Chinese military researchers have extensively used outputs from advanced artificial intelligence models developed by OpenAI and Anthropic to train domestic AI systems for defense and security applications, indicating Beijing is exploiting a widely used AI training technique to narrow the technological gap with the United States despite tightening export controls.
A Reuters review of more than 80 Chinese academic papers and patent filings, including research compiled by the Washington-based Jamestown Foundation, found that institutions linked to the People’s Liberation Army (PLA), China’s military universities and defense research organizations have relied on “model distillation” to develop specialized AI systems for applications ranging from battlefield decision-making and drone navigation to cyber warfare and surveillance.
The findings provide one of the clearest public pictures yet of how China’s military research ecosystem is incorporating knowledge generated by leading U.S. frontier AI models while avoiding the enormous computational costs required to build comparable systems from scratch.
At the center of the issue is model distillation, a common AI development technique in which a smaller model learns from the outputs generated by a larger, more capable system. Rather than recreating a frontier model from the ground up, developers query an advanced AI model, collect its responses, and use those outputs to train a lighter model optimized for specific tasks.
The approach significantly reduces computing costs while allowing organizations to deploy AI on local infrastructure, including devices with limited processing power such as drones, satellites and battlefield computers.
Distillation itself is widely accepted throughout the AI industry and is used by companies worldwide to improve efficiency. The dispute instead centers on whether some organizations have extracted proprietary capabilities from commercial AI systems without authorization, potentially violating intellectual property rights and undermining U.S. export restrictions.
That distinction has become a bone of contention as Washington intensifies efforts to protect advanced AI technologies from military applications in China.
Military-Linked Institutions Used Frontier U.S. AI Models
Reuters identified widespread evidence that Chinese defense researchers view leading U.S. AI models not only as useful research tools but also as a means of accelerating domestic military AI development.
According to the review, researchers affiliated with PLA Unit 96941, a Beijing-based military intelligence and cyber warfare unit, published a paper last year describing how they used OpenAI’s GPT-3.5 to process sensitive military software code. Recognizing that foreign commercial AI services were unsuitable for handling classified information directly, the researchers reportedly used GPT-3.5 to summarize source code before training a domestic model capable of operating entirely within secure Chinese military networks.
Other studies demonstrated similarly broad military applications.
Researchers from the PLA’s National University of Defense Technology described using distilled AI models to reduce the size of image-recognition systems so they could operate onboard unmanned aerial vehicles. The optimized models enable drones to analyze live video feeds and assist navigation and targeting even when communications with operators are interrupted.
Separately, China’s Academy of Military Sciences published research showing how distilled AI models could support target recognition during simulated maritime operations involving unmanned submarines, naval vessels and drones.
Outside direct military applications, researchers at North University of China, an institution closely linked to the country’s weapons industry, reportedly used Anthropic’s Claude 3 Haiku model to generate synthetic training data for systems designed to classify online content for social media monitoring and content moderation.
Experts say Chinese researchers are interested not simply in copying AI outputs but in capturing the reasoning processes that distinguish today’s most advanced frontier models.
Sunny Cheung, a fellow at the Jamestown Foundation who analyzed more than 60 of the papers, said the objective is to transfer sophisticated reasoning capabilities into domestic systems that can be deployed independently.
“Teaching a model the right answer is one thing, but teaching it the reasoning behind the answer is much harder,” he said.
Cheung said the research indicates Chinese military scientists are attempting to preserve the reasoning patterns of Western AI models for surveillance, cyber operations and battlefield decision-making.
That objective exposes one of the most significant developments in modern AI. Increasingly, competitive advantage comes not simply from producing accurate answers but from building models capable of complex reasoning across multiple tasks.
AI Becomes Another Battleground In U.S.-China Rivalry
The findings arrive as artificial intelligence becomes a central arena of strategic competition between Washington and Beijing.
The Trump administration has accused several Chinese AI companies of improperly extracting capabilities from U.S. frontier models through large-scale distillation, warning that such practices circumvent export controls while appropriating valuable intellectual property.
The dispute has centered particularly on Beijing-based startup Moonshot AI, whose recently released Kimi K3 model attracted attention for advanced coding capabilities. U.S. officials have alleged that Moonshot distilled Anthropic’s Claude models to accelerate development, accusations the company has denied, insisting its performance improvements resulted from proprietary architectural innovations.
China has rejected broader U.S. allegations, accusing Washington of pursuing what it describes as “AI hegemonism” while arguing that American companies have also benefited from similar techniques throughout AI development.
The disagreement has emerged as a major issue ahead of expected bilateral discussions on AI governance, safety and national security.
Distillation Offers Advantages—But Not Full Independence
Although distillation allows developers to build capable AI systems at a fraction of the computational cost, experts caution that the technique has inherent limitations.
Unlike frontier models trained on massive proprietary datasets using vast computing resources, distilled models typically inherit only selected capabilities optimized for specific applications.
Trevor Koverko, co-founder of AI data company Sapien, said distilled systems should not be viewed as replacements for frontier AI.
“It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI,” he said.
Chinese researchers themselves appear increasingly aware of those limitations. In January, researchers at the Army Engineering University published work examining the risks associated with “data-free distillation,” a technique that attempts to reconstruct model capabilities without direct access to underlying parameters.
The researchers proposed defensive mechanisms intended to conceal logical reasoning embedded within publicly accessible model outputs, highlighting growing concerns that AI models themselves have become valuable strategic assets vulnerable to reverse engineering.
However, the widespread use of distillation reflects China’s broader response to U.S. restrictions on advanced semiconductors and AI hardware. Unable to freely acquire the latest high-performance AI chips, Chinese researchers have focused on making AI systems more efficient through lightweight models capable of running on limited computing resources.
Central and local governments have directed funding toward edge computing, compact AI models and autonomous systems that can operate independently on drones, satellites, robotics platforms and military equipment.
Rather than competing solely by building ever-larger frontier models, China is now emphasizing efficient deployment across operational environments where computing resources are constrained.
That approach could allow Chinese defense organizations to field capable AI systems across a wide range of military platforms without requiring access to the world’s largest supercomputers.






