Kimi K3, the Distillation Allegation, and the Contract Question a Buyer Can Actually Resolve

Last updated: July 24, 2026

Tier C

Document-first briefing. No hands-on testing. Future Stack Reviews did not test Kimi K3, call the Kimi API, inspect model weights, or reproduce any provenance claim. Every factual statement below comes from a document FSR opened and read on 24 July 2026, or from named reporting attributed to its publisher.

Last evidence check: 24 July 2026 (JST). Mandatory recheck: 27 July 2026 release package, terms version changes, restricted-party status.

Kimi K3 is Moonshot AI’s 2.8 trillion parameter mixture-of-experts model, with a stated context window of 1,048,576 tokens and a hosted API priced at $3.00 per million standard input tokens. Full weights are promised by 27 July 2026. US officials have alleged the model was built by distilling Anthropic’s Claude Fable 5. This briefing covers what a buyer can verify from documents.

Verdict: do not treat Kimi’s public no-training statement as a contractual fact until Moonshot confirms in writing which agreement governs the account.

Best for

  • Teams evaluating K3 behind a model abstraction layer with a tested fallback
  • Procurement staff who need to know which Kimi agreement binds their account
  • Buyers deciding whether to wait for the 27 July release package
  • Anyone who has to justify a K3 decision to a security or legal reviewer

Not for

  • Readers wanting a finding on whether Moonshot did what it is accused of
  • Buyers who need processor terms, transfer documentation, fixed retention or audit evidence before deployment
  • Anyone needing legal analysis of export controls, sanctions or IP
  • Teams that need measured latency, quality or effective cost per task

Key facts

ItemRecordStatusRecheck trigger
DeveloperMoonshot AI, described in reporting as Beijing-basedReportedCorporate filings
Contracting entity in the termsMoonshot AI PTE. LTD., SingaporeIn the documentsTerms revision
Stated size and context2.8T parameters, 16 of 896 experts active, 1,048,576 token contextMoonshot statesTechnical report
API price$0.30 cache-hit in / $3.00 cache-miss in / $15.00 out, per 1M tokens. Excludes tax, calculated at checkout by jurisdictionPublished rate, 24 Jul 2026Before purchase
API access modelTop-up from $1; rate tier set by cumulative rechargeIn the documentsPricing page change
WeightsPromised by 27 Jul 2026. No K3 repository on the official Hugging Face or GitHub organisations when FSR checkedPoint-in-time observation27 Jul 2026
LicenceNot publishedNot located27 Jul 2026
Deployment guidanceSupernode of 64+ accelerators recommended; MXFP4 weights, MXFP8 activationsVendor recommendation, not a stated minimumTechnical report
Governing lawSingapore, SIAC arbitration, one-year limitation periodIn the documentsTerms revision
Public DPA, SCCs, subprocessor listNot located publicly. A data processing addendum is referenced in the Business SupplementNot locatedVendor response
Restricted-party statusNot screened for this briefingOut of scopeDay of transaction
FSR hands-on evidenceNoneTier Cn/a

“Moonshot states” marks a vendor claim FSR has not independently verified. “Not located” describes a search boundary, not proof of non-existence.

Identify the product before you trust the promise

Kimi reaches buyers through several routes, and they do not share one contract. Moonshot’s own business page lists Kimi Business and Kimi API under the heading “Two ways to use Kimi at work,” and describes the API as usage-based access rather than a subscription.

Most coverage of Kimi’s data-use position quotes one page and stops there. The page usually quoted is the API Help Center, which answers the training question with a flat no. That page is support content. It is not the instrument accepted at signup, and it carries no visible revision date.

Product surface map

SurfaceHow it is boughtDocuments visible on that pathUnresolved
Kimi consumerFree or personal planKimi Terms of Service (21 Jan 2026), Privacy PolicyScope and handling of the email opt-out
Kimi Business$599 per seat per year, workspace, admin-managedBusiness page; Business Supplement (1 Jun 2026); page footer links the consumer TermsOrder form, referenced data processing addendum, exact service scope
Self-serve OpenPlatform APITop-up from $1, usage-basedAPI Help Center; OpenPlatform Terms (27 May 2026); OpenPlatform Privacy Policy (30 Apr 2025)Whether the Business Supplement applies at all
Negotiated enterprise APISales contactOrder form, supplement, data processing addendumEverything, until the paper exists
Self-hosted K3Weight download after releaseLicence, model card, technical reportAll of it, pending 27 July

Document dates are as displayed on each page when FSR opened it on 24 July 2026.

The buyer question this produces is narrow. Which row describes the account you are about to open, and does that row carry a no-training commitment you could enforce.

Sources: Kimi Business, accessed 24 July 2026 · Kimi recharge and rate limiting, accessed 24 July 2026 · Kimi Help Center, accessed 24 July 2026

What the four API documents say

Four published documents bear on data use for the OpenPlatform API. They are not four versions of one policy. Two are contractual instruments, one is a privacy disclosure, and one is support content.

The API Help Center gives the clearest operational answer. Asked whether user data is used for model training, it answers no, states that input and model output submitted through the API are not used to train or improve Kimi’s models, and says data is used solely to fulfil the current request and is not persistently stored for training purposes. The same page describes automated content review, file deletion, and unnamed “relevant security certifications.” No issuing body, product scope, or audit period is given, and the page shows no revision date.

The OpenPlatform Terms of Service, last updated 27 May 2026, are broader. They define input and output together as Content, and permit Moonshot to use Content to provide, maintain, develop, support and improve the Services. Customers wanting restrictions on the use of Customer Content for training or improving Moonshot’s models are directed to contact the company about enterprise arrangements or separate written agreements. The clause closes by stating that unless otherwise expressly agreed in writing, Customer Content may be used for those purposes.

The OpenPlatform Privacy Policy, last updated 30 April 2025, is a processing disclosure rather than a content licence, and the distinction matters. It describes user content as helping to optimise models, and lists training and refining underlying technology among the purposes for which information is used. Its subject is personal information, and its scope is not identical to the contractual definition of Customer Content. It is also fourteen months older than the Terms that incorporate it.

The Business Supplement, effective 1 June 2026, contains the strongest public protection. For covered Business Services it commits that Moonshot will not use Customer Content to train, optimise or improve its models without express authorisation or a legal requirement. It also carries an explicit precedence clause: it prevails over the general Terms of Service for Business Services, and an applicable order form prevails over it.

The scope question

The Supplement applies to Kimi Business and to other paid business subscription, workspace, seat-based, administrator-managed or organization-level services. Kimi’s own business page presents Kimi Business and Kimi API as two separate ways to use Kimi at work, and describes the API as usage-based rather than subscription-based. The API platform’s documentation index, which the vendor describes as the complete index of available pages, lists exactly two agreement documents: the OpenPlatform Terms and the Privacy Policy. The Business Supplement is not among them.

The Supplement does define Customer Content to include API request and response data. That defines what is protected once the Supplement applies. It does not, on its own, extend the Supplement to services outside its own scope definition, and this briefing does not treat it as doing so.

The finding

Public materials do not establish that an ordinary self-serve OpenPlatform API account receives the Business Supplement’s no-training protection. A buyer should not assume that it does.

This is not evidence that Moonshot trains on API data. It is evidence that a Help Center answer and a contractual no-training protection are different things, and that the public documents do not show which one governs a self-serve account.

Diagram showing four Kimi documents pointing at a single self-serve pay-as-you-go API account: the API Help Center stating no training or improvement, the OpenPlatform Terms allowing broader content use unless agreed otherwise in writing, the Business Supplement giving no training for covered services, and an order or checkout document that may control the purchased service. A panel below reads that the public scope is not resolved.
Four documents can bear on the same self-serve API account, and they do not give one answer. An order form can override the others for a purchased service, and FSR did not obtain one. Sources: Kimi API Help Center, the OpenPlatform Terms of 27 May 2026 and the Business Supplement of 1 June 2026, all accessed 24 July 2026.

The strongest response to this finding

Moonshot’s best answer would be that these documents address different products, customers and data categories, that the Supplement resolves the question for the buyers it covers, and that the Help Center accurately describes how API data is handled in practice. That answer is available and would be reasonable. It has not been given publicly, and FSR has not obtained it. Until it is, the gap is a procurement risk rather than a policy finding.

The Kimi API Platform confirmed receipt at 22:37 JST on 24 July 2026 and displayed a message saying a reply would follow. FSR asked whether a self-serve pay-as-you-go OpenPlatform API account falls within the Business Services covered by the Business Supplement of 1 June 2026.
The Kimi API Platform confirmed receipt at 22:37 JST on 24 July 2026 and displayed a message saying a reply would follow. FSR asked whether a self-serve pay-as-you-go OpenPlatform API account falls within the Business Services covered by the Business Supplement of 1 June 2026.

Sources: Kimi Help Center, “Data processing & security”, accessed 24 July 2026 · Kimi OpenPlatform Terms of Service, §4 Content, updated 27 May 2026 · Kimi OpenPlatform Privacy Policy, §§1–2, updated 30 April 2025 · Kimi Business Supplement, preamble and §§1, 5.3, effective 1 June 2026 · Kimi Business, accessed 24 July 2026 · Kimi API Platform documentation index, accessed 24 July 2026

How the public terms allocate risk

The provenance dispute concerns the vendor. The public terms leave the associated risk with the customer.

The OpenPlatform Terms disclaim implied warranties, and the list of disclaimed warranties expressly includes non-infringement. The indemnity in those Terms runs one way, from customer to Moonshot. Aggregate liability is capped by reference to fees paid in the preceding twelve months. In the consumer-facing Terms that cap is the greater of twelve months of fees or one hundred US dollars. The Business Supplement follows the same shape.

FSR did not locate a vendor-side output or intellectual property indemnity in any of the public documents reviewed for this briefing. That does not establish that one is unavailable through negotiation. It means a self-serve buyer should not assume the standard public paperwork moves provenance risk back to Moonshot.

One clause pair deserves care. The OpenPlatform Terms state that Customer Content is deemed the customer’s Confidential Information, and separately reserve the right to use Content to develop and improve the Services. Those provisions are not necessarily in conflict. A confidentiality obligation can sit alongside a granted licence to use the same material for defined purposes. Confidential does not by itself mean unused.

Sources: Kimi OpenPlatform Terms of Service, §§4, 6, 8, 9, 10, updated 27 May 2026 · Kimi Terms of Service, §§7–9, effective 21 January 2026 · Kimi Business Supplement, §§12–14, effective 1 June 2026

What the provenance record establishes

Five-stage diagram of the public record on the distillation allegation. Access attribution and output collection are marked as official claims. Training use and K3 causation are marked as not disclosed. Legal adjudication is marked as not located. A separate note records the Fable to K3 claim as a US official claim whose evidence is not public. A banner below reads that the record supports attributed reporting but does not support a K3 lineage verdict.
The chain from account access to a legal finding has five links, and the public record covers the first two. FSR reproduced none of the stages independently. Sources: Anthropic’s report of 23 February 2026 and named official statements of 22 July 2026.

Anthropic published a report on 23 February 2026 describing what it called industrial-scale extraction campaigns by DeepSeek, Moonshot and MiniMax. It said the three campaigns together produced over 16 million exchanges through approximately 24,000 fraudulent accounts, and that the Moonshot-attributed campaign accounted for over 3.4 million exchanges through hundreds of accounts. It listed the targeted capabilities as agentic reasoning and tool use, coding and data analysis, computer-use agent development and computer vision, and said a later phase attempted to extract and reconstruct Claude’s reasoning traces. Attribution was described as resting on IP correlation, request metadata, infrastructure indicators and, in some cases, corroboration from industry partners.

The report does not identify Kimi K3. It refers to Moonshot’s Kimi models generally, and K3 did not exist when it was published. The report does not identify Fable 5 either. The underlying account records, query corpus and any training records are not public.

On 22 July 2026, Michael Kratsios, director of the White House Office of Science and Technology Policy, wrote on X that the government had information that Moonshot distilled Anthropic’s Fable for the development of the K3 model, and that Moonshot had used GB300 servers, either newly acquired or through Thailand, to train its models. CyberScoop, reporting the same day, noted that Kratsios did not provide details on how the government learned this, and that a request for comment sent to Moonshot was not returned before publication. Treasury Secretary Scott Bessent said separately that sanctions and Entity List designations would be on the table, a conditional statement about possible future action. FSR did not screen the official restricted-party lists for this briefing and establishes nothing about current status in either direction.

Where the record stops

Access attributionAnthropic describes its method and states high confidence. Underlying records are not public.
Collection of outputsDescribed in the same report, at stated volume, as an Anthropic claim.
Use in trainingNo training logs, dataset manifests or pipeline records located.
Fable-specific useAsserted by a named US official on 22 July 2026. Supporting evidence not disclosed.
K3-specific causationNo ablation, checkpoint comparison or causal analysis located.
AdjudicationNo court decision, regulatory finding or effective restriction located.

“Not located” describes the boundary of FSR’s search on 24 July 2026. It is not a finding that evidence does not exist, and it is not exoneration.

A date correction

A rebuttal circulating since launch holds that Fable 5 went public on 1 July and K3 launched on 15 July, making the alleged cycle implausible. Anthropic’s launch page is dated 9 June 2026 and carries two update notices: access to Fable 5 and Mythos 5 was suspended on 12 June 2026 and the models were redeployed on 1 July 2026. The 1 July date is a restoration date.

Correcting it does not settle the chronology. Public availability is not the same as access, and the February report describes activity that predates Fable 5 entirely. Any timeline argument has to state which clock it is using and why.

What the architecture record shows

Moonshot’s public GitHub organisation, which FSR opened on 24 July 2026, lists 39 repositories. Two are relevant to the architecture claim: an Attention Residuals repository, and FlashKDA, described as high-performance Kimi Delta Attention kernels and carrying an MIT licence with a last update in May 2026. Both are the components Moonshot cites as the basis for K3’s efficiency gains, and both were published as code before the July dispute.

That establishes a documented research line. It does not establish anything about K3’s training data, and it should not be read as a rebuttal to the allegation. The two questions are separate.

On the word watermark

A generated-text watermark is a statistical bias deliberately embedded in a model’s output so that a key holder can later test whether a passage came from that model. Testing such a claim requires a stated method, the key assumption, sample size, decision threshold, null distribution, error rates and independent replication. FSR located none of those elements in any public document connected to K3. Anthropic’s February report describes classifiers and behavioural fingerprinting and does not use the word. In vendor terms of service the same word usually means something else, namely labelling applied to AI-generated content that users must not remove.

Why screenshots and self-identification are weak

Reports of K3 identifying itself as Claude have circulated since launch, and several informal analyses have been published. FSR did not obtain the protocols behind any of them and does not characterise their results.

The general limitation holds regardless. A model that answers with the wrong name is predicting likely tokens. That behaviour can follow from contamination of public training data with transcripts of other assistants, from third-party synthetic data, from system prompt leakage, from role-play, or from client-side labelling. None of those require a distillation campaign, and none can be ruled out from a screenshot.

Benchmark resemblance carries even less weight here, and Moonshot’s own footnotes explain why. The published comparison mixes agent harnesses across models, recalibrates some tasks to different hardware than the official configuration, cites some competitor scores from third-party leaderboards and vendor blogs rather than running them, and states that Claude Fable 5 hit fallbacks on 35 per cent of the tasks in one evaluation, which the company says may have affected the measured result.

Moonshot’s response

FSR found no formal written response from Moonshot or Kimi on the company’s official channels within the searches reviewed, and no reference to the allegation in the K3 launch materials or the API platform documentation. CyberScoop reported on 22 July that a request for comment had not been returned before publication. Chinese-language outlets have reported executive comments rejecting a distilled-model explanation; FSR could not open the cited article and has excluded those comments from this briefing rather than rely on a summary.

Sources: Anthropic, “Detecting and preventing distillation attacks”, 23 February 2026 · Anthropic, “Claude Fable 5 and Claude Mythos 5”, 9 June 2026, with update notices of 12 June and 1 July 2026 · CyberScoop, 22 July 2026 · South China Morning Post, 23 July 2026 · Moonshot AI on GitHub, accessed 24 July 2026 · Kimi K3 tech blog, benchmark footnotes, accessed 24 July 2026

The release package and what 27 July changes

Moonshot’s launch page states that full model weights will be released by 27 July 2026, with architecture, training and evaluation detail to follow in a technical report. That deadline had not arrived when this briefing was written. Nothing here describes a missed commitment.

Release artefacts, checked 24 July 2026, before the deadline

Model weightsNot on the official Hugging Face or GitHub organisations
Licence textNot published
File manifest and hashesNot published
Model cardNot published
Technical reportPromised with the weights
Tokenizer and config filesNot published
Serving integrationvLLM prefix-caching contribution stated as releasing with the model
Commercial and redistribution rightsNot published
Hosted APILive, model identifier kimi-k3

FSR opened Moonshot AI’s official Hugging Face and GitHub organisation pages and found no K3 repository on either. This is a point-in-time observation of dynamic pages and will be re-audited after 27 July 2026.

The platform documentation has not caught up either

The gap is wider than the weight file. K3 is live and billable, and parts of the developer surface around it still describe the previous generation.

The K3 pricing page carries a notice that the web_search tool is being updated, that Moonshot does not recommend using it in the near term, and that the documentation on that page is outdated. The token-estimation endpoint, which is how a buyer would price a request before sending it, documents a model parameter with eleven permitted identifiers. None of them is kimi-k3, and the documented default is kimi-k2.5. That describes the published documentation rather than tested endpoint behaviour, and FSR made no API calls to check the difference.

For a buyer, the practical effect is that cost modelling for the flagship model cannot be done from the documented tooling, and one shipped capability carries a vendor advisory against use.

The release should make licensing and deployment questions inspectable. It will not resolve the provenance allegation, which needs different evidence entirely. Until the licence exists, “open” describes an intention rather than a set of rights, and the questions that decide whether a weight file is usable in a product remain open: commercial use, derivative redistribution, hosted resale, and any field-of-use restriction.

Sources: Kimi K3 tech blog, accessed 24 July 2026 · Moonshot AI on Hugging Face, accessed 24 July 2026 · Moonshot AI on GitHub, accessed 24 July 2026 · Kimi K3 pricing, accessed 24 July 2026 · Kimi token estimation API reference, accessed 24 July 2026

What weights do not remove

A downloaded checkpoint removes dependence on Moonshot’s hosted API for inference. The rest of the stack stays where it was.

The licence governs what may be done with the file. Accelerator supply remains a constraint, and Moonshot recommends supernode configurations of 64 or more accelerators, which puts the deployment outside single-node hardware for most buyers. The cloud contract, the payment rails and the export and sanctions clauses already accepted in the terms are unaffected. Those clauses oblige the customer not to use, export or provide access to the services in violation of US, Singapore or EU rules.

A self-hosted checkpoint also receives no security patches unless someone ships them, and the vendor’s own deprecation record is worth reading before assuming a long support horizon. The pricing overview lists the Moonshot V1 series with a full platform sunset expected on 31 August, about six weeks after K3’s launch. Model generations at this vendor turn over quickly, and a buyer planning around K3 should price the migration rather than assume permanence.

Owning weights changes the dependency map. A buyer should be able to name which specific dependency the change removes before treating self-hosting as a risk answer.

Sources: Kimi K3 tech blog, “Architecture and Infrastructure”, accessed 24 July 2026 · Kimi OpenPlatform Terms of Service, §13 Export and Sanctions, updated 27 May 2026 · Kimi model inference pricing overview, accessed 24 July 2026

The decision, and the questions to send

Four-step buyer workflow. Step one, choose the route between the self-serve API, negotiated business terms and self-hosted weights. Step two, identify what controls, covering account type, purchase flow and precedence. Step three, verify the boundary, covering data use, data lifecycle and governance. Step four, decide by workload, from low-sensitivity evaluation through confidential work to self-hosting. A banner below reads that the assurance may exist and that a buyer should confirm their account receives it.
The sequence a buyer can complete without waiting for the provenance allegation to be resolved. Built from public Kimi documents accessed 24 July 2026. FSR did no hands-on testing.
ProceedLow-sensitivity evaluation behind a model abstraction layer, with no confidential data and a migration path already tested against a second model.
Wait for a written answerAny confidential or client-controlled workload. Get confirmation of the controlling agreement and the data-use rule before the first production call.
Stay at evaluationTeams that require processor terms, transfer documentation, fixed retention, named certifications or audit evidence should not move past evaluation until those requirements are documented.
Wait for the packageAnyone whose plan depends on self-hosting, licence terms, redistribution rights or reproducible evaluation.
Do not inferDo not treat the allegation as settled in either direction, and do not read an unresolved contract scope as proof that customer data is being used.

Published token rates are not the effective cost of an agentic workload. Output expansion, retries, tool-call turns and the recharge-based rate tier all move the real figure, prices exclude tax and are calculated at checkout by jurisdiction, and the documented token-estimation endpoint does not list kimi-k3 among its permitted models. FSR has no hands-on measurement of effective cost for K3. Self-hosting cost is unpriced until the deployment requirements are published.

Eight questions to send before sending data. Which agreement governs the account, and whether the Business Supplement applies to a self-serve paid API account. Which document controls when the Help Center answer and the general Terms disagree. Whether no-training covers prompts, uploaded files, outputs, tool traces, metadata, moderation logs and support tickets. Whether service improvement that does not update model weights is included or excluded. The retention and deletion periods for each of those data classes. Whether human review of content is possible. Whether a data processing addendum, transfer mechanism and subprocessor list can be provided. Which named certification covers which entity, product, region and audit period.

Sources: Kimi OpenPlatform Terms of Service, updated 27 May 2026 · Kimi Business Supplement, effective 1 June 2026 · Kimi K3 pricing, accessed 24 July 2026 · Kimi recharge and rate limiting, accessed 24 July 2026

FAQ

Does Kimi train on my API data?

The Help Center says no. The OpenPlatform Terms, updated 27 May 2026, permit use of Customer Content to develop and improve the Services unless otherwise expressly agreed in writing. The Business Supplement prohibits training use by default for Business Services. Public materials do not establish that a self-serve API account is covered.

Is Kimi K3 open source?

FSR could not evaluate an open-source claim before the licence and release package were available. Moonshot describes K3 as open and committed to publishing full weights by 27 July 2026. On 24 July, no weights, licence or model card were published. Open weights and open source are separate claims.

Can I self-host Kimi K3?

Not before the weights and licence exist, and then only at scale. Moonshot recommends supernode configurations of 64 or more accelerators, which puts the deployment beyond single-node hardware for most buyers. Patching, support and update paths for a self-hosted checkpoint are not addressed in the public documents.

Has Moonshot responded to the allegation?

Not on its official channels, within the searches FSR reviewed. CyberScoop reported on 22 July that a request for comment was not returned before publication. Executive comments reported in Chinese-language outlets were excluded from this briefing because FSR could not open the cited article.

Does the allegation mean I should avoid K3?

The allegation is unresolved and is not the operative buyer question. What decides the matter for most teams is the contractual data-use rule for their account, the availability of processor terms, and whether a migration path has been tested. Those can be settled without settling the allegation.

Is Moonshot AI on a restricted-party list?

This briefing does not establish either answer and did not screen the official lists. A Treasury statement described designations as being on the table, which is conditional. Screening status is volatile and must be checked against the Consolidated Screening List, the BIS Entity List and OFAC on the day of the transaction.

Methodology and limitations

This is a document-first Tier C briefing. FSR did not test Kimi K3, call the API, inspect weights, or attempt to reproduce any lineage claim.

Sixteen vendor and lab documents were opened and read on 24 July 2026: Anthropic’s distillation report; Anthropic’s Fable 5 and Mythos 5 launch page including its update notices; the Kimi K3 tech blog with its benchmark footnotes and stated limitations; the Kimi API Help Center data processing page; the Kimi OpenPlatform Terms of Service; the Kimi OpenPlatform Privacy Policy; the Kimi Terms of Service; the Kimi Business Supplement; the Kimi Business page; the Kimi API Platform documentation index; the recharge and rate limiting page; the model inference pricing overview; the K3 pricing page; the token estimation API reference; Moonshot AI’s Hugging Face organisation page; and Moonshot AI’s GitHub organisation page.

Statements are separated by class throughout. A primary document establishes what that document says. A vendor claim is marked as such and has not been independently verified. Named reporting is attributed to its publisher and treated as a third-party account. Social posts are treated as signal and are not quoted directly, because FSR could not retrieve them.

Six limits should be stated. FSR did not screen the official restricted-party lists, so this briefing establishes nothing about designation status. FSR did not obtain the protocols behind any published behavioural analysis and does not characterise their results. Chinese-language reporting of an executive interview was located at search-result level, but the cited article URL returned a 404 when checked, so those comments are excluded rather than cited to a summary. FSR has not obtained an order form, a data processing addendum, or any written answer from Moonshot on the scope question. FSR made no API calls, so the documentation gaps described in section five describe published documentation rather than tested endpoint behaviour. And the release package section describes a state before a stated deadline and will be replaced after 27 July 2026.

Where a fact could not be established, this briefing says so. The absence of a document from a search is recorded as an absence from that search.

Primary documents: Anthropic, 23 February 2026 · Anthropic, 9 June 2026 · Kimi K3 tech blog · Kimi Help Center · Kimi OpenPlatform Terms, 27 May 2026 · Kimi OpenPlatform Privacy Policy, 30 April 2025 · Kimi Terms of Service, 21 January 2026 · Kimi Business Supplement, 1 June 2026 · Kimi Business · Kimi API Platform documentation index · Kimi recharge and rate limiting · Kimi model inference pricing overview · Kimi K3 pricing · Kimi token estimation API reference · Moonshot AI on Hugging Face · Moonshot AI on GitHub. Reporting: CyberScoop, 22 July 2026 · South China Morning Post, 23 July 2026

Verdict

The provenance allegation is specific and its supporting evidence is not public. Anthropic’s February report is detailed, remains one party’s account, and does not name K3 or Fable. The July statement names both and arrives without the underlying record. Neither position moves on anything a buyer can read this week.

The contractual question does move. Kimi publishes a categorical no-training answer in support content, a broader content-use right in the OpenPlatform Terms, a training and refining disclosure in a privacy policy fourteen months older than those Terms, and a no-training default in a Business Supplement whose scope covers subscription and seat-based services. Moonshot’s own pages present the API as a separate product from Kimi Business. A buyer opening a self-serve API account cannot show from public documents that the Supplement protects them.

Around that gap sits a platform still catching up with its own flagship. The weights are promised and not shipped, the licence does not exist, the token-estimation reference does not list the model, and one shipped tool carries a vendor advisory against using it. None of that is misconduct. All of it is evidence that K3 is earlier in its lifecycle than the benchmark tables suggest.

One written answer from Moonshot would close the contract question. Until it arrives, low-sensitivity evaluation behind an abstraction layer is a reasonable position. Sending confidential data through a self-serve account on the strength of a Help Center page is not.

Sources: Kimi OpenPlatform Terms of Service, §4, 27 May 2026 · Kimi Business Supplement, §5.3, 1 June 2026 · Kimi Business, accessed 24 July 2026 · Kimi token estimation API reference, accessed 24 July 2026 · Anthropic, 23 February 2026

Related FSR briefings

Tier B means FSR tested the product hands-on. Tier C means a document-first briefing with no hands-on testing.

Tier B

Tier C

Future Stack Reviews is an independent publication. This is a document-first Tier C briefing and is not legal, financial or compliance advice. Statements attributed to Anthropic, Moonshot AI, US officials or news publishers are their statements and not findings by FSR. Pricing, terms, availability, release status and regulatory status are volatile and were accurate only as at the evidence check date below.

Last evidence check: 24 July 2026 (JST). Mandatory recheck: the 27 July 2026 release package, terms and policy version changes, restricted-party status, and any formal Moonshot response.