Versatile AI Risk Assessment

AI threat catalogueAttacks on the Running Model and ServiceProduction

Model Theft

Attackers create a working copy of a proprietary AI model, either by querying it at scale or by breaking into the infrastructure. They steal the intellectual property without ever touching the original.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 8 verified sources

Description

A proprietary model embodies expensive development work. Attackers reproduce it in two ways. In the first, they query the model at scale through its normal interface and use the collected input-output pairs to train their own imitation, a so-called shadow or clone model that behaves almost identically. In the second, they break into the infrastructure and copy the model files directly. Side channels such as the hardware's electromagnetic emissions can also give details away. Motives include saving usage fees, building a competing product, circumventing export controls, or preparing further attacks.

Possible impact

The organisation loses intellectual property that often forms the basis of its business: a competitor gains comparable capabilities without bearing the development costs. The copied model also serves as a springboard for further attacks, for example to prepare adversarial inputs at leisure. The EU AI Act explicitly names model theft as a threat to be defended against and requires adequate protection of model weights and infrastructure for models with systemic risk.

Example

A provider offers a specialised classification model as a paid interface. A competitor sends millions of automated queries over several weeks, stores the answers and uses them to train its own model that replicates the service at a fraction of the cost.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM10:2025NIST AI RMF Section 2.10 · NISTAML.031MITRE ATLAS AML.T0040 · AML.T0044EU AI Act Article 55(1)(d)BSI R24BIML BIML78 model:5

Verified references (8)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Attacks on the Running Model and Service.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Model Theft”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/model-theft/

← Back to the full catalogue