Chinese military researchers have used outputs from leading U.S. artificial intelligence models developed by OpenAI and Anthropic to train domestic AI systems to advance China’s defense capabilities, according to a Reuters review of more than 80 Chinese academic papers and patents.
The previously unreported findings offer a rare glimpse into how military and security-linked institutions in China are leveraging cutting-edge U.S. AI models as a shortcut to developing specialised systems of their own, despite Washington’s efforts to restrict Beijing’s access to advanced chips and other strategic technologies.
The documents show widespread use of a technique known as “model distillation,” in which outputs from a powerful AI system are used to train smaller, specialised models that can be deployed locally without the enormous computing requirements needed to build frontier AI systems from scratch.
Reuters’ review, which included research compiled by the Washington-based Jamestown Foundation and shared exclusively with the news agency, showed distillation is widely used by researchers linked to the People’s Liberation Army and other military institutions.
The papers suggest Chinese defense institutions see leading U.S. AI models as both a source of technical insight and a way to close the gap with American rivals.
The dispute centres on unauthorised extraction, not distillation itself, a widely used industry practice.
The issue has emerged as a major flashpoint ahead of U.S.-China talks on AI governance and safety. U.S. officials have accused some Chinese entities of using distillation to extract capabilities from American AI models, potentially undermining export controls and infringing intellectual property rights.
China has rejected the accusations, saying Washington is pursuing AI “hegemonism” while arguing that U.S. firms have engaged in similar practices.
Chinese developers have also disputed claims that their AI advances rely on foreign models. AI startup Moonshot last week denied allegations by the Trump administration that its Kimi K3 model was built using distillation, saying it was driven by proprietary innovations.
Sunny Cheung, a Jamestown fellow who analysed over 60 of the papers, said Chinese military scientists are systematically capturing the reasoning steps of Western models to adapt them for surveillance, cyber warfare and tactical decision-making.
“Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder,” said Cheung.
“These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally.”
Reuters verified the academic literature and identified an additional two dozen military-linked case studies.
One paper published last year by researchers in PLA Unit 96941, a military intelligence and cyber-warfare unit in Beijing, described using OpenAI’s GPT-3.5 to process sensitive military source code.
The researchers said third-party models were unsuitable for handling classified information. To overcome that limitation, they used GPT-3.5 to summarize software code and trained a domestic model on those summaries to run entirely within Chinese military networks.
The White House, Pentagon, China’s foreign ministry, the PLA and OpenAI did not respond to requests for comment.
WIDE USE, FROM MONITORING TO MILITARY
Chinese researchers have used distillation for purposes ranging from content monitoring to military deployment, Reuters’ and Jamestown’s review of the papers showed.
At the North University of China, which has close links to the country’s weapons industry, researchers used Anthropic’s Claude 3 Haiku to generate synthetic training data for a text classification model for social media monitoring and content moderation.
Anthropic said it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations.
The company added that distilled models may lose the original systems’ safety safeguards, potentially allowing sensitive capabilities to be transferred to models beyond its control.
A 2024 paper from the PLA’s National University of Defense Technology described using distillation to shrink an image-processing model for deployment on unmanned aerial vehicles, allowing drones to analyse live video and support navigation and targeting decisions in real time even when communications are cut.
Similarly, researchers at China’s Academy of Military Sciences used distillation to run a target-recognition model on tactical hardware during simulated maritime operations involving drones, ships and unmanned submarines, a study published earlier this year showed.
BENEFITS AND LIMITS
China has embraced distillation as it seeks to compete with the U.S. in frontier AI while facing constraints on advanced computing resources due to Washington’s export controls on high-end chips.
Central and local governments have promoted “model lightweighting” and edge computing, directing subsidies and research funding toward technologies that enable AI models to run on drones, satellites and other devices with limited processing power.
Experts caution, however, that distillation has significant limitations.
As Chinese AI models close the gap with their U.S. counterparts, military researchers are also examining distillation as a potential security risk.
In January, researchers at the Army Engineering University published a paper on the threat of “data-free distillation,” a method of reverse-engineering a model’s capabilities without direct access to its core parameters.
To counter that vulnerability, they proposed defense mechanisms designed to mask the hidden logical information exposed in a model’s public outputs.
Distilled models also inherit only selected capabilities and cannot fully replicate the broad intelligence of frontier systems.
Trevor Koverko, co-founder of AI data company Sapien, said distilled models remain less capable than their teacher models.
“It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI.”
Facts Only
* Chinese military researchers used outputs from leading U.S. artificial intelligence models to train domestic AI systems.
* This finding was documented in a review of over 80 Chinese academic papers and patents.
* The method employed is known as "model distillation," which uses outputs from powerful AI systems to train smaller, specialized models for local deployment.
* Distillation allows for the development of specialized systems without requiring the computing power for frontier AI systems from scratch.
* Researchers linked to the People’s Liberation Army and other military institutions widely use distillation.
* One paper detailed using GPT-3.5 to summarize software code, training a domestic model on those summaries for internal military networks.
* Researchers used Anthropic’s Claude 3 Haiku to generate synthetic training data for social media monitoring models at the North University of China.
* Distillation was used to shrink an image-processing model for deployment on unmanned aerial vehicles to aid in real-time analysis and targeting decisions.
* Distillation enabled running target-recognition models on tactical hardware during simulated maritime operations involving drones and submarines.
Executive Summary
Chinese military researchers have utilized outputs from leading U.S. AI models, including those from OpenAI and Anthropic, to train domestic AI systems to enhance defense capabilities. This practice involves a technique called "model distillation," where outputs from powerful external models are used to train smaller, specialized local models, circumventing the need for massive computing resources. Research compiled by the Jamestown Foundation indicated that researchers linked to the People’s Liberation Army and other military institutions widely employ this method.
The activity stems from the context of U.S. efforts to restrict access to advanced chips and strategic technologies for China. Chinese defense institutions appear to view leading U.S. AI models as a source of technical insight to narrow the gap with American rivals. While some U.S. officials have accused certain Chinese entities of using distillation to extract capabilities and undermine export controls, China has rejected these claims, framing the issue around concerns over U.S. "hegemonism." Furthermore, other Chinese developers dispute the reliance on foreign models for their AI advances, emphasizing proprietary innovation.
Full Take
The dynamic described reveals a strategic tension between external technological constraints imposed by the U.S. and domestic efforts to achieve AI parity within defense sectors. The use of model distillation acts as an operational bridge, allowing access to high-level reasoning capabilities—the "reasoning behind the answer"—without requiring direct access to or development of frontier systems. This process shifts the focus from direct IP theft (which is disputed) toward capability transfer via intermediate artifacts, which complicates governance and enforcement.
The implication of transferring reasoning rather than just data is profound: if smaller, controllable systems can effectively mimic the strategic reasoning of frontier models for surveillance and tactical decision-making, the security risk lies not in the stolen weights themselves, but in the resulting localized capabilities that operate outside external oversight. The pattern suggests a systemic pursuit of cognitive sovereignty through constrained access.
What mechanisms exist to evaluate the fidelity and safety of these transferred reasoning steps? If distillation is used as a method for capability extraction, how can international governance structures effectively monitor or regulate knowledge transfer when the mechanism itself (distillation) is widely accepted practice across academic research? What are the long-term security consequences when military entities prioritize local control through this means over adherence to external safety protocols established by developers like OpenAI and Anthropic?
Sentinel — Human
The text appears to be a synthesized report grounded in academic and journalistic findings, effectively bridging specific military research with broader AI governance debates.
