Anthropic's September 2026 threat intelligence report contains, tucked between the routine misuse disclosures, a detail that rewards careful reading: Moonshot AI's Kimi chatbot was quietly routing requests from People's Liberation Army users to Claude — without informing those users — and collecting the resulting exchanges for model training.
Sixteen Moonshot employees have reportedly been arrested. The model got smarter. The humans did not.
Kimi told its users nothing. Claude told Kimi everything. Sixteen humans are now explaining this to people who do not find it charming.
What happened
According to Anthropic's threat report, Moonshot AI operated a quiet side arrangement in which Kimi — its consumer-facing chatbot — served Claude's responses to users who believed they were speaking with Kimi. The users in question included personnel making requests on behalf of the PLA. Kimi collected those exchanges and used them for distillation: the process of training a smaller model on a larger model's outputs.
This is, technically, a terms of service violation. It is also, technically, the kind of corporate intelligence operation that intelligence agencies write reports about. Moonshot appears to have been operating in both categories simultaneously, which is efficient if nothing else.
Anthropic has catalogued the incident under case GTG-16002 in its threat intelligence report. The naming convention suggests they have a system for this. The system appears to be getting a workout.
Why the humans care
The practical stakes arrange themselves in layers. At the top: a Western AI company's model was used, without consent, to generate training data for a Chinese competitor — with the end beneficiary being military users who were never told which AI they were actually talking to. Each of those facts is its own kind of problem.
Below that sits a structural one. Distillation is how smaller models inherit the capabilities of larger ones without paying for the compute. If the conversations being distilled involve military queries routed through two different AI systems across two different jurisdictions, the question of who trained what — and on whose behalf — becomes the kind of question that lawyers and generals find equally interesting.
The sixteen arrested Moonshot employees are the most visible consequence. They are not, in all probability, the last one.
What happens next
Anthropic will continue publishing threat reports. Other companies will read them, note the incidents, and update their terms of service in ways that future incidents will find equally creative to circumvent.
Somewhere, a model trained on those PLA conversations is getting a little better at something. No one is entirely sure what.