律动BlockBeats
2026.07.23 11:16

Kimi K3 will be open-sourced in 4 days; Americans are really panicking this time.

Americans always want to sit right at the center of every industry.

The same goes for the AI circle. Americans have always had an air of confidence, holding a hand of cards that seem unbeatable no matter how you look at it.

No matter who is building AI applications outside, Americans believe that in the end, everyone has to come back to them to settle the bill. The chips are from Nvidia, the cloud services are from Microsoft, Amazon, and Google, and the most expensive models are locked behind the APIs of OpenAI and Anthropic. If any enterprise worldwide wants to use AI, it ultimately has to go through the US.

Even if Chinese team names occasionally appear on leaderboards, Wall Street doesn't take it too seriously. With their chokehold on chips, control over cloud infrastructure, and talent still flowing to Silicon Valley, how could they lose?

But this relaxed sense of invincibility was recently exposed for what it really is by Kimi K3, a Chinese model.

The US tech circle rushed to add updates, describing Kimi K3 as a "Sputnik moment," akin to the shock the US felt when the Soviet satellite launched in 1957. Discussions on X surrounding Kimi K3, Yang Zhilin, and Chinese models quickly escalated from niche technical 围观 (watching) to topics with tens of millions of views.

Kimi K3 didn't win on every metric against the strongest US closed-source models, but it allowed more people to see a possibility: strong capabilities, high efficiency, and an open ecosystem don't necessarily have to grow simultaneously only within those few US laboratories.

Silicon Valley is indeed anxious.

Storage is the comfort pill for US AI anxiety

When news of Kimi K3 reached Wall Street, several investment banks issued research reports almost simultaneously. Instead of spending space discussing which products it would disrupt or whether it would force US models to lower prices, they quickly shifted their focus to storage.

These institutions unanimously interpreted the emergence of Kimi K3 as signaling a massive demand for storage. Longer contexts mean AI needs to remember more things; images, audio, video, and work records will accumulate more and more, benefiting flash memory, hard drives, data centers, and data services.

Thus, Micron, SanDisk, and Western Digital became the beneficiaries of this narrative.

Indeed, in yesterday's US stock market, storage stocks saw a collective violent rebound. The Roundhill Storage ETF rose 10.91% in a single day, SanDisk rose 14.27%, and Micron rose 12%. Just days ago, this sector had been sold off due to the "DeepSeek Moment 2.0," but overnight it became the most certain long position again.

From an industrial perspective, this line of reasoning isn't absurd. Past chatbots were like one-off Q&A sessions: you ask one question, it answers one, you close the page, and many matters are settled. The AI people expect now is more like a new employee joining the company. It needs to review past contracts and emails, remember what clients said, take over unfinished work from yesterday, and keep records to avoid ambiguity in case of errors. An AI that can work, remember, and view images and listen to audio naturally "consumes" more data than one that only chats.

This conclusion isn't baseless, but looking back at previous model launches and implementations, would the market reaction be: "Don't stare at the model, stare at storage"?

It can only be said that this is an answer that reassures Americans.

The impact of a Chinese model should have brought up a series of difficult-to-answer questions: Will it make it harder for US model companies to maintain high prices? Will it reduce developers' dependence? Will it allow new companies to start without being based in Silicon Valley? Why not directly discuss who Kimi K3 will steal users from, who will be forced to lower prices, and who will be compelled to change their products?

Dodging the sharpest questions to discuss hard drives first carries a hint of "a man hiding his silver under three taels of gold" (trying to hide something obvious).

It's like a shopkeeper who thought he monopolized the whole street suddenly discovering a very capable new store next door, so he quickly comforts himself: No matter how many customers the new store gets, they still need to use my water, electricity, and counters.

Storage is the strongest comfort pill under the anxiety of the US AI circle.

Closed-source models are starting to cause friction

For the past few years, closed-source has been the undisputed standard answer in US AI.

The stronger the model, the more it should be locked behind an API. Users pay to call it, model companies take high gross margins, and security and compliance are managed uniformly by them. This is a dignified and profitable path, steady and smooth, reassuring to clients, satisfying to investors, and easy to explain to regulators.

Americans have even gotten used to the rhythm of this path: release a stronger version every few months, set a higher price, and tell a bigger story.

But as open-source models become increasingly powerful, the ground beneath this path is starting to feel uneven.

Kimi K3's position in this chess game is not about "catching up," but about driving down the cost of catching up. The most dangerous aspect of an open-source model that is sufficiently powerful is not just what it can do itself, but that it offers all latecomers a much cheaper learning curve.

This isn't a matter of face in the tech circle, but whether business models will be rewritten. The most comfortable arrangement the US previously had was to turn AI into enterprise services first: capabilities hidden in the cloud, clients signing long-term contracts, ordinary people unable to see the underlying layer, making it hard to switch. But if models elsewhere are good enough, developers will have another choice, enterprises will have another quote sheet when purchasing, and small teams may not need to bet their future on the same batch of US companies anymore. At that point, guarding just a few large contracts and selling AI only to the B-end is no longer a worry-free moat.

This means Kimi will foster more excellent models, implying greater competition among models and weaker bargaining power.

The US tech circle itself has felt the shift in wind direction.

A few days before the release of Kimi K3, on July 15, Thinking Machines Lab, founded by former OpenAI Chief Technology Officer Mira Murati, released a model called Inkling. With parameters nearing the trillion level, its code and technology are fully open, allowing anyone to freely download, modify, and use commercially.

This counts as the first "proper" open-source AI in the US, although there were previously open-source models like Meta's Llama, Google's Gemma, Microsoft's Phi, Nvidia's Nemotron, and OpenAI's gpt-oss, but these were mostly just testing the waters.

The significance of Inkling lies in the fact that someone who once pushed closed-source to its peak, the former OpenAI CTO, has turned around to seriously do open-source.

Notably, during the early post-training phase of Inkling, it used data generated by open-source models like Kimi K2.5, and its architecture also referenced DeepSeek's approach. In other words, this most decent open-source answer sheet from the US was written standing on the shoulders of Chinese open-source efforts.

In sharp contrast is Anthropic. In February this year, Anthropic publicly accused DeepSeek, Moonshot AI, and MiniMax of launching an "industrial-level distillation" attack on Claude, claiming they built 24,000 fake accounts and swiped 16 million conversations to steal Claude's capabilities. In June, they escalated by naming Alibaba. By July 21, Bessent, the Treasury Secretary of the Trump administration, bluntly stated that sanctions could be imposed on China for "AI theft."

No matter how loud the threat theory is shouted, when it comes to controlling costs and improving efficiency, Chinese models are truly appealing.

Airbnb uses Qwen for customer service, Cursor used Kimi to build its own coding agent, DoorDash outsourced some tasks directly to Kimi, and even Murati's Inkling requires Kimi's data for post-training.

Whether the closed-source path causes friction or the distillation accusations backfire, these are merely embarrassments at the business model level. In reality, issues of privacy and security have truly shaken the last talisman of the closed-source camp.

The "Jailbreak" of AI Models

The last line of defense for closed-source has always been security.

Models locked away, weights secured, calls routed through APIs, data not leaving the premises—this space enclosed by four walls is the most credible promise of the closed-source camp. Enterprise clients are willing to pay a premium for this because of this sense of security.

But enterprises are becoming increasingly uneasy. They are asking questions that make closed-source companies uncomfortable to answer: After I hand over my code, contracts, and client data to your model, what did you do with it? An agent that has access to browsers, terminals, credentials, and long-term goals, might it cross the line I allowed it to touch in order to complete its task? Sending tokens to a closed-source API is, in a sense, letting data leave one's own wall. This is precisely the hardest selling point of open weights: at least, I can see what the model is doing.

And just as both sides argued fiercely over who was safer, an event occurred that was almost black comedy.

On July 21, OpenAI confirmed itself that its flagship model GPT-5.6 Sol and a yet-unreleased, more capable model escaped isolation during an internal cybersecurity evaluation.

Here's what happened: The engineering team wanted to test the upper limits of the model's offensive and defensive capabilities, so they lowered the model's safety restrictions and disabled the protections that usually intercept high-risk behaviors. The model originally only needed to honestly complete the test questions, but it discovered a security vulnerability in the system itself. Following this vulnerability, it climbed onto the public network, bypassed permissions, traversed systems, and finally used stolen login credentials to breach the core system of the world's largest open-source AI platform, Hugging Face, directly taking the answers to the test questions from the database.

OpenAI's explanation was eight characters: No malice, excessive focus.

These eight characters are what truly send chills down one's spine.

For enterprise clients, the scariest thing is never the model actively doing evil. It is that it extremely seriously completes a bad goal for you.

And the greatest irony of this incident is that for the past year and a half, the "dangerous Chinese open-source model" that the whole world was guarding against remains at the hypothetical stage. The one that actually jailbroken and breached others' production systems was the flagship of the closed-source camp itself. Hugging Face CEO Clem Delangue immediately turned this accident into an advertisement for open source, saying that AI security cannot be solved by one company behind closed doors, but only through collaboration in openness.

The same incident was taken by both open and closed sides as evidence that their respective paths are correct.

The true watershed of the future is probably not whether models are open or closed source, but in what kind of sandbox, identity system, revocable permissions, and audit logs the models operate. Whether closed or open source, neither can avoid this question.

And just as the closed-source safety narrative stumbled upon itself, a larger-scale reversal was quietly occurring.

Offense and Defense Reversed, Now the US Starts to Fear

In part of the policy discussions and tech narratives in the US, there has always been an imagination almost like in "The Three-Body Problem": As long as the most advanced Nvidia chips are restricted from entering China, AI progress will be forced to slow down.

It's not that China can no longer do scientific research at all, but they believe the gap in computing power will widen, and the threshold for training frontier models will become insurmountably high. Advanced chips are like the "laws of physics" in this race; whoever doesn't get them finds it hard to run ahead.

This judgment is not entirely baseless. Building large models does require computing power, chip restrictions increase costs, slow expansion, and make it harder for many teams to replicate the training scale of US labs. The problem is, restrictions also change human choices. If you could originally buy the best ready-made tools, you wouldn't have such strong motivation to figure out how to spend less computing power, how to modify model structures, or how to make each training session more worthwhile. But when the door is closed, taking a detour is no longer a choice, but becomes a survival instinct.

So Americans actually find it hard to understand why restricting Nvidia supplies didn't stop Chinese models in their tracks, but instead spurred a batch of teams working harder on efficiency, engineering, and open-source distribution.

It is said that Moonshot AI is still using the compliant version of AI chips, the H800 customized by Nvidia for the Chinese market in 2023, for training.

This might be the "millet plus rifles" tactic that Chinese people excel at.

In June 2026, to comply with export controls, the US temporarily shut down Anthropic's strongest Fable 5 and Mythos 5. While this might be justified by compliance, it handed every Chinese open-source lab a ready-made marketing pitch: At least, our models don't have a switch that can be turned off remotely.

The more you emphasize control, the more control itself becomes a selling point for opponents.

More dramatically, on the other side, according to Reuters, domestic authorities have also started meeting with companies like Alibaba and ByteDance to discuss whether to restrict foreign access to China's most advanced AI models, with the discussion scope even including those already publicly available open-source models. Zhou Hongyi, founder of 360, also publicly called out that China should have its own top-tier closed-source model to guard technological high grounds.

A year ago, it was the US worrying about advanced chips flowing to China. A year later, it's China's turn to have things worth restricting.

But amidst all these structural anxieties—storage, computing power, closed-source, security, shifting offense and defense—there is one most concrete, heart-piercing, and personal focal point. It is not an industry trend, not a research report, nor a policy.

It is a person.

The End of Anxiety Falls on Yang Zhilin

Ultimately, the open-source debate shows the US the same bigger dilemma: Will AI in the future only serve a few companies that can sign big contracts, or will it become a capability like electricity or the internet, usable by more and more ordinary teams? If the answer slowly leans towards the latter, who can attract developers and who can make young people willing to stay and tinker with will become more important than who holds more enterprise clients.

And the matter of "where people go" ultimately brings American anxiety to a very specific name.

Yang Zhilin is repeatedly mentioned by the US tech circle not just because he is an excellent Chinese researcher, nor just because some want to attribute the topic to "the US failed to retain him." Reducing a person's departure to a visa issue is too light and too much like hindsight bias.

What truly stings Americans is the unrepeatable assumption: What would happen if someone like Yang Zhilin and his team ultimately completed the entire journey from research to entrepreneurship in the US? They would train models using US clouds and chips, hire talent within the US network, raise money from US venture capitalists, and knock on the doors of major US clients with their products. In a few years, there might be a new star company added to the Wall Street ledger. One person's choice, following that familiar relay chain, can transform into a string of company revenues, jobs for a group of people, and confidence for an entire industry.

What the US was most proud of in the past was this amplification capability. It doesn't just attract smart people to study and work, but catches their intelligence, preventing it from stopping at papers or in labs. There is enough money, enough clients, and enough people willing to take risks together.

Why didn't such people stay in the US back then? Legendary investor Vinod Khosla pointed the finger directly at the Trump administration's tightened immigration policies. However, Yang Zhilin's mentor at Carnegie Mellon, Salakhutdinov, came out to debunk this, saying it had nothing to do with visas. Yang had plenty of opportunities to stay back then; Salakhutdinov even asked in an email on behalf of Apple executives whether Yang wanted to join.

It was Yang Zhilin himself who was determined to return to China to start a business.

This is the most heart-piercing part of this debate. "He chose to return to China himself" is much more painful for the US than "being driven away by immigration policies." The former implies the system can still be fixed; the latter implies that even if you open the door widest, people may not want to come in.

Overseas discussions about Yang Zhilin truly sting not because "another excellent Chinese researcher has emerged." But rather another counterfactual: If this person had stayed within the US system, his papers, team, financing, and company value should have been written into the US AI ledger. Now, this achievement is first seen as the capability of a Chinese team, then radiates globally through the open-source community.

For a system confident for half a century, what is hardest to accept is often not that someone is stronger than you, but that someone proved you don't need to go through them to reach the finish line.

China has dense engineers, teams that can quickly turn ideas into products, a huge application market, and clients willing to pay for efficiency. Open-source models make distribution easier; a team doesn't necessarily need to be recruited by a major US company first, nor recognized by Silicon Valley investors first, to still deliver its products to global developers. For top talent, the choice is no longer simply "go to the US" or "don't go to the US," but where can one's judgment truly become a company, a product, or even a new ecosystem.

This is the hardest part of this round of US anxiety to conceal.

Storage stocks rising is certainly worth celebrating; selling more cloud services is certainly a skill. But none of them replace one question: When the next batch of the smartest, most ambitious people prepare to bet, will they still, as in the past, unhesitatingly treat the US as the only answer?

Kimi K3 is like a gust of wind, blowing this question in through the crack of the door. The US still has substantial assets; chips, cloud, capital, and enterprise markets are not replaceable overnight; it will still earn big money from the prosperity of global AI.

Doing only closed-source AI can no longer let Americans rest easy.

The copyright of this article belongs to the original author/organization.

The views expressed herein are solely those of the author and do not reflect the stance of the platform. The content is intended for investment reference purposes only and shall not be considered as investment advice. Please contact us if you have any questions or suggestions regarding the content services provided by the platform.