China’s military has found a clever back door around Washington’s hardware embargoes by borrowing the brains of top American artificial intelligence systems to develop its own battlefield tech.
A Reuters review of more than 80 Chinese academic papers and patent filings, drawing in part on material compiled by the Washington-based Jamestown Foundation, shows that institutions linked to the People’s Liberation Army (PLA) have used outputs from frontier models built by OpenAI and Anthropic to train specialized domestic defence systems.
The distillation shortcut
To pull this off, researchers rely on a technique called "model distillation". Instead of spending billions of dollars and consuming massive computing power to build frontier AI models from scratch, scientists feed queries into powerful Western models and use those outputs as synthetic training data for lighter, localized "student" models.
"Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," said Sunny Cheung, a Jamestown Foundation fellow, according to Reuters.
"These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally."
The applications detailed across the documents span multiple defence fronts:
- Battlefield hardware: A 2024 paper from the PLA’s National University of Defense Technology detailed how to shrink an image-processing model so that unmanned aerial vehicles could analyze live video and make navigation decisions in real time, even during communications blackouts.
- Naval warfare: Researchers at China's Academy of Military Sciences used distillation to run target-recognition models on tactical hardware during simulated maritime operations involving ships, drones, and unmanned submarines.
- Secure cyber operations: Researchers in PLA Unit 96941 — a Beijing cyber-warfare unit — used OpenAI’s GPT-3.5 to summarize military source code, then trained a local model capable of running within classified military networks.
- Social monitoring: At the North University of China, researchers fed prompts to Anthropic’s Claude 3 Haiku to generate synthetic data for text classification and content monitoring.
High-tech shadow boxing
The trend exposes a strategic reality that semiconductor export controls cannot fully address. While Washington can restrict high-end GPU hardware, curbing access to public-facing API outputs or leaked model responses remains nearly impossible.
This dynamic transforms modern technological friction into an asymmetric game of reverse engineering. Western labs absorb the astronomical costs of frontier development, while rival militaries extract targeted logic steps to field operational edge AI directly on satellites, drones, and field radios.
However, distilled systems inherit clear trade-offs. Distilled models remain narrower, lack generalized intelligence, and can lose the built-in safety guardrails of the parent models.
Industry and geopolitical fallout
The findings put Western AI developers and security officials in a tough spot. Anthropic noted that it does not sell commercial access in China and uses active monitoring to catch policy violations, warning that distilled copies strip out vital safety mechanisms.
Meanwhile, US officials argue the unauthorized extraction undercuts IP rights and export controls, whereas Beijing dismisses the criticism as "AI hegemonism."


