Researchers linked to the Chinese military have used large language models developed by US AI companies to train domestic defence systems. Academic papers and patent applications reviewed showed that the method has been applied to practical military use cases, not just theoretical research.

More than 80 academic papers and patents from military-linked institutions contained examples of adapting outputs from US AI models to defence technologies. Researchers used outputs from models of US-based companies including OpenAI and Anthropic to feed smaller, local AI systems.

Distillation as a strategic shortcut

The approach aimed to transfer advanced reasoning capabilities to defence-focused applications without requiring expensive, high-level computing infrastructure. The common approach in the studies was to transfer data and reasoning patterns produced by large, costly models into smaller systems, rather than deploying the large models directly.

The approach is known in the industry as 'distillation' and is seen as a critical shortcut for countries with limited access to chips and computing power. The core risk is not the model itself but the use of the model's high-quality outputs to train other systems.

Application areas and tactical use

The documents highlighted application areas including cyber operations, surveillance, target recognition, unmanned aerial vehicle navigation, and tactical decision support. Highlighted use cases in the documents included target detection and classification, drone route and mission optimisation, cyber attack and defence scenarios, processing of large-scale surveillance data, and tactical-level decision support systems.

Applications in unmanned systems and cyber operations in particular increase the possibility of wider-scale use at lower cost.

Implications for US restriction strategy

The US has in recent years sought to restrict China's access to advanced semiconductors and AI accelerators in order to slow its military capacity growth. The findings indicate that information outputs provided directly or indirectly by advanced models have created a new channel that circumvents the US restriction strategy.

The situation has strengthened the argument that technology embargoes limited only to hardware and direct software access may not provide sufficient protection. The debate has moved beyond the question of whether China can access the most advanced chips to the question of through which other pathways the knowledge of the most advanced models can be transferred.

In the AI race, the next critical issue is no longer hardware superiority alone but how quickly and to what extent the knowledge of advanced models can be converted into local military systems.

Industry response and future controls

The development has increased security pressure on AI companies. US companies have recently been tightening access controls to limit misuse of their models. Open-source tools, intermediary platforms, and reuse of model outputs are making oversight more difficult.

In the coming period, the US is expected to tighten rules not only on chip sales and direct model access but also on the reuse of model outputs. Companies may tighten filters on corporate customer oversight, API access, and defence-linked activities.