NewsMacroUS Cyber Assessment Finds Moonshot AI's Kimi K3 Trails Top American AI Models

US Cyber Assessment Finds Moonshot AI's Kimi K3 Trails Top American AI Models

Author: BeInCrypto·

Key Takeaways

  • Kimi K3 scored 32% on ExploitBench, ahead of China’s GLM-5.2 but far below leading US models at about 76%.
  • On a simulated 32-step corporate network attack, Kimi K3 averaged step 17 and completed the full sequence once in 10 attempts.
  • The evaluation included caveats because Kimi K3 was only partially tested and US models were assessed with safety filters turned off.
  • CAISI said Kimi K3’s guardrails did not prevent attempts to build hacks or attack systems.
  • Washington has accused Moonshot of copying Anthropic’s Claude Fable 5 through distillation, a claim Anthropic supports.
US Cyber Assessment Finds Moonshot AI's Kimi K3 Trails Top American AI Models

The US government has conducted a cybersecurity evaluation of China's newest AI model, concluding that Moonshot AI's Kimi K3 falls significantly short of the best American models.

The Center for AI Standards and Innovation (CAISI), a US agency, carried out the tests in collaboration with a British partner. The results were released just one day after Washington accused Moonshot of building Kimi K3 using stolen US technology. Offensive cyber capabilities have become a priority focus for AI safety evaluations in both the US and UK, as governments assess whether frontier models could automate hacking tasks that currently require skilled human operators.

Kimi K3 Falls Short on US Cyber Benchmarks

The Commerce Department released the findings on Thursday, stating that Kimi K3 ranked well below top US models based on a joint assessment with British experts.

CAISI's latest blog post evaluates Kimi K3 and its cyber capabilities. Based on a preliminary cyber-focused evaluation, Kimi K3 performed significantly below the leading U.S. frontier AI models. — U.S. Department Commerce (@CommerceGov) July 23, 2026

Moonshot launched Kimi K3 on July 16. Demand was high enough that the company had to pause new signups within two days. The launch also sent tremors through US chip stocks and raised fresh questions about America's position in the global AI race.

One benchmark, called ExploitBench, uses real Chrome browser vulnerabilities developed by Carnegie Mellon University. Kimi K3 scored 32%, topping China's GLM-5.2 at 24%, but trailing the leading US models, which achieved approximately 76%.

The most difficult step involves taking full control of a target machine. Kimi K3 failed that step on all 41 tests, while the best US models succeeded on 20.

A second test, called The Last Ones, simulates an attack on a fake corporate network with 32 steps. A human expert typically needs about 20 hours to complete it. Kimi K3 reached step 17 on average, while the top US models reached step 28.5. Kimi K3 completed the entire sequence just once in 10 attempts, whereas the best US systems reportedly did so six or seven times.

The Gap May Appear Larger Than It Is

However, the numbers do not tell the whole story. The report's own fine print contains several caveats.

First, the US models were tested with their safety filters turned off, a setting that reveals their full capabilities. Public versions keep those filters active, meaning the US scores represent a best-case scenario rather than real-world performance.

The evaluation team also described the work as early and limited. Kimi K3 was scored on just one test, and only part of the full suite was run, making its rating uncertain. Some tests are private as well, meaning independent observers cannot verify the results.

There is also a fundamental mismatch in the comparison. Kimi K3 is an open model that anyone can download, whereas the US models are locked, proprietary systems. The UK institute has previously found that open models typically run four to seven months behind the best closed ones. CAISI said it will give Kimi K3 the full test only after Moonshot releases it to the public.

Furthermore, these tests are not real attacks. The simulated network had no human defenders and no alarms to trigger. Even so, Kimi K3 outperformed the previous top open model and did complete the full attack chain once.

The timing and institutional context also raise questions. CAISI was formerly known as the US AI Safety Institute before the Trump administration renamed it in June 2025. It operates within the same department that restricts US chip sales to China. Its report on a Chinese competitor arrived just a day after the theft allegation.

Weak Safeguards Raise Concerns

Low scores do not necessarily mean Kimi K3 is safe, however. The test found that its guardrails did not prevent it from attempting to build hacks or attack systems.

This finding is significant given what comes next. Moonshot plans to release the full model on July 27. Once released, it cannot be recalled — anyone can download it and strip away the safety filters. The irreversibility of open-weight releases has become a central issue in the US policy debate over whether powerful models should face release restrictions, a conversation that has intensified as Chinese labs increasingly publish capable open models despite American export controls on advanced chips.

The assessment also follows a theft allegation. Washington says Moonshot built Kimi K3 on stolen US AI technology. White House tech chief Michael Kratsios said the firm secretly copied Anthropic's Claude Fable 5 using a technique called distillation, which trains a new model on a stronger one's outputs.

Anthropic supports the claim. In February, the company traced over 3.4 million Claude chats to Moonshot through hundreds of fake accounts. Anthropic warned that copied models lose the safety controls of the original — the same vulnerability this test identified.

The US still spends 23 times more on AI than China, yet Chinese labs continue to close the gap. The definitive assessment will come when Kimi K3 goes public and independent experts can evaluate the claims themselves.