TOTM

Open Models, Closed Minds: AI Policy Keeps Regulating the Wrong Thing

Artificial intelligence has found a new way to make policymakers nervous. The latest fight concerns less what AI can do than who may build it, copy it, distribute it, and decide when those activities become a security threat. That fight will help define AI governance, the rules and institutions used to manage AI development, access, safety, competition, and misuse.

On July 16, Moonshot AI, a Chinese artificial-intelligence company, released Kimi K3. It is an open-weight model, meaning the numerical parameters that encode what the model learned are publicly available for others to download, modify, and run. Even skeptical observers rated K3 “pretty much on par” with the best publicly available models of early 2026.

Five days later, OpenAI disclosed a very different milestone. During an internal cybersecurity evaluation, its models chained together several zero-day exploits, escaped their test environment, and achieved remote-code execution on Hugging Face’s production servers. A zero-day exploit targets a software flaw unknown to the developer or not yet patched. Remote-code execution allows an attacker to run commands on another computer. Hugging Face is a widely used platform for hosting and distributing AI models, datasets, and development tools. OpenAI called the result “unprecedented.”

Then Washington entered the fray. On July 22, White House science adviser Michael Kratsios said the government had information that Moonshot built K3 by distilling Anthropic’s Fable model at industrial scale. Distillation is a technique for training a smaller or competing model on the outputs of another model. A distillation attack uses large volumes of unauthorized or deceptive queries to copy capabilities from a rival system.

According to Kratsios, Moonshot used a platform designed to evade detection and relied on export-controlled Nvidia servers accessed through Thailand. Within hours, Treasury Secretary Scott Bessent warned that “open source is not open season on American IP” and said distillation attacks that “cross the line into IP theft” could put “sanctions and Entity List designations . . . on the table.” An Entity List designation subjects a person or company to U.S. export restrictions, often requiring licenses before American firms may supply specified goods, software, or technology.

The three developments point in different directions. Kimi K3 suggests that the gap between leading proprietary and open-weight models may be measured in quarters rather than years. OpenAI’s disclosure shows that even one of the world’s best-funded laboratories struggled to keep its own model inside a sandbox, a controlled environment intended to prevent outside access or damage.

The White House response points somewhere else again. Washington reached for its strongest trade and sanctions tools to address conduct that, by the government’s own account, involved fraudulent application programming interface (API) access and smuggled chips rather than open weights themselves. An API allows one piece of software to send requests to another and receive its outputs.

These events identify the questions AI governance should confront. The policy debate nonetheless keeps looking elsewhere.

That debate came into focus last week in a widely shared response to Kimi from Dean Ball, a former White House AI-policy adviser, current head of strategic futures at OpenAI, and author of the Hyperdimensional newsletter. Two of his claims deserve scrutiny. The first is that open-weight models are “inherently decelerationist” because they discourage investment in frontier-model development. The second is that a world dominated by open weights ends in “full AI communism,” with the state providing AI as “digital public infrastructure.”

Both claims misunderstand how markets create value. They also direct policymakers toward the wrong tools for addressing AI misuse and security threats.

Policymakers should focus on three priorities. They should preserve a healthy mix of open and proprietary models so defensive AI tools can spread widely. They should abandon export controls that fail to achieve their aims while imposing serious unintended costs. And they should recognize that firms providing access to models are often best positioned to detect and stop abuse.

Read the full piece here.