Key takeaways
- Reuters reviewed more than 80 Chinese papers and patents confirming PLA-linked researchers used outputs from OpenAI and Anthropic models to train defense AI systems.
- The technique used—model distillation—requires only API access, not stolen weights or chips, exposing a fundamental gap in current US export controls.
- The Trump administration rescinded the Biden-era AI Diffusion Rule in early 2026, which would have controlled model weight exports, just as evidence of the distillation campaign emerged.
- Congress has passed chip-control legislation but no bill addresses the API/output layer that the Reuters investigation proves is the actual vulnerability.
- For every dollar the US spends training a frontier model, an adversary can distill an approximation via API for a tiny fraction of that cost—a strategic asymmetry of orders of magnitude.
On July 31, 2026, Reuters published an investigation that rewrites the assumptions underpinning US AI policy. After reviewing more than 80 Chinese academic papers and patents, the news agency confirmed that researchers linked to the People's Liberation Army (PLA) and Chinese defense universities have been systematically using outputs from leading US AI models—those built by OpenAI and Anthropic—to train domestic systems for defense applications.
The technique at the center of the story is model distillation: querying a frontier model millions of times, capturing the outputs, and using them to train a smaller, locally controlled model that approximates the original's capabilities. It does not require stealing model weights or breaching a datacenter. It requires only API access—or access to an intermediary willing to share one.
The implication is stark. For four years, US export control policy has been built on a hardware thesis: restrict the sale of advanced GPUs (initially Nvidia's H100s, later H800s, then H200s and Blackwell-class chips), and you slow China's military AI progress. The Reuters findings show that strategy has a gaping hole. You can wall off the silicon, but if the model's intelligence is accessible via API, it can be siphoned, compressed, and redeployed.

What the Reuters Investigation Found
The Reuters review, published on July 31, 2026, spanned dozens of publicly available Chinese academic publications and patent filings. The reporting is granular and document-based—not a single anonymous claim, but a pattern visible across the open scientific record.
Among the concrete findings:
- Scale: More than 80 papers and patents reviewed showed PLA-linked institutions using outputs from US frontier models to build local defense-oriented AI systems.
- Models named: The research drew on outputs from models developed by OpenAI and Anthropic. The applications ranged from intelligence processing to electronic warfare analysis and decision-support tools.
- Institutions involved: Affiliations included entities tied to the PLA, the National University of Defense Technology (NUDT), and other Chinese defense universities and state laboratories.
- Method: The dominant technique was distillation—using a powerful "teacher" model to generate labeled outputs that train a smaller "student" model. The resulting models are smaller, more efficient to run, and easier to deploy in constrained environments like military edge devices.
This is not hypothetical future risk. The papers describe working systems. In several cases, the Chinese researchers explicitly acknowledged that their models were trained on outputs from US systems—a notable admission, given that Beijing's own regulations restrict the domestic use of foreign generative AI.
The disclosure lands in a specific political context. In January 2026, the Trump administration reversed course on key elements of the prior administration's chip export policy, loosening some restrictions on advanced AI chip sales to China. At the same time, the Commerce Department rescinded the Biden-era AI Diffusion Rule—a framework that would have placed controls not just on chips but on the export of advanced closed-weight model weights. The Reuters finding now puts pressure on both decisions. The hardware gates were opened just as evidence emerged that the software layer was already compromised.
Why Distillation Breaks the Current Control Model
Distillation is not new. It is a standard technique in AI development—used by OpenAI, Google, Anthropic, and Meta to create smaller, faster models from larger ones. What the Reuters investigation reveals is its strategic weaponization: using the outputs of America's most capable models to bootstrap Chinese military AI without paying the compute cost of training from scratch.
The economics are brutal for the US side. Training a frontier model from scratch can cost hundreds of millions of dollars in compute. Distilling an approximation from that model via API calls costs a tiny fraction of that—often tens of thousands of dollars in query fees, according to analyses from researchers at Stanford HAI and RAND. The gap between what the US spends to build capability and what an adversary spends to copy it is asymmetrical by orders of magnitude.

This exposes a category error in current export control thinking. The Bureau of Industry and Security (BIS) has built its framework around two objects: chips and model weights. Chips are physical and cross borders through customs. Weights are large files that can, in theory, be tracked as they move. But model outputs—the text, code, and reasoning generated by an API call—are not controlled at all. They flow continuously across the internet to anyone with a credit card and an account.
A 2026 analysis published by the US-China Economic and Security Review Commission (USCC) flagged this precise vulnerability, noting that distillation allows actors to "obtain many of the benefits of a model without gaining access to the underlying weights." The Reuters investigation is the empirical proof that this is not a theoretical concern—it is happening, at scale, in PLA-affiliated labs.
The Corporate Response—and Its Limits
OpenAI and Anthropic both maintain terms of service that prohibit military use and restrict access from China. Anthropic, in particular, has moved aggressively in recent months. The company has updated its terms to block access from China-controlled entities, shut off advanced model access following national security directives, and even revoked API access from entities it suspected of policy violations.
These measures are necessary but insufficient. The Reuters reporting shows that Chinese defense researchers accessed the US models through intermediaries—third-party API resellers, front companies, cloud platforms in jurisdictions that are not blocked, and academic partnerships. The internet's architecture makes IP-level blocking a porous defense. VPNs, proxy services, and cloud compute instances in third countries all provide workarounds that a determined state actor will always find.
The result is a misalignment between corporate policy and strategic reality. A US AI lab can write exemplary terms of service, enforce them against direct Chinese customers, and still see its models' intelligence flow into PLA weapons research through indirect channels. The control point—the API—is structurally leaky.
The Policy Vacuum
The Reuters exclusive exposes a gap at the center of US AI strategy. The hardware controls have been the headline. The software controls were weakened. And the output layer—the actual intelligence generated by these systems—remains entirely unregulated.
Several frameworks have been proposed but not implemented. The rescinded AI Diffusion Rule would have placed controls on the export of model weights above a certain compute threshold. Just Security and other policy outlets have advocated for a "layered" approach that adds distillation-specific controls—monitoring abnormal query patterns, rate-limiting API access, and imposing liability on labs whose models are demonstrably used to train foreign military systems. None of these are currently law.
The political question now is whether the Reuters finding forces action. The House China Select Committee has already passed legislation strengthening export controls on advanced AI chips. But that bill addresses the hardware layer—the same layer the Reuters investigation just proved is insufficient. A serious legislative response would need to address API access, output-level controls, and the intermediary problem. As of early August 2026, no such bill has been introduced.

What Changes Now
The Reuters investigation does not reveal a technical breakthrough by China. Distillation is well understood. The PLA's use of foreign models was suspected by analysts for years. What the reporting changes is the evidentiary baseline. This is no longer a hypothetical risk to be modeled. It is a documented practice, visible in the public scientific record, involving the PLA and the most advanced US AI systems.
For AI labs, the calculation hardens. The assumption that terms of service and IP blocking constitute a meaningful barrier to state actors is now indefensible. Labs that sell API access to frontier models are, functionally, exporting capability to adversaries who will compress and weaponize it. The question is whether they bear any responsibility for that downstream use—and whether the US government will eventually make them bear it.
For policymakers, the choice is sharper. The current framework assumes the US can maintain an AI lead by controlling physical inputs. That framework has now been empirically falsified. The controls need to extend to the output layer, or the lead will continue to erode—not through a dramatic breach, but through a slow, steady distillation that turns American compute investment into Chinese military capability.
For enterprise leaders, the Reuters finding is a risk-management signal. Companies building on US frontier APIs should expect tighter controls, higher compliance costs, and new liability regimes. Those using open-weight models—Meta's Llama, DeepSeek, Alibaba's Qwen—face a different but related set of questions about provenance and security. The era in which AI capability was assumed to stay where it was built is over.
The AI arms race has gone dark. The front line is no longer a semiconductor fab in Taiwan or a datacenter in Arizona. It is an API call, routed through a third-country proxy, answered by a US model, and captured by a defense lab in Beijing. The intelligence crosses the Pacific invisibly. The weapons built from it will not.
The article shows the pattern. The app trains the response.
Continue in Tikva to turn the insight into a repeated response.
Open TikvaSources and educational notice
This article is educational. It does not provide a medical diagnosis or replace guidance from a qualified health, legal, tax, investment, or financial professional. Decisions about your health or finances should consider your individual circumstances.
- Reuters — Exclusive investigation confirming PLA-linked researchers used US AI model outputs to train defense systems, published July 31, 2026
- US-China Economic and Security Review Commission — Bulletin flagging distillation as a tactic allowing actors to benefit from models without accessing weights
- Just Security — Policy analysis advocating a layered US government response including legal authorities to counter Chinese AI distillation
- Bureau of Industry and Security — Announcement of the rescission of the Biden-era AI Diffusion Rule and changes to chip-related export controls in 2026
- Anthropic — Terms of Service update restricting sales and access in China and other unsupported regions
- Council on Foreign Relations — Overview of the AI Diffusion export control framework covering advanced chips, cloud access, and model weights
FAQ
What is model distillation and why does it matter for national security?
Model distillation is a machine learning technique where a smaller, less capable "student" model is trained using the outputs of a larger, more capable "teacher" model. In the context of national security, it matters because it allows an adversary to approximate the capabilities of a frontier AI system without stealing the underlying weights or building the model from scratch. The Reuters investigation documented more than 80 cases where Chinese defense-linked researchers did exactly this using outputs from US models.
How did Chinese military researchers access US AI models if OpenAI and Anthropic block China?
According to the Reuters reporting, access was obtained through intermediaries—including third-party API resellers, front companies, cloud platforms in unblocked jurisdictions, and academic partnerships. Both OpenAI and Anthropic maintain terms of service that prohibit use from China and for military applications, but IP-level blocking is structurally porous. Determined state actors route around these restrictions using proxies, VPNs, and third-country infrastructure.
Does this mean US export controls on AI chips have failed?
It means chip controls are necessary but insufficient. Restricting advanced GPUs raises the cost and time required for China to train frontier models domestically. But the Reuters finding shows that adversary capability can also be built through distillation, which does not require restricted chips—only access to model outputs. A control framework that covers hardware and weights but ignores outputs leaves a critical pathway open.
What would effective regulation of AI model outputs look like?
Proposals include monitoring abnormal query patterns that indicate distillation, imposing rate limits on API access from high-risk jurisdictions, extending liability to labs whose models are demonstrably used to train foreign military systems, and requiring Know-Your-Customer verification for API access to frontier models. As of August 2026, none of these measures have been enacted into US law, though the Reuters findings may accelerate legislative action.