Most Important Detection 2026 – Proprietary AI Model & IP Exfiltration for Extortion

This rule monitors for high-frequency download or access events of files associated with AI development, such as model weights (.pt, .ckpt, .safetensors, .h5, .onnx, .pkl, .pb), checkpoints, and research datasets from cloud storage. It triggers when an account accesses or downloads 20 or more unique AI-related files within a 60-minute window, which is indicative of unauthorized data exfiltration of intellectual property.