Washington spent years locking down semiconductor supply chains to starve Beijing of cutting-edge hardware. It turns out that building military-grade artificial intelligence doesn't always require direct access to high-end chips. You can just borrow the reasoning capabilities of American models instead.
Recent analysis of academic papers and patents reveals a glaring loophole in tech restrictions. Researchers linked to China's military and security apparatus are routinely tapping outputs from leading American artificial intelligence models—including systems built by OpenAI and Anthropic—to train domestic defense technologies. In similar news, take a look at: What Happens When The Us Government Tells Satellite Companies To Go Dark.
If you think export bans on advanced processors solved the national security puzzle, you're missing how software actually moves across borders.
The Mechanics of Model Distillation
The core method driving this cross-border knowledge transfer is called model distillation. Building a frontier artificial intelligence model from scratch demands billions of dollars and massive clusters of specialized hardware. Most nations can't easily replicate that compute scale under strict trade sanctions. Wired has provided coverage on this important topic in extensive detail.
Distillation bypasses that roadblock entirely.
Here is how it works in practice. Researchers query a powerful Western model, capture its high-quality outputs, and feed that data into a much smaller, localized model. The smaller system learns the underlying logic without needing the original computing infrastructure.
Sunny Cheung, a researcher at the Jamestown Foundation who analyzed dozens of these academic papers, points out that teaching a system the final answer is simple, but teaching it the logic behind it is hard. By using US models as teachers, Chinese military scientists manage to transfer expensive, proprietary reasoning into compact systems that run locally.
Where the Tech Shows Up in Defense
This isn't theoretical laboratory work. Real-world applications documented in recent literature span multiple branches of tactical operations.
Researchers at the National University of Defense Technology used distillation to shrink image-processing models. They packed these compressed systems onto unmanned aerial vehicles, allowing drones to analyze live video feeds and execute targeting calculations locally even when communication links go dark.
Meanwhile, teams at the Academy of Military Sciences applied similar techniques during simulated maritime exercises involving coordinated swarms of drones, surface ships, and autonomous submarines. Other units used early outputs to handle sensitive source code parsing by creating summaries that bypass the need to plug classified networks directly into third-party servers.
Security policy analysts like William Hannas have long argued that keeping determined adversaries out of open digital cookie jars is nearly impossible. When foundational models and research are widely shared or accessible via APIs, clever engineering finds a way around perimeter defenses.
The Policy Dead End
The Biden and Trump administrations enacted sweeping restrictions to protect American technological dominance. Those rules targeted physical hardware like advanced graphics processing units. They assumed that without physical silicon, advanced development would stall.
They miscalculated how software behaves.
Model distillation turns proprietary intelligence into a fluid asset. You can't put a traditional trade embargo on a sequence of token outputs designed to train a smaller network. OpenAI and Anthropic explicitly forbid military applications in their terms of service, yet enforcement at the API boundary remains porous.
Tech policy experts now face an uncomfortable reality. Choke points built around hardware supply chains lose their effectiveness when the primary asset being extracted is pure logic.
Expect tougher scrutiny on API access, stricter usage monitoring, and a bitter debate over whether open-weight models pose an inherent national security hazard. Until regulators figure out how to police data distillation, software will continue to outrun hardware policy.