Chinese military trains defense AI with OpenAI and Anthropic models
Investigation reveals Chinese military researchers use distillation of US models to bypass chip export controls.
August 7, 2026 · 3 min read
TL;DR: The Chinese military has used AI models from OpenAI and Anthropic to train defense systems via distillation, a technique that bypasses chip export controls. The finding, based on a review of over 80 papers, highlights a gap in US restrictions.
New research has uncovered that Chinese military researchers have been using American artificial intelligence models, including those from OpenAI and Anthropic, to train defense systems. The finding, based on a review of more than 80 Chinese academic documents and patents, was initially published by Reuters and has sparked intense debate about the effectiveness of US technology export controls.
What happened?
The research, conducted by the Jamestown Foundation based in Washington and independently verified by Reuters, found that researchers linked to the People's Liberation Army (PLA) have used the technique known as model distillation. This process involves using the outputs of a large, capable model (such as GPT-4 or Claude) as training data for a smaller, more efficient model. The resulting model inherits specific behaviors from the original model but can run on much more modest local hardware.
According to the analysis, Chinese researchers have been distilling outputs from OpenAI and Anthropic models to create systems that can be deployed in military environments, where access to the cloud or advanced chips may be limited. One of the most prominent cases is the Kimi K3 model, developed by Chinese lab Moonshot AI, which according to claims by the Trump administration would have distilled Anthropic's Fable model.
Why is this important?
This revelation highlights a fundamental gap in US export controls. Current restrictions focus on limiting China's access to advanced chips needed to train cutting-edge AI models. However, distillation does not require those chips, as the expensive training process has already been carried out by the American company. As Sunny Cheung, an analyst at the Jamestown Foundation, explains, the value is not in the answers but in the reasoning: "Teaching a model to produce the correct answer is relatively easy, but teaching it the reasoning behind the answer is much harder."
Distillation allows transferring that proprietary knowledge to small systems that can run locally, without needing an internet connection or high-end hardware. This undermines the logic of export controls, which are based on regulating physical objects like chips, but cannot regulate the text generated by models.
Consequences for industry and geopolitics
This case has far-reaching implications. First, it highlights an asymmetry in Beijing's strategy: while China has restricted its citizens' access to Western models for security reasons and has pressured its labs to develop their own chips, its military researchers have been leveraging the outputs of American models. This double standard could further strain relations between the two powers.
For American companies like OpenAI and Anthropic, the news is concerning. Despite their terms of service prohibiting military use and resale of outputs, distillation makes it difficult to track and enforce these policies. This could lead to a tightening of security measures, such as implementing watermarks or limiting access to certain users, although these measures are not yet effective.
Furthermore, this situation could accelerate the race for technological sovereignty. If the US cannot prevent its models from being used by adversaries, it might be tempted to further restrict access to its technologies, affecting global AI collaboration. On the other hand, China could see this case as justification to intensify its efforts in developing its own models, reducing its dependence on the West.
What should readers know?
For professionals and companies using AI, this case underscores the importance of understanding the risks of distillation. While it is a legitimate technique for optimizing models, it can also be misused. Companies should review their usage policies and consider additional protective measures, such as monitoring access or implementing distillation detection technologies.
Likewise, this case reflects the need to rethink control mechanisms in the AI era. International agreements and regulations must adapt to the intangible nature of models and their outputs, something current frameworks do not adequately address.
In short, model distillation has become a strategic tool that challenges traditional boundaries. The international community will need to find new ways to balance innovation with security, a challenge that will define the future of technological geopolitics.