Reuters Review Finds Chinese Military-Linked Researchers Used OpenAI, Anthropic Model Outputs to Train Domestic AI Systems
The Facts
- A Reuters review of more than 80 Chinese academic papers and patents found that military- and security-linked researchers in China used outputs from US AI models developed by OpenAI and Anthropic to train domestic AI systems intended to advance China's defence capabilities.
- The documents describe the use of "model distillation," in which outputs from a powerful AI system are used to train smaller, specialised models that can be deployed locally without the computing resources required to build frontier systems from scratch.
- Part of the reviewed material was compiled by the Jamestown Foundation, a Washington-based research organisation.
- Reported military applications of the distilled systems include reconnaissance and intelligence, surveillance, cyber operations, target recognition and drone control.
- One paper describes personnel from a People's Liberation Army unit linked to military intelligence and cyber operations using GPT-3.5 to summarise software code, then training a domestic model on that material so it could run entirely within Chinese military networks; the researchers described third-party AI models as unsuitable for handling classified information.
- Distillation is a long-established and widely used AI research technique, but US officials and leading US AI companies have accused Chinese rivals of using it to extract capabilities from proprietary models without the developers' consent.
- China has turned to distillation while facing US export controls on high-end chips, and Chinese central and local governments have promoted "model lightweighting" and edge computing with subsidies and research funding for AI that can run on drones, satellites and other devices with limited processing power.
- Analysts cited in the reporting say distilled models have limits and drawbacks: they inherit only selected capabilities, cannot fully replicate the broader abilities of frontier systems, and carry potential security risks, prompting Chinese research into countermeasures.
- The dispute over distillation is described as a flashpoint in US-China relations ahead of talks between the two countries on AI governance and safety.
Context
What exactly is model distillation?
Model distillation uses the outputs of a large, powerful AI system to train a smaller model that can perform some of the same tasks with far fewer computing resources Yahoo! Finance,Economic Times,Express Tribune. It has long been a standard tool in AI research and lowers the cost of building and deploying models, but it is now contested because it can transfer capabilities from proprietary systems without the consent of the companies that created them Economic Times,mint.
Why does this matter for US export controls?
Washington has restricted Beijing's access to advanced chips and other strategic technologies to slow China's AI progress NDTV,Straits Times,Express Tribune. Because distillation requires far less computing power than training a frontier model from scratch, US officials worry it offers a route around those controls, and Chinese defence institutions are described in the reviewed papers as treating advanced US models as a source of technical knowledge and a way to narrow the gap with US rivals Independent,РБК-Украина,TimesNow.
What remains unresolved or unverified?
The findings come from one news organisation's review of published Chinese papers and patents and material compiled by the Jamestown Foundation, and the reporting itself notes the documents had not previously been made public NDTV,Times of India,Independent. The available coverage does not establish how operational any of the resulting systems are, and experts quoted caution that distilled models inherit only selected capabilities and carry security risks of their own Yahoo,Taipei Times.
Where Left and Right agree, and where they split
- Where Left and Right agree
- Outputs from US frontier models are already inside PLA-linked military AI work, and the containment tools invoked — export controls, IP claims — did not stop an ordinary industry technique.
- Where Left and Right split
- Private firms' capabilities flowing into weapons work with only IP law standing in the way, or a denial strategy that counted chips while capability walked out.
How left and right read it
Reuters reviewed more than 80 Chinese papers and patents and found military- and security-linked researchers using outputs from OpenAI and Anthropic models to train domestic systems for surveillance, target recognition and drone control. Distillation is ordinary industry practice. That is the difficulty: capabilities built by private firms flow into weapons work, and the guardrails invoked are export controls and intellectual property. Is corporate IP law really our arms-control regime?
“The practice itself is widely used across the AI industry. But U.S. officials have accused some Chinese organizations of using it to extract capabilities from American AI systems, potentially weakening U.S. export controls and intellectual property protections.” — The Independent
US export controls restricted high-end chips, and China turned to distillation: smaller models trained on the outputs of frontier systems, backed by central and local government subsidies for 'model lightweighting' on drones and satellites. A PLA unit linked to military intelligence trained its own model to run entirely inside military networks, judging third-party systems unfit for classified work. That is deliberate self-reliance. Measure denial by capability retained, not chips withheld.
The receipts — all 39 sources
Wire services (1)
Independent coverage (38)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.