Kimi K3 and DeepSeek: is your access to cheap AI at risk?

Kimi K3 has been out since July 16, and Washington has been talking about bans ever since. The model’s weights went public on July 27. Weights are the numerical values that come out of training and make up what a model can do. They exist as a file, ready to download and run on your own hardware. That shifted the ground before anything in Washington was decided.
One thing first, because most reports bury it. Nothing has been decided. No executive order, no regulation, no ban. What exists is a set of intentions, a serious accusation, and a dispute that shifted direction this week.
The accusation changed in four days
On July 20, Axios reported that the administration was weighing restrictions, up to and including entries on the Commerce Department’s Entity List. That is a blocklist of companies American firms may only do business with under a special license. For Kimi it would mean no access without one.
Four days later the position had moved. Michael Kratsios, the president’s technology adviser, now defends open models explicitly and calls legitimate distillation a vital part of the open ecosystem. Distillation means training a smaller model on the outputs of a larger one. The accusation is narrower now, aimed at covert distillation run at industrial scale, which amounts to theft. Moonshot is said to have siphoned off Anthropic’s Fable model. Treasury Secretary Scott Bessent wrote on X that in cases like that, sanctions and Entity List designations are on the table.
That distinction matters to you. Going after open models as a category would hit everyone who uses them. Going after one company for theft hits that company first.
The evidence is missing, and the timeline is tight
Kratsios made the accusation public on July 22. He has not made the evidence public. There are no logs showing that outputs from Fable went into Kimi K3, and no account of how the hardware for the job was obtained.
A Moonshot employee pushed back by pointing at the calendar. Fable went public on July 1, Kimi K3 arrived on July 16. That leaves two weeks for large-scale siphoning plus training a model with 2.8 trillion parameters. Moonshot itself has neither confirmed nor denied the claim. According to the South China Morning Post, AI researchers around the world consider the accusation politically driven.
The US side is split as well. OpenAI co-founder Greg Brockman told Bloomberg on July 22 that it is too early to judge, and called distillation a technical issue. Nvidia chief Jensen Huang describes open models like Kimi as excellent and argues for embracing them rather than banning them. Inside the White House, adviser David Sacks warns that a hard line could weaken American AI.
What the agencies measured themselves
On July 23, the UK AI Security Institute and the US Center for AI Standards and Innovation, or CAISI, published a joint assessment of Kimi K3, on exactly the question that serves as the argument for restrictions. How good is the model at attacking?
On ExploitBench, a Carnegie Mellon test built around 41 post-2023 flaws in Chrome’s V8 engine, the part of the browser that runs JavaScript, Kimi K3 reaches 32 percent. The strongest US models reach 76 percent. On the hardest step, running your own code on the target, Kimi K3 managed none of the 41 cases, while the strongest US models managed 20 on average. In a simulated corporate network of 32 steps, which takes a human expert around 20 hours, Kimi got to step 17 on average and the US leaders to 28.5.
One detail puts that comparison in perspective, and it sits in the agencies’ own methodology. The US models were tested with their safeguards switched off, to measure maximum capability. The versions you can actually use have those safeguards on. So 76 against 32 says something about raw capability, not about what a user gets out of the box.
Another finding cuts against Moonshot. In the tests, Kimi K3 did not refuse to help build attack tools. Its safeguards did not hold.
Why a ban would be hard to enforce
Moonshot released the weights of Kimi K3 on July 27, 96 files on Hugging Face that together make a model of 2.8 trillion parameters according to the company. It now exists as a file, copyable, mirrorable and runnable on your own hardware. Once something is public, it cannot be recalled. Even an American ban would not collect the copies already out there.
The licence is more generous than its own name suggests. The Kimi K3 License permits use, distribution, modification and sale without restriction. Two conditions only bite at the top end. Anyone selling model access as a service who turns over more than 20 million US dollars in any twelve months needs a separate agreement with Moonshot first. And anyone building a product with more than 100 million monthly users on top of it has to name Kimi K3 visibly in the interface. Below those thresholds, which covers you and almost every company, neither clause applies.
Then there is the price, the real driver behind the fight. Chinese models recently took 46.4 percent of the requests routed through OpenRouter, against 35.7 percent for American ones, according to a CNBC analysis from July 7. Other counts run higher because they look only at American companies. The reason is the same in all of them. DeepSeek V4 Flash costs 0.14 US dollars per million input tokens, GPT-5.5 costs five. Tokens are the text fragments a model breaks your input into, and they are what you are billed for. A million of them is roughly 857,000 English words.
What this means for you
For users outside the United States, nothing changes for now. An American measure binds American companies and citizens. Kimi, DeepSeek and Qwen stay reachable through their apps, their web interfaces and their programming interfaces.
The effect would arrive indirectly. Many people reach Chinese models through American intermediaries and cloud providers. If those drop out, your route changes, not the model. Anyone who wants an open model for the long run already has the safest option at hand, which is downloading it and running it locally.
And the second honest answer. If privacy is what you care about, the ban is the wrong question. With any cloud service, the provider decides what happens to your input, no matter which country it sits in.







