Reuters' review of 80+ Chinese papers and patents shows military linked researchers distilling — training smaller domestic models to imitate the larger US ones — OpenAI and Anthropic outputs into defense systems, a pattern chip export controls miss.
A Reuters review of more than 80 Chinese academic papers and patents shows researchers affiliated with China's People's Liberation Army and state security institutions using outputs from OpenAI and Anthropic models to train smaller, domestic AI systems. The technique, called model distillation, trains a smaller model to imitate a larger one by learning from its outputs.
The work spans robotics, surveillance, and targeting, and the academic record now makes the practice visible. The Jamestown Foundation, a Washington research institute, compiled the corpus of papers and shared it with Reuters. The published review is the first corpus-level look at the practice, and the pattern is consistent: the bottleneck the United States has tried to police, frontier chips, is no longer the layer at which capability is moving.
Distillation itself is not unusual. It is how startups, academic labs, and large companies produce capable smaller models at a fraction of the compute cost. The news in the Reuters review is not the technique, it is the actor, the scale, and the timing. Researchers at PLA-linked institutions used the technique to learn from the most capable US AI systems while bypassing the chip restrictions that have shaped US-China AI policy for the past three years.
The mechanism is structurally hard to block. Distillation transfers capability through model outputs, which are text and image data flowing over ordinary networks. The export-control architecture, in contrast, is built around hardware: the chips themselves, the lithography machines that make them, and the interconnects that tie them into training clusters. Once an adversary can reach a frontier model through an API, query it, and collect the answers, the policy of restricting silicon does not capture the resulting knowledge transfer.
Moonshot, a Beijing AI startup whose Kimi K3 model has drawn Trump-administration allegations, publicly denied that its system was built on distillation from US frontier models. Moonshot said the model was the product of proprietary innovation. The denial contests one specific allegation about one company; it does not address the broader pattern Reuters documented in the academic record.
The Reuters review lands inside the negotiating window for upcoming US-China AI governance talks, and just after Washington tightened chip export rules. The Chinese government has called US restrictions on advanced AI "AI hegemonism," a term that frames the dispute as a contest over who gets to lead the technology's development. US officials have argued that distillation by military-linked institutions undermines both export controls and intellectual property.
The policy question the review makes concrete is whether the next round of restrictions should focus on access to model outputs. API-level controls, rate limits, and usage monitoring can identify patterns consistent with bulk distillation, but they are blunt instruments that also slow ordinary research and commercial use. Hardware controls, by contrast, are precise at the chip level but miss the data flow entirely.
The Reuters record is not a verdict on whether frontier AI is being stolen; it is a documentation of how capability moves when one channel is closed and another remains open. The governance talks will argue over the symbolic question of who leads. The practical question the review raises is which layer of the stack the next round of policy actually has to police.