Chinese military-linked researchers built new defense AI systems this year without evading Washington's chip embargo at all. A Reuters review of more than 80 Chinese academic papers and patents found that Chinese military-linked researchers used outputs from OpenAI's and Anthropic's AI models to train domestic systems meant to advance China's defense capabilities, the investigation reported this week. The technique, distillation, needs no smuggled processor and no export license: a researcher queries a frontier model repeatedly through its ordinary public interface, then trains a smaller domestic model to imitate the answers.
One documented case makes the mechanism concrete. At the North University of China, which has close links to the country's weapons industry, researchers used Anthropic's Claude 3 Haiku to generate synthetic training data for a text-classification model built for social media monitoring and content moderation. No chip crossed a border, and no export form was filed. The model in question, Claude 3 Haiku, is a small, publicly accessible one, reached the same way any paying customer reaches it.
North University of China is one node in a larger pattern. The Jamestown review names distillation work across a spread of PLA-linked institutions, including Army Engineering University of PLA, Air Force Engineering University, PLA Information Engineering University, and Nanjing University of Science and Technology, one of the military-linked "Seven Sons of National Defense," alongside the state-owned China Electronics Technology Group (CETC), whose researchers distilled security models for cyberattack tracing and intelligence collection. That last name is not a stranger to US export enforcement: CETC's 30th Research Institute, the specific unit the review found doing that distillation work, has been on the US Commerce Department's Entity List since 2020 over its role in militarizing outposts in the South China Sea, a sanction built for a different kind of transfer entirely. It has nothing to say about a research arm of the same sanctioned conglomerate querying a chatbot.
It is worth slowing down on the word distillation, because the target is not incidental. A review of dozens of Chinese academic and industry papers published between 2024 and 2026 found systematic Chinese efforts specifically aimed at the step-by-step chain-of-thought reasoning built into frontier Western models, reasoning being among the most expensive capabilities to develop from scratch. That is the detail that separates this from ordinary AI adoption. The papers are not distilling any output; they are going after the single capability that costs the most in compute and research time to build independently, and getting it for the price of API calls instead. The gap between those two paths is not rhetorical. Epoch AI researchers put the compute cost of the single most expensive publicly-announced training run to date, OpenAI's GPT-4, at roughly $40 million. A separate academic reconstruction of comparable step-by-step reasoning, using the same distillation mechanism the Reuters review documents, needed only about seven H100 GPU-hours of fine-tuning after pulling chain-of-thought outputs from a frontier model's public API. That is a fraction of the scale standing in for a training run that costs eight figures to run from scratch.
The gate Washington actually built
The tool the United States built to stop exactly this kind of transfer is a hardware gate, not a query gate. The US Bureau of Industry and Security restricts the export of advanced computing chips to China based on two performance parameters, updated in October 2023 specifically to close a loophole in the original 2022 rules. Every version of the policy, from 2022 through the 2023 tightening, works the same way: it screens silicon leaving the country above a performance threshold. It has nothing to say about a researcher in Shanxi typing prompts into a commercial API and downloading the replies. That channel was never inside the regulation's field of view, because the thing moving across the border in a distillation run is not a chip. It is text.
The chip embargo and the distillation channel screen for two different things entirely.
| What is restricted | What the rule actually screens |
|---|---|
| Advanced computing chips exported to China | Physical hardware crossing a border, above a performance/density threshold |
| Model outputs reached through a public API | Nothing. No license, no screening, no quantity limit |
That gap is not a flaw in the execution of the export-control regime. It is a gap in what the regime was ever designed to cover. A chip is a physical object that can be tracked, licensed, and interdicted; a frontier model's output is just text, and a licensing regime built around semiconductor physics has no mechanism to touch it.
India sits on the identical channel
None of this is unique to a weapons-linked lab in China. The same unscreened channel, ordinary commercial access to a frontier model's outputs, is exactly what India's own AI buildout runs on, at both the public and private layer.
On the public side, India's government-backed IndiaAI Mission had made available around 34,000 GPUs of shared computing capacity by the end of May 2025, for use by startups, researchers and students, the most recent figure the government has given for that buildout. On the private side, the adoption curve is steep and getting steeper. A November 2025 EY survey of India's Global Capability Centres found 58% already investing in agentic AI and 83% already investing in generative AI, with GenAI pilots rising from 37% in 2024 to 43% in 2025.

Source: EY, India GCC Pulse Survey 2025. Chart: The Signal.
That is not evidence of anything improper. It is evidence that the channel Reuters documented in China, ordinary commercial access to a frontier model's outputs, is the same channel any country's AI ecosystem runs on by default, India's included. A governance regime built to screen chips has nothing to say about how any of these actors, benign or otherwise, use what a frontier model tells them.

Source: EY, India GCC Pulse Survey 2025. The percent-change figure is The Signal's calculation. Chart: The Signal.
The honest objection
The strongest case against calling this a governance gap is that distillation from API outputs is a shallow transfer next to what a smuggled chip cluster would provide. A classification model trained on synthetic data from Claude 3 Haiku, a small model, is nowhere near replicating a frontier reasoning system. Access to outputs is not access to weights, training data, or the compute to iterate at frontier scale, and the Reuters review documents dozens of narrow, task-specific systems, not a reconstructed frontier model.
That case holds for any single instance. It does not hold for the pattern. The papers reviewed for the 2024 to 2026 period were not distilling random capabilities; they specifically targeted chain-of-thought reasoning, the one capability that costs the most to build from scratch. A channel that lets an actor skip the most expensive part of frontier development, repeatedly, at API prices, across dozens of documented projects, is doing real transfer work even if no single output is a frontier model in miniature.
The Signal
This is not a story of a chip-border control failure; the chips never moved. It is a story of what a hardware-shaped policy cannot see: a capability transfer that happens entirely inside a browser tab. That software-layer response has already started on one side of the transaction: Anthropic says it does not provide commercial access to Claude in China or to Beijing-controlled firms, runs monitoring systems to detect policy violations, and has warned that a distilled model can shed the safety safeguards built into the one it was copied from; OpenAI did not respond to Reuters's request for comment on the same review. If that kind of screening becomes the industry norm rather than one lab's practice, the gap narrows. If it does not, distillation keeps working exactly as documented, for any actor with an API key, India's own GCCs and government compute programs included. A chip can be stopped at a port. A chat reply cannot.
Reporting basis: the core investigation, that Chinese military-linked researchers used OpenAI and Anthropic model outputs to train domestic defense-relevant AI, is Reuters's, carried here via The Express Tribune and via Yahoo News, both carrying the same Reuters wire report as one origin. The finding that Chinese distillation efforts specifically target chain-of-thought reasoning is a separate analysis from the Jamestown Foundation's China Brief, published alongside the Reuters investigation. The mechanics of the US chip export control regime, including the October 2023 update, are per the US Bureau of Industry and Security's own public statement. The IndiaAI Mission's GPU capacity is per All India Radio's report of the Union Minister's statement. The GCC investment and pilot-adoption figures are from EY's own November 2025 survey of India's Global Capability Centres. The $40 million GPT-4 training-cost estimate is Epoch AI's, from a 2024 arXiv paper on frontier training costs; the seven-GPU-hour reasoning-distillation figure is from a 2025 Stanford-led arXiv paper on the "s1" model. CETC-30's 2020 Entity List designation is per the US Federal Register's own notice.



