Skip to content
Wogenfels Consulting

BlogArtificial Intelligence

Kimi AI for SMEs: Check Subscriptions, Coding, APIs and Data

By Dominik Pototschnig20 min

AI-generated illustration of Dominik Pototschnig facing four AI access routes and a review grid for costs, contracts, data protection and human oversight
In this article

Quick answer

In this article, Kimi is an umbrella term for several offerings that must be assessed separately: the web interface, the coding tool, the Open Platform API and published model weights. The operator, contracting party and terms must therefore not be carried over from one access route to another.

Before testing Kimi, there is a procurement decision to make: web subscription, coding access, API or your own model weights. The costs, rights and data processing arrangements must be clarified for each route. Our recommendation for business procurement is to define the required capability first and then assess the corresponding offering.

A web subscription pays for the user-interface features listed in the account. An API, by contrast, is an application programming interface through which your own application sends model requests. Kimi explicitly states that membership benefits cannot be converted into general Open Platform credit. An existing subscription therefore does not demonstrate that you have a budget for integrating Kimi into your own software. Kimi: API guidance · Status: 15 September 2026.

Quick decision by type of work:

Your planned work Suitable first test Evidence required before approval
Handle individual tasks manually in an interface Web subscription Included plan scope, contract and data flow, plus the quality of your own use cases
Work in a clearly bounded codebase Kimi Code Permitted files and actions, technical isolation, change approval and output quality
Integrate Kimi into your own application Open Platform API Model, complete cost basis, contract, and rules on training, retention and deletion
Operate a specific model artefact yourself Kimi-K2.5 weights Licence, hardware, operations and the entire data flow, including additional tools

This means that Kimi qualifies only as a candidate for a controlled comparison test, not as a preferred provider. This article has no reliable price figure for an Austrian account; the relevant factors are the actual offer and measured total costs. There is no blanket data-protection verdict based on origin; the specific contract and data flow are what matter. DeepSeek, Qwen, GLM and MiniMax are assessed below only through named access routes, not as providers overall or in a performance ranking.

For an Austrian SME, the next decision is therefore: Which specific task should be tested, which access route does it require and which data may be used? We recommend a limited test with fictional data or lawfully usable public content that contains neither personal nor confidential information. Before using actual company data, you must clarify the written rules on data use and deletion in particular; the public Kimi documents differ on these points, as explained below. OpenPlatform Terms, enterprise data-retention documentation.

Research and source status: 15 September 2026. The information below describes documented offerings. Whether a particular plan can be purchased through your Austrian account, and how well it handles specialist tasks in German, still require specific checks.

Which Kimi service do you want to buy?

Assess four access routes separately. Whether web and coding services are bundled in a particular account is a plan-specific question; according to Kimi, general API access uses its own keys and usage-based billing. Kimi: product and billing distinction.

This table is a procurement aid. The feature descriptions come from the provider; the questions come from our editorial review framework. Status: 15 September 2026.

Access route Documented scope according to the provider Cost checks Data and operational checks
Kimi web subscription Membership benefits do not become general API credit. API guidance Which plan and additional costs apply to the Austrian account? Which operator and data rules apply to this access route?
Kimi Code Read code, edit files and run commands. Code overview Which quotas, bundles and additional usage apply? Which codebases, rights and approvals do you permit?
Kimi Open Platform API Model calls for your own integration; API and Code keys are not interchangeable. API guidance What input, output and other costs apply? Which written rules on training, retention and deletion apply?
Your own Kimi-K2.5 model weights A separate model artefact with a model card and Modified MIT licence. Model card, licence What costs arise for infrastructure, setup and oversight? Who reviews the licence, updates and the entire data flow?

Four Kimi access paths shown on equal footing by type of work: web subscription, Kimi Code, Open Platform API and K2.5 weights, each with the evidence required before approval

Wogenfels procurement aid: no ranking and no promise of availability in Austria, price, quality or GDPR compliance.

Web subscription and coding: What is included in the account?

Kimi Code is a coding agent: software that connects an AI model to tools for working with code and files. Kimi documents a command-line interface (CLI), meaning that it is operated through text commands, and an extension for the VS Code editor. This describes possible actions and access routes; it is not evidence of tested work quality or securely constrained permissions. Kimi Code: overview.

The included services are worth clarifying in writing: the membership documentation for Kimi Code describes shared membership and Code quotas, while the API guidance describes the products as independent. This does not establish a uniform web and Code package for Austrian accounts. Ask for the specific plan, usage limits and additional costs to be stated.

Your own integration via the API

If your own application is to send requests to Kimi, assess the Open Platform terms or explicitly agreed enterprise terms. The standard platform describes pay-as-you-go billing without a platform subscription; its keys are not interchangeable with Kimi Code keys. Kimi: API guidance.

The model version is also part of this assessment. The current Open Platform model list includes kimi-k3 and lists kimi-k2.5 as deprecated since 31 August 2026. This discontinuation applies to the named direct API model route. It says nothing about K2.5 weights that have already been downloaded or offerings from other operators. Kimi: model list · checked on 15 September 2026.

Your own weights: a different model, your responsibility

Model weights are downloadable model data for operating a model yourself under the applicable licence. Kimi-K2.5 has a separate model card and Modified MIT licence. Its additional conditions matter: under the commercial scale conditions described there, the model name must be displayed visibly. Calling it simply “MIT” would be incomplete here.

The weights are not an identical replica of the current Kimi web service. Our recommendation for this route is to assess the exact model artefact, licence, infrastructure and every data connection together. Which additional tools send content where? Who is responsible for updates and oversight? Our article on running AI models locally, including hardware and operating costs explores the infrastructure questions in more detail.

What does the chosen route cost in total?

A reliable cost estimate requires the specific access route and your own usage. No complete pricing information for an Austrian account has been substantiated for this article. We therefore provide neither subscription nor API amounts, but the cost items and a formula that you can fill in using a verified offer.

Record subscriptions, API usage and operations separately

The Kimi API charges for input and output in tokens. Tokens are units for pieces of processed text, not simply words. The pricing rules use “1M” to mean one million tokens; according to the documentation, applicable taxes are not included in the public API pricing. Kimi: explanation of model billing.

For Kimi K3, the billing documentation distinguishes new input from cache hits: reusable parts of an input that have a separate price. You should not assume a particular cache-hit rate. Kimi: Account and Billing · Status: 15 September 2026.

For this cost model, the symbolic formula is:

API cost = (new input tokens × price for new input + cached input tokens × cache price + output tokens × output price) ÷ 1,000,000

All prices must be per one million tokens and apply to the same model, region, plan, modality, context, currency and effective date. Also check the type of data, the permitted volume of content per request and the pricing date. New and cached input must not be counted twice. The result covers only these model calls; taxes, additional tools and operations may need to be added.

For a web or coding test, record the subscriptions and additional usage you actually need. For your own weights, record infrastructure and setup instead, among other items. Human oversight and ongoing operations belong in the total costs for the relevant route. Do not add fees for access routes you do not use.

A zero-figure procurement template helps prevent a comparison based only on the visible plan price:

Budget item Company-specific input
Offer Fixed price, term, commitment, notice period and scope actually included
Variable usage Billing unit, offer currency, excess usage and technical usage limit
Invoicing and taxes Ability to issue a suitable invoice, tax treatment and details required for procurement
Internal time Setup, specialist review, rework, operations and incident handling
Infrastructure and tools Hosting, storage, network, additional services, isolation, monitoring and backups
Switching and stopping Export, migration, shutdown, plus a predefined monthly test cap and stopping threshold

Enter only items that actually apply to the chosen route, and do not count anything twice. If the internally defined test cap is reached, stop the test until a new decision is made.

Cost per accepted output

For the business decision, we also recommend calculating:

Cost per accepted output = recorded total costs ÷ number of accepted outputs

“Accepted” means that a person has checked that the output meets the requirements defined in advance. Use the same test scope and currency for the comparison. In addition to fees, record setup, infrastructure, operations and human review where they apply to the test, without counting an item twice. If no output was accepted, this metric cannot be calculated.

The commercial review question is therefore: Does the tested route meet your quality requirements at total costs for which you can take responsibility? The calculation method alone does not demonstrate any savings.

What Kimi’s documents say about data and contracts

Before using actual company data, you should clarify in writing which rules apply to the specific access route. A general promise about data retention does not answer this for Kimi: the documents reviewed have different dates and scopes.

The OpenPlatform Terms, updated 30 July 2026 name Moonshot AI PTE. LTD. as the contracting party. The OpenPlatform Privacy Policy, updated 30 April 2025 mentions servers in Singapore. Both statements relate to this API service; they are not evidence of the contract or storage location for every Kimi access route.

Clarify non-training and ZDR in writing

Section 4 of the API Terms permits content to be used to improve the service unless otherwise agreed in writing. By contrast, the enterprise documentation states that enterprise customer data is not used for training by default. Your agreement must clarify how these statements interact and which rule is binding. The documents establish neither a particular training practice nor a non-training commitment for all accounts. OpenPlatform Terms, section 4, enterprise ZDR documentation.

Zero data retention (ZDR) here means an expressly agreed limitation on content retention, subject to exceptions. According to Kimi, it is available to enterprise customers on request. When ZDR is enabled, request and response content is to be deleted after the response, subject to legal requirements. The documentation also states limitations:

  • ZDR is not guaranteed for images and videos uploaded directly.
  • Operational data such as security logs and billing data is not covered.
  • Third-party models, connected third-party services and plugins are excluded from this ZDR policy.

These conditions come from the Kimi ZDR documentation, checked on 15 September 2026. ZDR is therefore neither a blanket promise that no data at all will be retained nor an automatic feature of every Kimi account.

Another unresolved point concerns account deletion: the billing guidance says it is not supported, while section 11 of the Terms describes a deletion request. You should therefore clarify the procedure, scope and data that remains in writing. This discrepancy in the documentation does not establish either a promised deletion deadline or a breach of law. Account and Billing, OpenPlatform Terms, section 11.

Which usage and contract rights must be documented in writing?

Data protection is only one part of procurement. The following Wogenfels review framework asks questions about the specific offer; it does not claim what answer any Kimi access route provides:

  • May the intended inputs, outputs and, for coding, code be used for the planned commercial purpose, and who retains which rights?
  • Which uses are excluded, and which technical or organisational obligations arise from those exclusions?
  • Which liability, warranty and indemnity provisions apply to the actual company account?
  • Which version of the terms becomes part of the agreement, and how are later changes announced or made effective?
  • How do cancellation, data and output export, and an orderly switch to another access route work?

Outstanding answers should be clarified in writing before placing an order or using actual data; a publicly accessible product page does not replace the specific contract.

Which evidence does your data flow require?

For personal data, the assessment starts with the parties’ actual roles. The controller determines the purposes and means of processing. A processor processes data on the controller’s behalf and under its instructions. Where processing on behalf of a controller takes place, this relationship must be governed by a contract under Article 28 of the General Data Protection Regulation (GDPR); this arrangement is commonly called a data processing agreement (DPA). European Data Protection Board: controller or processor.

For international data transfers, the European Data Protection Board describes three cumulative criteria: an entity is subject to the GDPR for the processing, it makes personal data available to another organisation, and that other organisation is located outside the European Economic Area (EEA). In addition to the other GDPR obligations, such transfers require a suitable mechanism under Chapter V. European Data Protection Board: international data transfers.

One possible instrument is standard contractual clauses (SCCs), which are contractual rules for a transfer. When this route is used, a transfer impact assessment (TIA) is also required: an assessment of the specific circumstances, the law in the destination country and any necessary supplementary safeguards. The legal basis and data minimisation must also be assessed. Regulatory guidance on transfer instruments and assessment.

Our procurement recommendation follows from this: assess the actual data flow and contracts. Neither a model’s origin nor a storage location in the EEA answers these questions. Record which data is processed, which organisations receive it, from which countries access occurs and which agreements cover it. This is a review framework, not blanket GDPR approval or a substitute for case-by-case assessment. Our article on local and cloud AI in a data-protection review compares the architectural options.

DeepSeek, Qwen, GLM and MiniMax under the same review framework

Compare specific offerings using the same questions: access route, documented scope, total costs and outstanding procurement points. This selection deliberately includes different product types. It contains no practical performance test and no ranking. Provider information checked on 15 September 2026:

Access route reviewed Documented difference Cost question Open procurement question
Reading rule for every row Only the named access route; no overall provider assessment and no performance ranking. No promise of availability in Austria or of a specific price. Clarify outstanding points in writing before procurement.
Kimi: web subscription, Code, API or your own weights Membership benefits are not converted into general API credit. API guidance Which access route incurs which costs? Which binding training and retention rule is included in the specific agreement?
DeepSeek: original R1 weights The model card lists MIT as the licence for the original model. This does not apply across all derived models or cloud services. R1 model card What do self-hosting and specialist review cost? Which model files, licence and data flow are actually used?
Qwen via Alibaba Cloud Model Studio The platform distinguishes the storage region from the compute location. For Frankfurt, it states that EU or Global can be selected for compute. Regions documentation Which model is available in the required workspace, and under which plan? Which compute scope and contracts cover your data flow?
Z.AI: GLM Coding Plan Documented as a coding subscription. GLM Coding overview Which usage limits and plan terms apply to your account? Which region, access permissions and data rules apply to this access route?
MiniMax: Token Plan Described as an extension of the previous Coding Plan; subscription keys and pay-as-you-go API keys are not interchangeable. Token Plan overview Which models and data types are included, and what does excess usage cost? Which contract and data rules apply to this access route?

For Qwen, the distinction is particularly important: a workspace in Frankfurt does not tell you which compute scope, EU or Global, has been selected. Model Studio also maintains region-specific model lists. Check the intended Qwen model in the selected configuration; the regions documentation establishes neither that every Qwen model is available in Frankfurt nor the terms of the separate Qwen Chat service. Alibaba Cloud: regions and endpoints.

The DeepSeek row must be read just as narrowly: it concerns the original R1 weights, not an API offering assumed to be current. This distinction is intended to make selection easier: if you need a coding access route, assess coding offerings first; if you are considering operating a model yourself, you particularly need to review the licence and operations. The table does not identify a winner for specialist tasks in German.

How to scope an initial test

We recommend comparing the same specialist task in German against acceptance criteria defined in advance. The following steps are an editorial test design, not a statement about capabilities already measured for the named offerings.

  1. Define the task and an acceptable output. What output do you need, and how will a suitably qualified person determine that it is correct and complete? Which errors would lead to rejection?
  2. Choose test data. Use fictional data or public content that you may lawfully use and that contains neither personal nor confidential information. Public accessibility does not automatically mean that content contains no personal data.
  3. Limit the access route and permissions. Record the product, model, plan and test environment. Do not give the test production write permissions or live credentials.
  4. Record output and effort. Document the specialist review, required rework, usage and costs of the chosen route. Compare them using the same criteria.
  5. Resolve outstanding evidence before using actual data. Which contract applies? How are roles, processing countries, training, retention and deletion governed? Where processing on behalf of a controller or an international data transfer takes place, consider the requirements described above.
  6. Name the accountable people and stopping criteria. Who decides whether to approve outputs and costs? Which errors or unresolved contract questions will stop the test? Who will later be responsible for updates, monitoring, deletion and switching providers?

Define coding permissions and output approval

Because the documentation states that Kimi Code can edit files and run commands, the test decision must include a technical permissions review. Kimi Code: documented actions. Use an isolated test project and specify explicitly: Which repositories and files can it access, which network destinations are permitted and which changes require approval? Verify the actual restrictions before including confidential code or production systems.

This does not replace a security review of the specific environment. For further discussion of an agent’s scope for action and tightly controlled processes, see agent permissions and controlled workflows with Hermes or n8n.

After the test, we recommend taking the next step only if the specialist outputs, total costs, contracts and operational accountability meet the requirements defined in advance. One convincing piece of text or one working code change should not, on its own, be the acceptance criterion.

Next step: record the task and test limits

Record the task, access route, data types and test limits. Add the outstanding cost and contract questions, as well as the person who will review outputs and decide what happens next. This makes the next decision specific: What has been clarified for a limited test, and which evidence is still missing before actual company data can be used?

Wogenfels no-go rule for the pilot: Do not use personal or confidential actual data while any material approval item in the following list remains unresolved.

  • The contracting party, applicable version of the terms and required usage rights are documented.
  • The roles, a DPA where required, recipients, subprocessors, processing countries and any required transfer mechanism are clarified.
  • Binding rules on training, retention, logging, deletion and return are recorded.
  • Permissions, isolation, access keys, permitted network destinations and security evidence are appropriate to the risk.
  • The test cap, cost alert, stopping criteria, export and shutdown are defined.
  • The internally designated accountable people have approved the test: at minimum, the business owner and IT or IT security, plus the data protection function where relevant to the case.

If any of this mandatory evidence remains outstanding, limit the test to fictional or demonstrably suitable, non-confidential data. This cautious pilot rule is not blanket legal approval.

If you would like to discuss how to define the task and test limits, contact us.

Source status

The direct sources used were checked during the research run on 15 September 2026. Product features, plan classifications and data-retention commitments are provider statements; they were not tested in practice for this article. The legal orientation is based on the European Data Protection Board. The review framework, test proposal and cost formulas are editorial deductions subject to the assumptions stated in the text.

  • Kimi AI
  • China AI
  • AI for SMEs
  • coding agents
  • GDPR

Back to overview

More articles

Let’s go

Let’s find a better way together

A conversation costs nothing and brings clarity. Tell us where things are stuck — we will say honestly whether we can help.