TRUST AND RELIABILITY

Your Competitor Does Not Need To Hack Your AI. They Can Just Ask It.

Connor T. MacIvor·AI implementation, Santa Clarita Valley·

A Chinese lab produced a model that performed remarkably close to a leading American one. They did not breach a network to do it. They asked the American model questions roughly 25,000 accounts worth of times and trained on the answers.

No intrusion. No stolen credentials. Nothing to prosecute in the way a break in would be. Just the most patient possible version of asking, at a scale no human would bother with.

There is a lesson in there for any Santa Clarita business putting an AI in front of the public, and it is not the one about international competition.

The valuable thing leaked out through the front door

Everything that made that model expensive to build, the judgment, the phrasing, the way it handles edge cases, was recoverable from the outside just by observing its behavior enough times.

That is a genuinely new category of exposure. We are all trained to think about security as keeping people out of systems. This was not that. The system worked exactly as designed. It answered questions, which is its entire function, and answering enough questions turned out to be equivalent to handing over the thing itself.

Where your business has the same shape

Ask what your public facing AI knows that you would not hand a competitor on paper.

The common local setup: a business builds a chatbot or an AI phone agent, and to make it useful they load it up with everything. Full price list including the discounts they will authorize. The objection handling script. The rules for when to hold firm and when to bend. The reasoning behind quoting one number to one kind of customer and a different number to another.

Then they point it at the open internet and let it answer anyone who asks.

A competitor does not need to do anything sophisticated with that. They need to be curious for an afternoon. Ask it enough variations of what if my situation were slightly different, and the structure underneath comes out, because explaining that structure is the job you gave it.

What separates a leak from a well designed system

Split what answers the public from what holds your advantage.

The public layer should know what you do, who you serve, how to reach a person, and enough to be genuinely useful to a real customer. That is the whole job and it is a valuable job. It should not know the floor on your pricing, the conditions under which you will discount, or the reasoning you use to decide what a given customer is worth.

Those live behind a human. Not because a human is more secure in some technical sense, but because a human notices on the fortieth strangely similar question that something is going on. Software optimized to be helpful notices nothing. It just keeps being helpful, which is what it was built for.

The monitoring that costs you nothing

Watch for query patterns that no real customer produces.

A genuine customer asks a handful of questions about their own situation and then either books or leaves. What extraction looks like is systematic coverage: the same question rotated through every variation, at volume, at hours when your customers are asleep, with no conversion at the end.

Most AI tools will show you conversation logs if you ask. Read them monthly. You are not looking for anything clever. You are looking for the conversation that reads like somebody mapping you rather than buying from you.

The principle worth keeping

The cheapest way to take something valuable is to ask for it enough times, politely, through the channel built for asking.

You cannot defend against that with a firewall, because nothing is being broken. You defend against it by deciding in advance what the answering layer is allowed to know. That decision costs an hour and it is the difference between an AI that sells for you and an AI that quietly explains your business to whoever is paying attention.

Common questions

How was the model copied without hacking?

By querying it at scale. A Chinese lab ran roughly 25,000 accounts worth of questions through a leading model and used the answers to train its own, capturing much of the capability without ever breaching a system.

Is that illegal?

It sits in a gray area and usually violates terms of service rather than computer crime law, which is exactly why it is effective. There is no break in to prosecute.

How does this apply to a small business?

If you have put your pricing logic, scripts, or process into a public facing AI, sustained questioning can pull that structure back out. Nobody has to breach anything to learn how you operate.

Does this mean I should not use AI in customer facing tools?

No. It means you should decide deliberately what the customer facing layer is allowed to know, and keep the parts that constitute your actual advantage out of it.

What is the practical safeguard?

Separate the public answering layer from your internal knowledge, rate limit and monitor unusual query patterns, and never load your full pricing logic or negotiation playbook into a tool that answers strangers.

More on this

This is part of AI For Santa Clarita Businesses: A 2026 Field Guide, the working guide to what AI is actually worth to a business in Santa Clarita.

Want this working in your business?

Connor builds the AI systems he writes about, here in Santa Clarita. Book a working session and bring your actual workflow.

Book a working session

Connor T. MacIvor · CalDRE #01238257 · Sync Brokerage, Inc. · DRE #02031490