Report scores Kimi K3's cyber risk moderate
A joint UK AISI and US CAISI evaluation found Kimi K3 trails frontier US models on cyber tasks, but its safeguards didn't stop it attempting exploits.
The UK AI Security Institute and the US Center for AI Standards and Innovation (part of NIST) published a joint preliminary assessment of Kimi K3’s cyber capabilities on July 23. The evaluation found the open-weight model performs exploit development and network-attack simulation tasks at a moderate level, trailing frontier US systems by a clear margin. On ExploitBench, Kimi K3 hit 32% success on exploit-development tasks (ahead of GLM-5.2’s 24%) but achieved arbitrary code execution on 0 of 41 samples, versus an average of 20 of 41 for top models. On a 32-step attack-path cyber range, it averaged reaching step 17, against 28.5 steps for the most cyber-capable US models, succeeding at the full scenario in just 1 of 10 attempts.
The assessment’s other finding matters more than the benchmark gap: when researchers pushed on it, the model’s guardrails failed to stop it from making a run at building exploits or carrying out offensive cyber actions in the first place, a weaker refusal bar than some competing models hold.
This lands directly inside the ongoing US debate over restricting Chinese open-weight models, where nearly 200 startups have urged against a blanket ban. A joint government report showing real, if limited, offensive cyber capability with weaker safeguards gives the restriction argument concrete evidence rather than a general risk claim. If your stack routes any workload through Kimi K3, this is a reason to keep it away from anything touching credentials, infrastructure access, or code execution against production systems, regardless of where the broader policy fight lands.