The first joint Kimi K3 cyber test complicated Washington's China narrative.
The U.K. AI Security Institute and U.S. CAISI reported that Kimi K3 reached an average of step 17 in a 32-step simulated corporate attack, versus 28.5 for the most capable U.S. models, and achieved arbitrary code execution on 0 of 41 exploit samples. Axios reported that the administration is pairing support for legitimate distillation with threats of sanctions for alleged industrial-scale theft.
Verified 7:32 AM PDT · 2 original sources
The evidence
What the reporting establishes
What happened
The U.K. AI Security Institute and U.S. CAISI reported that Kimi K3 reached an average of step 17 in a 32-step simulated corporate attack, versus 28.5 for the most capable U.S. models, and achieved arbitrary code execution on 0 of 41 exploit samples. Axios reported that the administration is pairing support for legitimate distillation with threats of sanctions for alleged industrial-scale theft.
Pressure point
The evaluation is preliminary, used a selective benchmark set, and compared Kimi's hosted setup with U.S. models tested under different access and safeguard conditions. It measures cyber capability; it does not prove or disprove separate U.S. allegations about training data, chips, or intellectual property.
What to watch
The planned Kimi K3 open-weight release, broader independent evaluations, any Commerce Entity List or sanctions action, technical evidence for distillation claims, and whether U.S. open-weight policy survives pressure from incumbent labs.
Audit the story
Original sources
Company claims remain company claims. Follow the reporting and judge the evidence directly.
- U.K. AI Security InstituteUK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber Capabilities ↗
- AxiosWhite House draws new AI line on China ↗
Continue the morning