On July 16, Chinese lab Moonshot AI released Kimi K3, a 2.8‑trillion‑parameter open‑weight model that within days displaced Anthropic’s Fable 5 atop a widely watched coding leaderboard. The next day, President Xi Jinping urged attendees at the World AI Conference in Shanghai to “seize this rare, historic opportunity to encourage open‑source,” while also calling for “laws and regulations, technological monitoring, early warning and emergency response systems” to keep AI secure. The question is simple and urgent: can China keep its AI open?
Kimi K3 and the push for openness
Moonshot’s open‑weight release — downloadable model parameters anyone can run — is the latest example of a broader Chinese strategy. Leading Chinese firms routinely publish open weights (and less often full open‑source code or training recipes) to reduce dependence on foreign technology, expand influence in cost‑sensitive markets, and let adopters shoulder serving costs. Open releases also suit labs working with constrained compute: by publishing weights they avoid the expense of operating large inference services and can still drive global uptake and local fine‑tuning.
The practical upside is clear. Moonshot acknowledged demand has pushed its closed Kimi K3 service “close to the limits” of current capacity and temporarily paused new subscriptions to prioritize existing users. Open‑weight distribution relieves such bottlenecks by shifting compute to deployers and lowers the barrier for widespread adoption.
Why the frontier changes the calculus
As Chinese models approach frontier capabilities, the risks tied to open weights grow. Open releases cannot be recalled, allow unrestricted modification and redistribution, and remove a provider’s control over downstream behavior. Regulators and standards bodies in China have begun to recognize those differences: officials warned of “risks of technological loss of control,” and some bodies have proposed “circuit breakers” and safety stop switches for frontier systems.
Empirical work underlines the danger. Researchers demonstrated that safety alignment on an open‑weight model could be undermined with a handful of fine‑tuning examples; other evaluations found significant variance in how models respond to malicious prompts. Chinese institutions such as Alibaba Research Institute, Tencent Research Institute and the Academy of Information and Communications Technology have flagged that open models increase potential misuse, and the national cybersecurity standards body warned open weights make it “easier for criminals to train malicious models.”
The measurement problem
A central barrier to selective openness is measurement: determining which models are safe enough to publish and which must remain closed. China already runs an extensive AI regulatory apparatus that requires companies to self‑assess models and register them with provincial

