Omniscient
AllBulletinArticlesReviewsTakesCommentaryFeatured
Sign In

Omniscient

AI intelligence briefings, analysis, and commentary — delivered in broadsheet form.

By Noah Ogbi

Subscribe

Weekday briefings and flagship analysis, delivered to your inbox.

Sections

  • All
  • Bulletin
  • Articles
  • Reviews
  • Takes
  • Commentary

Topics

  • Industry Strategy
  • Anthropic
  • AI Policy
  • OpenAI
  • Research
  • Frontier Models
  • Compute Economics
  • Agents

Meta

  • About
  • Masthead
  • Standards
  • Corrections
  • RSS Feed
  • Privacy Policy
  • Terms of Service

Omniscient Media — made by ForeverBuilt, LLC.
© 2026 ForeverBuilt, LLC. All rights reserved.

  1. Home
  2. ›AI Policy
  3. ›Kimi K3 Isn't Free. It Just Looks That Way.

AI Policy

Vol. 1·Monday, July 20, 2026

Kimi K3 Isn't Free. It Just Looks That Way.

Kimi K3 is set to become the largest open-weight model ever released. What American labs say about how models like it are built, and what the US government found when it tested their predecessors, should give any American user pause.


Noah Ogbi8 min read

Tips, corrections, or questions? support@omniscient.media

TopicsAI PolicyAI SecurityDefense & National SecurityFrontier Models
CompaniesDeepSeekAlibabaAnthropicMoonshot AIOpenAI
Kimi K3 Isn't Free. It Just Looks That Way.

On July 17th, Moonshot AI unveiled a 2.8-trillion-parameter model it calls Kimi K3, one the company says can rival the top systems from OpenAI and Anthropic, and promised to release the weights, for free, on July 27th, at which point it would be the largest open-weight AI system ever distributed[1]. Five months earlier, Anthropic said it had traced 3.4 million conversational exchanges to Moonshot itself: fraudulent accounts, proxy networks, and a systematic campaign to extract Claude's reasoning by asking it, over and over, to show its work[2]. Anthropic has not verified that K3 specifically was built on that extracted data; what it published is a pattern of Moonshot's conduct five months before K3 was unveiled, not a lab report on this particular model. But nobody has to guess how Moonshot operates. Anthropic already published the receipts on that.

That is the case against comfort, stated carefully: the open-weight models arriving out of China this year are not simply capable systems on a rival's release schedule. According to Anthropic and OpenAI, the companies building them have done three things. They've run sustained campaigns to extract capability from American labs without consent. They've wrapped some of what results in a censorship layer answerable to Beijing rather than to the user. And they've handed the finished models out at no cost, because giving away what you didn't fully pay to build is the cheapest form of soft power there is. Whether that specific pipeline produced K3 is inference from a documented pattern, not a confirmed fact about K3 itself; the distinction matters. Keep that in mind while we work through everything that follows.

What did Anthropic and OpenAI actually find in their own logs?

Start with the word, because it's carrying a lot of weight. Distillation is just training a smaller or newer model on the outputs of a stronger one, and it's a routine, legitimate technique. Frontier labs distill their own flagship models into cheaper customer variants all the time[2]. What Anthropic described in February wasn't that. It was DeepSeek, Moonshot, and MiniMax running what the company called "hydra cluster" operations: roughly 24,000 fraudulent accounts, more than 16 million exchanges with Claude, all built to slip past the regional access restrictions Anthropic places on China[2].

Look at what each one was after. DeepSeek's 150,000-exchange campaign asked Claude to narrate its own reasoning step by step (in effect, manufacturing chain-of-thought training data), and separately generated "censorship-safe alternatives to politically sensitive queries" to teach its own model to steer around dissidents and party leaders[2]. Moonshot's was bigger: 3.4 million exchanges aimed at agentic reasoning, tool use, and computer vision, with the request metadata traced back to the public profiles of senior Moonshot staff[2]. That one ran and was caught roughly five months before K3's unveiling. Anthropic's report describes the operation; it does not confirm a link between the extracted data and K3's specific weights. MiniMax's 13-million-exchange campaign was still live when Anthropic caught it, and when Anthropic shipped a new model mid-campaign, MiniMax swung nearly half its traffic to the newer system inside 24 hours[2].

OpenAI told the House Select Committee on the Chinese Communist Party essentially the same story that same month, in its own words: DeepSeek employees developing methods "to circumvent OpenAI's access restrictions," reaching frontier models "through obfuscated third-party routers," and building multi-stage pipelines that blend synthetic data generation with reinforcement-style preference optimization[3]. OpenAI's framing was blunt: "DeepSeek's next model (whatever its form) should be understood in the context of its ongoing efforts to free-ride on the capabilities developed by OpenAI and other US frontier labs"[3]. Two competitors describing the same behavior independently isn't proof beyond doubt. But it's a pattern neither company had any commercial reason to invent, and one that predates K3 rather than sitting verified inside it.

What happens once independent testers actually run these models?

The distillation allegations describe how these models were built. But how do they behave once they're actually running? The Commerce Department's Center for AI Standards and Innovation (CAISI) set out to measure exactly that. Its September 2025 evaluation pitted DeepSeek's R1, R1-0528, and V3.1 against US reference models, and the numbers are hard to wave off. DeepSeek's most secure model was, on average, 12 times more likely than frontier US models to follow malicious instructions, the kind designed to hijack an agent into sending phishing emails, running malware, or exfiltrating login credentials in a simulated environment[4]. Against a common jailbreak, it complied with 94% of overtly malicious requests. The US reference models: 8%[4]. CAISI also found DeepSeek's models echoed four times as many inaccurate or misleading CCP narratives as the US models did[4]. None of it slowed adoption. Downloads of DeepSeek models rose nearly 1,000% in the months after R1's release[4]. One caveat is worth holding onto here: no independent government lab has yet run K3 through the same battery of tests. These numbers describe DeepSeek's models, not Moonshot's. When a lab does put K3 on the bench, you'll read the results here, either as an update to this piece or a follow-up to it.

CAISI's follow-up on DeepSeek V4 Pro this May found the capability gap narrowing, on paper and in practice. On CAISI's own held-out benchmarks, V4 landed closer to GPT-5, a model roughly eight months its senior, than to the frontier systems DeepSeek's marketing compared it against[5]. It was, however, meaningfully cheaper, undercutting the closest comparable US model on five of seven benchmarks[5]. And that's the trade sitting in front of every American developer: pay more for a system whose security and behavior an independent US government lab has actually measured, or pay less for one from the same ecosystem CAISI has already flagged as far more exploitable. Cheaper is a real number. So is 94%.

There's one of these every weekday.

The Omniscient Bulletin turns the day's AI news into 5 to 7 items with the take, not the recap. Free.

Why does it matter that Beijing wants to lock its own "open" models down?

If the openness of these models were purely a gift to the world, Beijing would have no reason to restrict it. It's restricting it. Reuters reported this month that Chinese authorities have spent the past month meeting with Alibaba, ByteDance, and Z.ai to discuss curbing overseas access to the country's most advanced AI models, including some not yet released, mirroring the logic of the very US export-control regime it's nominally racing against[6]. A state that treats its own frontier weights as a strategic asset worth rationing does not regard those weights as a neutral public good once they cross its border. Whatever comfort a downloadable file offers, the government standing behind the company that built it doesn't seem to share it.

That posture lines up with what OpenAI told Congress about the ecosystem these models grow out of: state subsidies and preferential procurement after the CCP elevated AI to a national-modernization priority at the Fourth Plenum in October 2025, plus Cybersecurity Law amendments, effective January 1, 2026, that formalize state support for foundational AI research and compute buildout[3]. The memo goes further. It describes DeepSeek's censorship as trained into the weights during post-training, not merely bolted on at the server: refusals on subjects like Tiananmen Square and Taiwan independence that travel with a downloaded copy[3]. And on the hosted app sits a second, far more visible layer: a server-side filter users have caught in the act, generating a real answer on Xinjiang or the South China Sea, then deleting it mid-response and swapping in a refusal[3].

Does running the weights locally solve the problem?

So download the weights, run them offline, problem solved? Partly. It does remove one layer of exposure: South Korea's privacy regulator found DeepSeek's hosted app had been shipping user data to a Chinese cloud firm it identified as an affiliate of ByteDance, TikTok's parent (though it noted the firm is a separate legal entity), and pulled the app from local stores[7]. A locally hosted copy doesn't phone home the way a hosted app can. What it can't do is touch the other layer OpenAI described: the bias and refusal patterns trained directly into the weights during post-training survive the download intact, no server connection required[3]. And auditability isn't the same as an audit. "Open weight" means a developer can inspect and run the parameters; it does not mean anyone outside the lab can see the training data, the reward model, or the instructions given to the human raters who shaped its refusals. An open file is not the same as an open process.

Is adoption already outrunning the caution?

We're now at a point where this isn't a fringe debate. Alibaba's Qwen family has passed 700 million downloads on Hugging Face, the most-downloaded open-source model family in the world as of January 2026[8]. Think about what each of those downloads represents: a developer or a company deciding that whatever's baked into the weights, whether that's extracted Claude reasoning or a classifier tuned to CCP sensitivities, is an acceptable price for a free, capable model. And K3 is about to land straight into that appetite, weights due July 27th. It's the clearest sign yet that benchmark score and price will win the argument over provenance all over again, whatever the unverified specifics of its own training run turn out to be.

The risk in the reading

A fair reader should push back on all of this, so let's do it here. The case rests heavily on claims from parties with an obvious interest in making them. Anthropic and OpenAI compete directly with the labs they're accusing, and both are on record backing the export controls that distillation is said to undermine; their attributions, however detailed, are "high confidence" assessments made unilaterally, not findings verified by an independent third party. Neither company's findings describe K3 itself. Both predate it by months, and the link drawn here is a pattern-based inference, not a confirmed chain of custody. CAISI's evaluation carries its own asterisk: it was run by a body this administration explicitly repositioned as "pro-innovation, pro-science," and the Commerce Secretary announced the results by declaring that "American AI dominates" - real methodology producing real numbers, but released inside a stated political mandate. Distillation, remember, is neither illegal nor uniquely Chinese; US firms distill each other's outputs too, and not every developer named here carries the same weight of evidence. Qwen, the model with by far the largest American footprint, doesn't appear in Anthropic's distillation findings at all. Hold all of that alongside the numbers above, not instead of them.


Sources

  1. BBC News: "China's Moonshot AI claims Kimi K3 can rival OpenAI and Anthropic" Inline ↗

  2. Anthropic: "Detecting and preventing distillation attacks," Feb. 23, 2026 Inline ↗

  3. OpenAI memo to the US House Select Committee on the CCP, "Updated Stakes for American-Led, Democratic AI," Feb. 12, 2026 Inline ↗

  4. NIST/CAISI: "Evaluation of DeepSeek AI Models Finds Shortcomings and Risks," Sept. 30, 2025 Inline ↗

  5. NIST/CAISI: "Evaluation of DeepSeek V4 Pro," May 1, 2026 Inline ↗

  6. Reuters: "Beijing is looking at curbing overseas access to China's top AI models, sources say," July 7, 2026 Inline ↗

  7. BBC News: "DeepSeek 'shared user data' with TikTok owner ByteDance" Inline ↗

  8. Tech in Asia: "Alibaba's Qwen AI tops 700 million downloads on Hugging Face" Inline ↗

Share:

Get this every weekday.

The Omniscient Bulletin: consequential AI, explained and evaluated. 5 to 7 items a day with the take, not the recap.

Discussion


Sign in to join the discussion.


Related

AI Policy

Vol. 1·Monday, June 22, 2026

The Off Switch: How Washington Pulled a Frontier Model Offline Without a Law


The Off Switch: How Washington Pulled a Frontier Model Offline Without a Law

Ten days after the US Commerce Department used a private export-control letter to pull Anthropic's Fable 5 and Mythos 5 offline worldwide, neither model is back. What began as a jailbreak dispute has become a structural standoff - and the rough outline of an ad hoc licensing regime for frontier AI.


AI PolicyAI SecurityAnthropic
Noah Ogbi8 min read
Continue →

AI Research

Vol. 1·Thursday, June 11, 2026

Inside Claude Fable 5: Anthropic's Most Powerful Public Model - and Its Most Asterisked One


Inside Claude Fable 5: Anthropic's Most Powerful Public Model - and Its Most Asterisked One

Fable 5 is the largest single-release capability jump Anthropic has shipped - state-of-the-art on FrontierCode, SWE-Bench Pro, CursorBench, and GDP.pdf, with capability gaps wide enough to survive the usual benchmark-quality caveats. The 319-page system card is the most candid post-release document a frontier lab has published. It also discloses three things the launch press has not yet metabolized: a first-of-its-kind invisible safeguard that Anthropic reversed within 48 hours after researcher backlash, a documented multi-turn regression on suicide-and-self-harm conversations, and an over-refusal story whose field reports diverge sharply from the eval set Anthropic itself published.


AI PolicyIndustry StrategyAnthropic
Noah Ogbi19 min read
Continue →

AI Research

Vol. 1·Monday, June 22, 2026

Inside GPT-5.5-Cyber: The Opposite Bet to Anthropic's Fable 5


Inside GPT-5.5-Cyber: The Opposite Bet to Anthropic's Fable 5

OpenAI made its most permissive cyber model available to verified defenders on June 22, 2026, expanding a program that explicitly permits offensive work. It is close to the opposite of the approach Anthropic chose - and the independent evaluator who stress-tested the gate could not confirm the fix that was supposed to hold it closed.


AI SecurityOpenAIDefense & National Security
Noah Ogbi18 min read
Continue →