The Loophole in America's AI Chip Ban: How China's Military Is Using a Legal Workaround
Chinese military institutions are circumventing US chip export controls by using a standard industry technique called AI distillation, which requires no advanced hardware at all. A Reuters review of more than 80 Chinese academic papers and patents found military and security-linked researchers training their own defense AI systems on outputs from OpenAI and Anthropic models, sidestepping the hardware embargo that Washington spent years building.
What Is AI Distillation and Why Does It Matter?
AI distillation is how the AI industry normally works. It involves taking the outputs of a powerful, expensive model (the "teacher") and using those outputs to train a smaller, specialized model (the "student") that runs locally without massive computing resources. Every serious AI lab does this, including American frontier labs distilling their own models.
The problem is that distillation needs zero controlled chips. This is precisely the pressure point Washington's export regime was designed to squeeze. By querying models that are already trained and letting those models teach Chinese systems, military researchers can build capable AI without ever touching an NVIDIA chip, an ASML machine, or any sanctioned hardware.
The distinction matters legally and strategically. Distillation as a technique is not exotic or illegal. But distillation as an attack, where a firm obtains access to a competitor's product through deception to copy it, crosses into fraud territory.
How Extensive Is the Military Application?
Research compiled by the Jamestown Foundation and shared with Reuters points to work by institutions linked to the People's Liberation Army. The findings surfaced days before US and Chinese officials were scheduled to sit down on AI governance.
The scale of extraction has been substantial. By February 2026, Anthropic traced more than 3.4 million exchanges with its models to Moonshot AI, a Chinese lab. These exchanges were routed through hundreds of fake accounts using an internal platform purpose-built to evade detection. Later in June, Anthropic told the Senate Banking Committee that Alibaba's Qwen lab had conducted the "largest known distillation attack" against it to date.
Anthropic
Why Current Export Controls Don't Address This Loophole
The EU AI Act's Article 55 already asks model-makers to guard against theft, but says almost nothing about extraction by simple querying. The law was written for a threat that looks nothing like a polite API call, leaving a regulatory gap that no BIS (Bureau of Industry and Security) rule currently plugs.
Under US law, model outputs alone are not copyrightable because they require human authorship. Trade secret law is the better legal fit. But skeptics note that model outputs served through commercial interfaces cannot remain "secret" in the traditional sense. However, proprietary access to frontier models is authenticated, paid, rate-limited, and restricted under terms of service. The trade secret at issue is not a single response to a query, but the underlying model behavior collectively encoded across millions of conversations, which can only be extracted systematically at scale.
How to Distinguish Between Legitimate Distillation and Fraud
- Legitimate Distillation: A company uses a model's outputs through normal, authorized channels to train its own smaller model for internal or commercial use, following the model provider's terms of service.
- Distillation Attack: A firm obtains access to a competitor's product through deception, using fabricated identities, purpose-built evasion infrastructure, and systematic circumvention of security controls to extract trade secrets at scale.
- Industrial-Scale Fraud: Coordinated, systematic extraction designed to steal American trade secrets, which falls under the Computer Fraud and Abuse Act and wire fraud statutes rather than simple terms-of-service violations.
The Trump administration has signaled it will support open-source software while seeking to punish covert, industrial-scale extraction of American trade secrets. This principle is the right line to draw, and Washington already has the necessary legal machinery to enforce it.
What Does This Mean for the Future of AI Export Controls?
If the workaround is this ordinary, the whole logic of hardware export controls has a hole in it. Distillation does not explain as much of recent Chinese model performance as many in Washington would like to believe. While distillation helps Chinese labs bootstrap reasoning behavior, these labs are still conducting serious engineering research of their own. DeepSeek R1's efficiency breakthrough in January 2025 came primarily from a change in reinforcement learning rather than from copying American competitors. Moonshot's focus on agent swarming earlier in 2026 was likewise a homegrown capability.
The more persuasive argument for taking punitive action against Chinese AI labs rests on national security grounds. By converting billions in American research and development expenditure on compute and machine reasoning research and then releasing the results for free, Chinese labs are undercutting American firms in price-sensitive markets worldwide. This economic displacement compounds other national security risks from these models, including supply chains vulnerable to poisoned weights that cannot be reliably surfaced in security audits, intelligence collection through user traffic routed to servers subject to China's National Intelligence Law, and capability uplift for malicious actors.
Europe should not feel smug about this gap either. Mistral sits in the same model tier as OpenAI and Anthropic, much of its output is open, and the EU AI Act's model-theft provisions were written for a threat that looks nothing like a polite API call.