Kimi K3 Cybersecurity Test Scores Approach GPT-5.6, Sparking U.S. AI Regulation Debate
0xBroomberg
Moonshot AI's open-source Kimi K3 detected 23 of 26 known vulnerabilities — matching OpenAI's mid-tier GPT-5.6 Terra at one-quarter the cost of the flagship Sol — forcing Washington to confront whether safety guardrails on US models are handing Chinese rivals a competitive edge.
What exactly did this test measure?
Swiss cybersecurity firm Aikido Security tested leading AI models against 26 known, recently disclosed vulnerabilities, scoring detection rate and cost efficiency.
The key design choice: all vulnerabilities were recent. This means → models could not have memorized them from training data — the test measured genuine reasoning ability.
Kimi K3 — Moonshot AI's 2.8-trillion-parameter open-source model — detected 23 out of 26, matching OpenAI's mid-tier GPT-5.6 Terra.
How much cheaper — and why does that matter?
Kimi K3's running cost is one-quarter that of OpenAI's flagship GPT-5.6 Sol.
In plain terms = the same security scan costs four times more on Sol than on Kimi K3.
Aikido's report calls Kimi K3 the strongest open-weight model in cybersecurity, "far surpassing" Zhipu AI's GLM-5.2 released last month.
Vercel CEO Guillermo Rauch offered a calibration: Sol still leads "by an order of magnitude," but Kimi K3 is already a "top-tier" cybersecurity model — at a significantly lower price.
Open-source catching closed-source — why does it matter?
Aikido researcher Philippe Dourassov stated plainly: the results reflect a "major leap" in the Kimi family's capabilities — "open-source models are no longer behind closed-source ones."
This reflects a deeper shift — in cybersecurity, a field that demands strong reasoning, the ceiling for open-source models is rising fast.
This means → the default assumption that "closed-source = stronger" no longer holds, at least in the cybersecurity lane.
Why is Washington nervous?
The core tension: the US imposes safety guardrails on its top AI models, while Chinese open-source models keep closing the capability gap.
In plain terms = if America ties its own hands while rivals face no such constraints and keep improving, US firms risk falling behind.
Since Anthropic launched Claude Mythos in April, AI systems capable of autonomously finding and exploiting cyber vulnerabilities have advanced rapidly — this signals that the competitive landscape is shifting fast, and the policy window is narrowing.
Content is for reference only, not financial advice.