A Reuters review of more than eighty Chinese academic papers and patents found that Chinese military-affiliated researchers have used outputs from leading American models built by OpenAI and Anthropic to train domestic AI systems intended to advance China's defense capabilities. The findings were previously unreported, and they offer a rare, document-grounded look at how frontier model capability crosses a boundary that current export controls were not designed to police.
The mechanism is distillation rather than exfiltration, and that distinction carries the entire policy weight of the story. Nothing here requires obtaining weights, and nothing here requires smuggling accelerators. It requires querying a hosted model at scale, retaining the outputs, and using them as training signal for a separate system built domestically. The resulting artifact is a downstream model rather than a copy, so every control premised on possession — the chip controls, the weight-transfer restrictions, the entity listings — sits upstream of the actual transfer. Usage terms prohibit this behavior, but terms of service are a contractual instrument between a vendor and an account holder, not an export-control regime, and the enforcement surface is account-level detection of an activity that is indistinguishable at the request level from ordinary heavy API use.
The academic literature is where the evidence sits, which is itself worth noting methodologically. Papers and patents document their training procedures because that is what publication requires, so the paper trail exists precisely in the corpus that is easiest to search and hardest to suppress. That makes this class of finding reproducible rather than anecdotal, and it means the volume can be measured over time rather than inferred from a single leak.
The context around the reporting sharpens it further. A CSET translation published the same week carries a Chinese Ministry of Commerce press statement rejecting United States accusations that Chinese AI companies had distilled from American frontier models, so the two documents now sit directly against each other in the public record — one a government denial, the other a survey of the technical literature. Set that alongside the rest of this week's coverage: a Chinese open-weights checkpoint reaching parity with a Western frontier-lab flash model on an independent index, and a broad argument inside the American policy community about whether restricting open-weight releases would slow anyone down. The distillation channel is the awkward fact underneath that debate, because it does not care whether the frontier model is open or closed. It only cares whether the model can be queried.