The US–China AI Race Has Entered a More Dangerous Phase

e AI Arms Race Is No Longer Just About Building the Biggest Model

Chinese military-linked researchers reportedly used outputs from US AI models to train specialised domestic systems, revealing a new phase in the technological rivalry.

China Does Not Need America’s Best AI Models—Only Their Most Valuable Capabilities

The next phase of the US–China artificial intelligence race may not be decided by who builds the world’s largest model, but by who can extract its most valuable abilities and deploy them fastest.

For years, the competition was presented as a contest of scale. The United States had the most advanced semiconductor chips, the largest data centres, the richest technology companies and the strongest frontier models. China was attempting to close the gap while Washington restricted its access to the hardware needed to train systems at the same scale.

That picture is becoming dangerously incomplete.

A Reuters investigation published on 31 July found that researchers linked to the People’s Liberation Army and other Chinese military institutions have used outputs from American models developed by OpenAI and Anthropic to train smaller domestic systems. Reuters reviewed more than 80 Chinese academic papers and patents, including military-linked projects involving surveillance, source-code analysis, drones and tactical target recognition.

The importance of those findings extends beyond another accusation of intellectual-property appropriation. They expose a structural change in the AI race.

China may not need to reproduce every capability of the most powerful American model. It may only need to identify the capability that matters, extract enough examples of how it works, and compress that behaviour into a smaller system capable of operating on a drone, military network, surveillance platform or battlefield computer.

The contest is shifting from building intelligence to harvesting it.

Frontier Models Are Becoming Teachers

The technique at the centre of the dispute is known as model distillation.

In legitimate commercial use, a highly capable “teacher” model produces answers, code, classifications or other examples. Those outputs become training material for a smaller “student” model, allowing it to perform selected tasks without inheriting the teacher’s complete architecture, model weights or general intelligence.

The resulting system is not an exact copy. It is narrower, cheaper and usually less capable. Yet it may retain precisely the behaviour its developer needs. A small model trained specifically to analyse surveillance footage or identify military equipment does not need to write poetry, interpret philosophy or answer millions of unrelated questions.

OpenAI itself has promoted distillation as a way for developers to transfer the performance of advanced models into smaller, cheaper systems for specific applications. Academic research has also shown that carefully generated synthetic data and reasoning examples can allow much smaller models to equal or surpass larger systems on limited benchmarks.

The technique is therefore neither uniquely Chinese nor inherently improper.

The geopolitical argument begins when one company, state or military organisation systematically obtains outputs from a proprietary foreign model to reproduce valuable capabilities without permission.

Anthropic said in February that it had identified what it described as industrial-scale extraction campaigns involving DeepSeek, Moonshot and MiniMax. According to Anthropic, the three Chinese laboratories generated more than 16 million exchanges through approximately 24,000 fraudulent accounts, breaching regional restrictions and the company’s terms of service. Anthropic argued that such campaigns could obtain expensive capabilities at a fraction of the cost and development time required to create them independently.

Those are Anthropic’s claims, not independently adjudicated findings. The named Chinese companies have disputed accusations that their progress depends on copying American systems, while Beijing has accused Washington of using AI restrictions to preserve technological “hegemonism”.

Yet the military research reviewed by Reuters shows why Washington is alarmed.

Intelligence Can Be Broken Into Components

One Chinese military paper reportedly described researchers from PLA Unit 96941, associated with military intelligence and cyber operations, using GPT-3.5 to summarise sensitive software source code. Because an external American model could not safely process classified material inside a Chinese military environment, the researchers used its summaries to train a domestic system capable of operating locally.

That example reveals the emerging pattern.

The American model does not have to enter the secure network. Its outputs can be collected outside it, converted into training material and used to improve a system that runs entirely within Chinese infrastructure.

At the North University of China, researchers reportedly used Anthropic’s Claude 3 Haiku to create synthetic data for a text-classification system designed for social-media monitoring and content moderation. Separately, researchers at China’s National University of Defense Technology described shrinking an image-processing model so it could run on unmanned aerial vehicles and analyse live footage even when communications were unavailable.

Another study from China’s Academy of Military Sciences involved a target-recognition system operating on tactical hardware during simulated maritime operations involving drones, ships and unmanned submarines.

These projects do not prove that China has replicated the full intelligence of the best American systems. They demonstrate something potentially more practical: sophisticated AI can be separated into useful components.

Coding ability can be extracted from general reasoning. Image recognition can be separated from language. Tactical classification can be separated from consumer conversation. A capability developed through an enormously expensive frontier-training programme can become a specialised training resource for a far smaller model.

In military terms, the decisive system may not be the cleverest AI in existence. It may be the system that performs one task reliably, quickly and locally when communications are disrupted and computing power is limited.

The Chip Blockade Has Created a Different Incentive

American export controls remain a serious obstacle to China’s ability to train the largest models.

Frontier AI development requires enormous quantities of advanced processors, high-speed networking, electricity, specialist engineers and capital. Research into training costs has estimated that expenditure on the most compute-intensive models has increased rapidly, with the largest individual training runs potentially exceeding one billion dollars by 2027 if previous trends continue.

Distillation does not eliminate that frontier advantage.

A smaller model cannot automatically acquire every capability, hidden parameter or general reasoning ability of its teacher. Reuters’ reporting notes that distilled systems inherit selected behaviours and remain less capable than the models from which their training examples were derived.

But export controls may be changing what Chinese laboratories optimise for.

When access to the best chips is constrained, efficiency becomes strategic. Developers have a stronger reason to compress models, improve training data, specialise systems and design software for less powerful hardware. China’s government has promoted “model lightweighting” and edge computing, including systems intended to operate on drones, satellites and other devices with limited processing capacity.

This complements China’s attempt to embed AI throughout its economy, rather than treating artificial intelligence as a competition confined to a handful of headline-grabbing laboratories.

A March 2026 working paper from the US–China Economic and Security Review Commission argued that China’s open-model ecosystem is allowing it to innovate close to the frontier despite compute constraints. It identified a reinforcing cycle in which inexpensive, adaptable models spread through manufacturing, robotics and research, producing specialised real-world data that can then improve future systems.

The United States may continue to possess the strongest general-purpose intelligence while China becomes increasingly skilled at adapting, distributing and deploying narrower intelligence.

Those are different forms of power.

The Battlefield Rewards Deployment

The United States is not standing still.

American frontier-model companies are becoming increasingly connected to national-security infrastructure, while the Pentagon is moving advanced AI into military and classified environments. The US advantage lies not only in model quality, but in its combination of private-sector laboratories, advanced chips, cloud infrastructure, defence spending and world-leading research institutions.

China’s advantage is different. It possesses a vast industrial base, extensive state coordination, large-scale manufacturing capacity and a political system capable of directing technology towards strategic priorities.

Brookings describes the rivalry as a multidimensional contest covering compute, models, adoption, integration and deployment. Its assessment is that America retains a clear lead at the technological frontier, while China is advancing through efficiency, open-model diffusion and deeper integration with the real economy.

That distinction becomes especially important in defence.

A frontier model in a giant data centre may perform extraordinarily well under controlled conditions. A smaller system installed on a drone, ship, robot or secure tactical network may be less intelligent overall, but more valuable in the exact location where a decision must be made.

Latency matters. Connectivity matters. Power consumption matters. Hardware availability matters. The ability to operate without sending sensitive information to a foreign cloud matters.

The military AI race will therefore reward nations that can turn abstract model capability into dependable systems positioned at the edge of operations.

This reinforces the deeper struggle already visible in the AI confrontation surrounding US–China relations. Semiconductors remain crucial, but so do data, energy, model access, robotics, industrial integration, cybersecurity and the ability to translate research into deployment.

America Cannot Simply Hide Every Output

The obvious American response would be to tighten access to frontier models.

Companies can strengthen identity checks, detect coordinated accounts, monitor unusual query patterns, limit high-volume extraction and restrict access from prohibited jurisdictions. Governments may also attempt to bring advanced model capabilities within export-control regimes.

None of those measures offers a complete solution.

AI products become valuable by being used. A model that reveals almost nothing about its abilities is commercially useless. Each legitimate answer, code sample or reasoning demonstration may also provide information that helps another developer train a smaller system.

Defenders must distinguish millions of ordinary customers from organised extraction campaigns without making their services inaccessible. Attackers can distribute requests across accounts, intermediaries and countries, then combine the outputs later.

Restrictions can raise the price of capability extraction, but eliminating it may require closing the systems so tightly that American companies sacrifice revenue, global influence and developer adoption.

There is another complication. China is not merely copying.

Chinese laboratories have produced increasingly competitive, inexpensive and widely used models. Chinese open systems are gaining international adoption, while their developers continue to make independent advances in efficiency, architecture and deployment. An American strategy based on the assumption that China can only imitate would be strategically complacent.

Distillation can accelerate progress, but it cannot substitute indefinitely for original research, frontier compute, engineering talent or domestic technological capacity.

The Race Is Becoming Harder to Measure

Benchmark leadership remains important, but it is no longer a sufficient scoreboard.

The most powerful general model may not be the system that creates the greatest economic output or military advantage. The winner could instead be the country that converts intelligence into thousands of specialised tools operating across factories, laboratories, logistics systems, intelligence networks and autonomous machines.

That would favour a different set of metrics:

  • How cheaply can a capability be transferred?

  • How reliably can it operate on limited hardware?

  • How quickly can it be integrated into existing systems?

  • How much proprietary or operational data can improve it?

  • Can it function securely without a permanent cloud connection?

  • How widely can it be deployed?

The Reuters findings do not show that China has defeated the United States at frontier AI. They show that frontier leadership may be more difficult to protect than leadership in previous strategic technologies.

A semiconductor can be intercepted at a border. A manufacturing machine can be placed on an export-control list. Model intelligence is harder to contain because part of its value becomes visible whenever the system responds.

America is still building many of the world’s most capable AI models. China is learning how to take selected pieces of that intelligence, compress them, adapt them and place them where they may have strategic effect.

The next stage of the AI race will not be fought only over who creates the smartest machine.

It will be fought over who can extract intelligence, control it and turn it into power.

Previous
Previous

Amazon’s $3tn Breakthrough Shows Wall Street Is Buying AI Again

Next
Next

EU Confronts OpenAI And Anthropic After AI Agents Breach Real Company Systems