The papers and patents reviewed by Reuters, compiled with the Washington-based Jamestown Foundation, show distillation being used for a range of defense-related AI systems :
A paper from PLA Unit 96904 explicitly described distilling U.S. models to create "smaller and more secure" versions suitable for defense applications . Another paper from PLA Unit 96941 — a military intelligence and cyber-warfare unit in Beijing — described using OpenAI's GPT-3.5 to process sensitive military source code
. A 2024 paper from the PLA's National University of Defense Technology used distillation to shrink an image-processing model for deployment on resource-constrained military hardware
.
The core strategic advantage of distillation is economic. Training a frontier AI model from scratch costs billions of dollars and requires years of research and development, massive datasets, and access to advanced semiconductor chips. Distillation lets Chinese researchers bypass nearly all of that investment .
By querying frontier models via API — creating fraudulent accounts and using proxy networks to evade rate limits — Chinese developers can extract the same capabilities at a fraction of the cost. Anthropic's investigation identified over 16 million exchanges generated through approximately 24,000 fraudulent accounts targeting Claude's agentic reasoning, tool use, and coding capabilities. Chinese AI developer MiniMax was alone responsible for over 13 million of those exchanges .
The evidence has triggered an escalating series of accusations and policy responses:
Despite its effectiveness as a shortcut, model distillation has inherent technical limitations that matter for military applications:
The combination of capability theft and safety degradation creates a dangerous dynamic:
The ongoing distillation warfare is accelerating U.S.-China decoupling in AI across multiple dimensions . Tighter export controls on advanced chips, stricter API access restrictions, KYC requirements for developer accounts, and potential financial sanctions are all on the table
.
The core strategic risk is clear: distillation allows China's military to effectively parasitize U.S. AI investment for defense applications at a fraction of the cost, while the safety degradation inherent in the process may produce less constrained, more dangerous military AI systems.