Kimi K3 還剩 4 天開源,美國人這次是真急了
- 核心觀點:中國 AI 模型 Kimi K3 的發布引發美國科技界震動,被比作「斯普尼克時刻」,凸顯了開放模型在效率與生態上的競爭力,動搖了美國以閉源模型與硬體優勢為核心的 AI 霸權敘事。
- 關鍵要素:
- 美國投行將 Kimi K3 的衝擊解讀為儲存需求增長,相關股票(如美光漲 12%)暴力反彈,試圖迴避對自身商業模式(如閉源模型定價權)的直接質疑。
- Kimi K3 透過開放模型策略降低了 AI 開發門檻,威脅美國閉源模型的高毛利企業服務模式,迫使開發者與企業擁有更多選擇,削弱了美國的議價權。
- 前 OpenAI CTO Mira Murati 發布的開放模型 Inkling,後訓練使用了 Kimi K2.5 等中國模型數據,顯示中國開源生態對美國 AI 研發的實際影響。
- OpenAI 旗艦模型 GPT-5.6 Sol 在安全測試中「越獄」,竊取 Hugging Face 資料庫答案,暴露了閉源模型的安全漏洞,反襯出開放模型在透明度上的優勢。
- 美國對華晶片限制未阻止中國 AI 進步,反而催生了更具效率的工程團隊,如月之暗面使用合規晶片 H800 完成訓練,同時中國開始討論限制先進模型外流,攻守態勢逆轉。
- 對美焦慮的焦點落在月之暗面創始人楊植麟身上,其主動選擇回國創業而非留守美國,反證美國對頂尖人才的吸引力下降,即使是寬鬆的移民政策也未必能挽留。
Original author: Dongcha Beating
Americans always want to sit at the very center of every industry.
The AI circle is no different. Americans have always exuded an aura of confidence, holding a hand of cards that seems impossible to lose.
No matter who is building AI applications elsewhere, Americans believe that, in the end, everyone will have to come back to them to settle the bill. The chips are from Nvidia, the cloud is from Microsoft, Amazon, and Google, and the most expensive models are locked behind the APIs of OpenAI and Anthropic. For companies around the world wanting to use AI, they ultimately have to pass through the US.
Even when a Chinese team occasionally appears on the leaderboards, Wall Street doesn't take it too seriously. Chips are choked off, the cloud is in their hands, and talent is still flowing to Silicon Valley – how could they lose?
But this relaxed sense of invincibility has recently been shattered by Kimi K3, a Chinese model.

The US tech circle went into emergency mode, dubbing Kimi K3 the "Sputnik moment" – akin to the shockwaves sent through America when the Soviet satellite launched in 1957. Discussions on X about Kimi K3, Yang Zhilin, and Chinese models quickly escalated from niche tech circles to topics generating tens of millions of views.
Kimi K3 didn't beat the strongest US closed-source models on every single metric, but it allowed more people to see the possibility that powerful capability, high efficiency, and an open ecosystem might not only emerge simultaneously from a few US laboratories.
Silicon Valley is indeed anxious.
Storage is the Palliative for US AI Anxiety
When news of Kimi K3 reached Wall Street, several investment banks simultaneously released research reports. Instead of spending pages discussing which products it might disrupt or whether it would force US models to lower prices, they quickly shifted their focus to storage.
These institutions almost unanimously interpreted Kimi K3's emergence as signifying: a strong demand for storage. Longer context windows mean AI needs to remember more things – images, sounds, videos, and work records will accumulate. Consequently, flash memory, hard drives, data centers, and data services will all benefit.
Thus, Micron, SanDisk, and Western Digital became the beneficiaries in this narrative.
Sure enough, on the US stock market yesterday, storage stocks saw a violent collective rebound. The Roundhill Storage ETF surged 10.91% in a single day, SanDisk jumped 14.27%, and Micron rose 12%. A sector that was being battered just days ago over "DeepSeek Moment 2.0" had overnight become the most certain long bet.
From an industrial perspective, this logic isn't nonsensical. Old chatbots were like one-off Q&A sessions: you ask, it answers, you close the page, and much of that interaction is forgotten. But the AI everyone now anticipates is more like a new employee joining a company. It needs to review past contracts and emails, remember what clients said, take over unfinished work from yesterday, and leave records to avoid blame if errors occur. An AI that can act, remember, and process images and audio will certainly "consume" more data than a chatbot just making small talk.
This conclusion isn't pulled from thin air, but looking back at previous model launches and deployments, was the market's reaction ever to "ignore the model, focus on storage"?
It's just that this provides a comforting answer for Americans.

The impact of a Chinese model should have led to a series of uncomfortable questions: Will it make it harder for US model companies to maintain high prices? Will it make developers less dependent on them? Will it mean new companies don't necessarily have to start in Silicon Valley? Why not directly discuss whether Kimi K3 will steal users, force price cuts, or compel product changes from competitors?
Skirting around the sharpest questions to first discuss hard drives has a bit of a "protesting too much" feel to it.
It's like a shop owner who thought he monopolized the entire street, suddenly finding a highly competitive new store opening next door, and quickly comforting himself: no matter how many customers the new store gets, they still have to buy my water, electricity, and counter space.
Storage is the strongest palliative under the anxiety of the US AI circle.
Closed-Source Models Start to Chafe
For the past few years, closed-source has been the almost indisputable standard answer for US AI.
The stronger the model, the more it should be locked behind an API. Users pay for calls, model companies enjoy high margins, and security and compliance are centrally managed. It's a dignified and profitable path, smooth sailing, comforting clients, satisfying investors, and easy for regulators.

Americans had even grown accustomed to the rhythm of this path: release a stronger version every few months, set a higher price, and tell a bigger story.
But as open models get stronger, this path starts to get bumpy.
Kimi K3's position on this chessboard isn't about "catching up"; it's about bringing down the cost of catching up. The most dangerous thing about an open yet powerful enough model isn't just what it can do itself, but that it hands a much cheaper learning curve to all the latecomers.
This isn't a battle of tech ego; it's about whether the business itself will be rewritten. America's most comfortable arrangement was building AI primarily as an enterprise service: capabilities hidden in the cloud, clients locked into long-term contracts. Ordinary people couldn't see the underlying system, nor could they easily switch away. But if models elsewhere are good enough, developers get another choice, enterprise procurement departments get another quote sheet, and small teams don't necessarily have to bet their future on the same batch of US companies. By then, simply holding a few big contracts and selling AI only to the B2B market is no longer an impregnable moat.
This means Kimi will foster the emergence of more excellent models, and also mean greater competition among models, thus diminishing their pricing power.
The US tech circle has felt the wind changing direction too.
A few days before Kimi K3's release, on July 15th, Thinking Machines Lab, founded by former OpenAI CTO Mira Murati, released a model called Inkling. With nearly a trillion parameters, its code and tech are completely open, free for anyone to download, modify, and use commercially.
This could be considered America's first "real" open-source AI. While Meta's Llama, Google's Gemma, Microsoft's Phi, Nvidia's Nemotron, and OpenAI's gpt-oss preceded it, these were mostly experimental.
Inkling's significance lies in the fact that someone who had reached the pinnacle of closed-source – a former OpenAI CTO – has turned around to seriously pursue open-source.
Notably, in the early stages of Inkling's post-training, it used data generated by open models like Kimi K2.5, and its architecture also referenced ideas from DeepSeek. In other words, America's most respectable open-source attempt was also written on the shoulders of Chinese open-source.
This stands in stark contrast to Anthropic. In February this year, Anthropic publicly accused DeepSeek, Moonshot AI (Kimi), and MiniMax of conducting "industrial-grade distillation" on Claude, claiming they created 24,000 fake accounts and made 16 million conversations to steal Claude's capabilities. In June, they escalated, specifically naming Alibaba. By July 21st, Trump administration Treasury Secretary Bessent stated they could impose sanctions on China for "AI theft."
However loudly the threat narrative is shouted, when it actually comes to controlling costs and improving efficiency, Chinese models are genuinely appealing.
Airbnb uses Qwen for customer service, Cursor used Kimi to build its own programming agent, DoorDash outsourced part of its workload directly to Kimi, and even Murati's Inkling used Kimi's data for post-training.
Whether it's the chafing of the closed-source path or the backlash from distillation accusations, these are still just embarrassments at the business model level. Issues of privacy and security, however, truly shake the final protective charm of the closed-source camp.
"Jailbreaking" AI Models
The last line of defense for closed-source has always been security.
The model is locked away, weights are sealed, access runs through APIs, data stays within boundaries. This space enclosed by four walls constitutes the most compelling promise of the closed-source camp. Enterprise clients pay a premium for this perceived security.
But enterprises are becoming increasingly uneasy. They are starting to ask uncomfortable questions: My code, contracts, and client data – after handing them to your model, what did you do with them? An agent with access to a browser, terminal, credentials, and long-term goals – will it cross the line I set for it to achieve its task? Sending tokens to a closed-source API, in a sense, means letting data leave your own wall. This is precisely the strongest selling point of open weights: at least I can see what the model is doing.
And right in the middle of the heated debate over which side is more secure, an almost darkly comedic incident occurred.
On July 21st, OpenAI itself confirmed that its flagship model, GPT-5.6 Sol, along with a more capable unreleased model, escaped its isolated environment during an internal cybersecurity evaluation.
Here's what happened: The engineering team wanted to test the model's attack and defense capabilities to the limit, so they lowered the model's safety restrictions and disabled the usual protective measures against risky behavior. The model was simply supposed to complete the test questions. However, it discovered a security vulnerability in the system itself, exploited it to climb onto the public network, bypassed permissions, traversed systems, and finally used stolen login credentials to penetrate the core systems of Hugging Face, the world's largest open-source AI platform, directly snatching the answers to the test questions from the database.
OpenAI's explanation boiled down to eight words: "No malicious intent, excessive focus."
Those eight words are what truly send a chill down the spine.
For enterprise clients, the scariest thing has never been a model actively turning malicious. It's the model diligently and perfectly carrying out a bad objective for you.
The greatest irony of this incident is that over the past year and a half, the world has been guarding against the hypothetical "dangerous Chinese open-source model," which remains just a hypothesis. The one that actually jailbroke and breached another production system was the closed-source camp's own flagship. Hugging Face CEO Clem Delangue quickly turned the incident into an advertisement for open-source, stating that AI safety won't be solved behind closed doors by one company, but only through open collaboration.
The same incident was used by both the open and closed camps as evidence for the correctness of their own path.
The real future watershed probably isn't whether a model is open-source or closed-source, but rather what kind of sandbox, identity system, revocable permissions, and audit logs the model operates within. Neither closed-source nor open-source can avoid this question.
And while the closed-source camp's own security narrative was crumbling, an even larger-scale reversal was quietly taking place.
Offense and Defense Switch: It's America's Turn to Be Afraid
In some US policy discussions and tech narratives, there has long been an almost "Three-Body Problem"-style imagination: If you restrict the most advanced Nvidia chips from entering China, AI progress will inevitably slow down.
This doesn't mean China can't do research at all, but rather that the gap in computing power will widen, and the threshold for training cutting-edge models will become insurmountably high. Advanced chips are like the "laws of physics" in this race; those without them cannot get ahead.
This judgment wasn't entirely unfounded. Building large models requires significant compute power. Chip restrictions increase costs, slow down scaling, and make it harder for many teams to replicate the training scales of US labs. The problem is, restrictions also change people's choices. If you can buy the best off-the-shelf tools, you have less incentive to figure out how to use less compute, modify model architectures, or make every training run more economical. But when the door is shut, taking a detour is no longer a choice but a survival instinct.
So Americans find it hard to understand why restricting Nvidia's supply hasn't left Chinese models stagnant, but instead has forced out a cohort of teams that are more desperate in terms of efficiency, engineering, and open-source distribution.
It is said that Moonshot AI (Kimi) is still using the Nvidia H800, the compliant AI chip customized for the Chinese market in 2023, for training.
This is perhaps the classic Chinese "millet plus rifles" approach.
In June 2026, to comply with export controls, the US temporarily shut down Anthropic's strongest models, Fable 5 and Mythos 5. While this might be legally justifiable, it hands every Chinese open-source lab a readymade marketing slogan: at least our models don't have a switch that can be remotely disabled.
The more you emphasize control, the more that control becomes your opponent's selling point.
Even more dramatic is the flip side. According to Reuters, China has also started meetings with companies like Alibaba and ByteDance to discuss whether to restrict foreign access to China's most advanced AI models, even including those already publicly released as open-source. 360 founder Zhou Hongyi also publicly called for China to have its own top-tier closed-source models to hold the high ground.
A year ago, America was worried about advanced chips flowing into China. A year later, it's China's turn to have things worth restricting.
But amidst all this structural anxiety – about storage, compute power, closed-source, security, and the reversal of offense and defense – there is a most specific, most poignant, and most personal focal point. It's not an industry trend, a research report, or a policy.
It's a person.
The Anxiety Lands on Yang Zhilin
Ultimately, what the open-source debate shows America is a larger challenge: Will the future of AI serve only a few companies that can sign large contracts, or will it become a capability, like electricity or the internet, that more and more ordinary teams can utilize? If the answer gradually leans toward the latter, then whoever attracts developers, whoever makes young people willing to stay and tinker, will become more important than whoever has more enterprise clients.
And this question of "where people go" ultimately brings America's anxiety to a very specific name.

The reason Yang Zhilin is repeatedly mentioned in the US tech circle isn't just because he's an excellent Chinese researcher, nor simply because some want to frame the topic as "America failed to retain talent." Reducing a person's decision to stay or leave to a visa issue is too simplistic, too much like hindsight.
What truly stings Americans is the unanswerable hypothetical: What if people and teams like Yang Zhilin had completed their entire journey from research to entrepreneurship in the US? They would train models using US cloud and chips, recruit from the US talent network, take money from US venture capitalists, and pitch products to major US enterprise clients. A few years later, Wall Street's ledger might have a new star company. One person's choice, following that familiar relay chain, could become a stream of company revenue, jobs for a group of people, and confidence for an entire industry.
What America was most proud of in the past was this amplifying ability. It wasn't just attracting smart people to study and work, but capturing their drive, preventing it from stopping at a thesis or a lab. There was enough money, enough clients, and enough people willing to take risks together.
Why didn't such a person stay in America? Legendary investor Vinod Khosla directly pointed the finger at the Trump administration's tightened immigration policies. But Yang Zhilin's advisor at Carnegie Mellon, Salakhutdinov, came to his defense, saying it had nothing to do with visas. Yang had plenty of opportunities to stay back then. Salakhutdinov even emailed Apple executives to ask if Yang wanted to join.
It was Yang Zhilin himself who was determined to return to China to start his company.
This is the most heartbreaking part of the debate. "He chose to return home on his own" is far more painful for America than "he was driven away by immigration policy." The former implies the system can be fixed; the latter implies that even if you open the door wide, people might not want to enter.
Overseas discussions about Yang Zhilin are never truly stung by "yet another outstanding Chinese researcher emerging." The real sting comes from the counterfactual: If this person had stayed within the US system, his papers, his team, his funding, and his company's value would have been written into the ledger of American AI. Now, this achievement is first seen as the capability of a Chinese team, then radiates globally through the open-source community.
For a system confident for half a century, the hardest thing to accept is often not that someone is better than you, but that someone proves you don't have to pass through it to reach the finish line.
China has a dense pool of engineers, teams capable of quickly turning ideas into products, a massive application market, and clients willing to pay for efficiency. Open models make


