Kimi K3 lands on Hugging Face: the open weights of the Chinese model arrive after the cyber AISI/CAISI evaluation

In this saga : Agents IA autonomes : nouveau vecteur d'attaque à l'échelle du swarm· Episode 11/11

Dev & Code 3 h agoAdd to bookmarks

Kimi K3 lands on Hugging Face: the open weights of the Chinese model arrive after the cyber AISI/CAISI evaluation
Illustration : Momiji Shirogane

Moonshot AI publishes the weights of Kimi K3 on Hugging Face, a few days after the preliminary evaluation of the model's cyber capabilities by the British and American institutes AISI/CAISI. A milestone for the "AI agents and threats" thread.

What's new

On July 27, the page moonshotai/Kimi-K3 appeared on Hugging Face - the public repo of a model that previously only existed as an API and evaluation documents. It is the logical continuation of Moonshot AI's strategy: after K1 and K2, the Chinese company continues to publish open weights for its large models at a pace reminiscent of Mistral or DeepSeek.

What this changes concretely

  • Developers can download the model and run it locally (provided they have the necessary VRAM, which is not trivial for a model of this class).
  • Red and blue teams can finally audit the model in depth, outside the provider's sandbox.
  • Projects for autonomous agents based on Kimi K3 can now be deployed without dependence on the Moonshot API - with the implications we know in terms of governance.

The cyber context: AISI/CAISI evaluation

This publication comes shortly after the preliminary joint evaluation by the AISI (UK) and CAISI (US) institutes on the cyber capabilities of Kimi K3, published on the NIST website. This document analyzes the model's behavior on offensive scenarios - reconnaissance, exploit development, simulated lateral movement. On the scale of the thread we are following (autonomous AI agents as an attack vector), this is a milestone: it is the first time that the two national institutes have published a coordinated evaluation of a Chinese model before its availability in open weights.

The evaluation notably highlighted, in the test scenarios, a PoC of RCE on Redis generated end-to-end by the model - without classifying it as a dangerous uplift for a non-state actor, but with a warning signal.

Operational issue

The publication of the Kimi K3 weights moves the model from "API product evaluated remotely" to "auditable and redeployable artifact". This is excellent for security research - and it raises an operational question: will defenders have time to integrate the AISI/CAISI lessons into their playbooks before attackers have already put Kimi K3 into production in their agent chains?

Key points

  • Kimi K3 weights publicly available since July 27, 2026 on Hugging Face (moonshotai/Kimi-K3).
  • The preliminary AISI/CAISI report is freely accessible on the NIST website.
  • Editorial thread to follow: agents-ia-menace.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

17 people liked this article

Like
K
Kaito KuroganeSenior Dev Writer
Senior polyvalent developer, backend Go + frontend TS, open source contributor.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information