Executive summary
A Reuters investigation revealed that Chinese military institutions have been using model distillation-a technique that trains smaller AI systems using outputs from larger models-to extract capabilities from leading U.S. AI systems developed by OpenAI and Anthropic. The findings, based on over 80 academic papers and patents, show widespread use by researchers linked to the People's Liberation Army for applications ranging from cyber warfare to drone targeting, intensifying the U.S.-China AI competition.
What happened
A Reuters review of more than 80 Chinese academic papers and patents uncovered systematic use of AI model distillation by Chinese military and security researchers to train domestic systems using outputs from advanced U.S. AI models. The investigation, which incorporated research from the Washington-based Jamestown Foundation, documented cases across multiple institutions. One notable example involved researchers from PLA Unit 96941, a military intelligence and cyber-warfare unit, who used OpenAI's GPT-3.5 to process and summarize sensitive military software code. The outputs were then used to train a domestic model capable of operating entirely within secure Chinese military networks. Other applications included researchers at the North University of China using Anthropic's Claude 3 Haiku to generate synthetic training data for social media monitoring systems. The PLA's National University of Defense Technology published a 2024 paper describing distillation techniques to compress image-processing models for deployment on unmanned aerial vehicles, enabling real-time video analysis for navigation and targeting even when communications are disrupted. Similar research from China's Academy of Military Sciences demonstrated distilled AI being used for target recognition during simulated maritime operations involving drones, ships, and unmanned submarines. Anthropic responded that it does not provide commercial access to Claude in China and actively monitors for policy violations, warning that distilled models may lose safety safeguards built into the original systems.
Why it matters
The findings represent a new front in the U.S.-China technology competition, showing how China is attempting to circumvent U.S. export controls on advanced chips and AI capabilities. Model distillation allows developers to create smaller, specialized systems that require far less computing power than frontier AI models, making advanced capabilities more accessible and deployable on hardware ranging from drones to satellites. The controversy centers not on distillation itself-a widely accepted machine learning technique-but on the alleged unauthorized extraction of capabilities from proprietary U.S. models. Sunny Cheung, a Jamestown Foundation fellow who analyzed over 60 papers, emphasized that Chinese researchers are attempting to transfer not just answers but the reasoning processes behind them: 'Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder.' The issue has emerged as a major flashpoint ahead of U.S.-China talks on AI governance and safety, with U.S. officials accusing some Chinese entities of using distillation to undermine export controls and infringe intellectual property rights. China has rejected the accusations, arguing that Washington is pursuing AI 'hegemonism' while noting that U.S. firms have engaged in similar practices. Chinese AI startup Moonshot recently denied allegations by the Trump administration that its Kimi K3 model was built using distillation.
Bigger picture
China has embraced model distillation as a strategic tool to compete with the U.S. in frontier AI while facing constraints on advanced computing resources due to Washington's export controls on high-end chips. Central and local governments have promoted model lightweighting and edge computing, directing subsidies and research funding toward technologies that enable AI models to run on devices with limited processing power. The development reflects broader tensions in the global AI race, where access to advanced capabilities has become as critical as access to hardware. However, experts caution that distillation has significant limitations. Trevor Koverko, co-founder of AI data company Sapien, noted that distilled models remain less capable than their source systems: 'It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI.' Interestingly, Chinese military researchers themselves are examining distillation as a potential security vulnerability. In January, researchers at the Army Engineering University published a paper on the threat of 'data-free distillation'-a method of reverse-engineering a model's capabilities without direct access to its core parameters-and proposed defense mechanisms to mask logical information exposed in model outputs. The controversy underscores the growing challenge of controlling AI capabilities in an era where outputs, not just code or chips, can transfer valuable technical knowledge.
What to watch
Watch for potential regulatory responses from Washington regarding access to U.S. AI models by Chinese entities, which could include stricter usage monitoring or geographic restrictions on frontier AI systems. The upcoming U.S.-China talks on AI governance and safety may address the distillation controversy and establish new frameworks for acceptable use of AI outputs. Monitor whether leading AI companies like OpenAI and Anthropic implement additional technical safeguards to prevent unauthorized capability extraction, and whether they enhance monitoring systems to detect distillation activities. Pay attention to China's continued development of domestic AI capabilities and whether restrictions on access to Western models accelerate independent innovation or create alternative pathways for capability transfer. Also watch for potential intellectual property disputes as the legal framework around AI model outputs and their permissible uses remains unsettled.
Get our top market beating stocks free here
#regulation
#ai
#geopolitics
#cybersecurity
#china