Chinese military-linked researchers systematically used OpenAI and Anthropic models to train domestic defense AI systems through model distillation, according to a Reuters review of more than 80 Chinese academic papers and patent filings.
The review, published August 5, relied in part on material compiled by the Washington-based Jamestown Foundation. Researchers at institutions affiliated with the People's Liberation Army used a technique known as distillation: submitting queries to advanced Western models and using the outputs as synthetic training data for smaller, locally controlled systems they could deploy on tactical hardware.
The applications span battlefield hardware, naval warfare, cyber operations, and social monitoring.
A 2024 paper from the PLA's National University of Defense Technology describes reducing an image-processing model so unmanned aerial vehicles can analyze live video and make navigation decisions in real time, even during communications blackouts. Researchers at China's Academy of Military Sciences used distillation to run target-recognition models on tactical hardware during simulated maritime operations involving ships, drones, and unmanned submarines.
Researchers in PLA Unit 96941, a Beijing-based cyber-warfare unit, used OpenAI's GPT-3.5 to summarize military source code and then trained a local model to operate within classified military networks. At the North University of China, researchers used Anthropic's Claude 3 Haiku to generate synthetic data for text classification and content monitoring.
"Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," said Sunny Cheung, a Jamestown Foundation fellow. "These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally."
The findings expose a strategic challenge that existing export controls cannot fully address. While Washington can restrict the export of high-end GPU hardware, limiting access to public API outputs or leaked model responses is substantially harder. The result is an asymmetric situation in which Western labs bear the cost of frontier model development while rival militaries extract targeted reasoning to deploy on satellites, drones, and field radios.
However, the report notes that distilled systems have inherent limitations. They can only reproduce reasoning patterns already present in the teacher model and lack the ability to extend beyond their training distribution.
Sources



