Beijing/Washington – In a significant and previously unreported development, Chinese military researchers are systematically utilizing advanced artificial intelligence models developed by leading U.S. tech firms, OpenAI and Anthropic, to bolster China’s domestic defense capabilities. A comprehensive review of over 80 Chinese academic papers and patents by Reuters, corroborated by research from the Washington-based Jamestown Foundation, reveals a widespread practice of "model distillation," allowing Beijing to shortcut its path to specialized AI systems despite stringent U.S. export controls aimed at restricting China’s access to strategic technologies.

This revelation highlights a critical flashpoint in the escalating technological rivalry between the United States and China, exposing the complexities of controlling dual-use technologies in a globally interconnected AI landscape. While model distillation is a recognized industry practice, its application by military and security-linked institutions in China to adapt proprietary Western AI for sensitive defense applications has ignited concerns over intellectual property infringement, national security, and the potential undermining of U.S. efforts to curb China’s military modernization.

The Method: Model Distillation Explained

At the heart of this strategic maneuver is a technique known as "model distillation." This process involves taking the sophisticated outputs and learned reasoning patterns from a powerful, large-scale AI system (the "teacher model") and using them to train a smaller, more specialized AI model (the "student model"). The student model effectively learns to mimic the behavior and decision-making logic of its more capable teacher, but with significantly reduced computational requirements.

The appeal of distillation for Chinese defense researchers is multifaceted. Building cutting-edge "frontier" AI systems from scratch demands colossal computing power, vast datasets, and extensive research and development — resources that even leading nations find challenging to amass. By leveraging the outputs of established U.S. models like OpenAI’s GPT-3.5 and Anthropic’s Claude 3 Haiku, Chinese institutions can bypass these monumental requirements. This allows them to create compact, efficient, and specialized AI systems that can be deployed locally within their own networks, often on hardware with limited processing capabilities, such as drones, satellites, or tactical ground systems.

This method offers a potent workaround to Washington’s attempts to restrict China’s access to advanced semiconductors and other strategic AI components. By extracting the ‘intelligence’ rather than the underlying hardware, Chinese researchers are effectively gleaning the fruits of billions of dollars of U.S. investment in AI research and infrastructure. While distillation itself is a common industry practice for optimizing models for specific tasks or environments, its application in this context – particularly by military entities to adapt proprietary foreign AI for defense purposes – raises profound ethical, legal, and security questions.

A Strategic Shortcut Amid Geopolitical Tensions

The findings underscore China’s determined pursuit of AI dominance, viewing leading U.S. AI models not merely as tools but as invaluable sources of technical insight and a means to bridge the technological chasm with American rivals. This strategy represents a pragmatic approach to innovation, capitalizing on existing advanced capabilities to accelerate domestic development.

Washington’s strategy has been to erect barriers, primarily through export controls on high-end chips and related technologies, to slow China’s progress in critical areas like AI, quantum computing, and advanced semiconductors. The premise is that by denying China access to foundational components, its ability to develop sophisticated military applications would be hampered. However, the widespread adoption of model distillation by Chinese military-linked institutions suggests that these controls, while impactful, are not entirely airtight and can be circumvented through ingenious technological means.

Chinese military researchers tap U.S. AI models to train defence systems

This "shortcut" has transformed into a major flashpoint ahead of crucial U.S.-China talks on AI governance and safety. U.S. officials have openly voiced concerns that Chinese entities are engaging in unauthorized extraction of capabilities from American AI models, thereby undermining export control regimes and infringing upon intellectual property rights. The implicit accusation is that China is unfairly leveraging the innovation of U.S. companies for its strategic advantage, particularly in military applications. China, in turn, has vehemently rejected these accusations, framing Washington’s stance as an attempt at "AI hegemonism" and retorting that U.S. firms have engaged in similar practices. This reciprocal blame game underscores the deep mistrust and divergent interpretations of responsible AI development and international technological ethics.

Chronology of Discovery and Research

The groundbreaking findings emerged from a meticulous review conducted by Reuters, which analyzed more than 80 Chinese academic papers and patents. This extensive body of work provided unprecedented insight into the methodologies and applications of AI within China’s defense sector. A significant portion of this research was compiled by the Jamestown Foundation, a Washington-based policy institute specializing in strategic global analysis, and shared exclusively with the news agency.

Sunny Cheung, a fellow at the Jamestown Foundation who personally analyzed over 60 of these critical papers, offered a stark assessment of the Chinese approach. Cheung highlighted that Chinese military scientists are not merely copying solutions but are systematically "capturing the reasoning steps of Western models" – a far more complex and valuable form of knowledge transfer. "Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," Cheung stated. "These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally." This distinction is crucial, as it suggests a deeper assimilation of AI intelligence rather than superficial replication.

Reuters further corroborated these findings by verifying the academic literature and independently identifying an additional two dozen military-linked case studies, reinforcing the prevalence and systematic nature of this distillation strategy across China’s defense apparatus. The cumulative evidence paints a clear picture of a deliberate and coordinated effort to integrate advanced AI capabilities, sourced indirectly from U.S. pioneers, into China’s strategic military planning and operations.

Supporting Data: Specific Military Applications

The reviewed papers provide concrete examples of how model distillation is being applied across various military domains, illustrating the breadth and sophistication of China’s defense AI strategy.

Cyber Warfare and Intelligence

One particularly revealing paper, published last year by researchers from PLA Unit 96941 – a military intelligence and cyber-warfare unit based in Beijing – described the use of OpenAI’s GPT-3.5. The unit utilized the model to process sensitive military source code. Acknowledging the inherent risks of handling classified information with third-party models, the researchers employed GPT-3.5 to summarize complex software code. These summaries then served as training data for a domestically developed model, which could operate entirely within secure Chinese military networks. This approach allowed the unit to leverage the advanced language processing capabilities of GPT-3.5 while mitigating the security risks associated with feeding classified data directly into a foreign-controlled AI system. It demonstrates a sophisticated understanding of both AI capabilities and operational security protocols.

Surveillance and Content Moderation

Beyond direct military applications, Chinese institutions are also leveraging U.S. AI for broader security and control objectives. At the North University of China, an institution with strong ties to the country’s weapons industry, researchers employed Anthropic’s Claude 3 Haiku. Their objective was to generate synthetic training data for a text classification model designed for social media monitoring and content moderation. This application points to the dual-use nature of AI technologies, where capabilities honed for commercial or general intelligence tasks can be repurposed for state surveillance and censorship, reinforcing the Chinese government’s control over information.

Chinese military researchers tap U.S. AI models to train defence systems

Autonomous Systems and Tactical Operations

Perhaps the most direct military applications of distilled AI are found in the realm of autonomous systems and real-time tactical decision-making.

  • Unmanned Aerial Vehicles (UAVs): A 2024 paper from the PLA’s National University of Defense Technology detailed the use of distillation to shrink an image-processing model. This miniaturized model was then deployed on unmanned aerial vehicles, enabling drones to analyze live video feeds, support navigation, and make targeting decisions in real time, even when communication links are severed. This capability is crucial for independent drone operations in contested environments, enhancing battlefield autonomy.

  • Maritime Operations: Similarly, researchers at China’s Academy of Military Sciences applied distillation to run a target-recognition model on tactical hardware during simulated maritime operations. This study, published earlier this year, involved coordinated actions by drones, ships, and unmanned submarines, showcasing how distilled AI can empower distributed, autonomous naval forces to identify and track targets with greater efficiency and less reliance on human intervention or constant communication.

These examples collectively demonstrate China’s strategic embrace of "model lightweighting" and edge computing – technologies that allow sophisticated AI models to run on devices with limited processing power. This strategy is heavily promoted by central and local governments, which direct significant subsidies and research funding toward these areas, explicitly seeking to overcome the constraints imposed by Washington’s export controls on high-end chips.

Official Responses and Denials

The emergence of these findings has predictably drawn sharp reactions and a lack of direct comment from key parties. The White House, Pentagon, China’s foreign ministry, the PLA, and OpenAI all declined to respond to Reuters’ requests for comment, indicating the sensitivity and potentially classified nature of the revelations.

U.S. officials have previously articulated concerns regarding unauthorized extraction and the infringement of intellectual property rights, framing such actions as direct challenges to export controls. The implicit message is that using the outputs of U.S. AI models for military purposes, especially without authorization, is a violation of international norms and national security interests.

Anthropic, one of the implicated U.S. AI developers, stated that it does not provide commercial access to its Claude models in China or to Beijing-controlled firms. The company also confirmed it employs monitoring systems to detect policy violations, underscoring its efforts to prevent misuse. Crucially, Anthropic added a significant caveat: "distilled models may lose the original systems’ safety safeguards, potentially allowing sensitive capabilities to be transferred to models beyond its control." This highlights a critical risk dimension, suggesting that even if the primary model has built-in ethical and safety guardrails, these might not transfer to a distilled student model, potentially creating AI systems that operate with fewer constraints.

Chinese military researchers tap U.S. AI models to train defence systems

On the Chinese side, there have been outright denials regarding reliance on foreign models. For instance, AI startup Moonshot last week refuted allegations from the Trump administration that its Kimi K3 model was built using distillation, asserting that its innovations were proprietary. This stance reflects a broader Chinese narrative that emphasizes self-reliance and indigenous innovation, often downplaying the role of foreign technology in its advancements. China’s accusation of "AI hegemonism" further frames the U.S. position as an attempt to maintain technological dominance rather than a genuine concern for fair play or security.

Implications and Future Outlook

The systematic use of model distillation by Chinese military researchers carries profound implications for the global AI landscape, U.S.-China relations, and the future of technological competition.

Strategic Implications for AI Competition

This practice illustrates China’s strategic agility in navigating U.S. restrictions. By focusing on extracting and adapting the "intelligence" rather than directly acquiring the restricted hardware, Beijing demonstrates its capacity to continue its pursuit of AI dominance. It underscores the dual-use nature of AI, where advancements in civilian AI can be rapidly repurposed for military applications, blurring the lines between commercial innovation and national security. For U.S. policymakers, this presents an enormous challenge: how to effectively contain technology transfer when the "transfer" occurs at the level of abstract knowledge and model outputs rather than tangible goods. The efficacy of current export controls, while not entirely negated, is shown to be less comprehensive than perhaps intended.

Technical Limitations and Security Risks

While effective as a shortcut, model distillation is not without its limitations. Experts caution that distilled models inherently inherit only selected capabilities and cannot fully replicate the broad intelligence and versatility of the original frontier systems. Trevor Koverko, co-founder of AI data company Sapien, succinctly put it: "It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI." This means China’s distilled military AI, while potent for specific tasks, may still lack the general intelligence and adaptability of the most advanced U.S. models.

Intriguingly, Chinese AI researchers are themselves examining distillation as a potential security risk. In January, researchers at the Army Engineering University published a paper on the threat of "data-free distillation" – a method of reverse-engineering a model’s capabilities without direct access to its core parameters. To counter this vulnerability, they proposed defense mechanisms designed to mask the hidden logical information exposed in a model’s public outputs. This indicates an awareness within China’s defense sector that the same techniques they employ could potentially be used against their own advanced AI systems, initiating a complex cat-and-mouse game in AI security. Furthermore, Anthropic’s concern that distilled models might lose the original systems’ safety safeguards adds another layer of risk, raising questions about the ethical deployment and potential unintended consequences of such repurposed AI.

Geopolitical Ramifications

The revelations are poised to significantly impact upcoming U.S.-China talks on AI governance and safety. The U.S. will likely leverage these findings to press for greater transparency, accountability, and potentially new mechanisms to prevent such "unauthorized extraction." China, conversely, will likely continue its narrative of self-reliance and accusations of U.S. "AI hegemonism," making any substantive agreement on AI governance difficult to achieve. This dynamic risks escalating the tech warfare between the two superpowers, potentially leading to further restrictions, retaliatory measures, and a more fragmented global AI ecosystem. The challenge extends beyond mere competition; it delves into the fundamental questions of intellectual property in the age of AI, the ethics of open-source models, and the very definition of responsible state behavior in the development and deployment of advanced technologies. The ongoing saga of Chinese military researchers leveraging U.S. AI models underscores the urgent need for international frameworks that can address the complex interplay of innovation, national security, and global cooperation in the rapidly evolving field of artificial intelligence.