A new investigation has reignited concerns over how far Washington’s export controls can actually reach in an era where artificial intelligence capabilities can be extracted without ever crossing a border. A Reuters review of more than eighty Chinese academic papers and patents found that researchers linked to China’s military and security institutions used outputs from advanced American AI models, including systems built by OpenAI and Anthropic, to train smaller domestic systems for defence and surveillance applications. The findings suggest that a widely used AI technique called model distillation may be offering Chinese researchers a shortcut around chip and technology restrictions rather than a way to defeat them outright.
How Distillation Turns a Restriction Into a Workaround
Model distillation is not, in itself, a controversial or unusual technique. It involves using the outputs of a powerful “teacher” model to train a smaller “student” system, which can then run on far less computing power while retaining selected reasoning or classification abilities from the original. The approach is standard practice across the AI industry and underpins much of the push toward efficient, on-device AI deployment worldwide.
What has drawn scrutiny in this case is where and how the technique was allegedly applied. According to the Reuters review, conducted alongside research compiled by the Washington-based Jamestown Foundation, one paper published last year by scientists from PLA Unit 96941, described as a military intelligence and cyber warfare unit, detailed using OpenAI’s GPT-3.5 to summarise military-related software code before training a domestic model capable of operating entirely within Chinese military networks. The paper reportedly noted that external AI services were unsuitable for handling classified information directly, indicating the distillation step was used specifically to route around that restriction.
From Content Moderation to Drone Targeting
A separate study cited in the review found researchers at the North University of China, an institution with close ties to the country’s defence industry, used Anthropic’s Claude 3 Haiku model to generate synthetic training data for a text classification system built for social media monitoring and content moderation. Anthropic told Reuters it does not provide commercial access to Claude in China or to Beijing-controlled firms and said it actively monitors for violations of its usage policies. The company also cautioned that distilled models can lose the safety safeguards built into their original systems, a warning that speaks directly to why regulators view the technique as a potential blind spot in export enforcement.
The defence-linked applications extended well beyond text and social media analysis. A 2024 paper from the PLA’s National University of Defense Technology reportedly described compressing an image-processing model so it could run aboard unmanned aerial vehicles, enabling drones to analyse live video, assist navigation and support targeting even without active communication links. Another study reportedly documented distilled target-recognition systems tested in simulated maritime operations involving drones, naval vessels and unmanned submarines, underlining how a civilian AI technique can migrate quickly into battlefield use once adapted.
A Widening Fault Line in Global AI Governance
The findings arrive against the backdrop of an already tense standoff over AI supply chains, with Washington tightening restrictions on China’s access to advanced semiconductors even as distillation-based workarounds appear to sidestep the compute bottleneck those restrictions were designed to create. Notably, the Reuters findings follow closely on Anthropic’s own disclosure weeks earlier that it had detected what it described as a large-scale distillation campaign against Claude linked to Chinese technology group Alibaba, involving millions of automated exchanges through thousands of fraudulent accounts, a case that suggests unauthorised extraction attempts against frontier models are neither isolated nor limited to state-linked defence research alone.
An AI researcher at Algoritha Security noted that distillation is a legitimate and widely accepted training technique across the industry, but said concerns arise specifically when proprietary capabilities are extracted without authorisation or applied within sensitive military contexts. The researcher added that distilled systems generally cannot replicate the full intelligence, reasoning depth or performance of the frontier models they are drawn from, a caveat that tempers, without eliminating, the security implications of the practice.
For India, which is simultaneously building its own AI governance framework and expanding indigenous compute capacity, the episode is a reminder that questions of AI security and intellectual property protection are no longer confined to the countries directly named in such investigations. As global discussions over export controls, model access and defence-linked AI applications intensify, the distillation debate is likely to remain a persistent fault line in how nations attempt to police technology they can no longer fully contain within their own borders.
