

1

5

. Chinese developers have disputed claims that their advances rely on foreign models. AI startup Moonshot denied allegations by the Trump administration that its Kimi K3 model was built using distillation, stating it was driven by proprietary innovations

2

5

.

US Treasury Secretary Scott Bessent has threatened to sanction Chinese AI firms deemed guilty of unauthorized distillation, though critics point out the irony given that Anthropic's models were trained on massive amounts of internet data without permission

4

. The dispute centers on unauthorized extraction rather than distillation itself, which remains a widely used industry practice employed by US researchers and companies including Stanford University's Alpaca project and Microsoft's Orca research

1

.

Long-Term Implications and What to Watch

While distillation enables Chinese researchers to match US model capabilities in narrow applications, experts suggest it does not provide a path to surpassing American AI leadership. SapienX co-founder Trevor Koverko characterized distillation as "transferring selected capabilities into a cheaper, locally controlled system" rather than achieving independence from frontier AI

4

. Chinese researchers will still need original breakthroughs to outperform US rivals

4

.

The White House has registered the problem at both the chip and distillation levels, but identifying the issue differs from having effective control mechanisms

3

. The debate over whether distillation constitutes theft or standard practice may matter less than the fact that neither characterization offers a workable regulatory solution

3

.

Anthropic warned that distilled models may lose the original systems' safety safeguards, potentially allowing sensitive capabilities to be transferred to models beyond its control

5

. This safety dimension adds another layer of concern beyond the geopolitical and intellectual property issues. The White House, Pentagon, China's foreign ministry, the PLA and OpenAI all declined to comment on the Reuters findings

2

5

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved