Blog Post

Cyber Loss When the Stolen Asset Is a Trained Model

October 1, 2026

Table of Contents

A trained model is expensive to produce, cheap to copy and impossible to recall. Where one is taken, the organization still holds it, and the loss is not that the asset is gone.

‍

What ends is exclusivity. Lost exclusivity is a different quantity from a destroyed asset, it carries no notification obligation, it appears in no breach cost dataset, and most estimates therefore put it at zero by omission rather than by judgment.

‍

Is a Model Legally Protected?

‍

Less firmly than most organizations assume, and the weakness is structural rather than jurisdictional.

‍

Analysis of the position finds uncertain protection across all three routes. Patents cover inventions and processes rather than parameter values. Copyright covers creative expression, and weights are mathematical outputs. Trade secret protection requires reasonable measures to maintain secrecy, and a model offered through a public interface may not satisfy that condition.

‍

Which Creates an Uncomfortable Tension

‍

The commercial act of exposing a model through an interface is in tension with the legal condition that protects it. An organization monetizing access is arguably weakening the secrecy claim it would rely on after an extraction, and that is a product decision with a legal consequence attached.

‍

Does Theft Require Access to the Weights?

‍

No, and this is why perimeter thinking fails here.

‍

Exceedance curve showing the likelihood of annual loss exceeding successive percentages of revenue with the average marked on the curve
Expressing exposure against revenue is the workable frame where the loss is erosion of a position rather than destruction of an asset.

Query-based extraction builds a substitute model from ordinary interface access, with no access to training data and no knowledge of the architecture required, using only inputs and the responses returned. The resulting model mirrors the target's behavior closely enough to be commercially useful, so protecting the weights file addresses one route and leaves the cheaper one open.

‍

Which Makes Detection the Binding Problem

‍

Extraction through an interface resembles heavy legitimate use. Volume, breadth of coverage and systematic exploration of the input space are the signals, and many organizations have no visibility into whether their models are being probed at all, so dwell time has no natural limit and the loss may be discovered when a competitor ships.

‍

How Do You Value It?

‍

Not by replacement cost, and litigation practice supplies the methods that work where the obvious ones fail.

‍

Retraining cost prices reproduction rather than exclusivity, so it understates. Market value does not exist for a unique model with no comparable transaction. Trade secret damages practice offers three established damages approaches instead, being the claimant's own loss, the defendant's gain, and a reasonable royalty representing what a license would have cost.

‍

Which One Is Most Usable?

‍

The royalty, because it is designed for exactly this situation. It exists as a defensible basis where other methods are impractical or the evidence is thin, which describes a model extraction precisely, and it produces a figure without requiring proof of lost sales.

‍

What Does the Defendant's Gain Add?

‍

An unusually computable term, and one the victim can evidence better than the perpetrator can dispute.

‍

Breakdown of extreme annual loss by damage type showing which categories contribute most at the one-in-hundred level
A damage type breakdown is what keeps a category with no notification cost and no remediation cost from disappearing out of a figure.

Avoided research and development is the training spend, which the organization knows to the currency unit from its own accounts. Acceleration to market and margin capture follow from that. So the defendant's gain has a floor the claimant can document precisely, which is rare in any loss category.

‍

The Claimant's Loss Is Largest and Hardest

‍

Foregone sales and price erosion are the biggest terms and require establishing causation between the extraction and the commercial outcome. Proving them needs rigorous modeling, and the strength of the causal link determines the recovery, so a figure asserted without that work is not a figure anybody will pay.

‍

Is There Any Notification Duty?

‍

None, in the usual case, and the absence changes the response rather than reducing the loss.

‍

Model weights are not personal data, so statutory notification does not engage. There is no regulator to inform, no individuals affected and no deadline. An organization whose entire incident process is built around notification has nothing to run, which a loss category a model can miss entirely covers.

‍

What Replaces It?

‍

A commercial and legal assessment. Whether the interface terms prohibited extraction, whether the access pattern is evidenceable, and whether the party responsible is identifiable and worth pursuing. Those determine whether the loss is recoverable, and none of them is a security question.

‍

What Is the Reliable Protection?

‍

Contract, which is the practical conclusion the legal analysis arrives at.

‍

Interface terms that expressly prohibit extraction, restrict use of outputs for training a competing model and specify remedies create obligations that are enforceable where the intellectual property routes are uncertain. Organizations have pursued action on that basis, and it is currently the strongest available position.

‍

Which Makes the Terms a Control

‍

A prohibition nobody wrote cannot be enforced afterward, and the clause costs nothing to include at the point an interface is launched. So the control is drafted rather than deployed, and it belongs in the same category as a weakness that accrues while it stays open for as long as the terms are silent.

‍

Does the Extraction Reveal the Training Data?

‍

Sometimes, and where it does the loss category changes entirely.

‍

A substitute model built from interface responses inherits what the original learned, which can include information about the data it was trained on. Where that training data included personal information or another organization's confidential material, an extraction is no longer only a competitive loss, since the inherited information may carry the obligations that attached to its source.

‍

Which Reintroduces the Duty That Was Absent

‍

An extraction with no notification consequence and an extraction that transmits training data are different events with different response requirements, and the difference is a property of what the model was trained on rather than of how it was taken. So the determination depends on a training data record, and what a component inventory does not establish covers why that record is frequently absent.

‍

What Should Be Recorded Per Model?

‍

Whether the training set contained personal data or third-party confidential material, and under what terms. Two fields, captured when the model is trained, which decide whether a later extraction is a commercial event or a regulatory one. Neither can be reconstructed once the training run is historic, and an AI governance record is where they belong.

‍

What Should Be Established?

‍

Four things, and two of them are already in your own records.

‍

The training spend per model, since it is the floor of the defendant's gain. What a license to the model would reasonably cost, since that is the most usable damages basis. Whether the interface terms prohibit extraction and competitive training, because that determines enforceability. Then whether query patterns are monitored for systematic exploration, since without it the loss is discovered externally. Cyber risk quantification built on those inputs produces a figure for a category most models score at zero.

‍

The Asset Stays, the Exclusivity Goes

‍

A stolen model leaves the organization still holding it, so the loss is the end of exclusivity rather than the destruction of an asset, and that is why it appears in no breach dataset and defaults to zero. Legal protection is uncertain across patents, copyright and trade secrets, and offering a model through a public interface may itself weaken the secrecy condition trade secret protection depends on. Extraction needs no access to the weights, since a substitute can be built from ordinary interface access, which makes detection rather than perimeter control the binding problem. Replacement cost prices reproduction rather than exclusivity, and litigation practice offers a reasonable royalty as the basis designed for exactly this evidential position. Kovrr's cyber risk quantification prices the category rather than omitting it.

‍

To see exposure modeled for a loss category with no notification cost and no remediation cost, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Model Theft Valuation FAQs

Speak to an Expert

Are trained model weights protected by copyright or patent?

Does trade secret law protect a model exposed through an API?

Can a model be stolen through an API?

How do you value a stolen AI model?

Does model theft trigger a notification obligation?

What is the most reliable protection against model extraction?