Moonshot AI
Kimi K3
vK3 · open-weights · Released July 17, 2026
Updated July 25, 2026
2.8T-parameter open-weight model from Chinese developer Moonshot AI. UK AISI and CAISI found built-in safeguards failed to block offensive cyber attempts ahead of the July 27 open-weight release. No technical safety report was published at launch, and Chinese-origin open-source AI is now under active US sanctions and export-control scrutiny.
Enterprise guidance
Kimi K3 pairs a 1-million-token context window and native vision with explicit marketing for long-horizon autonomous coding under minimal human oversight, so agent permission boundary and kill-switch controls should be in place before any developer adoption begins. No vendor-published technical report or safety evaluation exists to support a standard risk assessment; the UK AISI/CAISI pre-release cyber assessment is the only independent safety signal currently available. Given active US Treasury scrutiny of Chinese open-source AI for IP theft and a revived executive push to restrict Chinese models, document the adoption decision now in case retroactive compliance obligations follow.
Active Compliance Flags5
UK AISI and CAISI jointly assessed Kimi K3 four days before its open-weight release and found its built-in safeguards did not prevent the model from attempting offensive cyber tasks. Self-hosted deployments inherit this gap with no managed-API safeguard layer.
Primary source →No full technical report, model card, or safety evaluation was published alongside the July 17 launch, leaving compliance teams unable to complete a structured risk assessment under frameworks such as California SB 53 or the EU GPAI transparency provisions before evaluation or deployment.
Primary source →US Treasury announced it will examine Chinese open-source AI developers for IP theft and may impose OFAC sanctions. Moonshot AI has not been named individually, but the review follows directly from the Kimi K3 launch and could create prohibited-counterparty exposure for adopters if a designation follows.
Primary source →The Trump administration is reportedly reviving efforts to restrict or ban Chinese-origin AI models following the Kimi K3 launch, citing cybersecurity concerns. Open weights already in public distribution make enforcement of any ban difficult, but formal action would still create retroactive compliance obligations for current adopters.
Primary source →Developed by Moonshot AI, a Chinese company. Hosted access via Kimi.com, Kimi Work, and Kimi Code is subject to Chinese data and national security law; self-hosting the open weights removes this data residency risk.
Primary source →Data handling
Default data retention
Hosted API: not published. Self-hosted: your own infrastructure.
Zero-retention available
NoNot available via hosted API. Self-host open weights for full data control.
API data used for training
YesMoonshot AI has not published an enterprise data processing agreement or training opt-out for hosted API access. Treat hosted-API usage as data-training-eligible until confirmed otherwise.
GDPR Data Processing Agreement
Not availableHIPAA Business Associate Agreement
Not availableNot available. Self-host and arrange a BAA with your cloud infrastructure provider.
Data residency options
Hosted API: not confirmed, likely China-based given developer jurisdiction. Self-hosted: your own infrastructure.
Vendor compliance certifications
Key use restrictions
- —Hosted API (Kimi.com/Kimi Work/Kimi Code): likely subject to Chinese data and national security law; not suitable for regulated or sensitive data
- —Self-hosted open weights (released July 27, 2026): recommended path for enterprise use pending a full technical report
- —No published technical report, model card, or third-party red-team results as of this review; treat capability and safety claims as unverified
- —UK AISI/CAISI found built-in safeguards did not block offensive cyber task attempts; self-hosted deployments inherit this gap with no managed-API safeguard layer
Safety documentation
No technical report, model card, or system card was published at the July 17 launch. UK AISI and CAISI ran an independent pre-release cyber-capability assessment, published July 23, and found that Kimi K3's built-in safeguards failed to block offensive cyber attempts.
Safety documentation →Related governance resources
Governance controls
AI System Intake and Approval Workflow
Use a standard intake process before new AI systems enter the organization. Record use case, data classification, risk tier, and ownership. Route approvals across relevant functions and retain governance, risk, and compliance (GRC) records.
Agent Permission Boundaries
Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).
Agent Kill Switch and Emergency Stop
Maintain an immediate stop for any agent session, workflow, or type of agent. It must work without agent cooperation and support recovery to a known-safe state.
Self-Hosted Open-Weight AI Model Governance
Set intake rules for AI model files (weights) downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.
AI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
National Security and Dual-Use AI Risk Assessment
Assess AI systems and research with both commercial and national security or weapons applications. Address export controls from the US Commerce Department's Bureau of Industry and Security (BIS), defense-related ITAR arms export duties, dual-use research protocols, and monitoring for foreign adversarial misuse.
Playbook guides
How do we intake and govern open-weight and self-hosted AI models?
Review open-weight models before downloading, fine-tuning, or self-hosting them. Set deployment and maintenance controls suited to those responsibilities.
How do we govern agentic coding assistants and AI developer tools?
Review coding assistants and AI developer tools before approval. Examine codebase access, data boundaries, and separate transmission and retention settings.
How do we comply with China's AI regulations?
Review requirements for AI services accessible in China. Cover CAC regulation, security assessments, content labels, and differences from Western approaches.
Status history
July 17, 2026· yellow to yellow
Added to Model Radar at launch given the combination of minimal-oversight agentic design, missing safety documentation, and immediate US regulatory scrutiny of Chinese open-weight models.
