Loading the catalogue…
Loading the catalogue…
Moonshot AI is a privately-held Beijing company (with a Hong Kong/Cayman holding structure and a Singapore-incorporated API entity) best known for the Kimi chatbot and the Kimi K2 family of open-weight, trillion-parameter models. For EU regulated customers, the open-weight releases (self-hostable, Modified MIT licence) reduce vendor lock-in, but the hosted Kimi API retains and trains on user content with no clearly bounded retention period, no independent security certification has been identified, and the firm was named by Anthropic in 2026 as having run a large-scale unauthorized data-extraction campaign against a competitor's API — all of which warrant caution for sensitive workloads routed through Moonshot's own infrastructure.
Anthropic publicly accused Moonshot of running an industrial-scale unauthorized data-extraction ('distillation') campaign against Claude using hundreds of fraudulent accounts, later escalating to targeted extraction of reasoning traces.
Ultimate ownership and operational control sits with a China-based founding team and Chinese corporate/VC backers (Alibaba, Tencent), routed through Hong Kong/Cayman Islands holding entities — exposing customer data and model governance to PRC jurisdiction and national-security-related data laws even though no direct CLOUD Act nexus was found.
Moonshot's hosted API terms permit broad use of customer content to 'develop and improve' services, with no clearly stated retention period and community reports that data use cannot be easily opted out of even for paying API customers.
No EU AI Act compliance statement, GPAI Code of Practice signature, or systemic-risk self-classification was found, despite Kimi K2 being a trillion-parameter model trained at a scale plausibly triggering systemic-risk GPAI obligations.
No published SOC 2, ISO 27001, penetration-testing programme, or bug bounty was identified for Moonshot AI, limiting independent verification of its security posture.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Flagship Kimi K2 models (K2, K2.5, K2.6, K2.7 Code) are released with open weights and code on Hugging Face/GitHub under a permissive Modified MIT licence, enabling self-hosting and independent audit.
Kimi K2 became the top-downloaded model on Hugging Face immediately after release and Kimi K2.7 Code was adopted as the first open-weight model option in GitHub Copilot.
Published a technical paper and open-sourced the Muon/MuonClip optimizer implementation and checkpoints used to train Kimi K2, alongside a detailed technical report.
The consumer-facing Kimi privacy policy includes a dedicated EEA/Switzerland/UK section describing legal bases for processing personal data, indicating some awareness of GDPR-adjacent obligations.
Published safeguards & certifications