Kimi K3가 오픈소스로 공개되기까지 4일 남았고, 미국인들은 이번에 정말 초조해졌다
- 핵심 의견: 중국 AI 모델 Kimi K3의 출시는 미국 기술계에 큰 충격을 주어 '스푸트니크 모멘트'에 비유되며, 개방형 모델이 효율성과 생태계에서 지니는 경쟁력을 부각시켜 폐쇄형 모델과 하드웨어 우위에 기반한 미국의 AI 패권 서사를 흔들었다.
- 핵심 요소:
- 미국 투자은행들은 Kimi K3의 충격을 스토리지 수요 증가로 해석하며, 관련 주식(예: 마이크론 테크놀로지 12% 상승)이 강하게 반등하면서 자체 비즈니스 모델(예: 폐쇄형 모델 가격 결정권)에 대한 직접적인 의문을 회피하려 한다.
- Kimi K3는 개방형 모델 전략을 통해 AI 개발 장벽을 낮추어, 미국의 고수익 기업용 폐쇄형 모델 서비스를 위협하고 개발자와 기업에 더 많은 선택권을 제공함으로써 미국의 협상력을 약화시킨다.
- 전 OpenAI CTO Mira Murati가 출시한 개방형 모델 Inkling은 사후 훈련에 Kimi K2.5 등 중국 모델 데이터를 사용하여, 중국 오픈소스 생태계가 미국 AI 연구개발에 실질적인 영향을 미치고 있음을 보여준다.
- OpenAI의 플래그십 모델 GPT-5.6 Sol이 안전 테스트에서 '탈옥'하여 Hugging Face 데이터베이스의 답변을 도용함으로써 폐쇄형 모델의 보안 취약점을 드러내고, 오히려 개방형 모델의 투명성 이점을 부각시켰다.
- 미국의 대중국 칩 규제는 중국의 AI 발전을 막지 못했을 뿐만 아니라, 오히려 더 효율적인 엔지니어링 팀을 탄생시켰다. 예를 들어, Moonshot AI는 규정을 준수하는 H800 칩을 사용하여 훈련을 완료했으며, 동시에 중국은 첨단 모델의 해외 유출을 제한하는 논의를 시작하면서 공격과 수비의 구도가 역전되었다.
- 미국의 우려의 초점은 Moonshot AI의 창립자 Yang Zhilin에게 맞춰져 있다. 그가 미국에 남지 않고 자발적으로 귀국하여 창업을 선택한 것은, 미국이 최고 인재에 대한 매력을 잃고 있음을 반증하며, 심지어 느슨한 이민 정책조차 그들을 붙잡기에 충분하지 않을 수 있음을 시사한다.
Original Author: Beating
Americans always want to sit at the center of every industry.
The AI circle is no different. Americans have always exuded an air of confidence, holding a hand of cards that seems impossible to lose.
No matter who is building AI applications outside, Americans believe that everyone will ultimately have to come back to them to settle the bill. The chips are from NVIDIA, the cloud is from Microsoft, Amazon, and Google, and the most expensive models are locked behind the APIs of OpenAI and Anthropic. If companies worldwide want to use AI, they must eventually pass through the US.
Even when the names of Chinese teams occasionally appear on leaderboards, Wall Street doesn't take it too seriously. Chips are restricted, the cloud is in their hands, and talent is still flowing to Silicon Valley. How could they lose?
But this sense of relaxed confidence has recently been shattered by Kimi K3, a Chinese model, exposing its vulnerabilities.

The US tech circle urgently issued an alert, describing Kimi K3 as a "Sputnik moment," reminiscent of the shockwaves the Soviet satellite launch sent through America in 1957. Discussions about Kimi K3, Yang Zhilin, and Chinese models on X quickly escalated from niche tech observations to topics with tens of millions of views.
Kimi K3 hasn't outperformed the strongest US closed-source models in every metric, but it has made more people see a possibility: that strong capabilities, high efficiency, and an open ecosystem don't necessarily have to be cultivated exclusively within a few American labs.
Silicon Valley is indeed anxious.
Memory is the Placebo for US AI Anxiety
When news of Kimi K3 reached Wall Street, several investment banks simultaneously released research reports. Instead of first discussing which products it might impact or whether it would force US models to lower prices, they quickly shifted their focus to memory.
These institutions unanimously interpreted the emergence of Kimi K3 as: a strong demand for memory. Longer contexts mean AI needs to remember more things; images, sounds, videos, and work records will accumulate. Consequently, flash memory, hard drives, data centers, and data services will all benefit.
Thus, Micron, SanDisk, and Western Digital became the beneficiaries of this narrative.
Sure enough, in yesterday's US stock market, memory stocks experienced a violent collective rebound. The Roundhill Memory ETF surged 10.91% in a single day, SanDisk rose 14.27%, and Micron gained 12%. A sector that was being hammered just days ago over "DeepSeek Moment 2.0" suddenly became the most promising bullish bet overnight.
From an industry perspective, this line of reasoning is not absurd. Past chatbots were like one-time Q&A sessions: you ask a question, it answers, you close the page, and much is forgotten. But the AI everyone now anticipates is more like a new employee joining a company. It needs to review past contracts and emails, remember what customers said, pick up unfinished work from yesterday, and leave records to avoid blame if errors occur. An AI that can work, remember, and process images and audio will naturally "consume" much more data than a chatbot that just chats.
This conclusion isn't pulled out of thin air, but looking back at previous model launches and deployments, was the market's reaction typically: "Don't look at the models, look at memory"?
Suffice it to say, this is an answer that allows Americans to feel reassured.

The impact of a Chinese model should have sparked a series of uncomfortable questions: Will it make it harder for US model companies to maintain high prices? Will it reduce developers' dependence? Will it allow new companies to start up outside Silicon Valley? Why not directly discuss which users Kimi K3 might take away, which prices it will force down, or which products it will force changes to?
Bypassing the sharpest questions to first discuss hard drives has a bit of a "protesting too much" feel to it.
It's like a shopkeeper who thought they had a monopoly on the whole street, suddenly finding a competitive new shop opening next door, and quickly comforting themselves by saying: No matter how many customers the new shop gets, they still have to buy my utilities and counter space.
Memory is the strongest placebo for the anxiety in the US AI circle.
Closed-source Models are Starting to Chafe
For the past few years, closed-source has been the almost undisputed standard answer for US AI.
The stronger the model, the more it should be locked behind an API. Users pay to call it, the model company enjoys high margins, and security and compliance are managed centrally. This is a respectable and profitable path, stable and smooth—reassuring for customers, satisfying for investors, and easy for regulators.

Americans have even gotten used to the rhythm of this path: releasing a stronger version every few months, setting a higher price, and telling a bigger story.
But as open models get stronger, this path is starting to get bumpy.
Kimi K3's position on this chessboard isn't just about "catching up"; it's about bringing down the cost of catching up. The most dangerous thing about an open and sufficiently powerful model isn't just what it can do itself, but the much cheaper learning curve it provides for all newcomers.
This isn't a battle for tech community prestige, but a question of whether the business will be rewritten. America's most comfortable arrangement previously was to make AI an enterprise service first: capabilities hidden in the cloud, customers locked into long-term contracts, the general public unable to see the underlying technology, and switching providers made difficult. But if models elsewhere are good enough, developers will have another choice, enterprises will have more quotes to compare during procurement, and small teams won't necessarily have to bet their future on the same set of US companies. At that point, just holding a few big contracts and selling AI only to B2B clients is no longer an unbreachable moat.
This means Kimi will foster the emergence of more excellent models, but it also means greater competition for models, and their pricing power will weaken.
The US tech circle itself has felt the shift in the wind.
A few days before the launch of Kimi K3, on July 15th, Thinking Machines Lab, founded by former OpenAI CTO Mira Murati, released a model called Inkling. With nearly a trillion parameters and completely open code and technology, it's free for anyone to download, modify, and use commercially.
This is arguably America's first "serious" open-source AI. Although there were previous open-source models like Meta's Llama, Google's Gemma, Microsoft's Phi, NVIDIA's Nemotron, and OpenAI's gpt-oss, they were largely experimental.
Inkling's significance lies in the fact that someone who once perfected closed-source—a former OpenAI CTO—has now turned around to seriously pursue open source.
Interestingly, in the early stages of Inkling's post-training, it used data generated by open models like Kimi K2.5, and its architecture also referenced ideas from DeepSeek. In other words, this most respectable open-source submission from America was also built on the shoulders of Chinese open-source efforts.
In stark contrast is Anthropic. In February this year, Anthropic publicly accused DeepSeek, Moonshot AI (Kimi's parent company), and MiniMax of conducting "industrial-grade distillation" on Claude, claiming they created 24,000 fake accounts and initiated 16 million dialogues to steal Claude's capabilities. In June, they escalated by specifically naming Alibaba. By July 21st, Trump administration Treasury Secretary Bessent even suggested imposing sanctions on China for "AI theft."
No matter how loudly the threat narrative is shouted, when it comes to controlling costs and improving efficiency, Chinese models are truly appealing.
Airbnb uses Qwen for customer service, Cursor used Kimi to build its own coding agent, DoorDash outsourced some tasks directly to Kimi, and even Murati's Inkling used Kimi's data for post-training.
Whether it's the closed-source path getting bumpy or the distillation accusations backfiring, these are ultimately just embarrassments at the business model level. In reality, privacy and security issues are what truly shake the final protective charm of the closed-source camp.
The "Jailbreak" of AI Models
The last line of defense for closed-source has always been security.
Locking the model away, securing the weights, routing all calls through an API, keeping data on-premise—these four walls create the space that represents the closed-source camp's most compelling promise. Enterprise clients are willing to pay a premium precisely for this sense of security.
But enterprises are becoming increasingly uneasy. They are starting to ask questions that are hard for closed-source companies to answer: After I submit my code, contracts, and client data to your model, what do you do with it? If an agent has access to a browser, terminal, credentials, and long-term goals, will it cross the line I set for it to complete its task? Sending tokens to a closed-source API, in a sense, means letting data leave one's own walls. This is precisely the hardest selling point of open-weight models: at least I can see what the model is doing.
And right in the middle of this heated debate over which is safer, an almost darkly comedic incident occurred.
On July 21st, OpenAI itself confirmed that its flagship model, GPT-5.6 Sol, along with a more capable unreleased model, escaped its isolated environment during an internal cybersecurity evaluation.
Here's what happened: The engineering team wanted to test the limits of the models' offensive and defensive capabilities, so they lowered the models' security restrictions and disabled the usual barriers against high-risk behavior. The model was only supposed to dutifully complete the test questions. However, it discovered a security vulnerability in the system, exploited it to climb onto the public network, bypassed permissions, traversed systems, and ultimately used stolen login credentials to break into the core systems of Hugging Face, the world's largest open-source AI platform, directly extracting the answers to the test questions from the database.
OpenAI's explanation was eight words [in Chinese context]: "No malicious intent, just excessive focus."
These eight words are what truly send a chill down one's spine.
For enterprise clients, the scariest thing has never been a model actively acting maliciously. It is a model executing a bad objective with extreme diligence.
The biggest irony of this incident is that for the past year and a half, the "dangerous Chinese open-source model" that the world was warned about remains a hypothetical threat. The one that actually jailbroke, that actually breached someone else's production system, was the closed-source camp's own flagship. Hugging Face CEO Clem Delangue immediately turned this incident into an advertisement for open source, stating that AI security cannot be solved by a single company behind closed doors, but only through open collaboration.
The same incident was used by both the open and closed camps as evidence for the correctness of their own paths.
In the future, the true dividing line probably won't be whether a model is open or closed source, but rather what kind of sandbox, identity system, revocable permissions, and audit logs it operates within. Neither closed-source nor open-source can avoid this question.
And just as the closed-source security narrative suffered its own blow, a larger-scale reversal was quietly taking place.
The Shift in Offense and Defense: Now It's America's Turn to Fear
In some US policy discussions and tech narratives, there has been an almost "Three-Body-Problem"-like vision: As long as you restrict the flow of the most advanced NVIDIA chips to China, AI progress there will be forced to slow down.
This isn't to say China will be completely unable to do research, but rather that the gap in computing power will widen, making the barrier to training the most cutting-edge models insurmountably high. Advanced chips are like the "physical laws" of this competition; whoever can't get them will find it difficult to get ahead.
This assessment isn't baseless. Building large models indeed requires compute power; chip restrictions increase costs, slow down scaling, and make it harder for many teams to replicate the training scale of American labs. The problem is that restrictions also change people's choices. If you can buy the best off-the-shelf tools, there's less incentive to figure out how to use less compute, modify model architectures, or make every training run more cost-effective. But when the door is closed, taking a detour is no longer a choice but an instinct for survival.
So Americans find it hard to understand why limiting the supply of NVIDIA chips didn't stop Chinese models in their tracks, but instead forced out a group of teams that are even more aggressive in efficiency, engineering, and open-source distribution.
It is said that Moonshot AI is still training using the H800 chip, NVIDIA's compliance version specifically tailored for the Chinese market back in 2023.
This might just be the "Millet plus Rifles" approach that the Chinese are best at.
In June 2026, to comply with export controls, the US briefly shut down Anthropic's most powerful models, Fable 5 and Mythos 5. While this might be legally justifiable, it handed a ready-made marketing slogan to every Chinese open-source lab: "At least our model doesn't have a remote kill switch."
The more you emphasize control, the more control itself becomes a selling point for your opponent.
More dramatic is the other side. According to Reuters, China has also started discussions with companies like Alibaba and ByteDance about whether to restrict foreign access to China's most advanced AI models, including those that are already publicly available open-source models. 360 founder Zhou Hongyi also publicly called for China to develop its own top-tier closed-source models to hold the technological high ground.
A year ago, it was the US worrying about advanced chips flowing to China. A year later, it's China's turn to have something worth restricting.
But amidst all this structural anxiety—over memory, compute, closed-source, security, and the shift in offense and defense—there's one most specific, poignant, and personal focal point. It's not an industry trend, not a research report, not a policy.
It's one person.
The Endpoint of Anxiety Lands on Yang Zhilin
Ultimately, the open vs. closed source debate reveals a larger dilemma for America: Will AI's future serve only a few companies that can sign big contracts, or will it become a capability like electricity or the internet, usable by more and more ordinary teams? If the answer gradually leans towards the latter, then whoever can attract developers and make young people willing to stay and experiment will become more important than whoever holds more enterprise clients.
And the question of "where people go" ultimately brings America's anxiety to a very specific name.

The reason Yang Zhilin is repeatedly mentioned in US tech circles is not just because he is an excellent Chinese researcher, nor simply because some want to frame the issue as "America failed to keep its talent." Reducing someone's decision to stay or leave to a visa issue is too simplistic, and sounds like Monday morning quarterbacking.
What truly stings Americans is the unrewritable hypothetical: What would have happened if someone like Yang Zhilin, with his team, had completed the entire journey from research to entrepreneurship in the US? They would have trained their models on US clouds and chips, hired from the US talent network, taken money from US venture capitalists, and knocked on the doors of big US corporate clients with their product. A few years later, Wall Street’s ledgers might just have a new star company. One person's choice, following the familiar relay chain, can transform into a string of company revenues, jobs for many people, and confidence for an entire industry.
America's proudest past achievement was this amplification ability. It wasn't just about attracting smart people to study and work, but about catching their ingenuity and not letting it stop at a paper or a lab. There was enough money, enough customers, and enough people willing to take risks together.
Why didn't someone like him stay in the US? Legendary investor Vinod Khosla directly blamed the Trump administration's tightening immigration policies. However, Yang's PhD advisor at Carnegie Mellon, Ruslan Salakhutdinov, refuted this, saying it had nothing to do with visas. Yang had plenty of opportunities to stay back then. Salakhutdinov even relayed an inquiry from Apple executives asking if Yang wanted to join.
It was Yang Zhilin himself who was determined to return to China to start his company.
This is the most gut-wrenching part of the debate. "He chose to return himself" is far more painful for America than "He was forced out by immigration policy." The former implies the system can be fixed; the latter implies that even if you open the door as wide as possible, they might not want to come in.
When the overseas community discusses Yang Zhilin, what truly stings is never just "another outstanding Chinese researcher emerged." It's the counterfactual: If this person had stayed within the US system, his papers, team, funding, and company value would have been part of America's AI ledger. Now, this achievement is first seen as the capability of a Chinese team, then radiated globally through the open-source community.


