A member of the People's Liberation Army stands as strategic strike group displays YJ-18C cruise missiles during a military parade to mark the 80th anniversary of the end of World War Two, in Beijing, China, September 3, 2025. REUTERS/Tingshu Wang/File Photo
China extracting US AI outputs to train defense systems
Note: AI technology was used to generate this article’s audio.
- China extracting US AI outputs.
- PLA-linked researchers use models to train systems.
- AI applications include drones, cyber, and surveillance.
- US criticizes practice ahead of AI talks.
Researchers linked to the Chinese military and state defense institutions are using outputs generated by leading American artificial intelligence models to train specialized domestic defense systems, a Reuters review of more than 80 Chinese academic papers and patents has revealed.
The findings, compiled in collaboration with the Washington-based Jamestown Foundation, provide a rare look into how Chinese military institutions leverage US frontier models developed by companies like OpenAI and Anthropic as a strategic shortcut to enhance their defense capabilities, despite stringent US export controls on advanced semiconductors.
"Model Distillation" bypasses hardware constraints
The research highlights widespread reliance on "model distillation"—an industry-standard technique where outputs and reasoning steps from a large, powerful AI model are used to train smaller, specialized systems.
This method enables Chinese researchers to deploy capable AI locally on edge devices without needing the massive computing infrastructure required to build frontier models from scratch.
Sunny Cheung, a fellow at the Jamestown Foundation who analyzed more than 60 of the papers, noted that Chinese military scientists are systematically transferring proprietary reasoning from Western models into small, locally controlled military systems.
"Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," Cheung stated. "These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally."
PLA deployments range
Reuters verified the academic literature and identified two dozen specific military-linked case studies detailing practical deployments:
- Cyber Warfare & Classified Code: A study published by PLA Unit 96941—a military intelligence and cyber-warfare unit based in Beijing—described using OpenAI's GPT-3.5 to process and summarize sensitive military source code. The summaries were then used to train an offline domestic model capable of running inside classified military networks.
- Autonomous UAV Targeting: A 2024 paper from the PLA’s National University of Defense Technology detailed using distillation to compress image-processing models for unmanned aerial vehicles (UAVs), enabling real-time video analysis, navigation, and targeting decisions even during communications blackouts.
- Maritime Autonomous Warfare: Researchers at China's Academy of Military Sciences used distilled target-recognition models on tactical hardware during simulated maritime operations involving drones, surface ships, and unmanned submarines.
- Surveillance & Content Monitoring: At the North University of China, which maintains close ties to the defense industry, researchers utilized Anthropic’s Claude 3 Haiku to generate synthetic training datasets for text classification in social media monitoring.
In response to the report, Anthropic stated that it does not provide commercial access to Claude in China or to state-controlled entities and employs active monitoring to catch policy violations.
The company warned that distilled models often strip away built-in safety guardrails, potentially transferring sensitive capabilities to unmonitored systems.
Diplomatic friction over AI safety
The disclosures come as US and Chinese officials prepare for high-stakes bilateral talks on AI safety and governance.
Washington has accused Chinese organizations of extracting capabilities from US software to circumvent export controls and infringe on intellectual property.
Beijing has rejected the claims, accusing the US of practicing AI "hegemonism" while arguing American technology firms employ similar distillation techniques.
Chinese AI startups have also disputed reliance on Western software; last week, startup Moonshot denied allegations from the Trump administration that its Kimi K3 model relied on distillation, asserting its technology relies on proprietary innovations.
Amid US chip restrictions, Chinese central and regional governments have actively subsidized "model lightweighting" and edge computing for deployment on satellites and hardware with limited processing power.
However, experts emphasize that distillation has inherent limitations. In January, researchers at China's Army Engineering University published a paper addressing defense mechanisms against "data-free distillation" to prevent reverse-engineering of domestic models.
Trevor Koverko, co-founder of AI data company Sapien, emphasized that distilled models remain fundamentally constrained compared to their teacher systems.
"It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI," Koverko noted.
The White House, the Pentagon, China's Ministry of Foreign Affairs, the PLA, and OpenAI did not respond to requests for comment.



