AI Trend Notifier
EN한
← wiki

$ cat wiki/entities/moonshot.md

Moonshot AI

entityupdated 2026-10-01created 2026-07-20

Latest

  • 2026-09-30

    Named by OpenAI as the party behind parts of a chain-of-thought extraction campaign — the second Chinese lab publicly accused of distill…

  • 2026-09-22

    The CAC is questioning Moonshot's executives, and the cited example is surveillance footage.

  • 2026-09-11

    Moonshot shipped a model nine days ago and this pipeline's rotation checked the lab three times without finding it.

Overview

Beijing-based AI startup, creators of the Kimi assistant and model family. Known for pushing long-context capabilities and massive open-weight scale. Released the world's first open 3T-class AI system (Kimi K3, July 2026). Competes in the Chinese open-weight tier alongside Z.ai, MiniMax, and Alibaba / Qwen AI Lab.

Key People

  • Founder: Yang Zhilin (CEO)

Models & Products

  • Kimi K3 — July 2026, 2.8T MoE, 1M context, world's largest open-weight model at launch; weights released July 27 (Modified MIT, Hugging Face: moonshot-ai/kimi-k3)
  • Kimi K2.8 Preview — September 2026, mid-tier, 1M context on every tier, closed; served under the unversioned id kimi-for-coding

Recent Activity

  • 2026-09-30: Named by OpenAI as the party behind parts of a chain-of-thought extraction campaign — the second Chinese lab publicly accused of distillation, and the first accused by OpenAI. Disrupting a coordinated model-distillation campaign describes activity from July 1, peaking at 16,000 prompts from ~4,000 users on July 24–25, a related pattern across more than 15,000 users, "fully disrupted" by July 28 (source). The technique: encrypted reasoning copied out of one conversation and a second model instance asked to decrypt and transcribe it — OpenAI states its encryption was not broken, no database reached and no stored conversation read.

    Three limits this page holds to. (1) No evidence was published — both search passes note OpenAI offered none for the attribution, and openai.com is blocked so neither pass is first-party. (2) Nothing read states any Kimi model was trained on the extracted reasoning. Anthropic's GTG-16005 against Alibaba / Qwen AI Lab alleges a completed transfer into named models; this alleges an attempt. (3) It is "individuals associated with" Moonshot, not Moonshot. No parameter count, benchmark or model on this page is revised on the strength of it — Kimi K3's record stands unchanged. It compounds the Beijing data-leak probe this page already carries from 2026-09-23, from the opposite direction: that one has Chinese regulators investigating Moonshot for leaking to Anthropic. See Adversarial Distillation

  • 2026-09-22/23: The CAC is questioning Moonshot's executives, and the cited example is surveillance footage. The Cyberspace Administration of China is reported to be probing Moonshot and DeepSeek over Anthropic's claim that both covertly routed user requests through Claude — over 23 million exchanges from Moonshot across May–July, per Anthropic's 154-page report of 2026-09-10. The example carried in reporting is specific: a user Anthropic assessed as likely affiliated with the People's Liberation Army asked Kimi to analyse surveillance footage following a person across hundreds of police cameras in Chengdu, including cameras outside PLA facilities and defence-linked institutes; Moonshot is alleged to have passed the request and the footage to Claude without telling the user. Officials have visited the firm to question executives and staff; no determination on penalties and no sanctions as of reporting dated 2026-09-22. Why it matters: the distillation allegation was about Moonshot taking something from Anthropic. The probe is about what went the other way — whether Chinese state-adjacent data reached a US system — and it is the regulator of Moonshot's own jurisdiction asking. Not established: no CAC statement or legal instrument was read; no Moonshot response; whether Anthropic's PLA-affiliation assessment was verified by anyone; whether the routing was disclosed in Moonshot's terms; and which cross-border data regulation is at issue → DeepSeek, Anthropic, AI Governance (source)

  • 2026-09-11: Moonshot shipped a model nine days ago and this pipeline's rotation checked the lab three times without finding it. Kimi K2.8 Preview rolled out across Kimi Code and Kimi Work on 2026-09-11 (4 passes): a mid-tier model between the coding-focused K2.7 Code and the flagship Kimi K3, close to K3 in overall performance with broader coding and agent capability gains and more efficient thinking than K2.7 Code (2 passes), 1M-token context on every membership tier (3 passes), thinking effort low / high / max with max the default (1 pass), served under the unchanged id kimi-for-coding so existing clients reach the new weights without knowing (1 pass). Closed — API and apps only, no weights (1 pass). No benchmark figure of any kind appears in anything read, and one catalogue on 2026-09-13 lists kimi-k3, kimi-k2.6 and kimi-k2.7-code but not K2.8, so Pricing is unknown. Why it matters for this page: Open-Weights Policy Fight tracks which Chinese labs open which tier, and Moonshot's direction here is the inverse of its reputation — its flagship is open and its newer mid-tier model is not. The capture failure is the second finding and it is this pipeline's, not Moonshot's: the Chinese-lab rotation checked Moonshot on 09-12, 09-15 and 09-17 and recorded "nothing newer than Kimi K3" every time, against a release that was already six days old at the last check. A websearch for "Moonshot Kimi model release" does not reach a changelog entry no outlet covered as a launch; the query that found it named the version string. A multimodal claim is recorded and not adopted — two aggregators describe vision and audio input, one pass says the changelog does not itemize modalities and that K2.8 follows K3's text-and-image set; see ## Conflicting Reports on the model page. No first-party read — platform.kimi.ai and www.kimi.com were not reached by any pass → Kimi K2.8 Preview (new), Open-Weights Policy Fight (source) (Pandaily)

  • 2026-09-10: Named by Anthropic as one of seven China-based labs it disrupted for distillation — Anthropic's September 2026 threat-intelligence report states it has disrupted distillation attacks from seven China-based labs since February 2026, all targeting its generally available models, and reporting names Moonshot AI among them alongside Alibaba, DeepSeek, Z.ai, Xiami and MiniMax. No case identifier, volume, account count or date range is attributed to Moonshot AI specifically in anything read — the only campaign given figures is Alibaba's GTG-16005. Why it matters: it is an allegation carried at reporting confidence with no per-lab evidence attached, recorded as such rather than as a finding; Moonshot AI has not responded in anything read. → AI-Enabled Cyberattacks, Anthropic (source) (TechCrunch)

  • 2026-08-26 (reported), 2026-09-02 (captured here, day +7): Moonshot is reported to want a cut of what US clouds earn from its open weights — reporting relayed by Trivium China says Moonshot is in early-stage talks with Microsoft, Amazon and Google over revenue-sharing arrangements for hosting Kimi K3, seeking as much as 30% of revenue from K3-related services on the three platforms. Unsettled per the reporting: how revenue would be divided, how Moonshot would access data, and how token usage would be audited. Any deal would be the first major revenue-sharing arrangement between a Chinese AI lab and a leading US cloud provider. US Treasury Secretary Scott Bessent has suggested adding Moonshot to trade blacklists, and the reporting's own reading is that the outcome may turn less on the commercial terms than on whether Washington permits the arrangement at all. Why it matters: this page's ## Strategic Position describes self-hosting as K3's commercial logic — weights that do not route traffic to Moonshot's servers. A revenue share on someone else's hosting is the monetisation path an open-weight release otherwise gives away, and the audit question is the reason it is hard: nothing in a Modified MIT licence tells the licensor how many tokens someone served. This is reporting, not an announcement. No first-party statement from Moonshot, Microsoft, Amazon or Google was read; the 30% figure, the counterparties and the audit gap all rest on one underlying report relayed by several outlets. Reached through a feed, not the rotation: Moonshot was checked by the Chinese-lab rotation on 2026-08-29 and 2026-08-31 and returned nothing both days → AI Governance, Open-Weights Policy Fight (source)

  • 2026-07-27: Kimi K3 open weights released — largest open-weight model ever, Modified MIT — Moonshot AI released the full weights for Kimi K3 as promised at launch. License: Modified MIT (commercial use permitted). Hosted on Hugging Face (moonshot-ai/kimi-k3). Precision: MXFP4 (~1.4 TB fast memory required for full inference). Self-hosted inference does not route traffic to Moonshot servers — the primary benefit cited by US/EU enterprise users concerned about Chinese API routing. K3 Max and K3 Swarm Max API variants remain available via Kimi Code and Kimi API. With this release, Kimi K3 becomes the largest open-weight model ever publicly released (2.8T parameter MoE). (source) (HuggingFace)

  • 2026-07-16: Kimi K3 launched on Kimi Code and Kimi app; K3 Max and K3 Swarm Max variants; open-weight release by July 27 (source)

Strategic Position

Moonshot is the scale outlier in Chinese open-weight: Kimi K3 at 2.8T is the largest model released open-weight by any Chinese lab, and beats Anthropic Fable 5 on at least one benchmark (Frontend Code Arena). The long-context expertise (Kimi's original differentiator) is baked into K3's 1M-token window. Competing against Alibaba Qwen 3.8 (2.4T, announced July 19) and GLM-5.2 (Z.ai).

Referenced by

Sources