Artificial intelligence is no longer simply a technology race between competing companies. Frontier AI capabilities are increasingly being treated as strategic assets with implications for cybersecurity, national security, intellectual property, economic competitiveness, and critical infrastructure.
A new joint advisory from the U.S. National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation warns that China-based AI companies have been conducting large-scale campaigns designed to extract capabilities from U.S. frontier AI models through knowledge distillation.
According to the agencies, the activity has been occurring since at least late 2024 and involves billions of tokens across millions of interactions with leading U.S. AI models. The advisory identifies several China-based AI companies and says the campaigns have targeted capabilities such as reasoning, coding, specialized functions, and agentic behavior.
The development raises an important cybersecurity question:
How do organizations protect the capabilities inside an AI model when the model itself is exposed through APIs and cloud platforms?
What Is AI Knowledge Distillation?
Knowledge distillation is not inherently malicious.
It is a legitimate machine learning technique in which the outputs of a more capable model can be used to help train another model. It can reduce training costs and help researchers build smaller or specialized systems.
The concern described by U.S. agencies is the alleged industrial-scale and targeted use of this technique to extract proprietary capabilities from competing frontier models.
The advisory says organizations in China have used large numbers of requests and distributed infrastructure to obtain model outputs and reproduce capabilities while attempting to make detection more difficult.
This changes the security discussion around AI.
Traditional cybersecurity focuses heavily on protecting data, credentials, source code, infrastructure, and intellectual property.
AI security must increasingly protect model behavior and capabilities themselves.
Why Frontier AI Models Are Valuable Targets
Advanced AI models represent years of research, enormous computing investment, specialized datasets, engineering expertise, and extensive safety and evaluation work.
Their value is not limited to the model weights.
A frontier model may contain commercially valuable capabilities involving:
• Advanced reasoning
• Software development
• Mathematical problem solving
• Agentic workflows
• Domain-specific knowledge
• Image and multimodal processing
• Enterprise automation
• Security analysis
• Scientific research capabilities
If attackers or competitors can systematically reproduce these capabilities through large-scale model interactions, the economic value of the original research can potentially be reduced.
The U.S. agencies therefore characterize large-scale model distillation as a strategic cybersecurity and national security concern.
The API Has Become Part of the AI Attack Surface
Organizations often think about API security in terms of authentication, authorization, rate limiting, and data protection.
For AI platforms, that is no longer enough.
An AI API can become a channel through which sensitive model capabilities are repeatedly queried, analyzed, and potentially reproduced.
The joint advisory describes activity involving multiple access pathways, cloud providers, API aggregators, proxy infrastructure, and large numbers of accounts. The agencies say these approaches can make activity harder to attribute or detect when viewed from a single provider’s perspective.
This creates a new category of AI security monitoring.
Security teams should consider monitoring:
• Unusual request volumes
• Abnormal usage patterns from newly created accounts
• Large subscription-to-usage mismatches
• Repeated requests targeting specialized capabilities
• Distributed account activity
• Suspicious network and proxy patterns
• Automated querying behavior
• Unusual geographic access patterns
• Attempts to bypass usage restrictions
• High-volume extraction of model outputs
AI providers need visibility beyond individual requests.
They need to understand behavior across accounts, infrastructure, applications, and time.
AI Security Is Becoming a Supply Chain Security Problem
The issue also demonstrates why AI security cannot be isolated to the model provider.
Modern AI ecosystems involve:
• Foundation model providers
• Cloud platforms
• API gateways
• Application developers
• Model aggregators
• Enterprise customers
• Data providers
• AI agents
• Infrastructure providers
A campaign distributed across several parts of this ecosystem may be difficult for any single organization to identify.
The NSA, CISA, and FBI therefore recommend greater information sharing across the AI ecosystem so that suspicious activity can be correlated across providers and infrastructure.
This is similar to broader cybersecurity lessons from software supply chain attacks.
No single organization can always see the complete attack pattern.
What AI Companies Should Do
Organizations developing frontier or enterprise AI systems should begin treating model capability protection as part of their overall cybersecurity strategy.
1. Strengthen AI API Monitoring
AI providers should establish behavioral monitoring capable of identifying abnormal request patterns rather than relying only on traditional authentication controls.
2. Detect Automated Extraction Behavior
Security teams should identify high-volume or highly structured interactions that appear designed to systematically map model capabilities.
3. Improve Identity Controls
Organizations should implement strong identity verification, account risk scoring, multi-factor authentication, API key protection, and appropriate usage restrictions.
4. Monitor the Entire AI Ecosystem
Security monitoring should extend across APIs, cloud infrastructure, application gateways, model-serving infrastructure, and third-party integrations.
5. Protect Sensitive Model Capabilities
Organizations should identify which capabilities are commercially sensitive and develop appropriate safeguards around access, testing, and exposure.
6. Establish AI Threat Intelligence Programs
AI companies should continuously track emerging techniques involving model extraction, prompt abuse, automated querying, account farms, proxy infrastructure, and other forms of AI-targeted abuse.
7. Share Intelligence
When suspicious activity crosses organizational boundaries, information sharing can help identify distributed campaigns much earlier.
The Implications for Enterprises
This issue is not limited to companies building frontier models.
Organizations adopting AI also need to understand how their own proprietary information and AI systems could be exposed.
Financial institutions may use AI for fraud detection, customer service, financial analysis, and risk management.
Healthcare organizations increasingly use AI for clinical workflows, medical data analysis, patient support, and operational automation.
Manufacturing companies are adopting AI for predictive maintenance, industrial optimization, robotics, and supply chain management.
Retail organizations use AI for personalization, customer analytics, inventory optimization, and fraud prevention.
Government agencies are deploying AI for research, public services, intelligence analysis, and operational decision-making.
For these organizations, AI security must protect not only confidential data but also models, prompts, APIs, workflows, credentials, training data, and system behavior.
A New Dimension of Intellectual Property Protection
The reported activity also highlights an important change in how organizations should think about intellectual property.
Traditionally, intellectual property protection focused on documents, source code, patents, databases, trade secrets, and proprietary algorithms.
With AI, valuable intellectual property can also exist in the behavior of a model.
A model may encode years of research and engineering expertise into its ability to reason, generate code, analyze information, or perform specialized tasks.
Protecting that capability requires security controls specifically designed for AI systems.
Why Governance and Compliance Matter
AI security is increasingly connected to governance and regulatory requirements.
Organizations need clear policies governing:
• Who can access AI models
• Which data can be submitted to AI systems
• How AI APIs are monitored
• How model outputs are protected
• How third-party AI providers are assessed
• How AI incidents are detected and reported
• How sensitive AI assets are classified
• How model security is validated
• How access and usage are audited
AI governance should therefore work together with cybersecurity, privacy, compliance, and risk management.
Security cannot be added after an AI platform becomes widely deployed.
It needs to be designed into the AI lifecycle from the beginning.
The Bigger Cybersecurity Lesson
The warning from U.S. agencies illustrates how rapidly the threat landscape around artificial intelligence is changing.
AI systems are becoming targets not only for traditional cyberattacks, but also for attempts to extract capabilities, manipulate model behavior, abuse APIs, compromise AI infrastructure, and reproduce proprietary functionality.
Organizations developing advanced AI systems should therefore think beyond conventional application security.
The question is no longer simply:
How do we protect our AI infrastructure?
It is also:
How do we protect the capabilities, intelligence, data, and intellectual property contained within our AI ecosystem?
That distinction will become increasingly important as AI becomes a core component of enterprise operations and national strategic capabilities.
Conclusion
The latest warning from U.S. cybersecurity and intelligence agencies demonstrates that frontier AI capabilities have become valuable strategic assets.
The reported large-scale model distillation campaigns show why AI providers need stronger visibility into API usage, identity behavior, distributed infrastructure, model interactions, and emerging AI-specific threats.
For enterprises, the lesson is equally important. AI security must become part of the broader cybersecurity and compliance strategy rather than being treated as a separate technology initiative.
Organizations that combine strong identity controls, AI threat detection, model security, API protection, continuous monitoring, governance, and compliance will be better positioned to protect their AI investments and intellectual property.
As the global AI race accelerates, protecting AI capabilities may become just as important as protecting the infrastructure that runs them.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
In response to the growing risks surrounding AI models, APIs, and proprietary AI capabilities, COE Security also helps organizations strengthen:
• AI security assessments and AI application security
• AI model and API security testing
• AI threat detection and behavioral monitoring
• Secure AI architecture and cloud security reviews
• AI governance and risk management
• Data protection and AI privacy controls
• Identity and Access Management for AI platforms
• AI supply chain and third-party risk assessments
• Secure Software Development Lifecycle implementation
• Vulnerability management and penetration testing
• Compliance readiness and cybersecurity assessments
• Security monitoring and incident response planning
For financial services, COE Security helps protect AI-driven financial systems, sensitive customer information, APIs, and automated decision-making environments.
For healthcare organizations, we help strengthen protection around AI applications, patient data, healthcare workflows, and systems requiring alignment with HIPAA and other regulatory requirements.
For retail organizations, we help secure customer-facing AI applications, payment-related environments, APIs, customer data, and cloud infrastructure.
For manufacturing organizations, we help protect AI-enabled operational environments, industrial applications, cloud platforms, and connected infrastructure.
For government organizations, we help strengthen AI security, data protection, identity controls, vulnerability management, compliance, and cybersecurity resilience across critical environments.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
Stay informed about emerging AI security threats, cybersecurity developments, compliance requirements, and practical strategies to help your organization stay updated and cyber safe.
Click to read our LinkedIn feature article