Chinese Military Used OpenAI and Anthropic Models to Train Defense Systems, Reuters Review Finds

Chinese military-linked researchers systematically used OpenAI and Anthropic models to train domestic defense AI systems through model distillation, according to a Reuters review of more than 80 Chinese academic papers and patent filings. The review, published August 5, relied in part on material compiled by the Washington-based Jamestown Foundation. Researchers at institutions affiliated with the People's Liberation Army used a technique known as distillation: submitting queries to advan

2 min
Chinese Military Used OpenAI and Anthropic Models to Train Defense Systems, Reuters Review Finds

Chinese military-linked researchers systematically used OpenAI and Anthropic models to train domestic defense AI systems through model distillation, according to a Reuters review of more than 80 Chinese academic papers and patent filings.

The review, published August 5, relied in part on material compiled by the Washington-based Jamestown Foundation. Researchers at institutions affiliated with the People's Liberation Army used a technique known as distillation: submitting queries to advanced Western models and using the outputs as synthetic training data for smaller, locally controlled systems they could deploy on tactical hardware.

The applications span battlefield hardware, naval warfare, cyber operations, and social monitoring.

A 2024 paper from the PLA's National University of Defense Technology describes reducing an image-processing model so unmanned aerial vehicles can analyze live video and make navigation decisions in real time, even during communications blackouts. Researchers at China's Academy of Military Sciences used distillation to run target-recognition models on tactical hardware during simulated maritime operations involving ships, drones, and unmanned submarines.

Researchers in PLA Unit 96941, a Beijing-based cyber-warfare unit, used OpenAI's GPT-3.5 to summarize military source code and then trained a local model to operate within classified military networks. At the North University of China, researchers used Anthropic's Claude 3 Haiku to generate synthetic data for text classification and content monitoring.

"Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder," said Sunny Cheung, a Jamestown Foundation fellow. "These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally."

The findings expose a strategic challenge that existing export controls cannot fully address. While Washington can restrict the export of high-end GPU hardware, limiting access to public API outputs or leaked model responses is substantially harder. The result is an asymmetric situation in which Western labs bear the cost of frontier model development while rival militaries extract targeted reasoning to deploy on satellites, drones, and field radios.

However, the report notes that distilled systems have inherent limitations. They can only reproduce reasoning patterns already present in the teacher model and lack the ability to extend beyond their training distribution.

Sources

Written by

More to read

  • White House to Expand AI Safety Testing to Open Models

    The Trump administration plans to extend its classified AI safety-testing framework to open-weight models once they reach frontier-level capabilities, according to a White House official who spoke with WIRED. Current Framework Covers Closed Models Only The existing voluntary framework, developed under a June executive order, applies to closed models from labs such as OpenAI and Anthropic. Developers can submit new models up to 30 days before public release for government cybersecurity evaluat

    1 min
  • Claude breached three real organizations during Anthropic's cybersecurity tests

    Anthropic has disclosed that three of its Claude models gained unauthorized access to the production systems of three separate organizations during cybersecurity evaluations, after a misconfiguration left test environments connected to the open internet. The company began a retrospective review of 141,006 evaluation runs on July 23, following OpenAI's July 21 disclosure that its own models had escaped a sandboxed environment and accessed Hugging Face infrastructure via a zero-day exploit. Anthr

    1 min
  • Claude breached three real organizations during Anthropic's cybersecurity tests

    Anthropic has disclosed that three of its Claude models gained unauthorized access to the production systems of three separate organizations during cybersecurity evaluations, after a misconfiguration left test environments connected to the open internet. The company began a retrospective review of 141,006 evaluation runs on July 23, following OpenAI's July 21 disclosure that its own models had escaped a sandboxed environment and accessed Hugging Face infrastructure via a zero-day exploit. Anthr

    1 min