Chinese military AI model distillation is emerging as a significant issue in the technology competition between the United States and China after researchers linked to the People’s Liberation Army used outputs from leading American artificial-intelligence models to train specialised domestic systems.
A Reuters investigation published by Defense News examined more than 80 Chinese academic papers and patents. The review found examples involving models developed by OpenAI and Anthropic and applications ranging from software analysis and surveillance to drone navigation and tactical target recognition.
The research does not indicate that the American companies knowingly supplied technology to Chinese military institutions. Instead, the papers describe researchers using responses, summaries or synthetic data generated by external models as training material for smaller systems that could subsequently be operated inside local or restricted networks.
This process is generally known as model distillation. It is a common artificial-intelligence technique, but it has become politically and commercially sensitive when access to a proprietary model is obtained without authorisation or used to reproduce valuable capabilities in violation of platform restrictions.
Key Facts
- Investigation: Reuters review published on 31 July 2026.
- Material examined: More than 80 Chinese academic papers and patents.
- Institutions involved: PLA units, military universities, defence research organisations and other security-linked institutions.
- US model providers identified: OpenAI and Anthropic.
- Named models: GPT-3.5 and Claude 3 Haiku.
- Primary technique: Model distillation using outputs from a larger model to train a smaller specialised model.
- Reported applications: Military-code analysis, surveillance, content monitoring, cyber research, UAV image processing and tactical target recognition.
- Deployment objective: Run smaller systems locally with lower computing and communications requirements.
- Key advantage: Selected model capabilities can be transferred without training an equivalent frontier model from the beginning.
- Key limitation: Distilled models do not reproduce the full intelligence or versatility of the original system.
- Policy issue: The dispute concerns unauthorised extraction, service restrictions, intellectual property and national-security controls rather than distillation as a general research method.
- Company response: Anthropic says it does not provide commercial Claude access in China and monitors suspected distillation campaigns.
- OpenAI response to Reuters: The company did not respond to the investigation’s request for comment.
What Did the Reuters Investigation Find?
Reuters reported that military and security-linked researchers in China had repeatedly used the outputs of advanced US artificial-intelligence systems to develop more compact domestic models.
The investigation combined research collected by the Washington-based Jamestown Foundation with additional papers and case studies independently identified by Reuters.
The documents suggest that Chinese defence institutions regard Western frontier models as both sources of technical knowledge and tools for generating high-quality training data.
Instead of reproducing an entire large language or multimodal model, researchers selected particular capabilities such as software summarisation, reasoning, image interpretation or text classification and transferred them into smaller systems designed for defined military or security tasks.
What Is AI Model Distillation?
Model distillation is a training process in which a powerful “teacher” model generates answers, classifications, explanations or other outputs that are used to train a smaller “student” model.
The smaller model is not an exact copy. It is normally optimised to imitate selected behaviour in a narrower field while requiring less memory, computing power and electricity.
AI companies use distillation legitimately to create faster and cheaper versions of their own models. Universities and open-source developers also use the method when the teacher model and its outputs are available under suitable licences.
The dispute begins when a proprietary system is accessed through fraudulent accounts, proxy services or other methods intended to bypass geographical, commercial or security restrictions.
| Area | Legitimate Distillation | Disputed or Unauthorised Distillation |
|---|---|---|
| Access | Authorised model or licensed outputs | Access obtained by circumventing restrictions or service terms |
| Purpose | Efficiency, compression or authorised product development | Extraction of another provider’s proprietary capabilities |
| Training data | Outputs generated under permitted conditions | Large-scale automated collection through coordinated accounts or proxies |
| Safeguards | Can be intentionally retained and evaluated | May be weakened or omitted in the student model |
| Legal and policy status | Generally accepted technical practice | May raise contractual, intellectual-property, export-control and security concerns |
How Was GPT-3.5 Reportedly Used for Military Software?
One case identified by Reuters involved a paper written by researchers from PLA Unit 96941, described in the report as a Beijing-based military intelligence and cyber-warfare unit.
The researchers reportedly used OpenAI’s GPT-3.5 to summarise military software code. Those summaries were then used to train a domestic model that could operate inside Chinese military networks.
The paper stated that external models were unsuitable for processing classified information directly. The proposed approach therefore used the foreign model during the preparation of training material, while the resulting smaller model was intended to run locally.
The public report does not establish whether classified code itself was uploaded to GPT-3.5. It states that the model was used to process or summarise source code and that the domestic system was intended to address the security limitations of relying on a third-party service.
How Was Claude 3 Haiku Used for Monitoring Research?
Researchers at North University of China reportedly used Anthropic’s Claude 3 Haiku to generate synthetic training data for a text-classification model.
The resulting system was intended for social-media monitoring and content-moderation tasks.
North University of China maintains links with the country’s weapons and defence-industrial sector. However, the cited research application should not automatically be treated as a deployed combat system. The available source describes a research project and its proposed or demonstrated technical use.
Anthropic told Reuters that it does not provide commercial Claude access in China or to organisations controlled by Beijing and that it operates monitoring systems to identify policy violations.
How Could Distilled AI Support Military Drones?
A 2024 paper from the PLA’s National University of Defense Technology described distilling an image-processing model for use aboard an unmanned aerial vehicle.
The objective was to create a model small enough to process live video on the aircraft rather than depending continuously on a remote data centre.
Local processing can support navigation, object recognition and targeting-related decisions when a drone’s communications link is interrupted, jammed or unavailable.
The source does not identify an operational aircraft type, deployment programme or fielded weapon associated with the research. It demonstrates the military value assigned to compact AI models operating at the tactical edge.
How Was the Technique Applied to Maritime Operations?
Researchers associated with China’s Academy of Military Sciences reportedly used distillation to operate a target-recognition model on tactical hardware during simulated maritime operations.
The scenario involved a network of drones, ships and unmanned underwater systems.
Running the model on tactical equipment would allow parts of the recognition and decision-support process to continue without transmitting all sensor data to a large central computing facility.
This approach is particularly relevant in maritime environments where platforms may operate across wide areas with intermittent, limited or contested communications.
Reported Chinese Military-Linked AI Applications
| Institution or Research Group | Teacher Model or Method | Reported Application | Deployment Objective |
|---|---|---|---|
| PLA Unit 96941 | OpenAI GPT-3.5 outputs | Military software-code summarisation and domestic-model training | Local operation inside military networks |
| North University of China | Anthropic Claude 3 Haiku | Synthetic data for text classification and monitoring | Smaller specialised monitoring model |
| National University of Defense Technology | Distilled image-processing model | Live UAV video analysis, navigation and targeting support | Onboard processing when communications are unavailable |
| Academy of Military Sciences | Distilled target-recognition model | Simulated maritime operations involving crewed and uncrewed platforms | Target recognition on tactical hardware |
Why Are Smaller AI Models Valuable to Armed Forces?
Frontier AI systems normally require large data centres, advanced accelerators, high electrical power and reliable network connections.
Military platforms often operate under the opposite conditions. Drones, vehicles, ships, satellites and field headquarters may have restricted computing capacity, limited electrical power and unreliable communications.
A distilled model can be optimised for one or several mission tasks and installed directly on a tactical device.
- Reduced dependence on cloud infrastructure
- Faster response to sensor information
- Lower communications-bandwidth requirements
- Continued operation during jamming or network disruption
- Improved protection of sensitive operational data
- Lower hardware and energy requirements
- Deployment across larger numbers of affordable systems
The trade-off is reduced general capability. A compact model trained for target recognition or code analysis will normally be less versatile than the frontier model that generated its training data.
Does Distillation Bypass Advanced-Chip Restrictions?
Distillation can reduce the computing resources needed to deploy a particular AI capability, but it does not eliminate the need for advanced computing throughout the development process.
Generating large quantities of teacher-model output, preparing synthetic data, training a student model and evaluating it can still require significant computing capacity.
The method may nevertheless help organisations use limited hardware more efficiently and deploy selected capabilities on systems that could not support a frontier model.
This explains why lightweight models and edge computing are receiving attention in China while access to some advanced US-designed chips and semiconductor-manufacturing equipment remains restricted.
What Is Anthropic’s Position on Distillation?
Anthropic distinguishes between ordinary distillation and what it calls illicit distillation attacks.
In February 2026, the company said it had identified large-scale campaigns involving DeepSeek, Moonshot and MiniMax. Anthropic attributed more than 16 million Claude exchanges conducted through approximately 24,000 fraudulent accounts to the three laboratories.
According to the company, the operations targeted reasoning, software development, tool use, data analysis, computer vision and agentic capabilities.
Anthropic said it was strengthening identity verification, behavioural detection, account coordination analysis and technical countermeasures intended to reduce the value of model outputs for unauthorised extraction.
Those company allegations concern commercial Chinese AI laboratories and are separate from the military research papers reviewed by Reuters. They nevertheless illustrate the wider dispute over access to proprietary US models.
What Are the Main Security Concerns?
The principal concern is that useful capabilities can be transferred while the original model’s safety and access controls are not.
A model provider can monitor and restrict activity on its own hosted platform. Once selected capabilities have been incorporated into an independently controlled system, the original provider may have no visibility into how that model is used.
- Military or intelligence applications outside the original provider’s approval process
- Removal of safeguards against weapons or cyber misuse
- Local deployment on closed or classified networks
- Mass surveillance or censorship applications
- Replication of specialised reasoning and coding capabilities
- Reduced effectiveness of geographical access restrictions
- Intellectual-property and contract disputes
- Acceleration of tactical AI deployment
What Does the Evidence Not Prove?
The available reporting does not establish that OpenAI or Anthropic intentionally supported Chinese military research.
It also does not demonstrate that every model described in the papers has entered operational service.
Academic publication may document a laboratory experiment, simulation, prototype or proposed application rather than a deployed capability.
The research does not show that a distilled Chinese model fully matches the capabilities of the original US frontier model. Distillation normally transfers selected behaviours and can introduce errors, reduced reliability and narrower performance.
Finally, the investigation does not establish that distillation itself is illegal in every circumstance. The legal and policy assessment depends on how access was obtained, the applicable licence or contract, the content used and the intended application.
Why Are Researchers Studying Defences Against Distillation?
Reuters also found that Chinese military researchers were examining model distillation as a security risk to their own systems.
Researchers from the Army Engineering University studied “data-free distillation,” in which an external actor attempts to reproduce parts of a model’s behaviour without access to its internal parameters or original training data.
They proposed methods intended to conceal logical information exposed through model outputs and make capability extraction more difficult.
This illustrates the dual character of the technology: the same institutions may seek to benefit from distillation while also attempting to protect their own systems against it.
What Could Governments and AI Companies Do Next?
- Strengthen verification for high-volume API customers
- Identify coordinated activity across multiple accounts and providers
- Monitor repetitive prompts designed to extract narrow capabilities
- Share indicators of suspected distillation campaigns
- Improve enforcement of geographical and organisational access controls
- Develop technical methods that reduce unauthorised reasoning extraction
- Clarify intellectual-property rules for synthetic model outputs
- Align model access controls with export-control policy
- Audit military and intelligence uses of commercial AI systems
- Develop internationally recognised rules for model extraction and reuse
Any technical response will need to distinguish between malicious extraction and legitimate research, benchmarking, interoperability and model compression.
What Does This Mean for Military AI Competition?
The investigation indicates that competition in military artificial intelligence is not limited to building the largest general-purpose model.
Operational advantage may also come from converting advanced capabilities into smaller systems that can function on drones, ships, vehicles, sensors and tactical computers.
This places model efficiency, synthetic-data generation, hardware optimisation and edge deployment alongside semiconductor access and frontier-model development as strategic areas of competition.
It also means that controls focused only on the export of physical computing hardware may not fully address the movement of AI capabilities through digital services and generated training data.
Conclusion
The Reuters investigation provides evidence that Chinese military-linked researchers are experimenting with the outputs of leading US AI models to accelerate the development of specialised domestic systems.
The reported projects cover military software, surveillance, UAV image processing and tactical target recognition, with a strong emphasis on local deployment and operation under limited communications.
The findings do not show deliberate cooperation by OpenAI or Anthropic, nor do they prove that every system has been operationally deployed.
They do, however, demonstrate how model outputs can become a transferable strategic resource. A frontier model does not have to be installed directly on a military platform for parts of its capability to influence the development of tactical AI.
The policy challenge will be to protect proprietary and security-sensitive capabilities without treating all model distillation as illegitimate. Distillation remains an essential efficiency technique, but access methods, intended use and the retention of safeguards increasingly determine whether it is viewed as normal engineering or strategic technology extraction.
For related coverage, visit Defence Agenda’s artificial intelligence, C4ISR, cyber and unmanned systems sections. Related reports include Airbus MARS networked UAV autonomy, Anduril FQ-44 production and Pentagon drone-launching unmanned boats.
Further Reading
- Defense News and Reuters: Chinese military researchers use US AI-model outputs
- Reuters investigation: Chinese military AI model distillation
- Reuters explainer: Model distillation and US-China competition
- Anthropic: Detecting and preventing distillation attacks
- OpenAI usage policies
- Jamestown Foundation: AI use in PRC military and security systems
- Jamestown Foundation: Large-language models in Chinese military research





