Topic · 11 stories
Kimi: Moonshot AI models and latest news
In short
Kimi is a family of large language models and an AI assistant from the Chinese company Moonshot AI. Its newest model, Kimi K3, launched on 17 July 2026 as an open 2.8-trillion-parameter model with a 1 million token context, and its weights reached Hugging Face in late July. It rivals top Western models on many benchmarks but trails them badly on offensive cyber skills.
What is Kimi
Kimi is a family of large language models and an AI assistant from the Chinese company Moonshot AI, a Beijing-based startup backed by Alibaba. After the release of DeepSeek R1, Kimi’s user rank fell, which pushed Moonshot AI to pivot from proprietary to open-source models, a path that ended in K3. Today Kimi is one of the main Chinese open-weights families, alongside Qwen and GLM: the weights can be downloaded and run yourself.
Which Kimi models exist
The newest and main model is Kimi K3, released on 17 July 2026. Moonshot AI launched it as the largest open model ever: 2.8 trillion parameters (another report says 2.88 trillion), a 1 million token context, native visual understanding and an always-on thinking mode. The model card on Hugging Face lists 2.8 trillion total parameters with 104 billion activated, built on Kimi Delta Attention. K3 uses a mixture-of-experts design that the company says delivers 2.5 times more intelligence per unit of compute.
Before K3 came the K2 series. Kimi K2.7 from June has 1 trillion parameters, 32 billion active, a 256k context and a modified MIT license. A day later came coverage of K2.7 Code, a variant for programming tasks, with a 262,000 token context and 260 tokens per second in high-speed mode. A quantized version shrinks it to 325 GB.
Moonshot AI also publishes benchmarks. In August it introduced PerceptionBench, which isolates visual perception. Among 16 frontier models GPT-5.6 Sol scored highest at 59.7 percent, Kimi K3 followed at 58.5 percent, and none broke 60.
Is Kimi as good as US models
On many tests yes, but not on cybersecurity. At launch K3 ranked third overall behind Claude Fable 5 Max and GPT-5.6 Sol Max, and first on several task automation benchmarks including BrowseComp and Frontend Code Arena. Since its mid-July announcement its results have stayed close to Fable 5 and GPT-5.6 Sol at a slightly lower cost.
A Frontier Radar analysis found that Chinese open-weights models from Moonshot, Alibaba and Z.ai now sit near the top of almost every demanding benchmark. At launch Artificial Analysis had K3 third on its Intelligence Index with 57 points, behind GPT-5.5 and Opus 4.8; Anthropic’s Opus 5 later retook the top with 61. Three Western advantages remain measurable. On abstract specialty tests such as ARC-AGI-2 the gap widens to 60.4 versus 89.2 percent. On reliability, K3 is the best open model on AA-AnalystAgent at 39 percent while Opus 5 leads with 54. And in cyber, a joint UK AISI and US CAISI assessment gave K3 32 percent on ExploitBench versus about 76 for top US models, and K3 failed all 41 tasks that required executing code on a target.
Two accusations hang over Chinese labs: that they used Western models as teachers through distillation, and that they tune for benchmarks without matching breadth, called benchmaxxing. An independent test of the K3 weights found cyber and math skills far behind frontier models, and the report says both gaps could suggest distillation.
How much does Kimi cost and is it free
Kimi K3 costs $3 per million input tokens and $15 per million output tokens through the API. Prices from Moonshot AI’s official pricing page (as of 10 October 2026, USD per million tokens):
| Model | Input, cache hit | Input, cache miss | Output | Context |
|---|---|---|---|---|
| kimi-k3 | 0.30 | 3.00 | 15.00 | 1,048,576 |
| kimi-k2.7-code | 0.19 | 0.95 | 4.00 | 262,144 |
| kimi-k2.7-code-highspeed | 0.38 | 1.90 | 8.00 | 262,144 |
| kimi-k2.6 | 0.16 | 0.95 | 4.00 | 262,144 |
For kimi-k3 cache writes are billed separately: $3 per million tokens for a 5-minute lifetime and $6 for one hour. The K3 prices match those announced at launch on 17 July. The official kimi.com homepage does not mention a free plan or paid membership, so I do not describe one. You can download the weights free of charge under the license terms below.
Is Kimi open source
The weights are open, but under a custom license rather than plain MIT. Moonshot AI published the K3 weights on Hugging Face with parts of its infrastructure: high-performance attention kernels and an MoE communication library. The official model card on Hugging Face (as of 10 October 2026) says the code and weights are released under the Kimi K3 License. The terms, as reported on 29 July: free access for individuals and small organizations, while commercial entities with over $20 million in annual revenue or more than 100 million users need a commercial license. I did not read the license text itself.
Open weights have practical effects. Cognition post-trained SWE-2 from K3, but SWE-2 itself has no open weights and no standalone API. For the wider risks of such models see open-weight model security.
Is Kimi safe
There is one documented flaw and no known exploitation. RuntimeWire found that the group chat updater in Kimi Desktop installs unverified code. It fetches a separate 19.7 MB Group Chat executable from a mutable CDN location. On Windows it replaces that file without checking a checksum or the publisher signature, even though the current file carries a valid Moonshot Authenticode signature. The ZIP archive ships without a checksum file. Someone with access to the publishing path or release process could substitute their own code. RuntimeWire found no evidence of active compromise.
The second question is political. The Trump administration reportedly favors targeted bans on specific Chinese open-weight models over a blanket ban, citing national security, according to The New York Times. See US restrictions on Chinese AI models. The same report notes that even Kimi K3 trails leading Western models by a wide margin on cybersecurity benchmarks.
Who owns Kimi and who builds on it
Kimi is built by Moonshot AI, founded in 2023 by Yang Zhilin, formerly at Google and Meta. As of 17 July 2026 it had raised about $1.5 billion at a valuation climbing to $4.3 billion. Others build on its models, first in coding: on 14 September Cognition, the company behind Devin, released SWE-2, a model post-trained from Kimi K3. It scored 50.0 percent on FrontierCode 1.1 Main against 44.2 for K3 itself and 50.9 for Fable 5.1, at 64 percent lower cost, and 92.8 percent on Terminal-Bench 2.1. The weak spot is Terminal-Bench 4: 27.3 percent versus 55.8 for Fable 5.1. FrontierCode is Cognition’s own benchmark, and all rival numbers come from its evaluation. SWE-2 runs only inside Devin and is free for paid tiers through 10 October 2026.
The second use is security. A volunteer group of 20-25 people, the Bitcoin Red Team, hunts AI-assisted threats in the Bitcoin ecosystem. One member said the arrival of Kimi K3 gave attackers and defenders unprecedented power. The group uses Chinese models far more than US ones because guardrails on American models can block security research. Context: crypto security.
What it means for you
- For coding and agent tasks K3 is a real cheaper alternative at $3 per million input tokens and a 1 million token context. Test it on your own tasks, because vendor and third-party benchmarks differ.
- Do not assume Western-level results in cybersecurity or math: independent tests showed large gaps.
- If you use Kimi Desktop on Windows, take updates only from official sources. The group chat updater flaw is documented, with no known abuse.
- Before commercial use, read the Kimi K3 License: the $20 million revenue and 100 million user thresholds change your terms.
Still open: whether the US adopts selective bans on Chinese open-weight models, whether the distillation and benchmaxxing accusations hold up, and whether Kimi keeps its prices as competition grows.
Key facts
- Cognition released SWE-2, a coding model post-trained from Kimi K3. It scores 50.0 percent on FrontierCode 1.1 Main, within one point of Fable 5.1 at 64 percent lower cost. (source)
- Bitcoin Red Team, a group of 20-25 volunteers, hunts AI-assisted threats in the Bitcoin ecosystem and relies mainly on Chinese models, including Kimi K3. (source)
- On ExploitBench, a joint UK AISI and US CAISI assessment gave Kimi K3 32 percent against about 76 for top US models. K3 failed all 41 tasks that required executing code on a target. (source)
- Kimi Desktop's group chat updater installs an executable from a mutable CDN without checking a checksum or signature. RuntimeWire found no evidence of active compromise. (source)
- Kimi K3's license gives free access to individuals and small organizations. Companies above $20 million in annual revenue or 100 million users need a commercial license. (source)
- Moonshot AI released the Kimi K3 weights on Hugging Face with attention kernels and an MoE communication library. An independent test found its cyber and math skills far behind frontier models. (source)
- Kimi K3 launched with 2.8 trillion parameters, a 1 million token context and an always-on thinking mode. API pricing is $3 per million input tokens and $15 per million output. (source)
- Kimi K2.7 has 1 trillion parameters, 32 billion active, a 256k context and a modified MIT license. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Cognition releases SWE-2 coding model built on Kimi K3 AI
- Bitcoin Red Team Forms to Fight AI-Assisted Security Threats Security
- China’s AI lead narrows as Western models keep edge in cyber and reliability AI
- Kimi Desktop Updater Installs Unverified Code from Mutable CDN Security
- New PerceptionBench benchmark shows AI models still fail at visual perception AI
- Moonshot AI releases Kimi K3, the largest open-source model with 2.88 trillion parameters AI
- Moonshot AI Releases Kimi K3 Open Weights, Raising Distillation Questions AI
- US Favors Selective Bans on Chinese Open Weight AI Models Over Blanket Restrictions AI
- Moonshot AI Releases Kimi K3, 2.8-Trillion-Parameter Open-Source Model Rivaling Top US Systems AI
- Kimi K2.7 Code: Moonshot AI’s open-source challenger to GPT-5.5 AI
Show older (1 story)
FAQ
What is Kimi AI?
Kimi is a family of large language models and an AI assistant from the Chinese company Moonshot AI. Its newest model, Kimi K3, launched on 17 July 2026 with 2.8 trillion parameters, a 1 million token context and native image understanding. The weights are open.
Is Kimi AI safe?
There is one documented flaw and no known exploitation. On 19 August 2026 RuntimeWire reported that the group chat updater in Kimi Desktop installs a Windows executable without checking its checksum or publisher signature, and it found no evidence of active compromise. Separately, K3 scored 32 percent on ExploitBench against about 76 for top US models.
Who owns Kimi AI?
Kimi is built by Moonshot AI, a Beijing-based startup backed by Alibaba. Yang Zhilin, formerly at Google and Meta, founded it in 2023. As of 17 July 2026 it had raised about $1.5 billion at a valuation climbing to $4.3 billion.
Is Kimi AI good?
On benchmarks, yes. At launch K3 ranked third on the Artificial Analysis Intelligence Index with 57 points, behind GPT-5.5 and Opus 4.8, and Opus 5 later retook the lead with 61. It is the best open model on the AA-AnalystAgent reliability test at 39 percent, against 54 percent for Opus 5 (21 August 2026).
How much does Kimi K3 cost?
Through the API, $3 per million input tokens, $15 per million output tokens and $0.30 per million cached input tokens. Those are the rates on Moonshot AI's official pricing page (as of 10 October 2026). The older kimi-k2.7-code costs $0.95 input and $4 output per million tokens.
Is Kimi K3 open source?
The weights are open, but under a custom license, not plain MIT. Moonshot AI published them on Hugging Face in late July 2026 under the Kimi K3 License. Per a 29 July report it is free for individuals and small organizations, while companies above $20 million in annual revenue or 100 million users need a commercial license.