China’s military is training its defense AI on American models.
A Reuters review of more than 80 Chinese papers and patents found military researchers using OpenAI and Anthropic outputs.
For related regulatory shifts, check out our ongoing coverage of AI policy changes.
The workhorse is model distillation, which trains a smaller model on a frontier model’s outputs.
The reporting, compiled with research from the Washington-based Jamestown Foundation, landed days before US-China talks on AI governance. It shows the exact workaround export controls can’t touch: you can block chips, but you can’t block tokens.
What model distillation actually is
Model distillation is a standard technique across the industry. You take the outputs of a powerful model and use them as training data for a smaller one. The result is a specialized system that runs on local hardware, without the massive compute a frontier model needs.
The dispute was never about model distillation itself. It’s about unauthorized extraction, and the Reuters reporting shows military-linked institutions doing exactly that at scale.
US officials have accused some Chinese entities of using distillation to extract capabilities from American models. They argue it undermines export controls and infringes intellectual property. Beijing rejects that framing, calling it AI hegemonism and pointing out that American companies use the same technique.
The Jamestown Foundation, including fellow Sunny Cheung, contributed research to the review. He said the real prize is the reasoning behind the answers, not just the answers themselves.
The papers show researchers trying to capture that reasoning for surveillance, cyber warfare, and tactical decision-making.
The PLA cases that matter
According to the Reuters review, papers from multiple PLA-linked institutions used distillation to train domestic models for defense applications.
Why export controls can’t stop model distillation
Washington restricts high-end chips, and Beijing’s answer has been model lightweighting, with government subsidies pushing AI that runs on drones, satellites, and other low-power hardware. Model distillation fits that strategy perfectly.
Anthropic told Reuters it doesn’t provide commercial access to Claude in China or to Beijing-controlled firms. The company says it uses monitoring systems to detect policy violations.
Anthropic also warned that distilled models can lose the original system’s safety safeguards, transferring sensitive capabilities beyond its control.
The timing matters. The new review shows model distillation is widespread in military-linked research. This isn’t the first distillation crackdown. Labs have previously accused Chinese entities of extraction campaigns. The pattern is consistent: block API access and the extraction shifts. It lands in academic papers, third-party resellers, or whatever account farm spins up next.
The limits nobody mentions
Distillation has real limits. Trevor Koverko, co-founder of AI data company Sapien, told Reuters that distilled models remain less capable than their teachers. Model distillation transfers selected capabilities into a cheaper, locally controlled system, not independence from frontier AI.
Chinese researchers know this. A January paper from the Army Engineering University examined the threat of data-free distillation. That method reverse-engineers a model’s capabilities without touching its parameters. They’re already thinking about how to defend against the same trick.
For builders, the practical lesson is uncomfortable. Model distillation lets you fine-tune a small local model for your business.
It also lets a well-resourced adversary compress a frontier model’s reasoning into a deployable military asset. There’s no watermark, no API policy, and no chip embargo that cleanly stops it.
The bottom line
Model distillation turns every frontier model into exportable technology. The debate over open-weight models is really a debate about this. Once a model’s reasoning is in outputs, anyone with an API key can train a local copy.
Labs say they monitor for violations, and I believe they’re trying. The papers show the practice is already embedded in China’s defense research pipeline.
Export controls on hardware were the easy part. The hard part is this. A frontier model’s most valuable output, its reasoning, can’t be fenced in.



