News
Chinese Military Researchers Trained Defense Systems on OpenAI and Anthropic Model Outputs
A Reuters investigation found that researchers linked to the Chinese military used outputs from GPT-3.5 and Claude 3 Haiku to train their own defense systems through a technique called distillation. Institutions involved include a PLA cyber intelligence unit and a university tied to the defense industry.
Researchers linked to the Chinese military used outputs from leading American AI models built by OpenAI and Anthropic to train their own domestic defense systems. That's according to a Reuters investigation that reviewed more than 80 Chinese research papers and patent filings published through July 2026.
How distillation works
The technique in question is called model distillation. It involves using responses generated by a large, advanced AI system to train a smaller, specialized model that can then run locally, without the enormous computing resources needed to build a system from scratch. It's a method familiar from commercial AI applications, but in this case it was used to build defense tools that operate entirely within Chinese military networks, cut off from the internet.
Eduardo Baptista, the Reuters journalist behind the investigation, wrote that the documents show the method being applied broadly, from monitoring social media content to direct use on the battlefield. Reuters worked with the Jamestown Foundation, a Washington-based security think tank, on the analysis.
Specific cases
The most striking example involves PLA Unit 96941, which handles military intelligence and cyber operations in Beijing. Its researchers used OpenAI's GPT-3.5 to generate descriptions of sensitive military system source code, then trained their own model on those descriptions, one that can run entirely within the Chinese military's closed networks.
The second case involves North China University, an institution closely tied to the country's defense industry. Researchers there used Anthropic's Claude 3 Haiku to generate synthetic training data for a text classification model designed to monitor social media and moderate content. Reuters also points to the PLA's National University of Defense Technology, where distillation was used to shrink image-processing models used by drones, and to the Chinese Academy of Military Science, which turned to the technique for simulated naval operations.
Corporate and government response
Anthropic said it does not make Claude commercially available in China or to Beijing-controlled entities and that it runs monitoring systems to detect usage policy violations. The company also noted that models produced through distillation lose some of the safeguards built into the original system. OpenAI, the Pentagon and the White House did not respond to Reuters' questions before publication. Chinese officials rejected the accusations, arguing that the United States itself uses similar methods against other countries' AI systems.
Chinese researchers are using distillation for purposes ranging from content monitoring to military applications - from the findings of the Reuters and Jamestown Foundation document review
Rivalry context
The disclosure lands at a tense moment in the technology relationship between Washington and Beijing. The US administration has already accused the Chinese company Moonshot AI of stealing an Anthropic model, and Beijing is threatening retaliation against US sanctions targeting AI companies accused of copying other firms' models. Both sides have scheduled talks for September on rules governing artificial intelligence, and the case described by Reuters could become one of the sticking points in those negotiations.
The case also exposes the weakness of existing export safeguards. US export controls mainly cover advanced chips used to train AI models, not the outputs of models made publicly available through an API. Distillation offers a way around that: Chinese researchers don't need access to restricted computing hardware, just access to responses generated by American models through an ordinary programming interface.
For Polish companies and institutions using OpenAI or Anthropic models, the case poses no direct threat, but it shows how hard it is for providers to control where the outputs generated by their systems end up. That question will keep resurfacing as export regulations and EU AI rules, which also call for oversight of dual-use applications, continue to develop.
Reuters did not disclose to what extent the systems described have already been incorporated into the actual Chinese military arsenal, versus remaining at the academic experimentation stage. Companies like Anthropic say they will keep tightening mechanisms that detect attempts to mass-harvest model responses for distillation, but acknowledge they cannot eliminate the risk entirely.


