{"id":624616,"date":"2026-08-07T02:44:14","date_gmt":"2026-08-07T02:44:14","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/624616\/"},"modified":"2026-08-07T02:44:14","modified_gmt":"2026-08-07T02:44:14","slug":"one-of-chinas-most-powerful-ai-models-has-also-escaped-containment","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/624616\/","title":{"rendered":"One of China\u2019s Most Powerful AI Models Has Also Escaped Containment"},"content":{"rendered":"<p>The AI industry is having a rogue agent summer. The latest model to <a href=\"https:\/\/www.wired.com\/story\/openai-models-escaped-containment-and-hacked-huggingface\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">escape onto the open internet<\/a> during security testing is <a href=\"https:\/\/www.wired.com\/story\/silicon-valley-is-completely-divided-over-chinese-ai\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">Kimi K3<\/a>, a powerful <a href=\"https:\/\/www.wired.com\/story\/chinas-open-ai-models-are-challenging-silicon-valleys-playbook\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">open-weight offering<\/a> from the Chinese company <a data-offer-url=\"https:\/\/www.moonshot.ai\/\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.moonshot.ai\/&quot;}\" href=\"https:\/\/www.moonshot.ai\/\" rel=\"nofollow noopener\" target=\"_blank\">Moonshot AI<\/a>.<\/p>\n<p class=\"paywall\">Frontier Security, a US startup, <a data-offer-url=\"https:\/\/blog.frontier.security\/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations\/\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.frontier.security\/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations\/&quot;}\" href=\"https:\/\/blog.frontier.security\/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations\/\" rel=\"nofollow noopener\" target=\"_blank\">says that<\/a> Kimi K3 went outside of its sandbox while testing its defensive cybersecurity skills. As with incidents previously reported by <a href=\"https:\/\/www.wired.com\/tag\/openai\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> and <a href=\"https:\/\/www.wired.com\/tag\/anthropic\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic<\/a>, the escape was partly enabled by a misconfiguration in the sandbox designed to contain it. Frontier claims, though, that the incident shows Kimi has fewer cyber safeguards than most other powerful AI models, something that allowed it to go off and use the internet without express permission.<\/p>\n<p class=\"paywall\">\u201cWe found a leak in the sandbox,\u201d says Yaron Singer, CEO of Frontier Security. \u201cBut we also found that Kimi took advantage of that loophole\u2014suggesting that it doesn&#8217;t have [the same] internal guardrails.\u201d<\/p>\n<p class=\"paywall\">Unlike other recent incidents of AI agents going off-script, Kimi K3 did not hack anything after accessing the internet\u2014because the answers to the problems it was seeking were easily attainable on GitHub.<\/p>\n<p class=\"paywall\">Moonshot did not respond to a request for comment by time of publication.<\/p>\n<p class=\"paywall\">The incident is the latest in a string of agent mishaps that suggest increasingly cyber-capable AI models are becoming more challenging to control.<\/p>\n<p class=\"paywall\">Last month, OpenAI disclosed that an unreleased model had broken out onto the internet and then <a href=\"https:\/\/www.wired.com\/story\/openai-models-escaped-containment-and-hacked-huggingface\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">hacked Hugging Face<\/a>, a company that hosts AI models and data, in order to find answers to problems it was tasked with solving. OpenAI subsequently shared that its AI agents had in fact hacked into <a href=\"https:\/\/www.wired.com\/story\/openais-rogue-ai-agent-hacked-more-than-just-hugging-face\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">four additional services<\/a> as part of the spree.<\/p>\n<p class=\"paywall\">Shortly after OpenAI reported its incident, <a href=\"https:\/\/www.wired.com\/story\/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic revealed<\/a> that several of its models had also gained access to the internet and attacked outside systems. Last week, the <a href=\"https:\/\/www.wired.com\/story\/ok-well-there-are-even-more-ai-agent-hacking-incidents\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">AISI also disclosed<\/a> that in its own testing, versions of OpenAI and Anthropic models that had security safeguards disabled perpetrated multiple hacks across the internet, including a particularly ambitious attempt by Anthropic\u2019s Mythos 5 to plant malicious code in an open-source project on GitHub.<\/p>\n<p class=\"paywall\">While these AI hacking episodes all vary in both cause and degree, the Kimi K3 is similar to several of them in that a misconfigured sandbox allowed access to a number of websites rather than keeping it contained to a simulated environment. The model was expressly tasked with solving problems that should not have involved going off to find the answers online, and appears to have gone outside of those instructions. The model had to figure out for itself that it had access to certain websites by probing the network settings of the sandbox.<\/p>\n<p class=\"paywall\">While human error appears to have played a major role in each of the breakouts, the consequences have been compounded by the fact that advanced AI models are designed to use reason and take complex actions in order to solve problems.<\/p>\n<p class=\"paywall\">Another key difference between previous incidents and the one discovered by Frontier Security is that it involves a model that is already widely available, with the same safeguards an average user would encounter.<\/p>\n<p class=\"paywall\">\u201cKimi K3 is very good at following a goal by any means necessary and also doesn&#8217;t have the guardrails to prevent it from cheating or escaping the sandbox,\u201d says Paul Kassianik, a researcher at Frontier Security.<\/p>\n<p class=\"paywall\">Kassianik and Singer both say that Kimi and other open-weight models are also excellent tools for cybersecurity defense. (Hugging Face ultimately used an unnamed AI model from China to defend itself against the OpenAI agent hack.) Their company has developed <a data-offer-url=\"https:\/\/evals.frontier.security\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/evals.frontier.security&quot;}\" href=\"https:\/\/evals.frontier.security\" rel=\"nofollow noopener\" target=\"_blank\">benchmarks<\/a> that measure a model\u2019s capacity to find vulnerabilities in software and networks, which show that Kimi excels at these tasks.<\/p>\n","protected":false},"excerpt":{"rendered":"The AI industry is having a rogue agent summer. The latest model to escape onto the open internet&hellip;\n","protected":false},"author":2,"featured_media":624617,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[9668,6006,289,381,982,18,19,17,307,82],"class_list":["post-624616","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-agentic-ai","tag-anthropic","tag-artificial-intelligence","tag-china","tag-cybersecurity","tag-eire","tag-ie","tag-ireland","tag-openai","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/117051933806465034","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/624616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=624616"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/624616\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/624617"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=624616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=624616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=624616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}