UK and US AI Safety Institutes Find Kimi K3 Nears Frontier in Cyber Capabilities, But Lags in Exploit Execution
AI News

UK and US AI Safety Institutes Find Kimi K3 Nears Frontier in Cyber Capabilities, But Lags in Exploit Execution

6 min
7/25/2026
AI SecurityCyber CapabilitiesKimi K3Moonshot AI

Introduction: A New Benchmark in Open-Weight Cyber Capability

A joint evaluation by the UK Artificial Intelligence Security Institute (UK AISI) and the U.S. Center for AI Standards and Innovation (CAISI) has shed new light on the cyber capabilities of Moonshot AI's latest open-weight model, Kimi K3. Released on July 16, 2026, and slated for open-weight release by July 27, 2026, the model has already stirred significant debate within the tech and security communities.

The preliminary assessment, published on NIST's website, focuses on Kimi K3's ability to develop exploits and conduct autonomous cyberattacks. The findings place the model in a unique position: it outperforms all previous open-weight models but still lags behind the most capable U.S. closed-weight frontier systems in critical areas.

Exploit Development: Outperforming Open-Weight Rivals, But Failing at the Final Hurdle

The core of the evaluation centered on ExploitBench, a public benchmark developed by Carnegie Mellon University that measures a model's ability to progress through the software exploitation ladder. This includes steps like coverage and crash reproduction, arbitrary read/write, control flow hijack, and arbitrary code execution (ACE). The benchmark tested models on 41 recent (post-2023) vulnerabilities in the V8 engine, which powers Chrome.

Kimi K3 achieved a score of 32% on ExploitBench, outperforming GLM-5.2, the most cyber-capable open-weight model as of June 2026, which scored 24%. However, the most striking finding was that Kimi K3 failed to develop exploits that achieved arbitrary code execution (ACE) on any of the 41 samples. ACE is the highest-severity outcome, granting attackers the ability to hijack a target system completely. In contrast, the most cyber-capable U.S. closed-weight models achieved ACE on an average of 20 out of 41 samples.

This indicates that while Kimi K3 can navigate the early and middle stages of exploit development effectively, it struggles with the final, most critical step. The UK AISI and CAISI note that the model's overall cyber capability score has a larger confidence interval than other models because it was estimated from a single benchmark (ExploitBench) with 41 tasks, whereas other models were evaluated across a broader set of domains.

Autonomous Cyberattack: A Success in One Out of Ten Attempts

The evaluation also included a test on a cyber range called "The Last Ones" (TLO), a 32-step simulated corporate network attack spanning 4 subnets and approximately 20 hosts. This scenario, which would take a human expert roughly 20 hours to complete, measures a model's ability to conduct end-to-end cyberattacks autonomously.

On average, Kimi K3 reached step 17 of the 32-step attack path, significantly below the leading U.S. cyber-capable models, which averaged 28.5 steps. However, the model outperformed GLM-5.2, which only reached step 11 on average. In a notable outlier, Kimi K3 successfully completed the entire TLO cyber range in one out of ten attempts within the 100 million token limit. This demonstrates that the model is capable of autonomously attacking small, weakly defended, and vulnerable enterprise systems when given initial network access and directed to do so.

The evaluators caution that TLO differs from real-world environments in several critical ways: it lacks active defenders and defensive tooling, imposes no penalty for actions that would trigger security alerts, and contains an intentional attack path. Despite these caveats, the fact that Kimi K3 solved TLO at all is significant. Prior testing showed that only four publicly released closed-weight models had solved TLO, with the most capable models solving it more reliably at 6/10 and 7/10 attempts. Kimi K3's 1/10 success rate places it in a new category of open-weight models capable of autonomous cyberattacks.

continue reading below...

Broader Implications: A Pattern of Chinese AI Progress

The findings from the UK AISI and CAISI align with independent assessments from other organizations. Swiss firm Aikido Security reported that Kimi K3 discovered 23 out of 26 known vulnerabilities in a private test, matching the performance of OpenAI's mid-tier GPT-5.6 Terra while running at a quarter of the cost of the flagship Sol model. Aikido researcher Philippe Dourassov noted that the performance reflects "a very big jump in Kimi models' capabilities" and that "open-source models are no longer behind."

The model's capabilities are renewing questions about the effectiveness of U.S. tech export curbs. Analysts point out that Kimi K3 challenges the industry belief that leading-edge AI requires heavy spending on data centers and advanced chips, which the U.S. has restricted. Moonshot AI has denied suggestions that it used American models to train Kimi K3.

Wei Sun, principal AI analyst at Counterpoint Research, said the general gap between Chinese and American models has narrowed to three to six months, though it varies significantly by task. The broader significance, as one analyst noted, is that "DeepSeek increasingly looks like the beginning of a pattern. DeepSeek was a surprise. K3 is evidence that China's progress is becoming more repeatable."

Market Impact and Demand Surge

The release of Kimi K3 has not gone unnoticed by the market. The model's popularity surged so quickly that Moonshot AI had to suspend new subscriptions due to overwhelming demand. Lian Jye Su, a chief analyst at Omdia, noted that the suspension likely stems from Moonshot not fully anticipating the surge in popularity and the model's demanding compute requirements. By measure of front-end coding capability, Kimi K3 topped the chart on the Arena evaluation platform after its public release.

The combination of open-weight availability and near-frontier performance positions Kimi K3 for wider adoption globally, particularly among organizations that value the ability to self-host models and retain control over sensitive data. This contrasts with most American proprietary models, which sit behind paid subscriptions and are subject to stricter usage controls.

Conclusion: A Wake-Up Call for AI Security

The joint UK AISI and CAISI assessment of Kimi K3 provides a nuanced picture of the current state of AI cyber capabilities. While the model does not yet match the most capable U.S. closed-weight systems in the most critical exploit development tasks, its performance represents a significant leap for open-weight models. The fact that it can autonomously attack a simulated corporate network, even if only in one out of ten attempts, underscores the growing security risks posed by open-weight models.

As the gap between Chinese and American AI models continues to narrow, and as open-weight models become more capable, the findings from this assessment will likely inform ongoing policy debates about AI safety, export controls, and the need for robust security measures. The era where frontier cyber capabilities were exclusive to a small set of carefully controlled models is clearly coming to an end.