Chinese Military Leverages U.S. AI Models to Train Defense Systems

Taylor Wilson
Published todayAbout 10 min read

A Reuters review of over 80 Chinese academic papers found that PLA researchers used outputs from OpenAI and Anthropic models to train domestic military AI systems, exposing a model-output gap in U.S. export controls.

01

How exactly are they using American models?

The core method is model distillation — using a large AI model's outputs to train a smaller, specialized model. No need to build frontier AI from scratch; the big model's "answers" serve as the training material.
This means → export controls blocked chips and compute, but did not block the output itself — and output alone can function as a textbook.
Sunny Cheung, a researcher at the Jamestown Foundation, analyzed over 60 of the papers and found PLA scientists systematically extracting Western models' reasoning steps for surveillance, cyber warfare, and tactical decision-making.
02

Which military applications showed up?

PLA Unit 96941 — a Beijing-based military intelligence and cyber-warfare unit — used OpenAI's GPT-3.5 to process sensitive military source code, then used the summaries to train a model running entirely inside China's military network.
North China University of Technology, closely linked to China's weapons industry, used Anthropic's Claude 3 Haiku to generate synthetic data for a text-classification model aimed at social-media surveillance and content moderation.
A 2024 paper from the PLA National University of Defense Technology described distilling image-processing models for deployment on drones, enabling real-time video analysis and navigation.
03

Do the U.S. companies know? Can they stop it?

Anthropic said it does not provide commercial access to Claude for China or Beijing-controlled entities and has deployed monitoring systems to detect violations.
But Anthropic also acknowledged that distilled models may lose the original system's safety guardrails, allowing sensitive capabilities to migrate into models it cannot control.
In plain terms = the company can control who logs in, but not what happens after the answers leave the platform — distillation happens at the output end, outside its reach.
04

What is actually in dispute?

The controversy is not about distillation itself — it is standard industry practice — but about unauthorized extraction.
U.S. officials accuse certain Chinese entities of using distillation to extract American AI capabilities, potentially circumventing export controls and infringing intellectual property. China denies the charges, calling U.S. policy AI "hegemonism."
Chinese AI startup Moonshot AI last week denied Trump administration allegations that its Kimi K3 model was built via distillation, saying it relied on independent innovation.
05

What larger problem does this reveal?

Distillation cannot replace the massive compute needed to build frontier AI from scratch, but this disclosure shows that compute controls are only half the wall.
This reflects a structural blind spot in the U.S. export-control regime: it restricted the "raw materials" for building models (chips, compute) but has no effective mechanism for controlling models' "products" (inference outputs, training data).
The White House, the Pentagon, China's Foreign Ministry, the PLA, and OpenAI all declined to comment to Reuters.

Content is for reference only, not financial advice.

Chinese Military Leverages U.S. AI Models to Train Defense Systems · nashnova