FT : What is the risk of using Chinese open AI models like Kimi K3?

What is the risk of using Chinese open AI models like Kimi K3?
The real problem is not overseas open-source but lack of co-ordination to protect infrastructure in the face of cyber attacks

Earlier this month, I sat in the Radiohead-themed conference room of Beijing start-up Moonshot and watched a demonstration of its powerful new Kimi K3 AI model. Founder Yang Zhilin, a music fan, named his company for Pink Floyd’s album Dark Side of the Moon — a fitting reference to uncharted yet high-reward territory. 

Within China, the surprise release of Kimi K3 has been hailed as another chance for the country to flex its tech expertise at the expense of US rivals. More US companies are opting to lower their costs by switching to cheaper, high-performing Chinese open AI models such as K3, Z.AI’s GLM, DeepSeek’s R-1 and Alibaba’s new Qwen 3.8 Max.

“Saves us millions of $ and we’re actually seeing an *increase* in performance on many core use cases. Transformative,” wrote Flo Crivello, CEO of San Francisco-based digital assistant platform Lindy AI, which switched to DeepSeek this year.

What is the security risk of using open-source AI models created by foreign companies? Washington seems focused on surveillance, IP theft, espionage and potential Chinese involvement in critical domestic infrastructure. The White House is reportedly exploring tools to curb the spread of, or even sanction, open Chinese models. The debate may look like a stand-off between national security and innovation, but it is not quite that simple.

The first point to make is that asking whether a model has been developed by a Chinese company is the wrong question for those concerned about security.

Open-source models such as Kimi K3 allow the parameters (the numbers learnt in training that determine how an AI model uses information to predict what comes next) to be downloaded and run by anyone. Companies download the weights, fine-tune the model and then run it on their own cloud or infrastructure.

What matters more, therefore, is who owns and operates the server that runs the model. US users worried about data being sent to China could run the AI models on domestic hardware they control or through third-party inference providers.

Chinese open models do not uniformly censor information either. Again, where the model is hosted changes things. When hosted on US infrastructure, models will answer questions that would be blocked inside China. Since weights are open, users can change content restrictions.

Even if data is hosted within China, where companies are required to co-operate with the National Intelligence Law, some push back in ways that mean the government does not necessarily have unfettered access. In March this year, Chinese government inspectors seeking access to data from the ecommerce platform Pinduoduo got into a brawl with staff trying to block entry. One official left with a broken finger.

The US does need a viable open-source option of its own. It is quickly becoming a crucial lever of national power projection. Kevin Xu of Interconnected Capital compares it to Disney movies and K-pop. But the real problem is that Washington lacks a comprehensive approach to shore up critical infrastructure in the face of powerful, AI-enabled cyber attacks that are no longer hypothetical.

Here the transparency provided by open weights (including those from China) could in fact improve security. Last week, Hugging Face used an open Chinese AI model to analyse an AI agent cyber breach. This all happened without data leaving Hugging Face’s system.

Governments on all sides still insist on framing AI as a global arms race. But neither threats nor innovation map neatly on to national boundaries. Addressing data access and control in an interconnected world requires a new way of understanding security protocols.

The writer is a senior fellow at New America and the Institute for America, China, and the Future of Global Affairs at Johns Hopkins University