Anthropic Says Moonshot Secretly Routed Kimi Requests to Claude
Anthropic’s September threat report alleges that Moonshot routed some customer requests through Claude while presenting the responses as Kimi output. Image: Anthropic
Cybersecurity & Privacy

Anthropic Says Moonshot Secretly Routed Kimi Requests to Claude

Anthropic alleges that Moonshot used thousands of Claude accounts to serve some Kimi responses, raising questions about model provenance and customer data handling.

By Laura Bennett • 4 mins read Edited by AIstify Team Published: Updated:

Key Notes

  • Anthropic alleges that Moonshot used Claude to answer some customer requests presented as Kimi output.
  • The company identified a network of 5,380 accounts that appeared to be located in Singapore and Japan.
  • The allegations raise questions about undisclosed data transfers but do not establish that all Kimi responses came from Claude.

Anthropic alleges that Moonshot AI secretly sent some customer requests to Claude and returned the resulting answers under its own Kimi branding. The accusation concerns the identity of the system answering users in real time, alongside a wider dispute over using rival models to develop competing products.

In its September threat report, Anthropic describes a network of 5,380 Claude accounts that appeared to be located in Singapore and Japan. It attributes the operation to Moonshot AI, the Chinese company behind Kimi.

The claims should be understood as Anthropic’s account of activity on its services. They do not establish that every Kimi response originated with Claude, or that Moonshot lacks independently developed models.

Serving Answers and Training Models Are Separate Claims

The alleged arrangement differs from the familiar practice of training a model on examples generated by another system. In live routing, the customer’s request is passed to an upstream provider, whose answer is then delivered back to the customer.

Distillation concerns how a model learns. Routing concerns which model actually performs an assignment. Both can occur within the same service, but evidence of one does not automatically prove the other.

Anthropic also alleges that some DeepSeek activity involved selective routing through Claude. The scope matters: an allegation about particular requests or service paths cannot be expanded into a claim that an entire competing model family is simply another product under a new name.

Moonshot’s previously announced Kimi K3 release remains a separate development. The existence of a released model and a dispute over how a hosted service handles some requests are compatible facts, rather than mutually exclusive explanations.

Customers Need to Know Where Prompts Go

The strongest practical implication concerns data privacy. If a service forwards a prompt to another company, the user’s interaction involves an additional recipient. A customer evaluating an AI vendor may care as much about that path as about the quality of the answer.

Consider a company that has approved one service for an internal document. If the document is sent onward, the original approval may no longer describe the actual workflow. Whether that creates a contractual or legal problem depends on the relevant agreements and circumstances; the routing allegation alone does not settle that question.

It also creates an accountability problem. When an output is wrong, the customer needs to understand which provider handled the request and which organization can investigate it. A brand name displayed above a chat window offers little help if it does not accurately describe the underlying service.

Provenance Becomes Part of Product Quality

There are legitimate reasons for an AI application to use multiple models. Different components may handle search, drafting or other parts of a task. The editorial issue raised by Anthropic’s allegation is the claimed lack of disclosure, not the mere existence of an upstream supplier.

For buyers, that makes model provenance a concrete procurement question. Product documentation can explain when requests leave the named provider, whether routing varies by task and what information accompanies the request. Such information is more useful than an unsupported assurance that a product uses only its own intelligence.

The same distinction affects comparisons between AI services. An assessment of a hosted product measures the whole service experienced by the tester. It cannot, without further evidence, reveal which underlying model deserves credit for every answer.

The Allegations Need Careful Attribution

Bloomberg reported Anthropic’s allegations on September 10. The available account leaves important questions about the full duration of the routing, the affected share of requests and what users were told.

Those limits should not obscure the central issue. Customers purchasing an AI service need a reliable account of who processes their information and produces their results. Anthropic’s allegations put that disclosure question at the center of a competitive dispute that cannot be resolved by comparing model benchmarks alone.

Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

AI & Machine Learning, Cybersecurity & Privacy, News