I wouldn't expect most companies to use "proper" models at this point; some will, but for most (especially when used for mass-surveillance) I'd expect low computational cost models.
This will change over time, but just for the moment we do have an AI bubble exceeding the supply of people who can make good AI.
Even then such attacks only work under very controlled conditions and do not generalize across models. You might be able to fool one vendor/generation, but not all the others.