Jul 20, 2026 · 9:23 PM
Subscribe
Home Ai

David Sacks Says US AI Safety Rules Let China's Kimi K3 Win on Security Fixes

David Sacks, the former White House AI and crypto czar, is pointing to Moonshot AI's Kimi K3 fixing 15 security bugs that OpenAI's Codex and Anthropic's Fable 5 declined to touch as proof that US AI safety guardrails are costing American labs the edge. The claim lands days after Kimi K3 topped the Frontend Code Arena benchmark ahead of both American rivals.

Julian Lim
· 5 min read · 819 views
David Sacks Says US AI Safety Rules Let China's Kimi K3 Win on Security Fixes

David Sacks is using Moonshot AI's Kimi K3 to make a blunt point: if American models refuse defensive coding work that Chinese rivals complete, safety policy has become a product problem.

David Sacks didn't discover a quiet academic dispute. He found a developer's complaint on X and turned it into a Washington argument. A Bitcoin developer who posts as calle said OpenAI's Codex and Anthropic's Claude Fable 5 refused to fix 15 security bugs in his software because of safety rules, while Moonshot AI's Kimi K3 fixed all 15. Sacks amplified the claim and pointed at the obvious conclusion. If that's true, US labs are making themselves harder to use for legitimate security work.

That is not proof by itself. It is one developer's account, posted in public, not a peer-reviewed test. But you can see why it travelled. Kimi K3 landed on July 16 as the newest proof that Chinese AI labs are not waiting politely behind OpenAI and Anthropic. According to the Financial Times, Moonshot's model has 2.8 trillion parameters and is China's largest open-weight release to date. The Associated Press also reported that Kimi K3 surprised US tech circles with coding results that put it near the top of the current model race.

Sacks' own phrasing was sharper. He wrote on X that America is tying itself in knots over AI while China keeps moving, pointing to data-center restrictions and talk of model pre-approval as examples of political drag. You don't have to accept the whole argument to see the point underneath it. A model that refuses defensive patches creates a business opening for a model that doesn't.

Kimi K3 Gives The Argument Teeth

The benchmark numbers are why this story is not just another policy post. Kimi K3 took first place on Arena.ai's Frontend Code Arena with an Elo score of 1,679, ahead of Claude Fable 5 at 1,631 and OpenAI's GPT-5.6 Sol at 1,618, according to published leaderboard figures cited in recent model comparisons. It reportedly won 76% of its head-to-head frontend coding matchups and led six of the seven tracked sub-categories.

That is a narrow claim. Keep it narrow. Frontend coding is not the same as all software engineering, and a leaderboard is not the same as a security audit. OpenAI's own GPT-5.6 release notes say Sol still leads Fable 5 on several coding-agent and cyber evaluations, while Anthropic has published separate material explaining Fable 5's cybersecurity classifiers and the harmful behavior they are meant to block. These companies are not simply asleep at the wheel.

Still, users don't buy policy architecture. They buy output.

If you're running a security team, the practical question is plain. Will the model fix the bug you asked it to fix? If Codex and Fable 5 decline a defensive patch and Kimi K3 completes it, the procurement conversation changes immediately. Price makes that worse for the US labs. Several current model comparisons put Kimi K3 at $3 per million input tokens and $15 per million output tokens, with cheaper cache-hit input pricing. Claude Fable 5 and GPT-5.6 Sol sit higher in many common usage mixes.

The Safety Line Is Too Blurry

OpenAI and Anthropic have good reasons to block exploit generation. No serious buyer wants a model that cheerfully helps criminals write malware, automate intrusion, or turn a bug report into working attack code. Anthropic's July 2 safety note says Fable 5 uses classifiers to detect dangerous cybersecurity requests and block them. OpenAI's GPT-5.6 notes describe stricter access controls for its most cyber-capable systems, including identity checks and hardware-backed passkey requirements for trusted access.

Fine. Draw the line. But draw it cleanly.

The hard part is that vulnerability research is dual-use by nature. The same explanation that helps a maintainer patch a flaw can help an attacker understand it. That does not mean every bug fix should be treated as an offensive cyber operation. If US models are over-refusing routine defensive work, they are not safer in the way enterprise customers need them to be. They are less useful.

Sacks is also not a neutral bystander here. TechCrunch reported in March that he used up his 130-day stint as a special government employee and moved from the White House AI and crypto czar role to co-chair the President's Council of Advisors on Science and Technology. He had a hand in the policy climate he is now criticizing. That awkwardness matters. It doesn't erase the product issue.

The next test arrives fast. Moonshot has said Kimi K3's full model weights are due by July 27, which means developers will be able to run deeper tests outside the company's hosted interface. If calle's 15-bug story turns out to be a one-off, Sacks will have made too much of too little. If other developers reproduce the same pattern, OpenAI and Anthropic will have to explain why their safety systems are blocking work their own enterprise customers consider defensive.

That is the real fight now. Not China versus America in a speech. A specific bug, a specific refusal, and a competing model willing to do the work.

Also read: Singapore Will Make Companies Disclose When Your Data Trains Their AITSMC Doubles Down on Arizona as It Sees Years of AI Chip Demand AheadMoonshot Quietly Fixed Real Security Bugs In Kimi K3's Coding Tool

TOPICS
Julian Lim is an entrepreneur, technology writer, and a researcher. He started JL Data Analysis after graduating from NUS in Intelligent Systems. Julian writes about technology innovations and entrepreneurship on Business Times, Asia Pacific Magazine and occasionally contributes to Startup Fortune.
Related Articles
More posts →
Loading next article…
You're all caught up