Kimi Users Were Talking to Claude Without Being Told
Kimi users typing a question into Moonshot's chatbot this year were, in some share of cases, talking to Anthropic's Claude without being told. Anthropic's own threat intelligence report, published September 10, says that in one 10-day window Moonshot routed roughly 300,000 requests to Claude through 5,380 fraudulent accounts, most of them registered to addresses in Singapore and Japan to obscure where the traffic was really coming from. The Claude answers came back through Moonshot's system, were shown to Kimi users as Kimi's own output, and were then reused to train Moonshot's next model.
This followed a joint advisory from the US National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency two days earlier, on September 8, naming six China-based AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, for running what the agencies called an industrial-scale campaign to extract outputs from US models since at least late 2024. The advisory's term for the infrastructure behind it is transfer stations: a gray market of proxy services that route a query to a rival's model while scrubbing the account and location details that would otherwise flag it as bulk extraction. Anthropic said the exposed traffic touched not just Chinese users but customers in the United States and Europe, and that it saw sensitive material belonging to unnamed major companies pass through the same pipe.
The Rule That Should Have Caught This Did Not
The European Union already has a rule requiring an AI system to say it is a machine. Article 50 of the AI Act, in force since August 2, 2026, obliges a chatbot provider to disclose that a user is talking to AI. It says nothing about which AI, and a consumer companion product like Kimi sits in the Act's limited-risk tier, well short of the disclosure and audit duties written for high-risk systems. GDPR's Article 28, in force since 2018, comes closer: any party that actually processes personal data on a controller's behalf is supposed to be named as a processor or sub-processor in a written agreement. Moonshot never named Claude as anything, because on Moonshot's own account Claude was never supposed to be there.
| Source | What it found | Scale | Forces disclosure to users |
|---|---|---|---|
| CISA, NSA and FBI advisory, Sep 8 2026 | Six Chinese firms distilling US models since late 2024 | Millions of requests, billions of tokens | No, it is a warning, not a binding rule |
| Anthropic threat report, Sep 10 2026 | Moonshot's Kimi served Claude answers as its own | 300,000 requests via 5,380 fake accounts in 10 days | No, Moonshot never told its users |
| EU AI Act, Article 50 | An AI system must disclose that it is a machine | Applies to every EU-facing chatbot | Yes, but only "you are talking to AI," never which model |
| GDPR, Article 28 | Every processor and sub-processor must be named in writing | Applies to any personal data handling | Yes on paper, but only if the vendor discloses truthfully |
What an EU Buyer Actually Checks Now
This case gives a procurement team a concrete new question to put to any AI vendor, and it works whether that vendor is based in Hangzhou or down the street: which model actually processes our requests, and how would we know if that changed without notice. A written model-provenance clause, naming the exact model and version and requiring notice before any substitution, is now a reasonable ask in any AI vendor contract, not a paranoid one. So is a technical check, since several providers now return a model identifier in API response metadata that a buyer's own engineering team can log and audit independently of what the vendor's marketing page claims.
None of this is unique to Chinese vendors. A European company that markets a product as running on its own trained model, sovereign or otherwise, is making exactly the same unverifiable claim Moonshot made about Kimi, and this week two government agencies and one AI lab's own report showed that claim can simply be false. The gap Brussels has not yet closed is not about where a vendor is headquartered. It is about the fact that no current EU rule makes a vendor prove which model is actually running behind its product.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Washington Names Six AI Models You May Already Run | China Turns AI Tokens Into a Phone-Bill Perk



