Chinese AI Model Kimi K3 Trails US Rivals in Cyberattack Capabilities, Joint UK-US Report Finds
En resumen
Chinese AI model Kimi K3 from Moonshot AI scored 32.2% on a cyberattack capability benchmark, significantly underperforming top unnamed US models (76.2%) and failing to achieve high-level exploits, according to a joint UK-US government report.
Resumen generado por IA
Por qué importa
Joint British-US government research evaluated Chinese AI model Kimi K3’s cyberattack capabilities using ExploitBench, a public benchmark for cybersecurity vulnerability exploits.
Chinese unicorn Moonshot AI’s Kimi K3 model trails far behind top American rivals in its ability to launch cyberattacks, joint British-US government research shows, challenging Washington’s brewing anxiety over the rapid rise of Chinese open-source artificial intelligence.
The model, currently considered China’s most powerful large language model, performs “significantly below the most recent frontier cyber-capable models”, according to a report published on Thursday by the UK Artificial Intelligence Security Institute (AISI) and the US Centre for AI Standards and Innovation (CAISI).
The AISI is a research arm under the UK Department for Science, Innovation and Technology, while the CAISI operates within the US Department of Commerce’s National Institute of Standards and Technology.
To evaluate capabilities, the two government bodies put Kimi K3 through ExploitBench, a public benchmark assessing an AI’s ability to develop exploits for cybersecurity vulnerabilities.
Kimi K3 achieved an overall score of 32.2 per cent, outperforming domestic rival Zhipu AI’s GLM-5.2 at 24.4 per cent, but lagging well behind top, unnamed US models that averaged 76.2 per cent.
Notably, Kimi K3 failed to achieve arbitrary code execution – the highest-level exploit granting full control of a target system – across all 41 ExploitBench tasks, whereas leading US models achieved it on 20 tasks.
Preguntas abiertas
- What are the names of the top US models?
- How will China react to the report's findings?
- What specific vulnerabilities did Kimi K3 fail to exploit?







