The 60-second summary
On 8 September 2026, CISA, NSA and the FBI released a joint advisory describing what they assess as industrial-scale campaigns to extract restricted capabilities from frontier AI models. The reported activity uses native APIs, cloud platforms, third-party aggregators, proxy services and pools of accounts to distribute requests and reduce traceability. This is threat intelligence and defensive guidance—not a new law, enforcement action or compliance deadline. The recommended controls include stronger account verification, behavioural analytics, query-rate controls, AI telemetry, adversarial testing and cross-provider intelligence sharing.
Timeline that matters
Late 2024 onward
Reported activity period
The agencies state that the campaigns have operated since at least late 2024.
8 September 2026
Joint advisory published
CISA, NSA and the FBI release the TLP:CLEAR advisory, indicators and mitigations.
No statutory deadline
Advisory status
The publication recommends defensive action but does not create a new legal obligation or effective date.
What changed
The agencies have published a detailed threat model for malicious AI knowledge distillation, including MITRE ATLAS mappings, detection indicators and operational mitigations. The advisory identifies high-volume coordinated querying, fraudulent or shared accounts, metadata sanitisation, multi-path routing, prompt injection and rapid account saturation as signs that model outputs may be systematically harvested. It also recommends cautious response changes for high-confidence malicious activity. Organisations should test such measures for accuracy, proportionality and legitimate-user impact before deployment.
Who should pay attention?
AI model and API providers
Protect inference endpoints, accounts, model behaviour and proprietary capabilities against systematic extraction.
Cloud platforms and AI aggregators
Correlate activity across tenants, endpoints and routes while preserving contractual, privacy and security boundaries.
Identity, fraud and security teams
Connect account verification, payment patterns, network signals, prompt telemetry and throughput anomalies.
AI customers and procurement teams
Ask vendors how model extraction, abusive automation, telemetry retention and escalation are governed.
Privacy and legal teams
Assess lawful, proportionate telemetry and information sharing, notice, retention, access and cross-border implications.
Global relevance — AI security spans providers and supply chains
Why this matters for global organisations.
AI capabilities can be extracted through distributed accounts, infrastructure and intermediaries, making isolated monitoring incomplete. Organisations need shared ownership across identity, fraud, platform security, privacy, legal, procurement and incident response.
- Treat model extraction as an abuse and security scenario in AI risk assessments.
- Define how signals can be correlated across accounts, endpoints and vendors without excessive collection.
- Build contractual escalation routes with cloud platforms, gateways and API intermediaries.
- Separate confirmed malicious activity from legitimate research, evaluation and accessibility use cases.
- Retain evidence showing how controls were tested for effectiveness and unintended impact.
13 actions to start now
- Inventory public, partner and internal inference endpoints, including third-party gateways and resellers.
- Baseline legitimate usage by account type, API key, model, geography-independent network pattern and workload.
- Detect shared-account access, immediate maximum usage, repeated quota exhaustion and 24/7 automation patterns.
- Correlate payment instruments, registration attributes, IPs, user agents, timing and prompt similarity under approved rules.
- Apply per-key, per-account and per-network rate limits with progressive throttling and documented exceptions.
- Strengthen account verification and enterprise entitlement controls for high-throughput access.
- Log security-relevant prompts, outputs and decisions with minimisation, access controls and defined retention.
- Test prompt-injection and model-extraction scenarios through authorised AI red-team exercises.
- Create a tiered response playbook for investigation, throttling, suspension and carefully governed response alteration.
- Validate detection quality and appeal routes to reduce harm to researchers, evaluators and legitimate customers.
- Establish intelligence-sharing and escalation channels with cloud providers, aggregators and infrastructure partners.
- Add model-extraction controls and evidence requests to AI vendor-risk assessments.
- Run a tabletop exercise covering distributed abuse across multiple accounts, vendors and endpoints.
Evidence worth retaining
- Current AI endpoint and intermediary inventory with accountable owners.
- Approved threat model mapped to the advisory and relevant MITRE ATLAS techniques.
- Baseline metrics and documented detection thresholds for account and throughput anomalies.
- Rate-limit, identity-verification and entitlement configurations with change history.
- Security telemetry schema, data-protection assessment, retention schedule and access records.
- AI red-team scope, approvals, results, remediation tickets and retest evidence.
- Investigation and response playbook, including escalation and appeal decisions.
- Vendor contracts and assurance responses covering abuse detection and intelligence sharing.
- Tabletop records, lessons learned and assigned improvements.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which model behaviours, outputs and system details are commercially or operationally sensitive?
- Can we identify coordinated activity spread across accounts, API gateways and cloud endpoints?
- What legal basis and notices support security telemetry, correlation and information sharing?
- How long should prompt and output telemetry be retained, and who can access it?
- What confidence threshold is required before throttling, suspending or altering service?
- How will we protect authorised researchers, evaluators and legitimate high-volume users from false positives?
- Do contracts with aggregators and cloud providers permit timely investigation and indicator sharing?
- Which incidents trigger customer, partner, insurer, law-enforcement or regulator escalation?
- How are response-alteration techniques tested for safety, accuracy and contractual consistency?
Official sources
- CISA — Joint Cybersecurity Advisory AA26-251A, 8 September 2026
- NSA — announcement of the joint advisory, 8 September 2026
- Joint advisory PDF — TLP:CLEAR, September 2026 version 1.0
- NIST AI 100-2 E2025 — Adversarial Machine Learning taxonomy and mitigations
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.