Back to Blog
Tech Observation

Who Gets to Train on Whom?

📅 2026.09 ⏱️ 8 min 👤 Eric Pan

The Kimi–Claude dispute is not only about whether one model crossed a line. It is also about where users' prompts went.

In a September 2026 threat-intelligence report, Anthropic alleged that Moonshot routed some Kimi customer requests to Claude and retained some exchanges to extract reasoning traces and train models. The report also states that Anthropic does not know whether Moonshot informed the affected customers.

It is tempting to reduce this to whether Kimi stole from Claude, or to wave it away by saying that large models learn from one another anyway. Both reactions skip the details that matter: how the model service was accessed, what the outputs were used for, and where the users' content went.

Sources were checked through September 17, 2026. This article discusses technology, contracts, and data governance and is not legal advice about any specific party.

Start With What the Report Actually Says

The report contains two numbers that are easy to blur together. Roughly 300,000 customer requests were routed during one ten-day window. Separately, more than 23 million distillation interactions from May through July 2026 were attributed to Moonshot. The second number is not a user count, and it does not prove that 23 million users had their data transferred.

This is still a technical attribution report published by Anthropic, not a court judgment. It offers evidence worth checking, but the access method, account relationships, user notice, and construction of the training data still need their own proof. Treating the report as a final ruling, or dismissing it solely because a competitor wrote it, would both be shortcuts.

Distillation Is Ordinary. Data Provenance Is the Hard Part

Knowledge distillation is not mysterious: one model learns from answers, explanations, or other signals produced by another. Companies use it internally, and partners use it with permission. The method is ordinary. The harder questions are where the examples came from and what the recipient was allowed to do with them.

Reasoning traces are more valuable than final answers because they preserve examples of decomposition, verification, and correction. But a reasoning trace is not a set of model weights, and it is not a copy of the whole model. There is still a large gap between observable output and protected internal information.

So, “Claude can learn from the internet, so why can Kimi not learn from Claude?” is worth asking, but it does not excuse either side. Claude's training data needs a provenance story, and so does Kimi's distillation data. Calling the first learning and the second theft, or simply reversing those labels, is choosing a side before examining the facts.

Owning an Output Is Not the Same as Owning Every Use

Anthropic's commercial terms say that customers own outputs to the extent permitted by law. The same terms restrict using the service to develop or train competing models. That sounds awkward, but the clauses address different things: who owns an output and what a customer agreed to do with it are not the same question.

AI outputs are not automatically protected in full by copyright. Human-authored elements, pre-existing expression reproduced in an output, and purely machine-determined expression can occupy different legal positions. A lack of copyright does not automatically erase an enforceable contract, while one company's terms do not become universal law without further analysis.

Instead of debating in the abstract who owns an answer, ask which version of the contract was accepted, which account and channel produced the output, whether the restriction actually became binding, and whether the conduct can be attributed to a specific party.

Model Companies May Agree Without Their Users Agreeing

Even if a source-model provider expressly permits distillation, real user tasks may still move through another chain:

User content → AI product → third-party model → retention and curation → student model

Prompts in that chain may contain personal information, internal company code, or third-party works. Being able to paste something into a text box does not mean the user can grant unlimited permission on everyone else's behalf. Agreeing to complete the immediate task is not the same as agreeing to long-term retention and training.

A product should therefore say who actually receives the content, why it is sent, how long it is kept, whether it can enter training, and whether the user can inspect, restrict, or delete it. Even an agreement between the source-model provider and the distiller cannot replace a user's knowledge of and choice over where their data goes.

To Judge Whether a Line Was Crossed, Ask Four Things

This kind of dispute cannot be settled by calling the conduct ordinary learning or technical theft. I would follow the actual process and ask four things:

For product teams, the practical changes are straightforward: disclose third-party model routing; let enterprise administrators restrict providers; ask separately about task completion and later training; and record data provenance and permitted uses. A routing audit needs the recipient, purpose, and authorization state, not another full copy of the conversation.

Do Not Write Users Out of the Story

Models need room to learn, and markets need room to compete. Otherwise a few providers can lock capability away indefinitely. But permission to learn cannot become a universal pass over access controls, contracts, and user data.

If you want to learn from another model, explain which boundaries you respected. If you want to stop others from learning, explain whether your claim rests on contract, copyright, or technical access controls. Either way, the user who submitted the original request should not disappear.

Model companies can keep arguing over who may learn from whom. At minimum, users should know where their content went and what it will be used for.

Key sources: Anthropic's September 2026 threat-intelligence report, Anthropic Commercial Terms, the U.S. Copyright Office note on AI outputs, China's Personal Information Protection Law, and the FTC guidance on AI privacy and confidentiality commitments.