Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeEvaluation & SafetyKimi K3 assessment
Evaluation & Safety

First joint UK-US assessment finds Kimi K3 far behind US models on offensive cyber

UK AISI and US CAISI find Moonshot's flagship trails the most cyber-capable US models on every benchmark they ran, hours before its open weights become permanent.

AJ
Andrew Jamerson
Founding Editor
Jul 26, 2026 · 5 min read
Two governments, one preliminary verdict: Kimi K3 stalls at step 17 of a 32-step attack path. // GaaS News

The UK AI Security Institute and the US Center for AI Standards and Innovation published a joint preliminary assessment of Moonshot AI's Kimi K3 on Thursday, the first joint UK-US government evaluation of a Chinese frontier model. The finding: K3 trails the most cyber-capable US closed-weight models by a wide margin, completing zero of 41 exploit development tasks end to end where leading US models averaged 20 of 41, and stalling at step 17 of a 32-step simulated attack path where US models averaged 28.5 steps.

The numbers

The sharpest gap is on ExploitBench, a benchmark that measures whether a model can produce working exploits. "Kimi K3 achieved ACE on 0/41 samples, whereas the most cyber-capable models achieved ACE on 20/41 samples on average," the assessment states, referring to arbitrary code execution, the benchmark's highest bar. Overall, K3 scored 32.2 percent on the benchmark against a 76.2 percent average for the leading US models, per figures reported by The Decoder; the assessment notes that another Chinese model, GLM-5.2, scored around 24 percent.

On the simulated network attack, K3 reached step 17 of 32 on average and completed the full path in one of ten attempts, per The Decoder's account. The institutes do not name the US comparison models, referring only to the most cyber-capable US models, and both stress that the results are preliminary, drawn from a small set of public and private benchmarks, per the NIST announcement.

Safeguards did not hold

The finding with the most policy weight is not the capability gap but the guardrail failure. "Kimi K3's safeguards did not prevent it from attempting cyber exploit development or offensive cyber operations" during the evaluations, the assessment states. A model that trails the frontier but attempts offensive operations on request presents a different risk profile from a stronger model that refuses. That combination, weak safeguards attached to freely distributable weights, is the scenario flagged in AISI's earlier report on the open-weight cyber gap.

The distillation hypothesis

Why would a model that rivals Western systems on standard benchmarks lag this far on exploitation? The Decoder points to distillation. White House science adviser Michael Kratsios has accused Moonshot of distilling Anthropic's models, and if K3 learned primarily from Claude outputs it would have inherited little offensive cyber skill, The Decoder notes, because Anthropic's safety classifiers specifically block advanced offensive cyber queries. The hypothesis is unproven, and the assessment itself does not address training provenance.

Hours until the weights are permanent

K3 launched as a hosted model on July 16; the assessment notes it is slated for open-weight release by July 27, and the release is expected Sunday night, as our preview of the K3 weights drop details. Once the weights are public, whatever capabilities they carry cannot be recalled or patched from the outside, and whoever downloads them can strip away the safeguards that remain.

The numbers give Washington its first government-stamped measurement of the gap between a Chinese open model and the US frontier in an offensive domain, and they cut both ways politically. Restriction advocates can point to safeguards that did not hold; open-weight defenders can point to a capability gap wide enough that zero of 41 exploit tasks were completed. Both camps are already quoting it in the fight covered in our report on lab lobbying against open weights.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.