Reuters reviewed more than 80 Chinese academic papers and patent filings and found that Chinese military researchers have long used outputs from advanced artificial intelligence (AI) models developed by U.S. companies such as OpenAI and Anthropic to train domestic AI systems, thereby strengthening China’s defense capabilities.
This previously unreported finding offers a rare glimpse into how Chinese military and security institutions are leveraging America’s most advanced AI models as a shortcut to rapidly develop specialized systems.
Despite ongoing U.S. restrictions on China’s access to advanced chips and other strategic technologies, Chinese entities continue attempting to accelerate their own technological development by exploiting existing AI capabilities.
Documents show that Chinese research institutions widely adopt a technique known as 'model distillation.' This method involves using the output generated by powerful AI systems to train smaller, more specialized AI models that can be deployed locally without requiring the massive computational resources needed to build cutting-edge AI systems from scratch.
Materials reviewed by Reuters include research reports compiled by the Washington-based Jamestown Foundation, which indicate that model distillation has been widely adopted by researchers affiliated with the Chinese People’s Liberation Army (PLA) and other military institutions.
Related papers suggest that Chinese defense agencies view leading U.S. AI models as two key resources: a source of technical insight and a means to narrow the technological gap with U.S. rivals.
The current controversy does not center on the technique of 'model distillation' itself—which is widely used across the industry—but rather on the unauthorized extraction of model capabilities.
This issue has become a key point of contention ahead of upcoming U.S.-China dialogues on AI governance and safety. U.S. officials accuse certain Chinese institutions of using model distillation to extract critical capabilities from American AI models, potentially undermining export control measures and infringing intellectual property rights.
China denies these allegations, countering that Washington is promoting AI 'hegemonism,' while also claiming that U.S. firms have engaged in similar practices.
Moreover, Chinese AI developers reject claims that their technological breakthroughs depend on foreign models. Chinese AI startup Moonshot last week denied U.S. government allegations that its Kimi K3 model was built using model distillation, stating the model stems primarily from the company’s own technological innovations.
Sunny Cheung, a researcher at the Jamestown Foundation who analyzed over 60 related papers, said Chinese military scientists are systematically extracting the reasoning processes of Western AI models and adapting them for use in surveillance, cyber warfare, and tactical decision-making.
"Teaching a model to give the correct answer is one thing, but teaching it to understand the reasoning behind that answer is far more difficult," Cheung said.
He added: "These papers show that researchers linked to the Chinese military are trying to transfer expensive, proprietary reasoning capabilities from Western models into smaller systems they can control and deploy domestically."
Reuters verified related academic literature and confirmed approximately 24 additional military-linked case studies.
One paper, published last year by researchers from PLA Unit 96941, revealed that the unit had used OpenAI’s GPT-3.5 to process sensitive military software source code.
Researchers noted that third-party AI models are unsuitable for handling classified information. To overcome this limitation, they first used GPT-3.5 to summarize software code, then trained a domestically developed Chinese AI model on those summaries, enabling it to operate entirely within China’s military network.
The White House, U.S. Department of Defense, China’s Ministry of Foreign Affairs, the Chinese People’s Liberation Army, and OpenAI did not respond to requests for comment.
China Expands Use of AI Distillation—from Social Monitoring to Unmanned Combat Systems
Reviews of related papers by Reuters and the Jamestown Foundation show that Chinese researchers apply model distillation across a broad range of fields, extending from content monitoring to military deployment.
At North University of China, closely tied to China’s weapons industry, researchers used Anthropic’s Claude 3 Haiku to generate synthetic training data for text classification models used in social media monitoring and content censorship.
Anthropic stated it does not grant commercial use rights for Claude to any entity in China or under Beijing’s control, and actively monitors for policy violations.
The company added that distilled models may lose the safety safeguards present in the original system, potentially allowing sensitive capabilities to be transferred to models beyond Anthropic’s control.
Additionally, a 2024 paper published by researchers at China’s National University of Defense Technology (NUDT) indicated that model distillation was used to shrink an image processing model so it could be deployed on drones.
This enables drones to analyze visual data in real time and support navigation and target identification decisions even when communications are disrupted.
Furthermore, researchers from the Academy of Military Sciences of the PLA have used model distillation to enable object recognition models to run on tactical-grade hardware.
Published earlier this year, the study describes the model being applied in simulated maritime combat environments involving drones, warships, and unmanned submarines.
China Bets on Model Distillation to Catch Up with the U.S., But Faces Technical Limits
China is actively adopting model distillation to catch up with the U.S. in the race for cutting-edge AI, while facing challenges due to Washington’s export controls on high-end chips, limiting access to advanced computing resources.
China’s central and local governments have recently pushed hard for 'model lightweighting' and edge computing, supporting the development of related technologies through subsidies and research funding, aiming to enable AI models to run on drones, satellites, and other devices with limited computing power.
However, experts caution that model distillation has clear limitations. As Chinese AI models gradually close the gap with their U.S. counterparts, Chinese military researchers are also beginning to focus on the security risks posed by model distillation.
In January, researchers from the PLA Army Engineering University published a paper discussing the threat of 'zero-data distillation'—a method that can infer and reconstruct model capabilities through reverse engineering without directly accessing the model’s core parameters.
To defend against such vulnerabilities, researchers proposed mechanisms to obscure hidden logic information exposed in public model outputs.
Nevertheless, distilled models typically only inherit specific capabilities from the original model and cannot fully replicate the broad intelligence of state-of-the-art AI systems.
Trevor Koverko, co-founder of AI data firm Sapien, said distilled models remain less capable than the original 'teacher models' they were derived from.
"The best way to understand it is as transferring specific capabilities to lower-cost, locally controllable systems—not achieving true autonomy in cutting-edge AI technology," he said.
FACT BOX
- Source: PR Times
- Category: Survey
- Organizations: OpenAI / Anthropic
- Products / services: GPT-3.5 / Claude 3 Haiku