Google's TIG says Gemini has been inundated by “commercially motivated” actors who are trying to clone it, including one campaign that prompted it 100K+ times
Context & Ripple Effects
Gemini’s expanding reach has increased the value of its observable behavior: related reporting said its API traffic climbed sharply in 2025 while Gemini Enterprise reached millions of subscribers. That scale makes efforts to reproduce model responses a commercial-security concern, not merely an abuse-monitoring issue.
Google had previously characterized state-linked use of Gemini as largely productivity-oriented rather than novel AI-enabled attacks in its assessment of APT use of Gemini. The reported cloning activity adds a distinct pressure point: extracting capability or behavior through sustained customer-facing access.
First-order effects
- Google’s threat-intelligence and product-security teams must treat repeated prompting aimed at model replication as a high-volume abuse pattern alongside conventional misuse.
- Actors seeking to build commercial alternatives can test Gemini’s outputs at scale; the reported 100,000-plus-prompt campaign illustrates the volume Google says it is confronting.
Second-order effects
- Model providers are likely to put more emphasis on detecting extraction-like query patterns and balancing those controls against legitimate high-volume developer and enterprise use.
- The issue raises the competitive value of non-public assets around a model—such as deployment controls and access management—rather than weights or benchmark performance alone.
Third-order effects
- If sustained API-based replication attempts become common, frontier-model competition may increasingly include an application-layer protection race over outputs, access, and abuse detection.
- The pattern could sharpen the boundary between broadly available AI services and the capabilities providers are willing to expose at scale, though the corpus does not establish how effective cloning attempts are.
The trend: As generative-AI services scale, protecting model behavior delivered through APIs is becoming a core commercial and security challenge.