Strategic Report  ·  2026-07-30

UK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber Capabilities

Strategic ReportHigh impactChina
The UK AI Security Institute (AISI) and the US Center for AI Standards and Innovation (CAISI) jointly evaluated Moonshot AI's Kimi K3 model (released July 16, 2026; open-weighted July 27, 2026), finding it 'performs below leading US frontier models on our preliminary cyber evaluations.' On the ExploitBench benchmark, Kimi K3 scored 32% (versus GLM-5.2's 24%, the previous most cyber-capable open-weight model) but achieved arbitrary code execution (the highest-severity exploit outcome) on 0 of 41 samples; on a 32-step simulated corporate-network attack ('The Last Ones'), it reached step 17 on average. Critically, the evaluators found Kimi K3's safeguards 'did not prevent it from attempting cyber exploit development or offensive cyber operations during our evaluations' — a first-disclosure safeguard failure finding. Methodology used an Item Response Theory-inspired aggregation approach across public and private benchmarks, with results explicitly flagged as preliminary and likely to underestimate true open-weight capability.
This is a first-of-its-kind joint UK-US government technical assessment quantifying the US-China frontier AI cyber-capability gap and disclosing that a released Chinese model's safety guardrails failed to block offensive cyber operation attempts during testing — directly relevant to CISOs assessing dual-use model risk and to policymakers weighing export-control and open-weight policy.
Brief security leadership on the open-weight cyber capability gap and update AI-in-the-loop threat models to account for models with permissive safeguards attempting offensive cyber tasks.
AISI: UK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber CapabilitiesNIST: UK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber Capabilities
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →