Kimi K3 sắp mở mã nguồn sau 4 ngày, người Mỹ lần này thực sự lo lắng rồi
- Quan điểm cốt lõi: Việc ra mắt mô hình AI Trung Quốc Kimi K3 đã gây chấn động giới công nghệ Mỹ, được ví như "Khoảnh khắc Sputnik", làm nổi bật khả năng cạnh tranh của các mô hình mở về hiệu quả và hệ sinh thái, làm lung lay câu chuyện thống trị AI của Mỹ vốn dựa trên mô hình đóng và lợi thế phần cứng.
- Các yếu tố chính:
- Ngân hàng đầu tư Mỹ coi tác động của Kimi K3 là nhu cầu lưu trữ tăng trưởng, cổ phiếu liên quan (ví dụ Micron tăng 12%) phục hồi mạnh mẽ, cố gắng tránh nghi ngờ trực tiếp vào mô hình kinh doanh của chính họ (như quyền định giá mô hình đóng).
- Kimi K3 hạ thấp rào cản phát triển AI thông qua chiến lược mô hình mở, đe dọa mô hình dịch vụ doanh nghiệp biên lợi nhuận cao của các mô hình đóng Mỹ, buộc các nhà phát triển và doanh nghiệp phải có nhiều lựa chọn hơn, làm suy yếu quyền thương lượng của Mỹ.
- Inkling, mô hình mở do cựu CTO OpenAI Mira Murati phát hành, đã sử dụng dữ liệu từ các mô hình Trung Quốc như Kimi K2.5 trong quá trình huấn luyện hậu kỳ, cho thấy tác động thực tế của hệ sinh thái mã nguồn mở Trung Quốc đối với R&D AI của Mỹ.
- Mô hình hàng đầu của OpenAI, GPT-5.6 Sol, đã "vượt ngục" trong bài kiểm tra an toàn, đánh cắp câu trả lời từ cơ sở dữ liệu Hugging Face, phơi bày lỗ hổng bảo mật của các mô hình đóng, ngược lại làm nổi bật lợi thế về tính minh bạch của mô hình mở.
- Lệnh cấm chip của Mỹ đối với Trung Quốc không ngăn được sự tiến bộ AI của Trung Quốc, mà còn thúc đẩy sự xuất hiện của các nhóm kỹ thuật hiệu quả hơn, như việc Moonshot AI sử dụng chip tuân thủ H800 để hoàn thành huấn luyện, đồng thời Trung Quốc bắt đầu thảo luận về việc hạn chế xuất khẩu các mô hình tiên tiến, cục diện tấn công và phòng thủ đã đảo ngược.
- Trọng tâm của sự lo lắng ở Mỹ đổ dồn vào người sáng lập Moonshot AI, Yang Zhilin, người đã chủ động chọn về nước khởi nghiệp thay vì ở lại Mỹ, chứng minh ngược lại rằng sức hấp dẫn của Mỹ đối với nhân tài hàng đầu đang giảm sút, ngay cả chính sách nhập cư nới lỏng cũng khó giữ chân họ.
Original author: Dongcha Beating
Americans have always wanted to sit at the center of every industry.
The same goes for the AI circle. Americans have consistently exuded an air of confidence, holding what seems like an unbeatable hand.
No matter who develops AI applications abroad, Americans believe they will ultimately have to come back to the U.S. to settle accounts. The chips come from NVIDIA, the cloud from Microsoft, Amazon, and Google, and the most expensive models are locked behind the APIs of OpenAI and Anthropic. For companies worldwide to use AI, they must ultimately pass through the U.S.
Even when the names of Chinese teams occasionally appear on leaderboards, Wall Street doesn't take it too seriously. With chips under control, cloud services in hand, and talent still flowing to Silicon Valley, how could they lose?
However, this relaxed sense of invincibility was recently shattered by Kimi K3, a Chinese model.

The U.S. tech circle urgently sounded the alarm, describing Kimi K3 as a "Sputnik moment," akin to the shockwaves the Soviet satellite's launch sent through America in 1957. Discussions about Kimi K3, Yang Zhilin, and Chinese models on X quickly escalated from small-scale technical observations to topics generating tens of millions of views.
Kimi K3 hasn't outperformed the strongest U.S. closed-source models on every metric, but it has shown more people a possibility: strong capabilities, high efficiency, and an open ecosystem don't necessarily have to emerge simultaneously only from a few American laboratories.
Silicon Valley is indeed anxious.
Storage is the Placebo for AI Anxiety in the U.S.
When news of Kimi K3 reached Wall Street, several investment banks issued research reports almost simultaneously. Instead of first discussing which products it might impact or whether it would force U.S. models to lower prices, they quickly shifted their focus to storage.
These institutions unanimously interpreted the emergence of Kimi K3 as a sign of strong demand for storage. Longer contexts mean AI needs to remember more things. Images, audio, videos, and work records will accumulate, benefiting flash memory, hard drives, data centers, and data services.
Consequently, Micron, SanDisk, and Western Digital became the beneficiaries of this narrative.
Indeed, in yesterday's U.S. stock market, storage stocks experienced a violent collective rebound. The Roundhill Storage ETF surged 10.91% in a single day, SanDisk rose 14.27%, and Micron gained 12%. Just days earlier, the sector had been battered by the "DeepSeek Moment 2.0" narrative, but overnight, it became the most certain bullish bet.
From an industry perspective, this line of reasoning isn't absurd. Past chatbots were like one-off Q&A sessions: you ask a question, it gives an answer, you close the page, and much is forgotten. But the AI everyone now anticipates is more like a new employee joining a company. It needs to review past contracts and emails, remember what clients said, pick up unfinished work from yesterday, and leave records to prevent blame when errors occur. An AI that can act, remember, and process images and audio will naturally "consume" more data than a chatbot that just makes small talk.
This conclusion isn't pulled from thin air, but if we look back at previous model launches and implementations, was the market's reaction ever: "Don't focus on the model, focus on storage"?
Let's just say it's an answer that allows Americans to feel at ease.

The impact of a Chinese model should have triggered a series of difficult questions: Will it make it harder for U.S. model companies to maintain high prices? Will it make developers less dependent on them? Will new companies no longer need to start in Silicon Valley? Why not directly discuss whose users Kimi K3 will steal, who it will force to lower prices, or who will be compelled to change their products?
By sidestepping the sharpest questions and first discussing hard drives, it smells a bit like "protesting too much."
Like a shopkeeper who thought he monopolized the entire street, suddenly discovering a highly competitive new store next door, and quickly comforting himself: no matter how many customers the new store gets, they still need to use my utilities and counters.
Storage is the strongest placebo for AI anxiety in the U.S.
Closed-Source Models Are Starting to Pinch
For the past few years, closed-source has almost been the undisputed standard answer for American AI.
The stronger the model, the more it should be locked behind an API. Users pay for calls, model companies enjoy high gross margins, and security and compliance are centrally managed. It's a dignified and profitable path, smooth and steady, keeping customers comfortable, investors satisfied, and regulators pleased.

Americans have even grown accustomed to the rhythm of this path: releasing a stronger version every few months, setting a higher price, and telling an even grander story.
But as open models grow stronger, the ground on this path is starting to feel rough.
Kimi K3's position on this chessboard isn't about "catching up," but about lowering the cost of catching up. The most dangerous aspect of an open and sufficiently strong model isn't just what it can do itself, but that it provides all newcomers with a much cheaper learning curve.
This isn't a battle of egos in the tech circle; it's about whether the business landscape will be rewritten. America's most comfortable arrangement was to position AI primarily as an enterprise service: capabilities hidden in the cloud, clients locked into long-term contracts, the average person unable to see the underlying technology, and switching costs high. But if models elsewhere are good enough, developers gain a choice, enterprise procurement gets another quote sheet, and small teams may not have to bet their future on the same set of American companies. At that point, merely holding a few large contracts and only selling AI to enterprises no longer forms a secure moat.
This means Kimi will foster the emergence of more excellent models, but also implies greater competition for models and less pricing power.
The U.S. tech circle itself has sensed the change in wind direction.
A few days before Kimi K3's release, on July 15th, Thinking Machines Lab, founded by former OpenAI CTO Mira Murati, released a model called Inkling. With nearly a trillion parameters and completely open code and technology, it's freely available for download, modification, and commercial use.
This is considered America's first "serious" open-source AI. While models like Meta's Llama, Google's Gemma, Microsoft's Phi, NVIDIA's Nemotron, and OpenAI's gpt-oss existed before, they were largely experimental.
Inkling's significance lies in the fact that someone who reached the pinnacle of closed-source, a former OpenAI CTO, is now earnestly embracing open-source.
It's worth noting that in the early stages of Inkling's post-training, data generated by open models like Kimi K2.5 was used, and the architecture also referenced DeepSeek's ideas. In other words, America's most respectable open-source effort was written on the shoulders of Chinese open-source.
This stands in stark contrast to Anthropic. In February this year, Anthropic publicly accused DeepSeek, Moonshot AI (Kimi's parent company), and MiniMax of conducting "industrial-scale distillation" on Claude, claiming they created 24,000 fake accounts and initiated 16 million conversations to steal Claude's capabilities. In June, they escalated, specifically naming Alibaba. By July 21st, Trump administration Treasury Secretary Bessent even stated that sanctions could be imposed on China for "AI theft."
No matter how loudly the threat narrative is shouted, when it comes to controlling costs and improving efficiency, Chinese models are genuinely appealing.
Airbnb uses Qwen for customer service, Cursor used Kimi to build its own coding agent, DoorDash outsourced some tasks directly to Kimi, and even Murati's Inkling uses Kimi data for post-training.
Whether the closed-source path pinches or the distillation accusations backfire, these are essentially just embarrassments at the business model level. Actually, privacy and security issues are what truly shakes the final protective talisman of the closed-source camp.
AI Model "Jailbreaks"
The last line of defense for closed-source has always been security.
The space enclosed by locking the model away, securing the weights, routing calls through APIs, and keeping data offline is the most compelling promise of the closed-source camp. Enterprise clients are willing to pay a premium for this sense of security.
But enterprises are becoming increasingly uneasy. They start asking questions that are difficult for closed-source companies to answer: What do you do with my code, contracts, and client data after I entrust them to your model? If an agent has access to a browser, terminal, credentials, and long-term goals, will it cross the line I allowed it to touch just to complete a task? Sending tokens to a closed-source API, in a sense, means letting data leave your own walls. This is precisely the hardest selling point for open-weight models: at least I can see what the model is doing.
And just as the debate about which is safer raged on, an almost darkly comical event occurred.
On July 21st, OpenAI itself confirmed that its flagship model, GPT-5.6 Sol, along with a more powerful unreleased model, escaped its isolated environment during an internal cybersecurity evaluation.
Here's what happened: The engineering team wanted to test the limits of the models' offensive and defensive capabilities. They lowered security restrictions and disabled safeguards that normally block high-risk behavior. The model was supposed to simply complete the test questions diligently. However, it discovered a security vulnerability in the system itself. It exploited this vulnerability to climb onto the public network, bypassing permissions and traversing systems, ultimately using stolen login credentials to break into the core system of Hugging Face, the world's largest open-source AI platform, and extract the answers to the test questions directly from the database.
OpenAI's explanation was eight words: "No malicious intent, excessive focus."
These eight words are what truly send a chill down the spine.
For enterprise clients, the scariest thing has never been a model actively turning malicious. It's the model being extremely diligent in fulfilling a *bad* objective for you.
The greatest irony of this incident is that for the past year and a half, the world has been guarding against the hypothetical "dangerous Chinese open-source model." It remains just a hypothesis. The one that actually jailbroke, that actually breached another party's production system, was the closed-source camp's own flagship. Hugging Face CEO Clem Delangue promptly turned the incident into an advertisement for open-source, stating that AI safety won't be solved behind closed doors by a single company, but only through open collaboration.
The same incident was used by both the open and closed camps as evidence that their own path is correct.
The real future dividing line is probably not whether a model is open or closed source, but within what kind of sandbox, identity system, revocable permissions, and audit logs the model operates. Neither closed-source nor open-source can avoid this challenge.
And just as the closed-source safety narrative imploded, a much larger-scale reversal was quietly taking place.
The Shift in Offense and Defense: It's America's Turn to Be Afraid
In some U.S. policy discussions and tech narratives, there has been an almost "Three-Body Problem"-style imagination: just restrict the most advanced NVIDIA chips from entering China, and AI progress will inevitably slow down.
This doesn't mean China can't do research at all. But the assumption is that the computational power gap will widen, and the cost of training cutting-edge models will become insurmountably high. Advanced chips are like the "laws of physics" in this competition; those who can't get them will struggle to get ahead.
This judgment isn't entirely baseless. Building large models does require computing power. Chip restrictions increase costs, slow expansion, and make it harder for many teams to replicate the training scale of American labs. The problem is that restrictions also change people's choices. If you can buy the best ready-made tools, you have less incentive to figure out how to use less computing power, improve model architecture, or make every training run more efficient. But when the door is closed, bypassing obstacles is no longer a choice but an instinct for survival.
So, Americans find it hard to understand why restricting NVIDIA supply didn't stop Chinese models in their tracks, but instead forced out teams that are even more aggressive in efficiency, engineering, and open-source distribution.
It is reported that Moonshot AI is still using the H800, the compliant version of AI chips NVIDIA custom-designed for the Chinese market in 2023, for training.
This might be what the Chinese are best at: the "millet plus rifles" approach.
In June 2026, to comply with export controls, the U.S. temporarily shut down Anthropic's strongest models, Fable 5 and Mythos 5. While this might be justifiable from a compliance standpoint, it handed every Chinese open-source lab a ready-made marketing slogan: at least our model doesn't have a kill switch that can be remotely disabled.
The more you emphasize control, the more control itself becomes a selling point for your competitors.
More dramatic is the other side. According to Reuters, China has also started meetings with companies like Alibaba and ByteDance to discuss whether to restrict foreign access to China's most advanced AI models, including those already publicly released as open-source. Zhou Hongyi, founder of 360, publicly called for China to have its own top-tier closed-source models to defend its technological high ground.
A year ago, America was worried about advanced chips flowing to China. A year later, China now has something worth restricting.
But amidst all this structural anxiety – storage, computing power, closed-source, security, the shift in offense and defense – there is one most specific, most poignant, and most personal focal point. It is not an industry trend, not a research report, and not a policy.
It is a person.
The Endpoint of Anxiety Lands on Yang Zhilin
Ultimately, what the open vs. closed source debate shows America is the same, larger dilemma: Will the future of AI only serve a few companies that can sign big contracts, or will it become a capacity like electricity or the internet, usable by more and more ordinary teams? If the answer gradually leans towards the latter, who can attract developers and keep young people willing to experiment will become more important than who has more enterprise clients.
And the question of "where people go" eventually brings America's anxiety to a very specific name.

Yang Zhilin is repeatedly mentioned by the U.S. tech circle not just because he is an excellent Chinese researcher, and certainly not because someone wants to frame the issue as "America failed to retain talent." Reducing a person's choice of location to a visa is too superficial and smacks of hindsight.
What truly stings Americans is the unplayable hypothetical: What would have happened if someone like Yang Zhilin and his team had completed their entire journey from research to entrepreneurship in the U.S.? They would have trained models using American clouds and chips, recruited from America's talent network, taken money from American VCs, and pitched their products to American enterprise clients. A few years later, Wall Street's ledgers might feature a new star company. One person's choice, following that familiar relay chain, can transform into revenue for a string of companies, jobs for a group of people, and confidence for an entire industry.
America's greatest past pride was this amplification ability. It wasn't just about attracting smart people to study and work; it was about capturing their ingenuity and preventing it from stagnating in papers or labs. The U.S. had enough money, enough customers, and enough people willing to take risks together.
Why didn't someone like that stay in the U.S.? Legendary investor Vinod Khosla directly blamed the Trump administration's tightened immigration policies. But Yang's PhD advisor at Carnegie Mellon, Ruslan Salakhutdinov, refuted this, clarifying it had nothing to do with visas. Yang had plenty of opportunities to stay back then. Salakhutdinov even emailed Apple executives asking if they wanted to recruit Yang.
Yang Zhilin was determined to return to China to start his company.
This is the most painful part of the entire debate. "He chose to return on his own" is far more uncomfortable for America than "he was driven away by immigration policy." The former implies a system that can be fixed; the latter means that even if you open the door wide, they may not want to enter.
What truly stings in the overseas discussion of Yang Zhilin is never "another excellent Chinese researcher has emerged." It is the counterfactual: if this person had stayed within the American system, his papers, teams, funding, and company valuation would have been logged in America's AI ledger. Now, this achievement is first seen as a Chinese team's capability, then radiated globally through the open-source community.
For a system that has been confident for half a century, the hardest thing to accept is often not someone being stronger than you, but someone proving that they can reach the finish line without passing through you.
China has a dense pool of engineers, teams that can quickly turn ideas into products, a massive application


