A Reuters review of more than 80 Chinese academic papers and patents has found that researchers linked to the People's Liberation Army and other military institutions used outputs from OpenAI and Anthropic models to train domestic AI systems, according to reporting published on 1 August 2026. The review drew on research compiled by the Washington-based Jamestown Foundation, and Reuters said it verified the literature and identified a further two dozen military-linked case studies.
What the papers describe
The documents describe extensive use of model distillation, a common industry technique in which outputs from a powerful model train smaller, specialised systems that run locally without frontier-scale computing. The reporting stresses that the dispute concerns unauthorised extraction, not distillation itself.
Sunny Cheung, a Jamestown fellow who analysed more than 60 of the papers, said Chinese military scientists are systematically capturing the reasoning steps of Western models to adapt them for surveillance, cyber warfare and tactical decision-making.
Named case studies
- Researchers in PLA Unit 96941, described in the reporting as a military intelligence and cyber warfare unit in Beijing, published a paper in 2025 describing the use of OpenAI's GPT-3.5 to summarise sensitive military source code; a domestic model was trained on those summaries to run entirely within Chinese military networks.
- At the North University of China, which has close links to the weapons industry, researchers used Anthropic's Claude 3 Haiku to generate synthetic training data for a text classification model used in social media monitoring and content moderation.
- A 2024 paper from the PLA's National University of Defense Technology described distilling an image-processing model for unmanned aerial vehicles, allowing drones to analyse live video and support navigation and targeting decisions when communications are cut.
- Researchers at the Academy of Military Sciences used distillation to run a target-recognition model on tactical hardware during simulated maritime operations involving drones, ships and unmanned submarines, a study published earlier in 2026 showed.
Responses and political context
Anthropic said it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations. It added that distilled models may lose the original systems' safety safeguards, potentially moving sensitive capabilities beyond its control. The White House, the Pentagon, China's foreign ministry, the PLA and OpenAI did not respond to requests for comment.
The findings arrive ahead of US-China talks on AI governance and safety. US officials have accused some Chinese entities of using distillation to extract capabilities from American models, potentially undermining export controls and infringing intellectual property rights. Beijing has rejected the accusations, saying Washington is pursuing AI "hegemonism", and argues that US firms do the same. In late July 2026, Moonshot denied Trump administration allegations that its Kimi K3 model was built through distillation, citing proprietary innovations.
Benefits and limits
With export controls restricting access to high-end chips, central and local governments in China have promoted "model lightweighting" and edge computing, funding work on running AI on drones, satellites and other low-power devices. Trevor Koverko of AI data company Sapien said distilled models remain less capable than their teachers, calling the technique a transfer of "selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI".
Chinese researchers also treat distillation as a threat. In January 2026, researchers at the Army Engineering University published work on "data-free distillation", a way of reverse-engineering a model's capabilities without access to its core parameters, and proposed defences that mask the logical information exposed in public outputs.
What is established and what is merely claimed
Established: the papers and patents exist and describe the uses set out above. Reuters reviewed more than 80 documents, verified the literature and identified about two dozen further military-linked case studies, building on the Jamestown Foundation analysis. Anthropic has confirmed its China access policy and its warning that distilled models can shed safety safeguards. The White House, the Pentagon, China's foreign ministry, the PLA and OpenAI declined to comment.
Merely claimed: that any of this amounted to unauthorised extraction or infringement is an accusation by US officials, not a legal finding. The description of a systematic transfer of proprietary reasoning into surveillance and cyber warfare tools is an analyst's assessment, not a proven fact. Beijing's counter-claim that US firms do the same is unproven, as is Moonshot's denial about Kimi K3. No cited source establishes how the outputs were obtained, whether terms of service were breached, or whether any resulting system has been operationally deployed.