# Model Extraction Becomes a Policed Harm Category

Frontier labs increasingly instrument their APIs to detect and publicly attribute large-scale distillation by rival labs, so expect recurring threat reports naming corporate extractors, account-level enforcement against them, and pressure to treat paid API access as a controlled export rather than an open commercial product.

- Conviction: 44 / 100 (weakening)
- Horizon: Emerging (watchlist)
- Tracking since: 2026-09-11T00:00:00.000Z
- Last updated: 2026-09-14T14:04:09.672Z
- Canonical: https://polylog.news/ai/trends/frontier-model-extraction-forensics
- Publisher: Polylog
- Affected regions: United States

## Recent score history

- 2026-09-13: 46
- 2026-09-14: 44

## Recent evidence

- [confirms] Anthropic Says DeepSeek and Moonshot Routed Customer Prompts to Claude Through Fake Accounts (2026-09-12): Anthropic publicly attributed 5,380 fraudulent Moonshot-linked accounts relaying roughly 300,000 requests in ten days, plus more than 12 million distillation attempts it assigns to DeepSeek over 14 days in July. This is the first named, quantified corporate attribution of large-scale extraction by rival labs, moving the practice from suspicion into an enforcement and policy category and strengthening the case for treating paid API access as controlled rather than openly commercial.
- [confirms] Anthropic Ties 151 Million Claude Exchanges to an Alleged Alibaba Distillation Campaign (2026-09-11): Anthropic's September threat report quantifies an alleged Alibaba distillation campaign at 151 million Claude exchanges and elevates model extraction to a named harm category alongside cyber operations and weapons research, with DeepSeek, Moonshot AI and MiniMax cited in smaller efforts.
