Showing posts with label AI Model Alert. Show all posts
Showing posts with label AI Model Alert. Show all posts

Tuesday, August 4, 2026

Anthropic representatives discuss AI Safety

See All Articles

The Glasswing Moment: When AI Cybersecurity Became a Geopolitical Flashpoint

In a revealing exchange with the European Parliament’s IMCO committee, Andrew Greenberg, the technical co‑lead of Anthropic’s Project Glasswing, laid bare the extraordinary promise and peril of frontier AI models in cybersecurity. What was intended as an “exchange of views” quickly turned into a tense reckoning with dependency, trust, and the sudden fragility of transatlantic technology alliances. The transcript of that session, now circulating widely, exposes a raw nerve in Europe’s digital sovereignty – and it deserves a careful, critical unpacking.

Mythos Preview: The Dual‑Use Genie Out of the Bottle

Greenberg presented a startling picture of a model that Anthropic did not specifically train for cyber offence but which, by virtue of its coding and reasoning prowess, unearthed thousands of previously unknown vulnerabilities. “In testing, it found thousands of previously unknown vulnerabilities, including in every major operating system and web browser,” he told the committee. The list includes a 27‑year‑old flaw in OpenBSD, one of the world’s most security‑hardened operating systems, and several Linux kernel bugs that the model chained together to seize control of the machine. The company’s Red Team blog details the critical bugs, and the message was unequivocal: releasing such a model broadly would be irresponsible.

Instead, Anthropic launched Project Glasswing – a company‑level partnership with cyber defenders to get ahead of AI‑driven offensive threats. Over 150 organizations in more than 15 countries were given gated access. The results, even within the first month, are staggering. Mozilla found and fixed 271 vulnerabilities in a single Firefox release – ten times what it found in the previous one. A table of publicly known highlights underscores the scale:

Software Vulnerability Age Severity Outcome
OpenBSD 27 years Critical Flaw identified
Linux kernel Multiple, chained High Full machine control achieved
Firefox (single release) Unknown 271 high/critical Fixed (10× previous rate)
Across Glasswing partners 10,000+ high/critical Found in first month

“Finding vulnerabilities is no longer the bottleneck,” Greenberg observed. “Fixing them and incorporating AI capabilities across defensive security programs is.” The bottleneck has shifted to triage, remediation, incident response, and configuration scanning – a systemic challenge that no single actor can solve alone.

The Export Control Shock and Its Aftermath

Then came the geopolitical tremor. On 12 June, the U.S. government applied export controls to Anthropic’s newest models – Fable 5 and Mythos 5 – forcing the company to suspend access for all foreign nationals. The controls were lifted on 30 June, and access was restored the following day. Greenberg described subsequent collaboration with U.S. agencies “to review and test our safeguards” and to increase their robustness on the Fable class. Notably, he clarified that the Mythos class – the models with the most worrying dual‑use cyber potential – were not the subject of that safeguard reinforcement; they have “limited safeguards” by design. No specific change was made to them before or after the restrictions.

The episode revealed an uncomfortable truth: a company legally bound to weigh public interest could be compelled overnight to withdraw a critical defensive tool from allies. For European lawmakers, the move was not merely a bureaucratic hiccup but a vivid demonstration of dependence. MEP Dirk Houtink (EPP) captured the mood, describing how the White House intervention had turned a noble technological mission “into a geopolitical tool and an economic tool,” shattering illusions of a solid transatlantic tech partnership.

Europe’s Anxiety: Can We Trust the Model, or Its Maker?

The committee’s questions were sharp and impatient. Would Anthropic even be buildable in the EU, given Europe’s regulatory thicket and energy constraints? Greenberg sidestepped, insisting the real issue was not one company but a global cybersecurity moment: “We expect our competitors to have models of similar capabilities quite soon … some of whom will be providing open weights or won’t be providing them with adequate safeguards.” In other words, fixating on Anthropic misses the point – an approaching wave of less scrupulous models threatens to flood the zone.

MEP Köstl‑Schaldemosen (S&D) raised a more fundamental worry: dependency. If Europe uses Anthropic’s services, it feeds data and growth back to a U.S. entity while remaining at the mercy of Washington’s political whims. Why not develop sovereign EU systems instead? Greenberg offered no real answer, only that the goal should be to up‑level cyber defence globally, using a diverse set of models, not to rely on “one special or magic model.”

The Greens’ Kim van Sparentaak did not hide her alarm: “What is Entropiq exactly doing to ensure people and businesses are safe, not only in the U.S. … but also in Europe?” She demanded to know whether the model could be weaponized for geopolitical gain. The phrasing – “Entropiq” (a misspelling that inadvertently underscored the alienness of the company from a European vantage) – encapsulated the trust chasm.

A Window Measured in Months

Perhaps the most chilling forecast was temporal. “Within three to six months, we expect many other AI companies will have models of this class, and some may release them without safeguards. The window in which defenders hold the advantage is measured in months,” Greenberg warned. The same capability that makes these models dangerous, he stressed, also makes them the most powerful defensive tool ever created – if wielded properly, technology favours defenders long‑term. But that optimism hinges on a global, coordinated response that is nowhere yet in evidence.

The company is working to avoid future circus‑style rollouts. Greenberg admitted that the staged, guarded release was “a long road” born of the need to build protections progressively and watch for misuse. The promise is that future models will be delivered to cyber defenders in a more targeted, predictable fashion. But given the geopolitical electricity that now courses through every AI deployment, that assurance will need far more than good intentions to be believed.

Criticisms

  • The United States government is criticized for abruptly imposing export controls on AI models without prior consultation with allies, thereby weaponising a defensive technology and undermining transatlantic trust.
  • Anthropic is faulted for its insufficient foresight in addressing the geopolitical dimensions of its dual‑use models, leaving European customers exposed to sudden access revocations.
  • The European Union’s regulatory framework is questioned for its potential to stifle indigenous AI development, reinforcing dependency on non‑European providers and slowing the emergence of sovereign alternatives.
  • The White House’s decision to lift controls after internal safeguards review is seen as opaque, with no public clarity on what changes were made to justify restored access, fuelling suspicion of secret concessions.
  • Member states are criticised for a reactive posture, failing to invest coherently in the AI‑enabled cyber defence infrastructure that Greenberg’s testimony makes urgently necessary.

Greenberg ended with a plea for “coordinated, highly collaborative action across many organizations.” It was a message that, in the tension‑filled room, sounded both noble and hollow. The power to act rests not with one technical co‑lead in New York, but with governments that have yet to prove they can match the speed and scale of the threat. The glass may be half‑full, but the window is closing fast.

Sunday, July 26, 2026

China's Moonshot AI Unveils World's Largest Open Model, Sparking New AI Showdown

See All Articles


5 Key Takeaways

  • Kimi K3 is the first open model with 2.8 trillion parameters, marking a milestone in the global AI race.
  • The model features a 1-million-token context window, Kimi Delta Attention, and native vision capabilities for processing long sequences and multimodal inputs.
  • Kimi K3 achieves competitive performance but still trails top US proprietary models like Claude Fable 5 and GPT 5.6 Sol, though the gap is narrowing.
  • Moonshot AI faces allegations of distillation (illicitly extracting capabilities) from US companies like Anthropic, raising intellectual property disputes.
  • The release highlights a strategic divergence: China's open-weight models (backed by Alibaba/Tencent) vs. US closed proprietary systems, with geopolitical implications for AI governance.



China’s Moonshot AI Drops a 2.8-Trillion-Parameter Open Model, Heating Up the Global AI Race

On July 17, 2026, Beijing-based startup Moonshot AI announced Kimi K3, an artificial intelligence model that shatters a symbolic barrier: it is the first “open” model to pack a staggering 2.8 trillion parameters. The release is both a technical showcase and a geopolitical flashpoint. While the model still cannot match the top-tier proprietary systems from American labs, it signals that China’s AI ambitions are now being built in the open—and that the debate over how advanced models should be shared, protected, and paid for is only beginning.

What Are Parameters and Why Do They Matter?

To understand why 2.8 trillion parameters is remarkable, it helps to know what a parameter is. In simplified terms, a parameter is one of the internal dials or weights that an AI model adjusts during training. Think of them as the model’s memory cells: the more it has, the greater its capacity to absorb patterns from data. A higher parameter count often correlates with improved performance on complex tasks like writing code, solving logic puzzles, or analyzing legal documents. Until Kimi K3, no organization had publicly handed out that many parameters in an open format—where outside developers can study the model’s architecture and run it on their own hardware.

Kimi K3: What’s Under the Hood

Moonshot AI’s new model isn’t just massive. It comes with a 1-million-token context window. A token is a chunk of text—sometimes a word, sometimes a part of one—and a 1-million-token capacity means the model can keep track of roughly 750,000 words at once. That is the equivalent of processing all three volumes of The Lord of the Rings in a single prompt. The company says Kimi K3 yields about a 2.5 times improvement in overall scaling efficiency compared to its predecessor, Kimi K2, which implies that it squeezes more performance out of every unit of computing power.

The architecture leans on two innovations Moonshot calls Kimi Delta Attention and Attention Residuals. These are mechanisms that help the model focus on the most relevant pieces of information in extremely long sequences of data, while also integrating visual understanding natively. In plain terms, Kimi K3 can look at a diagram, read a lengthy accompanying report, and reason about both simultaneously.

In its own announcement, Moonshot AI described the model this way:

“Kimi K3 is a 2.8T-parameter model built on our Kimi Delta Attention and Attention Residuals, with native vision capabilities and a 1-million-token context window. It is the world’s first open 3T-class model, designed for frontier intelligence across long-horizon coding, knowledge work, and reasoning.”

The startup was careful to label Kimi K3 an “open model,” not an “open-source” project. The full model weights—the numerical values that define its behavior—will be released by July 27, allowing researchers and companies to download, fine-tune, and adapt it. However, the underlying training data and certain technical recipes remain under the company’s control, a common hybrid approach.

Performance: Catching Up, Not Overtaking

Moonshot AI didn’t oversell its creation. In its own evaluation, Kimi K3 trails “powerful proprietary models” from the United States, specifically Claude Fable 5 from Anthropic and GPT 5.6 Sol from OpenAI. Those closed-door systems still lead the frontier. Yet Kimi K3 delivers what Moonshot calls frontier-level performance across its internal testing suite, and it outperforms older American models on several established benchmarks. The message is clear: the gap is narrowing, and the open-weight approach is closing it at a fraction of the sticker price.

The Accusation of “Distillation”

American AI companies have not welcomed this narrowing gap quietly. For months, they have alleged that Chinese firms are using a technique called distillation to piggyback on the expensive work of others. Distillation is a process where a smaller or cheaper model learns by studying the outputs of a larger, more capable one. When done without authorization, it becomes a lightning rod for intellectual property disputes.

Anthropic drew a hard line in February 2026, accusing three Chinese labs—DeepSeek, Moonshot, and MiniMax—of running what it described as industrial-scale campaigns to “illicitly extract Claude’s capabilities.” In a public blog post, Anthropic stated:

“These labs generated over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts, in violation of our terms of service and regional access restrictions.”

Such allegations feed a broader narrative in Washington and Silicon Valley: that Chinese AI developers are cutting costs and accelerating timelines by siphoning insights from models they are regionally blocked from accessing. Moonshot has not directly responded to the distillation claims in the Kimi K3 announcement, but the backdrop is impossible to ignore.

A Tale of Two Strategies: Open vs. Closed

Kimi K3’s arrival highlights a deepening strategic divergence between the two AI superpowers. American giants like OpenAI and Anthropic have concentrated their best-performing models inside proprietary shells, accessible only through paid application programming interfaces (APIs). The justification is commercial sustainability: developing frontier AI demands billions of dollars in computing infrastructure, and charging users per token helps recoup those costs. Keeping the models’ inner workings secret also, the argument goes, reduces the risk of bad actors misusing the technology.

Chinese firms, by contrast, have released a stream of customizable open-weight models, often under permissive licenses. The philosophy, articulated on Moonshot AI’s website, is to work toward artificial general intelligence while “sharing the latest research with the global open-source community.” This approach sacrifices a degree of exclusive control in exchange for rapid adoption, community contributions, and the soft power that comes from being the default tool in university labs and startup garages worldwide.

The economics also differ. Moonshot AI is backed by Chinese tech titans Alibaba and Tencent, companies with deep pockets and strategic interests in ensuring domestic AI infrastructure thrives. For them, an open model is a loss leader that can seed an entire ecosystem—cloud computing services, enterprise applications, and hardware sales all benefit when developers flock to a freely available, state-of-the-art model.

What Happens Next

The July 27 release of Kimi K3’s full weights will be a critical moment. Once the files are online, independent researchers can run their own benchmarks to verify Moonshot’s performance claims. Developers will begin fine-tuning the model for specialized tasks—perhaps turning it into a medical assistant, a legal research tool, or a coding partner that rivals Western offerings. The model’s 1-million-token context window makes it particularly suited for analyzing massive documents, entire codebases, or long multimedia transcripts in one go.

Geopolitical ripples are inevitable. U.S. officials have already tightened export controls on advanced chips and are increasingly scrutinizing open-weight releases as a potential way for adversaries to leapfrog. The distillation allegations add a layer of mistrust that could lead to further sanctions or, conversely, spur new transparency norms around training data provenance.

For everyday users, the immediate effect may be subtle: more AI-powered products with lower price tags and fewer usage restrictions. The underlying tension, however, is profound. Kimi K3 is not just a technical artifact; it is a statement that the frontier of AI is no longer contained within a handful of sealed-off data centers in California. It is being carved into downloadable files, shared across borders, and rebuilt by anyone with the compute power to run it. Whether that accelerated openness proves to be a boon for global innovation or a catalyst for a new kind of tech conflict will depend on what developers, regulators, and corporations do with the weights once they drop.


Read more