Cookie Consent by Free Privacy Policy Generator

US Agencies Warn of Systematic AI Model Distillation Campaigns by Chinese Companies

US federal agencies, including CISA, have issued a joint advisory warning that Chinese AI companies are conducting large-scale, systematic campaigns to extract proprietary capabilities from US-based AI models through a technique known as knowledge distillation, according to CyberScoop. The advisory alleges that these companies are using sophisticated systems to route millions of data requests to US AI models across different accounts, platforms and access points in order to replicate the functionality, behaviour and performance of those models without the underlying training data, infrastructure or research investment. The agencies describe this activity as forming the core of Chinese AI development strategy rather than a supplementary research technique, and warn that it represents a significant threat to the intellectual property and competitive advantage of Western AI companies.

Why this matters for UK organisations

For UK organisations, this highlights a broader strategic risk in how AI models and services are being used, accessed and potentially exploited at scale. Many UK businesses are integrating AI capabilities from US-based providers into their operations, and this advisory suggests that adversaries are systematically targeting those same platforms to extract and replicate their capabilities. While the focus of the advisory is on nation-state activity targeting AI companies, the techniques described, such as large-scale automated querying, account manipulation and cross-platform data harvesting, are relevant to how organisations think about API security, usage monitoring and third-party access controls more broadly. It also raises questions about the security and resilience of AI supply chains, particularly for organisations that are building proprietary AI capabilities or integrating AI into sensitive or commercially critical business processes. UK organisations using AI services should consider whether they have visibility into how those services are being accessed, whether usage patterns are being monitored for anomalies, and whether proprietary or sensitive data is being used to query third-party AI models in ways that could inadvertently expose intellectual property or competitive advantage.

What to review

UK organisations using or developing AI capabilities should review how AI model access is monitored and controlled, whether there are usage anomalies or patterns that could indicate systematic data extraction, and whether API rate limiting, access logging and account security controls are appropriately configured. Consider whether proprietary or sensitive data is being used to query third-party AI models, whether there are data classification and handling policies that account for AI-related risks, and whether there is visibility into which AI services are being used across the organisation. Organisations should also review whether AI supply chain risks are considered as part of broader third-party risk management processes, whether vendor security assessments account for AI-specific risks, and whether there is clarity on who owns responsibility for AI security, governance and risk management across the business.

Source: CyberScoop

News and blog posts
The National Cyber Security Centre has published new guidance addressing the...
Adobe has patched over 170 vulnerabilities across its product range, including...
US federal agencies, including CISA, have issued a joint advisory warning that...
Today's brief reflects two significant operational challenges for UK...