{"slug": "chinese-military-used-gpt-3-5-and-claude-for-defense-ai", "title": "Chinese Military Used GPT-3.5 and Claude for Defense AI", "summary": "Chinese military researchers used outputs from OpenAI's GPT-3.5 and Anthropic's Claude 3 Haiku to train domestic defense AI systems, according to a Reuters investigation published today. A review of more than 80 Chinese academic papers and patents documented at least five PLA-linked institutions running model distillation experiments for drone targeting, social media surveillance, naval warfare simulations, and military code analysis, all without acquiring a single restricted Nvidia chip.", "body_md": "Chinese military researchers used outputs from OpenAI’s GPT-3.5 and Anthropic’s Claude 3 Haiku to train domestic defense AI systems, according to a [Reuters investigation published today](https://www.defensenews.com/industry/techwatch/2026/07/31/chinese-military-researchers-tap-us-ai-models-to-train-defense-systems/). A review of more than 80 Chinese academic papers and patents documented at least five PLA-linked institutions running model distillation experiments — producing AI for drone targeting, social media surveillance, naval warfare simulations, and military code analysis — all without acquiring a single restricted Nvidia chip.\n\n## What the Chinese Military AI Papers Actually Show\n\nThe findings are documented in the researchers’ own publications, which is what makes this story unusually solid. PLA Unit 96941, a military intelligence and cyber-warfare unit based in Beijing, described using GPT-3.5 to summarize sensitive military software code, then training a local model on those summaries. That model now runs entirely within Chinese military networks — no external API dependency required after training. The North University of China, which has close ties to the country’s defense industry, used Claude 3 Haiku to generate synthetic training data for a social media monitoring and content moderation system.\n\nHowever, other institutions went further. Army Engineering University researchers explicitly targeted safety guardrail removal — distilling “attack knowledge” to break alignment mechanisms in Western frontier models. PLA Cyberspace Force units built watermark-stripping tools to remove the forensic attribution signals that OpenAI and Anthropic use to detect distillation. The Air Force Engineering University’s distillation work was funded under “Key Technologies for Data Security in Military Big-Data Collection.” These were not rogue academics — this was organized, funded, multi-institutional research.\n\n## Why Chip Controls Don’t Solve This\n\nWashington spent enormous political capital restricting Nvidia H100 and H200 exports to China. Model distillation routes around that entirely. You don’t need advanced chips to distill — you need API access, a training pipeline, and enough queries to build a representative dataset. The White House acknowledged this in NSTM-4, issued in April 2026: API calls “can be routed through any jurisdiction,” making unilateral enforcement structurally difficult. The Entity List controls hardware. It leaves cloud computing services — and the intelligence embedded in model outputs — essentially uncontrolled.\n\nThe technique itself is standard practice. Model distillation is how every lean ML team builds capable systems without frontier-scale compute: query a powerful model, collect input-output pairs, train a smaller student model on those pairs. The student inherits the teacher’s reasoning without needing the teacher’s weights or hardware. What distinguishes adversarial distillation from legitimate fine-tuning is intent, scale, and the deliberate evasion of detection — not the technical steps themselves. Washington is now [trying to draw a line around that technique](https://datainnovation.org/2026/06/the-united-states-needs-a-strategic-response-to-adversarial-ai-distillation/), and that line will eventually affect every developer using frontier AI APIs.\n\nRelated:[Anthropic’s Open-Weights Position: Not a Ban, but a Catch]\n\n## OpenAI and Anthropic Are Not on the Same Page\n\nAnthropic banned Chinese entities from Claude access entirely and, in February 2026, [disclosed that DeepSeek, Moonshot AI, and MiniMax had run coordinated extraction campaigns](https://www.cnbc.com/2026/02/24/anthropic-openai-china-firms-distillation-deepseek.html) using roughly 24,000 fraudulent accounts and 16 million Claude interactions. Anthropic also warned that distilled models can “lose important safety protections built into the original systems” — a claim the academic papers confirm, since several explicitly targeted guardrail removal.\n\nOpenAI’s position is different. Despite alleging that DeepSeek employees used obfuscated third-party routers to extract its model outputs, OpenAI has continued providing API access to Singapore-based subsidiaries of Alibaba, Baidu, and Tencent — all three listed on the Pentagon’s Entity List for suspected Chinese military ties. Those transactions are currently legal under US export rules, which is precisely the problem. Two leading AI companies, opposite policies on Chinese access, both technically within bounds.\n\nThe proof-of-distillation problem is real, and Chinese researchers know it. When Chinese Academy of Sciences researchers jailbroke domestic Chinese models, Qwen-Max identified itself as “Claude, an AI assistant created by Anthropic,” and DeepSeek-V3 claimed OpenAI origins — residual training signal from the distillation process. Chinese military researchers have also built explicit watermark-removal tools to strip exactly these forensic signals before deployment. It’s an arms race between provenance detection and evasion, and the evasion side has published its tooling.\n\n## What This Means for Developers\n\nThe policy response is moving fast. NSTM-4 tasked agencies with developing enforcement frameworks. The House Foreign Affairs Committee advanced the Deterring American AI Model Theft Act (DAAMTA) in April, which would mandate assessments of model extraction attacks and authorize sanctions against violators. Neither law nor memorandum is yet operational — but both signal where the pressure is heading: toward stricter API identity verification, jurisdiction-based access controls, and Anthropic’s restrictive posture becoming the industry standard rather than the outlier. For more on how national security concerns are reshaping developer tooling access, see [Residential Proxies Are Now a National Security Problem](https://byteiota.com/residential-proxies-national-security-threat/).\n\nFor developers, the near-term implications are narrow but real. Institutional affiliations will matter more at API signup. Rate limiting and anomaly detection will tighten. If you’re doing legitimate distillation — fine-tuning on model outputs for internal use — expect terms-of-service enforcement to become more rigorous. The underlying workflow isn’t going away. But its regulatory environment is changing, and the Reuters investigation is the clearest evidence yet of [why Washington considers this a national security problem, not a copyright dispute](https://www.justsecurity.org/137498/diagnosis-deterrence-us-response-distillation/).\n\n## Key Takeaways\n\n- Reuters documented PLA Unit 96941 and at least four other Chinese military institutions using GPT-3.5 and Claude 3 Haiku outputs to train domestic defense AI — for drone targeting, social media surveillance, and military code analysis\n- Model distillation bypasses chip export controls because it accesses AI capability through API calls, not hardware — a gap NSTM-4 explicitly acknowledges but has not yet closed\n- Anthropic has banned Chinese entity access; OpenAI continues serving Pentagon-blacklisted Chinese subsidiaries through Singapore entities — the industry has no consensus on where the line is\n- Chinese military researchers also built watermark-removal tools to defeat forensic attribution — making post-hoc detection harder than defenders expected\n- DAAMTA and NSTM-4 signal tighter API identity verification and jurisdiction-based restrictions ahead; legitimate distillation workflows will face more scrutiny, not less", "url": "https://wpnews.pro/news/chinese-military-used-gpt-3-5-and-claude-for-defense-ai", "canonical_source": "https://byteiota.com/chinese-military-used-gpt-3-5-and-claude-for-defense-ai/", "published_at": "2026-07-31 23:11:38+00:00", "updated_at": "2026-07-31 23:53:37.263040+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-policy", "ai-safety", "ai-research"], "entities": ["OpenAI", "Anthropic", "GPT-3.5", "Claude 3 Haiku", "PLA Unit 96941", "North University of China", "Army Engineering University", "Reuters"], "alternates": {"html": "https://wpnews.pro/news/chinese-military-used-gpt-3-5-and-claude-for-defense-ai", "markdown": "https://wpnews.pro/news/chinese-military-used-gpt-3-5-and-claude-for-defense-ai.md", "text": "https://wpnews.pro/news/chinese-military-used-gpt-3-5-and-claude-for-defense-ai.txt", "jsonld": "https://wpnews.pro/news/chinese-military-used-gpt-3-5-and-claude-for-defense-ai.jsonld"}}