reuters.com web signal

Chinese military researchers distill GPT-3.5, Claude for defense

TL;DR

  • A Reuters review of more than 80 Chinese academic papers and patents found military researchers distilling outputs from OpenAI and Anthropic models to train domestic systems.
  • Researchers used GPT-3.5 to summarize software code and trained a domestic model on those summaries to run entirely within Chinese military networks.
  • At North University of China, researchers used Anthropic's Claude 3 Haiku to generate synthetic training data for a social media text classification model.

The harder question in AI export policy is not about weights or chips. It is about what happens to model outputs once a frontier system emits them, and whether they can be governed at all.

Reuters reported that its review of more than 80 Chinese academic papers and patents shows Chinese military researchers using outputs from OpenAI and Anthropic systems to train smaller domestic models through a technique known as model distillation. In one example, researchers used GPT-3.5 to summarize software code and trained a domestic model on those summaries so it could run entirely within Chinese military networks, where third-party models are not permitted for classified information. In another, researchers at North University of China, which the report says has close links to the country's weapons industry, used Anthropic's Claude 3 Haiku to generate synthetic training data for a text classification model aimed at social media monitoring and content moderation.

Sunny Cheung, a Jamestown fellow who analysed over 60 of the papers, told Reuters that Chinese military scientists are systematically capturing the reasoning steps of Western models to adapt them for surveillance, cyber warfare and tactical decision-making. Anthropic said it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations.

The honest caveats are the ones the reporting does not settle. It does not spell out how the researchers obtained access to the US models in the first place, whether via VPN, resellers, or other routes, and it does not confirm which specific defense systems eventually shipped with the distilled models. Distillation from a third-party API is also hard to prove forensically after the fact, so read Cheung's characterisation as expert interpretation of the papers rather than chain of custody.

The reason this will land on desks in Washington and San Francisco is that the distillation vector routes around every export control designed for weights and hardware. If outputs are the pipe, then the lever moves to terms of service enforcement, output watermarking, and API-level anomaly detection, and none of those are today strong enough to stop what these papers describe.