Chinese Military Researchers Use US AI Models to Train Defense Systems

A Reuters review of more than 80 Chinese academic papers and patents, published July 31, 2026, found PLA-linked researchers used outputs from OpenAI's GPT-3.5 and Anthropic's Claude 3 Haiku, distilled into smaller domestic models, to build defense systems for surveillance, drone targeting and cyberwarfare. Neither company is publicly traded; the finding exposes a gap in US export controls that restrict chips and model weights but not distillation from a model's API responses.

A Reuters investigation published July 31, 2026 found that Chinese military-linked researchers used outputs from OpenAI's GPT-3.5 and Anthropic's Claude 3 Haiku to train smaller, specialized defense systems, based on a review of more than 80 Chinese academic papers and patents. The technique, known as model distillation, feeds prompts into a frontier US model and trains a compact domestic model on its responses, letting the resulting system run on Chinese hardware without the advanced chips Washington has restricted.

The papers name PLA Unit 96941, a Beijing-based military intelligence and cyberwarfare unit, using distilled outputs to process sensitive military source code, while a paper from the National University of Defense Technology described shrinking an image-processing model for real-time drone navigation and targeting. The Academy of Military Sciences applied the same approach to target recognition for unmanned maritime vessels, and North University of China used it for social media monitoring and content moderation.

The finding exposes a gap in existing US export controls, which restrict advanced chips and model weights but do not cover a researcher simply querying a model's API and training on the outputs, according to the report. That leaves enforcement to OpenAI's and Anthropic's own terms of service and API-level anomaly detection rather than any government mechanism, and the disclosure landed days ahead of scheduled US-China AI governance talks.

Anthropic said it does not sell commercial access to Claude in China or to Beijing-controlled entities and uses monitoring systems to flag policy violations, warning that distilled models can lose the original system's safety safeguards once retrained outside its control. OpenAI did not respond to a request for comment. Neither OpenAI nor Anthropic is publicly traded, so the direct market exposure is limited, but the episode could sharpen scrutiny of how US AI labs police API access and add momentum to closing the distillation loophole in export-control policy.

Powered by SentiSense - Intelligent Market Analysis