cd /news/artificial-intelligence/chinese-military-distilled-gpt-3-5-a… · home topics artificial-intelligence article
[ARTICLE · art-81905] src=machinebrief.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Chinese Military Distilled GPT-3.5 and Claude to Build Defense AI — 80 Papers Show Systematic Effort

Reuters reviewed more than 80 Chinese academic papers and patents showing PLA-affiliated researchers systematically used model distillation on OpenAI's GPT-3.5 and Anthropic's Claude 3 Haiku to train domestic AI for defense applications. One PLA unit distilled GPT-3.5 to build a code-summarization model for classified military networks, and North University of China researchers used Claude 3 Haiku for social-media surveillance classifiers. The July 31 exclusive exposes a structured effort to extract frontier-model capability through API access for air-gapped defense systems, despite terms of service prohibiting such use.

read3 min views1 publishedJul 31, 2026

Reuters reviewed more than 80 Chinese academic papers and patents showing PLA-affiliated researchers systematically used model distillation on OpenAI GPT-3.5 and Anthropic Claude 3 Haiku to train domestic AI for defense applications. One PLA unit distilled GPT-3.5 to build a code-summarization model for classified military networks. North University of China researchers used Claude 3 Haiku for social-media surveillance classifiers. The July 31 exclusive exposes a structured effort to extract frontier-model capability through API access for air-gapped defense systems. OpenAI and Anthropic terms of service prohibit such use, but enforcement against state actors routed through intermediaries is effectively impossible.

Reuters reviewed more than 80 Chinese academic papers and patents showing PLA-affiliated researchers systematically used model distillation on OpenAI's GPT-3.5 and Anthropic's Claude 3 Haiku to train domestic AI systems for defense applications. The July 31 exclusive report reveals a structured effort to extract capability from US frontier models without access to the underlying weights.

How It Worked #

Model distillation is simple in concept: you feed prompts to a teacher model, collect its outputs, then train a smaller student model to mimic those responses. The student never sees the teacher's architecture or training data — but if you have API access, you don't need to.

One PLA unit used distilled GPT-3.5 outputs to build a code-summarization model designed to run on classified military networks disconnected from the internet. Researchers at North University of China used Claude 3 Haiku to generate synthetic training data for social-media surveillance classifiers.

What They Targeted #

The papers span surveillance, cyber warfare, tactical decision-making, and code analysis. The common thread: specialized defense models that can operate on air-gapped networks where commercial API access is impossible. Distillation gives them frontier-model capability in a package they control.

OpenAI's terms of service prohibit using its models to develop competing AI systems. Anthropic says it doesn't sell Claude in China and monitors for policy violations. Both companies restrict API access from Chinese IP addresses — but researchers can route through third-party services or use proxy access.

The practical reality: API terms of service are not enforceable as law in China, and the PLA doesn't buy its own API keys. The distillation pipeline likely runs through intermediary accounts, academic collaborations, or third-country cloud providers.

The Policy Response #

This is the distillation fight Forbes profiled in June — the US-China AI conflict shifting from chip controls to model access controls. The Biden-era export restrictions targeted hardware. The distillation problem targets software and API access, which is much harder to control.

Congress has held hearings on model weight security. Industry proposals include mandatory KYC for frontier API access, watermarking outputs to trace distillation, and banning certain model architectures from cloud-hosted endpoints accessible from adversarial nations.

None of those proposals are law yet. Meanwhile, 80 papers suggest the distillation pipeline is already mature and producing results.

Get AI news in your inbox

Daily digest of what matters in AI.

Key Terms Explained #

Anthropic An AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.

Claude Anthropic's family of AI assistants, including Claude Haiku, Sonnet, and Opus.

Distillation A technique where a smaller 'student' model learns to mimic a larger 'teacher' model.

GPT Generative Pre-trained Transformer.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @reuters 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/chinese-military-dis…] indexed:0 read:3min 2026-07-31 ·