Chinese military researchers used API outputs from OpenAI and Anthropic models to train domestic defense AI systems.
A Reuters investigation of more than eighty Chinese academic papers and patents has found that researchers affiliated with China's military and security institutions used outputs from advanced American AI models—including systems built by OpenAI and Anthropic—to train smaller domestic systems for defence and surveillance applications. The findings suggest that model distillation, a widely used AI technique, may be offering Chinese researchers a shortcut around chip and technology restrictions rather than a way to defeat them outright.
Model distillation is a standard practice across the AI industry. It involves using outputs from a powerful "teacher" model to train a smaller "student" system that can run on far less computing power while retaining selected reasoning or classification abilities from the original. The technique underpins much of the global push toward efficient, on-device AI deployment.
What has drawn scrutiny is where and how the technique was allegedly applied. According to the Reuters review, conducted alongside research compiled by the Washington-based Jamestown Foundation, a paper published last year by scientists from PLA Unit 96941—described as a military intelligence and cyber warfare unit—detailed using OpenAI's GPT-3.5 to summarize military-related software code before training a domestic model capable of operating entirely within Chinese military networks. The paper indicated that external AI services were unsuitable for handling classified information directly, suggesting the distillation step was used specifically to circumvent that restriction.
A separate study found researchers at the North University of China, an institution with close ties to the country's defence industry, used Anthropic's Claude 3 Haiku model to generate synthetic training data for a text classification system built for social media monitoring and content moderation. Anthropic told Reuters it does not provide commercial access to Claude in China or to Beijing-controlled firms and said it actively monitors for violations of its usage policies. The company cautioned that distilled models can lose the safety safeguards built into their original systems—a warning that underscores why regulators view the technique as a potential blind spot in export enforcement.
The defence applications extended well beyond text and social media analysis. A 2024 paper from the PLA's National University of Defense Technology described compressing an image-processing model for deployment aboard unmanned aerial vehicles, enabling drones to analyze live video, assist navigation and support targeting without active communication links. Another study documented distilled target-recognition systems tested in simulated maritime operations involving drones, naval vessels and unmanned submarines, demonstrating how a civilian AI technique can migrate rapidly into battlefield use once adapted.
These findings emerge against an intensifying standoff over AI supply chains, with Washington tightening restrictions on China's access to advanced semiconductors even as distillation-based workarounds appear to sidestep the compute constraints those restrictions were designed to create. Notably, Reuters's findings follow closely after Anthropic's own disclosure that it had detected what it described as a large-scale distillation campaign against Claude linked to Chinese technology group Alibaba, involving millions of automated exchanges through thousands of fraudulent accounts—a case suggesting unauthorized extraction attempts against frontier models are neither isolated nor limited to state-linked defence research.
An AI researcher at Algoritha Security noted that distillation is a legitimate and widely accepted training technique across the industry, but concerns arise specifically when proprietary capabilities are extracted without authorization or applied within sensitive military contexts. The researcher added that distilled systems generally cannot replicate the full intelligence, reasoning depth or performance of the frontier models they are drawn from—a limitation that tempers, without eliminating, the security implications of the practice.
For India, simultaneously building its own AI governance framework and expanding indigenous compute capacity, the episode is a reminder that AI security and intellectual property protection questions are no longer confined to the countries directly named in such investigations. As global discussions over export controls, model access and defence-linked AI applications intensify, the distillation debate is likely to remain a persistent fault line in how nations attempt to police technology they can no longer fully contain within their own borders.