Earlier this month, Beijing-based start-up Moonshot showcased its recently released Kimi K3 artificial intelligence model, marking a notable development in China’s growing AI sector. Founded by Yang Zhilin, who named the company after Pink Floyd’s album *Dark Side of the Moon*, Moonshot has positioned Kimi K3 among a suite of Chinese AI models gaining international attention for their competitive performance and cost advantages.

Within China, Kimi K3 has been celebrated as a demonstration of the country’s technological capabilities, challenging U.S. dominance in the AI field. Several U.S. companies have reportedly begun adopting Chinese open AI models such as Kimi K3, Z.AI’s GLM, DeepSeek’s R-1, and Alibaba’s Qwen 3.8 Max to lower operational costs while improving performance. Flo Crivello, CEO of San Francisco-based Lindy AI, noted that switching to DeepSeek’s model has both cut expenses and enhanced core functionality.

Despite these benefits, the use of foreign open-source AI models raises questions about potential security risks. U.S. officials have expressed concerns around surveillance, intellectual property theft, espionage, and the possibility of Chinese access to critical domestic infrastructure via these tools. The Biden administration is reportedly considering regulatory measures to limit or sanction the deployment of Chinese AI models on U.S. soil.

However, experts argue that focusing solely on the nationality of the model developer overlooks deeper complexities. Open-source AI models, including Kimi K3, make their training parameters publicly available, allowing users to download, fine-tune, and operate the models independently on their own servers or third-party platforms. This means that security considerations largely hinge on who controls the infrastructure hosting the AI rather than the country of origin of the model itself.

Models hosted within the U.S., for example, are not subject to the same data censorship rules imposed in China and may respond more openly to queries. Moreover, users can customize the models’ content restrictions to suit their needs. Even when such models are run on Chinese servers, where laws require cooperation with national intelligence agencies, enforcement can be inconsistent. A recent incident involving Chinese officials attempting to access data from the e-commerce platform Pinduoduo ended in conflict and highlighted potential resistance to government intrusion.

The United States currently lacks a robust open-source AI framework of its own, which some analysts view as a strategic vulnerability. Kevin Xu of Interconnected Capital has compared open-source AI capacity to cultural exports like Disney films and K-pop in terms of national influence. Yet building secure infrastructure to defend against increasingly sophisticated AI-driven cyber threats remains a critical challenge.

Transparency enabled by openly shared model parameters may offer a route to mitigating risks. Recently, the U.S.-based platform Hugging Face used a Chinese open AI model to investigate a cyber breach involving an AI agent—conducted entirely within its own secure environment without data leaving its system.

While governments persist in framing AI competition as a global arms race, experts emphasize that the flow of innovation and threats rarely align neatly with national borders. Addressing issues of data control and security in an interconnected world requires updated protocols that go beyond traditional notions of national sovereignty.