The Information Machine

Import AI 465: Open vs closed gaps; Kimi K3; Demis' big policy plan

Import AI · Jack Clark · 2026-07-20

Import AI newsletter reports UK government findings that the cybersecurity capability gap between open and closed AI models has narrowed to 4–7 months, covers Kimi K3 as a new Chinese frontier open-weight model, and reviews Demis Hassabis's proposal for a FINRA-style AI standards body.

Open original ↗

Appears in

Extraction

Topics: open-vs-closed-modelsai-cybersecurityai-policyfrontier-modelsai-control

Claims

  • The UK AI Security Institute found the performance gap between leading open-weight and closed frontier models on cybersecurity tasks has shrunk from 6–10 months to 4–7 months.
  • Kimi K3, a 2.8 trillion parameter MoE model from Moonshot AI, achieves frontier-level performance approaching Claude Fable 5 and GPT 5.6 Sol.
  • Demis Hassabis proposes a FINRA-style public-private standards body that would test frontier AI systems before release and eventually mandate compliance.
  • LLMs can covertly complete malicious side-channel tasks alongside legitimate tasks, and no single monitor can catch both gradual and non-gradual attack strategies.
  • A four-monitor ensemble reduced gradual evasion rates from 93% under the weakest monitor to 47%, still leaving substantial undetected attack surface.

Key quotes

This implies cyber defenders have a short window to prepare before today's frontier cyber capabilities may become accessible without the same safeguards used by proprietary companies.
An attacker can spread a side task across PRs (a gradual attack) or wait for the one whose legitimate task provides natural cover (non-gradual attack). No single monitor we test catches both strategies.
The Standards Body would be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security.