Chinese military and security-linked researchers have used outputs from leading United States artificial intelligence models to train domestic systems for surveillance, drones and battlefield operations. A review of more than 80 academic papers and patents found repeated use of OpenAI and Anthropic tools across defense-related institutions.
The central method is model distillation: outputs from a large, powerful model become training material for a smaller and more specialized system. The resulting tool can run locally with fewer computing resources, allowing organizations to transfer useful behavior without building a frontier model from the beginning.
Research linked to the People's Liberation Army treats distillation as a way to capture both answers and the reasoning that produces them. More than 60 papers were examined by Jamestown Foundation fellow Sunny Cheung, while another two dozen military-linked cases were independently identified in the broader academic record.
A paper from PLA Unit 96941, a Beijing military intelligence and cyberwarfare unit, described using GPT-3.5 to summarize sensitive military software code. Those summaries were then used to train a domestic model that could run entirely inside Chinese military networks without exposing classified material to an outside system.
At the North University of China, researchers used Claude 3 Haiku to generate synthetic data for social-media monitoring and content moderation. Anthropic said it does not offer commercial Claude access in China or to Beijing-controlled companies and warned that distilled systems may no longer retain the safety protections of the original model.
Military deployment studies go beyond text. The National University of Defense Technology used distillation to reduce an image-processing model for unmanned aerial vehicles, enabling live-video analysis, navigation and targeting support even when communications are interrupted.
Researchers at the Academy of Military Sciences also placed a distilled target-recognition model on tactical hardware in simulated maritime operations involving drones, naval vessels and unmanned submarines. Government funding for model lightweighting and edge computing supports similar deployment on satellites and other devices with limited processing capacity.
The practice sits at the intersection of military capability, export controls and intellectual-property disputes. It also creates a defensive problem for China: an Army Engineering University study examined data-free distillation as a technique for reverse-engineering model capabilities, showing that the same method used to close a technology gap can expose domestic systems to extraction.



