Moonshot AI
Kimi K3
vK3 · open-weights · Released July 17, 2026
Updated July 25, 2026
2.8T-parameter open-weight model from Chinese developer Moonshot AI. UK AISI and CAISI found built-in safeguards failed to block offensive cyber attempts ahead of the July 27 open-weight release. No technical safety report was published at launch, and Chinese-origin open-source AI is now under active US sanctions and export-control scrutiny.
Enterprise guidance
Kimi K3 pairs a 1-million-token context window and native vision with explicit marketing for long-horizon autonomous coding under minimal human oversight, so agent permission boundary and kill-switch controls should be in place before any developer adoption begins. No vendor-published technical report or safety evaluation exists to support a standard risk assessment; the UK AISI/CAISI pre-release cyber assessment is the only independent safety signal currently available. Given active US Treasury scrutiny of Chinese open-source AI for IP theft and a revived executive push to restrict Chinese models, document the adoption decision now in case retroactive compliance obligations follow.
Active Compliance Flags5
UK AISI and CAISI jointly assessed Kimi K3 four days before its open-weight release and found its built-in safeguards did not prevent the model from attempting offensive cyber tasks. Self-hosted deployments inherit this gap with no managed-API safeguard layer.
Primary source →No full technical report, model card, or safety evaluation was published alongside the July 17 launch, leaving compliance teams unable to complete a structured risk assessment under frameworks such as California SB 53 or the EU GPAI transparency provisions before evaluation or deployment.
Primary source →US Treasury announced it will examine Chinese open-source AI developers for IP theft and may impose OFAC sanctions. Moonshot AI has not been named individually, but the review follows directly from the Kimi K3 launch and could create prohibited-counterparty exposure for adopters if a designation follows.
Primary source →The Trump administration is reportedly reviving efforts to restrict or ban Chinese-origin AI models following the Kimi K3 launch, citing cybersecurity concerns. Open weights already in public distribution make enforcement of any ban difficult, but formal action would still create retroactive compliance obligations for current adopters.
Primary source →Developed by Moonshot AI, a Chinese company. Hosted access via Kimi.com, Kimi Work, and Kimi Code is subject to Chinese data and national security law; self-hosting the open weights removes this data residency risk.
Primary source →Data handling
Default data retention
Hosted API: not published. Self-hosted: your own infrastructure.
Zero-retention available
NoNot available via hosted API. Self-host open weights for full data control.
API data used for training
YesMoonshot AI has not published an enterprise data processing agreement or training opt-out for hosted API access. Treat hosted-API usage as data-training-eligible until confirmed otherwise.
GDPR Data Processing Agreement
Not availableHIPAA Business Associate Agreement
Not availableNot available. Self-host and arrange a BAA with your cloud infrastructure provider.
Data residency options
Hosted API: not confirmed, likely China-based given developer jurisdiction. Self-hosted: your own infrastructure.
Vendor compliance certifications
Key use restrictions
- —Hosted API (Kimi.com/Kimi Work/Kimi Code): likely subject to Chinese data and national security law; not suitable for regulated or sensitive data
- —Self-hosted open weights (released July 27, 2026): recommended path for enterprise use pending a full technical report
- —No published technical report, model card, or third-party red-team results as of this review; treat capability and safety claims as unverified
- —UK AISI/CAISI found built-in safeguards did not block offensive cyber task attempts; self-hosted deployments inherit this gap with no managed-API safeguard layer
Safety documentation
No technical report, model card, or system card was published at the July 17 launch. UK AISI and CAISI ran an independent pre-release cyber-capability assessment, published July 23, and found that Kimi K3's built-in safeguards failed to block offensive cyber attempts.
Safety documentation →Related governance resources
Governance controls
AI System Intake and Approval Workflow
Define a standardized intake process for all new AI system deployments that captures use case, data classification, risk tier, and ownership before the system enters the organization's environment, with cross-functional approval routing and GRC recordkeeping.
Agent Permission Boundaries
Apply least-privilege principles to AI agents by explicitly defining and enforcing the tools, APIs, data sources, and actions each agent is authorized to access.
Agent Kill Switch and Emergency Stop
Maintain the operational capability to halt any running agent session, workflow, or agent class immediately — without relying on the agent itself to stop — and recover to a known-safe state.
Self-Hosted Open-Weight AI Model Governance
Establish an intake policy and governance controls for AI model weights downloaded from public repositories and deployed in the organization's own infrastructure, addressing integrity verification, license compliance, safety evaluation before deployment, and ongoing update management distinct from vendor-hosted AI procurement.
AI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
National Security and Dual-Use AI Risk Assessment
Establish a risk assessment process for AI systems and AI research activities that could constitute dual-use technology — with applications in both commercial and national security or weapons contexts — addressing BIS export control obligations, ITAR compliance for defense applications, dual-use research of concern protocols, and foreign adversarial misuse monitoring.
Playbook guides
How do we intake and govern open-weight and self-hosted AI models?
A governance framework for organizations that download, fine-tune, or self-host open-weight models — covering intake review, deployment controls, and ongoing maintenance obligations that differ from API-based vendor relationships.
How do we govern agentic coding assistants and AI developer tools?
A governance framework for evaluating, approving, and monitoring agentic coding assistants and AI developer tools, with specific focus on data boundary controls, the distinction between transmission and retention opt-outs, and the unique risks posed by tools that operate with codebase-level access.
How do we comply with China's AI regulations?
A compliance guide for organizations deploying AI systems accessible to users in China — covering the four-layer regulatory stack administered by the CAC, security assessment obligations, content labeling requirements, and the practical differences between China's framework and Western AI governance regimes.
Status history
July 17, 2026· yellow to yellow
Added to Model Radar at launch given the combination of minimal-oversight agentic design, missing safety documentation, and immediate US regulatory scrutiny of Chinese open-weight models.
