A review of over 80 Chinese academic papers and patents reveals that military and security-linked institutions in China have leveraged outputs from leading American artificial intelligence models—including those developed by OpenAI and Anthropic—to train domestic AI systems for defense and tactical applications.
The findings, compiled in part by the Washington-based Jamestown Foundation and verified by Reuters, shed light on how Chinese researchers use a technique known as “model distillation” to bypass US export controls and hardware limitations.
What Is Model Distillation?
Model distillation is a standard AI development technique where the outputs or “reasoning steps” of a large, highly capable “teacher” model are used to train a smaller, specialized “student” model.
-
Efficiency: Allows powerful AI capability to run on smaller, local hardware without requiring massive computing clusters.
-
Strategic Shortcut: Helps researchers capture complex reasoning processes developed by Western frontier models and adapt them into low-cost, locally controlled systems.
Key Applications Detailed in the Research
The review identified several specific instances of military and defense-related distillation:
-
Cyber Warfare & Code Processing (PLA Unit 96941): Researchers used OpenAI’s GPT-3.5 to analyze and summarize military source code, then trained an offline domestic model on those summaries to run securely within military networks.
-
Unmanned Aerial Vehicles (NUDT): The PLA’s National University of Defense Technology distilled image-processing models down to lightweight sizes suitable for deployment on drones, enabling real-time target recognition and navigation when offline.
-
Maritime Drone Swarms (Academy of Military Sciences): Researchers transferred target-recognition capabilities onto tactical hardware for simulated autonomous drone, ship, and submarine operations.
-
Social Media & Intelligence Monitoring (North University of China): Scientists utilized Anthropic’s Claude 3 Haiku to generate synthetic training data for text classification and content moderation models.
Geopolitical and Technical Implications
-
US-China AI Governance Flashpoint: The unauthorized extraction of capabilities from American models has raised IP and security concerns in Washington ahead of bilateral AI safety talks.
-
Safety Concerns: Anthropic noted that distilled models often lose the safety guardrails built into the original frontier models, potentially transferring sensitive capabilities without risk controls.
-
Limitations of Distillation: AI experts emphasize that distilled models only inherit targeted capabilities and remain less versatile than frontier models. Furthermore, Chinese institutions are also studying “data-free distillation” defenses to prevent their own models from being reverse-engineered in similar ways.

