Will it run?
Models

Chinese military distills Claude and GPT

By Rae Whitlock Clawpit staff
Chinese military distills Claude and GPT

The Chinese armed forces are not waiting for new Nvidia chips; instead they take finished models from OpenAI and Anthropic, such as Claude, run millions of queries on them, and train smaller models that run on locally sourced hardware. This model distillation was revealed over the weekend in a Reuters report that drew on a review of more than 80 Chinese papers and patents compiled by the Jameson Foundation, a Washington research institute. U.S. Science and Technology Secretary Michael Kratzios had already accused Moonshot AI of Beijing-based distillation of Anthropic’s “Fable” model for Kimi K3; the documents show the practice is far wider and involves official security institutions.

In a paper published last year, researchers from PLA 96941, the People’s Liberation Army intelligence and cyber-warfare unit, described using GPT-3.5 to process sensitive military source code. Because the OpenAI model blocks handling classified material, the researchers fed the code through GPT-3.5 for summarisation, then trained a local model on those summaries—a model that can run on Chinese military networks without the policy restrictions of a foreign supplier. Sunny Chang, a research associate at Jameson who analysed more than 60 papers, says Chinese military scientists “systematically capture the reasoning steps of Western models” to adapt them for monitoring, cyber-warfare and tactical decision-making.

Beijing rejected the findings, claiming Washington is building “AI hegemony” and adding that U.S. companies employ similar practices. Moonshot AI denied that Kimi K3 was created by distillation, insisting it is based on proprietary innovations. The White House, the Pentagon, China’s foreign ministry, the Chinese army and OpenAI did not respond to the report.

Experts who commented on the publication described the distillation as “a form of intellectual property theft” that enables developers to copy the core capabilities of a closed model. Anthropic earlier this year accused Alibaba of model distillation, alleging the Chinese campaign used 25 thousand fake accounts to run 28.8 million interactions over six weeks—a volume that clearly signals intent to replicate. When a model learns to infer via software vulnerabilities and attack pathways, copying its behaviour also copies that analytical ability.

Researchers note that copying AI models continues a long tradition of intellectual-property theft under Chinese sponsorship, likening it to counterfeit disk factories that operated there two decades ago. Others point out that OpenAI and Anthropic built their models on data and content taken without licence, so the line between learning and theft remains blurred, at least until regulators decide where the boundary lies.