Blog
|

On July 16, Moonshot AI released Kimi K3. It’s a 2.8-trillion-parameter mixture-of-experts model with a one-million-token context window and native visual understanding. Moonshot describes it as the world’s first open model in the 3-trillion-parameter class, the largest open-weight release to date.

Most executives can’t say which AI models their teams use, or what data those models see. Kimi K3 makes that blind spot far more dangerous.

Until now, the open, downloadable models your teams could grab on their own were clearly weaker than the ones you pay for and control.

On the independent Artificial Analysis Intelligence Index, K3 is the strongest open-weight model published to date, within a few points of the closed frontier. As of July 28, 2026, it scores 57, fourth overall behind Claude Opus 5, Claude Fable 5, and GPT-5.6 Sol, and level with the tier just below them. Moonshot’s own evaluations put it ahead of several frontier models across coding and agentic benchmarks. The distance between open-weight models and the closed Western frontier is now measured in months.

Artificial Analysis Intelligence
Artificial Analysis Intelligence Index v4.1, as of July 28, 2026. Source: Artificial Analysis

And Moonshot has now published K3’s full open weights, putting a frontier-class model on infrastructure any capable enterprise can run itself.

New to some of these terms?

  • Open-weight (open weights): A model whose trained values are published for download, so any organization can run it on its own hardware instead of only through the vendor’s service.
  • Self-host: Running the model on infrastructure you control rather than calling a vendor’s cloud, so your data stays inside your own environment.
  • Parameters: The internal values a model learns during training. More parameters generally means more capability, and the count is a rough proxy for a model’s size.
  • Mixture-of-experts: A model design that splits work across many specialized sub-networks and activates only a few for any given task, so a very large model runs at a fraction of its full computing cost.
  • Context window: The amount of text a model can hold in view at once, measured in tokens. A one-million-token window can take in thousands of pages in a single prompt.
  • Token: The unit a model reads and writes in. A token is roughly three-quarters of a word, so 1,000 tokens is about 750 words.
  • Benchmark: A standardized test used to compare AI models on a specific skill, such as writing code or answering technical questions.
  • Agentic: AI that carries out multi-step tasks on its own, such as browsing, running tools, and acting on the results, rather than just answering a single question.
  • Shadow AI: Employees using AI tools the organization hasn’t approved or can’t see, which puts sensitive data outside any policy or oversight.
  • LLM gateway: A single controlled entry point that all AI requests pass through, so an organization can apply security, filtering, and logging in one place. LLM stands for large language model.
The Reflex

The Wrong Place to Start

Most enterprises spent this week asking whether to block a Chinese open-weight model.

Blocking doesn’t work. Employees adopt tools faster than IT can restrict them, and the next capable model is always a few weeks out. You can ban Kimi K3 by name on Monday and have three teams running something equivalent by Friday. Once the weights are public, there’s no vendor to call and no switch to flip. Governing it falls to you.

The real question is how you govern the whole model landscape. How can you evaluate a new model, adopt the desirable ones, restrict the others, and audit all of it, without rebuilding your controls every time the market changes?

Why Blocking Fails

The Shadow AI Reality

Every enterprise already has shadow AI. Staff paste sensitive data into the model that provides the best answer, and most of that traffic never touches a policy check. A frontier-class open-weight model anyone can self-host makes the problem worse. It’s more capable and easier to run in the open.

Approval without governance is worse than the risk you’re trying to mitigate. Saying “yes” to a model with no policy engine, no data filtering, and no audit trail hands teams a powerful tool and no guardrails. Saying “no” just pushes the same usage underground.

In April 2026, Kimi disclosed one user’s real resume, including their name, phone number, and full work history, to an unrelated user during a routine task. The OECD’s AI Incidents Monitor catalogued it as a confirmed cross-user data isolation failure. A model that leaks one customer’s data to another is exactly the case you want to catch at a policy layer, not discover after your staff have been pasting sensitive data into it for weeks.

The Traffic Your Tools Can’t See

Nearly half of employees use AI tools their employer never sanctioned, and most security teams can’t see the data leaving.

Why bans don’t fix shadow AI

The Blueprint

What Good Governance Looks Like

A governance layer that survives a shifting model market has a few non-negotiable parts:

  • A model picker that allows or restricts specific models by policy, including or excluding Kimi K3, as a setting your team controls
  • A policy engine that filters PII and sensitive data before it reaches any model
  • A private gateway so prompts and data stay inside your walls rather than crossing into a vendor’s environment
  • Multi-model routing so you can switch models as the benchmarks move, without starting over each time
  • A full audit trail that shows the board and regulators which models touched which data

Build this in the next few months and you can adopt the best model available whenever it ships. Skip it and you’ll spend the next two years catching up to the market.

Is Your AI Labeled?

Blocking the prompt or the copilot only works if you can predict where AI will show up. The fix is to tag the data itself as AI-eligible.

The control belongs on the data

The Stakes

Regulated Industries

Those with the most sensitive data and the tightest oversight feel it first.

Energy and utilities

Critical-infrastructure operators can’t route operational data through a model they can’t contain. Data sovereignty is a hard requirement here, enforced by regulators.

Financial services

Between model risk management expectations and data-residency rules, a fintech needs to prove which model saw which data and why. You can’t do that without an audit trail.

Healthcare

HIPAA obligations don’t pause for a new model release. Every AI tool touching PHI needs the same governance any other system handling that data would get.

Whatever the industry, the board asks the same thing. “Can you prove you govern the models touching your data?”

Governed but not restricted

Introducing Sovereign AI by Armor

Armor built Sovereign AI to solve exactly this. It’s an enterprise AI governance platform. Every model, local or frontier, runs through one governed control plane with policy, PII protection, spending caps, and full audit. You govern what runs, without locking your teams out of the models they need.

Learn more at Black Hat

On August 5th, we’re launching Sovereign AI at Black Hat. Come see us at booth 8308, or read more at sovai.com.

About Sovereign AI

Sovereign AI is the governed AI work platform for the whole company, built by Armor. One control layer for every model, every team, and every dollar, inside your walls, under your rules. Armor has spent 17 years securing regulated industries, protecting over 1,700 organizations across 40+ countries held to the highest compliance bars in the business. Sovereign AI is what that experience looks like as a product. Learn more at sovai.com.

About Armor

Since 2009, more than 1,700 organizations in 40+ countries have relied on Armor to protect regulated data in the public and private cloud. AI is the next risk, so Armor built Sovereign AI to bring that same protection and compliance to how organizations use AI in the workplace: a fully governed platform that lets them leverage AI without creating undue risk to their data and their regulatory obligations. For more information, visit armor.com and sovai.com and follow us on LinkedIn.