One paper from PLA Unit 96904 explicitly described distilling U.S. models to create "smaller and more secure" versions suitable for defense applications .
The core strategic risk is that distillation allows China's military to effectively parasitize U.S. AI investment for defense applications at a fraction of the cost, while the safety degradation inherent in the process may produce less constrained, more dangerous military AI systems.