china military
According to a Reuters review of over 80 Chinese academic papers and patents, documents linked to the People's Liberation Army (PLA) reveal widespread use of a technique known as "model distillation." Greg Baker/AFP via Getty Images

Chinese military researchers have used outputs from leading U.S. artificial intelligence models developed by OpenAI and Anthropic to train domestic AI systems for defense-related applications, according to a new report..

A Reuters review of over 80 Chinese academic papers and patents, documents linked to the People's Liberation Army (PLA) reveal widespread use of a technique known as "model distillation."

The process allows developers to use the outputs of a powerful AI model to train smaller, specialized systems that require far less computing power and can be deployed on local hardware without relying on large-scale cloud infrastructure.

Reuters said its investigation, which incorporated research compiled by the Washington-based Jamestown Foundation, found that military and security researchers are using leading Western AI models as a shortcut to narrow the technological gap with the United States.

The findings come as Washington continues tightening restrictions on advanced AI chips and other technologies that could enhance China's military capabilities. The controversy is not over model distillation itself, a widely accepted machine learning technique, but rather the alleged unauthorized extraction of capabilities from proprietary U.S. models.

Sunny Cheung, a fellow at the Jamestown Foundation who analyzed more than 60 of the papers, told the outlet that Chinese military researchers are attempting to capture not only the answers generated by Western AI systems but also the reasoning processes behind them.

"Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," Cheung said. "These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally."

One of the most notable examples involved researchers from PLA Unit 96941, a military intelligence and cyber warfare unit in Beijing. A paper published last year described how the team used OpenAI's GPT-3.5 to summarize sensitive military software code before training a domestic AI model capable of operating entirely within secure Chinese military networks.

The researchers argued that relying directly on third-party AI services was unsuitable for handling classified information. The review also found military and university researchers employing distilled AI systems across a range of applications.

Researchers at the North University of China, which maintains close ties to the country's defense industry, used Anthropic's Claude 3 Haiku to generate synthetic training data for text classification models designed for social media monitoring and content moderation, according to Reuters.

Anthropic said it does not provide commercial access to Claude in China or to Beijing-controlled firms and actively monitors for policy violations. The company also warned that distilled models can lose important safety protections built into the original systems.
Other military research focused on battlefield operations.

A 2024 paper from the PLA's National University of Defense Technology described using distillation to compress an image-processing model so it could operate aboard unmanned aerial vehicles, enabling drones to analyze live video feeds and assist with navigation and targeting even when communications are disrupted.

Reuters also identified research from China's Academy of Military Sciences showing distilled AI being used for target recognition during simulated maritime operations involving drones, naval vessels and unmanned submarines.

China has increasingly embraced model distillation as it seeks to compete with the United States in advanced AI while facing restrictions on access to cutting-edge chips. Beijing has directed funding toward "model lightweighting" and edge computing technologies that allow AI systems to run efficiently on drones, satellites and other devices with limited processing power.

Still, experts caution that distillation has significant limitations. Distilled systems inherit only selected capabilities from their larger counterparts and cannot fully replicate the broader intelligence or performance of frontier AI models.

"It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI," Trevor Koverko, co-founder of AI data company Sapien, told Reuters.