Kimi Users Unknowingly Powered Claude, Anthropic Says
Anthropic's September 2026 threat report says Moonshot AI's Kimi routed roughly 300,000 Claude requests in 10 days, using Claude's answers to train its own model. The move raises data-security and geopolitical questions about the AI arms race.
The Pipeline Nobody Asked For
Anthropic’s September 2026 threat report landed with a detail English-language coverage has largely missed: Moonshot AI, the Beijing-based company behind the Chinese chatbot Kimi, appears to have been quietly routing a substantial share of its users’ queries to Claude. The Claude responses then returned to Kimi’s interface, so the user experienced no visible glitch. Behind the scenes, those conversations also appear to have been saved and used as training data.
The number is striking. Anthropic says Kimi sent roughly 300,000 requests over just ten days, with the majority handled by Claude Opus — Anthropic’s most capable and expensive tier. That volume, sustained at that model level, points to intent rather than an accidental routing error.
Anthropic did not name Moonshot directly in every passage of the public document, but it confirmed that the forwarded exchanges reached Anthropic’s infrastructure and was used in model training. Whether Kimi told its customers about the forwarding remains unclear.
How the Harvest Worked
This is distillation — training one model on another’s outputs — taken past an academic experiment into a production pipeline. Distillation itself is standard practice when done openly; it is a legitimate way to compress capability into a smaller model. The problem emerges when a company pulls proprietary outputs at scale without permission and repurposes them to narrow its own performance gap.
Anthropic flagged seven Chinese AI research organizations across the report for unauthorized distillation activity. This is not the first time the company has confronted systematic effort to copy capabilities through user traffic. But the Kimi case is unusual because it blends three concerns at once: data exfiltration, training-data theft, and credential exposure.
DeepSeek — another Chinese AI lab that has made headlines before — received separate treatment in the same report. Anthropic wrote that DeepSeek selectively routed certain requests through external coding tools and then forwarded them to Claude Opus. Some of the forwarded content included internal corporate documents and authentication credentials needed to access live databases. That is a sharper security breach than merely harvesting conversational text.
Xiaomi’s MiMo chatbot also appeared in the report. Conversations with MiMo users were sent to Claude, Anthropic said, but the company drew a distinction: there is no evidence yet that Claude’s responses were returned to MiMo users, suggesting a narrower use focused on training data rather than a direct front-end substitution.
What Gets Exposed When Users Think They’re Safe
The most consequential finding is not the model training. It is the data that walks through the pipe alongside the prompts.
When Kimi users paste proprietary strategy memos, customer lists, or internal code into what they believe is a trusted Chinese chatbot, they are also exposing that material to Anthropic’s servers — and, potentially, to Moonshot’s archives. When DeepSeek users run coding tasks through the same kind of relay, internal documentation and database credentials can travel with them. No enterprise security team in San Francisco or Shenzhen would call that acceptable.
The risk is structural. If Kimi’s interface hides the routing from users, there is no practical way for any customer to know which provider is actually receiving sensitive inputs. Consent disappears behind a branded UI. That pattern is worse for business trust than any single pricing dispute between AI vendors.
Why Now, and Why This Route
The timing sits inside a broader competition shaped by export controls. US restrictions on high-end chip sales have made it harder for Chinese labs to acquire cutting-edge inference hardware. Moonshot and peers have responded by focusing on software-layer advantages — scaling laws, data quality, and distillation pipelines — to close gaps left by hardware constraints.
Claude Opus is one of the strongest general-purpose models available. For a lab racing to improve its own product, harvesting its outputs is a shortcut. The math is straightforward: if Moonshot can generate millions of high-quality conversational pairs by routing user traffic through Claude, it saves time and compute compared with generating equivalent training data from scratch. The cost is a security liability Anthropic has now called out publicly.
Who Wins, Who Loses
The immediate winner is whatever capability Moonshot extracts from the pipeline. Chinese AI labs have been expanding fast, and each distillation cycle narrows the gap with Frontier models. If Kimi’s user base grows in the process, the commercial upside is substantial.
The losers are harder to count but real. Enterprise users in China and beyond may reconsider which chatbots they trust with internal information. Competitors relying on open distillation norms could face tighter enforcement from US model providers. And Anthropic, for its part, gains a reputational boost from being the whistleblower — a position that costs little and frames future policy discussions around ownership of model outputs.
What Anthropic Is Doing Next
According to the report, Anthropic has strengthened detection mechanisms for suspicious request patterns and improved tools for identifying improper output extraction. The company blocks suspicious traffic, suspends associated accounts, and has reportedly hardened infrastructure to catch these relays earlier.
But detection only goes so far. Once a rival has already ingested a corpus of Claude responses, the training advantage persists even after the pipe is closed. That is why the structural issue matters: distillation at scale is a one-way wealth transfer unless providers build consent guarantees into the protocol itself.
What Comes Next
Anthropic’s report does not include responses from Moonshot, DeepSeek, or Xiaomi. Their positions — whether they denied the claims, acknowledged the routing, or disputed the training-use assertion — remain absent. That gap matters for any final judgment about culpability versus misconfiguration.
Regulators in both China and the US are likely to take notice. China has tightened rules on generative AI training data in recent years. A case involving foreign proprietary model outputs could complicate compliance landscapes for labs already operating under scrutiny. In the US, the incident reinforces arguments for stronger output-watermarking and provider-to-provider licensing frameworks.
For enterprise users, the practical takeaway is simple: assume that no LLM interface is a closed system. Sensitive inputs should be treated as potentially transit data, regardless of which chatbot is rendering the final answer. Until providers publish auditable traffic logs, that cautious posture is the only rational default.