Model
Kimi
Publisher
Moonshot AI (China)
Family
Moonshot AI - Kimi K2
Licence
Modified MIT License (MIT plus a large-scale attribution clause)
Kimi is Moonshot AI's (Beijing) model/product line; its confirmed open release is Kimi K2 - a very large Mixture-of-Experts model with 1T total / 32B active parameters (384 experts, 8+1 selected), a 128K context window, and an explicit agentic/coding focus (trained with the MuonClip optimiser).
Do you really own it?
Partial
none·limited·partial·substantial·full
Analytical input: AOI C · 62.8/100
Floor-weighted, not averaged. The weakest factor caps the level, because ownership is a conjunction. Transparency is weak, which holds the whole verdict down regardless of the rest.
You substantially use, modify and commercialise the self-hosted Kimi K2 weights under a near-MIT grant - the sole condition is the verbatim 100M-MAU / $20M-revenue trigger to display 'Kimi K2' in your UI - and run entirely on your own infrastructure, so your data stays yours. What holds ownership at partial is transparency: the 15.5T-token corpus and training code are closed and the model carries China-aligned censorship you cannot inspect. Mind the weights-vs-hosted split - the platform.kimi.ai API trains on your content by default (opt-out only by enterprise agreement, Singapore law), so self-host if data control matters. Confirm the attribution trigger and the per-checkpoint LICENSE before shipping, and budget multi-node infrastructure to run it at all.
1
Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?
StrongNear-MIT weights: standard MIT permission to fine-tune, redistribute and commercialise the Base and Instruct checkpoints, gated by a single verbatim attribution trigger - only a commercial product or service over 100M monthly active users OR over $20M USD monthly revenue must prominently display 'Kimi K2' on its UI. Not OSI-certified, so verify the LICENSE per checkpoint, but for nearly every adopter it is an effectively clean grant.
How this scores (AOI sub-dimensions)
Openness3/5how much is released - weights, data, code, licence - and how freelyOpen-weights tier: Base and Instruct weights are downloadable under a permissive (modified) MIT license with a solid model card and technical report, but the 15.5T-token training data and training code are undisclosed and evaluation is only partially reproducible.
Legal3/5how permissive and clean the licence is for real commercial useThe broadly permissive modified MIT license is a real plus over a restrictive community license, but it is not OSI-certified and carries a large-scale attribution clause; there is no training-content summary or copyright policy; and a China-based provider is unlikely to furnish EU documentation.
2
TransparencyDo you know what it is: weights, training, behaviour, and legible terms?
WeakYou cannot see what the model is: the technical report documents a 1T/32B MoE trained on 15.5T tokens with MuonClip, but the training corpus and training code are closed, and the weights carry China-aligned topic censorship you cannot inspect.
How this scores (AOI sub-dimensions)
Provenance3/5how well we can trace and verify what went into the modelDistributed from the verified moonshotai org on Hugging Face as block-FP8 safetensors with checksums and no canonical-org malicious incident on record (checklist 5/8).
Governance3/5how accountable and well-documented the publisher isActive, accountable publisher (Moonshot AI) with a detailed technical report and a verified hub presence, but no documented vulnerability-disclosure or deprecation policy and no EU Code of Practice signature.
3
Doesn't fail youIs it reliable and good enough for the job?
ModerateFrontier-adjacent agentic and coding capability (e.g. SWE-bench Verified ~65.8), but safety tuning is lighter than Western frontier labs with no guard model, and the trillion-parameter scale makes even auditing it a multi-node exercise.
How this scores (AOI sub-dimensions)
Performance4/5how capable it is relative to its classFrontier-adjacent open capability, especially in agentic tool use and coding: on independent evaluation Kimi K2 (e.g.
Operational3/5how practical it is to run, serve and maintain in productionGood serving support (vLLM, SGLang, KTransformers, TensorRT-LLM) with an OpenAI/Anthropic-compatible API, but the trillion-parameter scale is a heavy operational burden: minimum viable deployment is a multi-GPU / multi-node cluster even in block-FP8, and there are no small variants - so it is far less portable than a laptop-to-datacentre size ladder.
Safety3/5whether misuse risks are evaluated and guardrails are providedThe Instruct variant is safety-tuned and withstands casual jailbreaks, but tuning is lighter than Western frontier labs, there is no companion guard model, and the model exhibits China-aligned topic censorship on politically sensitive prompts.
4
Doesn't extract your dataDoes running it keep your knowledge and data yours?
StrongSelf-hosted, the weights run entirely on your own infrastructure with no telemetry or data clawback - your data stays yours. The hosted platform.kimi.ai service is the opposite: its terms and privacy policy train on user prompts, audio, images, videos and files BY DEFAULT (opt-out only via an enterprise/separate written agreement, Singapore law / SIAC arbitration), so keep to the weights if data control is the point. The practical constraint on self-hosting is the ~1 TB block-FP8 footprint that forces multi-node serving.
How this scores
Not a scored AOI dimension. For a self-hosted model, data-control is a structural property of running the weights yourself, strong by default unless the model phones home or the licence claws back rights. For a hosted API this factor is the retention + train-on-inputs + residency read, scored from the binding terms.
How the AOI score is computed
The seven dimensions above, each scored 0 to 5, weighted and summed to the 0 to 100 headline. The score is the analytical input behind the ownership verdict, not the verdict itself.
DimensionScoreWeightPoints
Openness3/50.1810.8
Provenance3/50.169.6
Legal3/50.169.6
Safety3/50.169.6
Performance4/50.1411.2
Operational3/50.127.2
Governance3/50.084.8
HeadlineC · 62.8/100
Sources
Every rating traces to a primary document. Read means the text was verified; unverified means it is known to exist but has not yet been read.
DocumentWhat it grounds
Model cardread2026-07-25
Kimi-K2-Instruct model card on the verified moonshotai Hugging Face org: block-FP8 safetensors, 1T total / 32B active parameters, 128K context, Muon optimiser, and the statement that "Both the code repository and model weights are released under the Modified MIT License."
Licenceread2026-07-25
Kimi K2 LICENSE, read verbatim: standard MIT with one added clause - "Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than 20 million US dollars (or equivalent in other currencies) in monthly revenue, you shall prominently display 'Kimi K2' on the user interface of such product or service." Otherwise standard MIT.
Documentationunverified2026-07-25
The moonshotai/Kimi-K2 repository documents the MoE architecture (384 experts, 8+1 selected), the MuonClip optimiser, block-FP8 weights and deployment on vLLM, SGLang, KTransformers and TensorRT-LLM with an OpenAI/Anthropic-compatible API.
Technical_reportread2026-07-25
Moonshot's arXiv technical report "Kimi K2: Open Agentic Intelligence" (2507.20534), read: a 1T-total / 32B-active MoE trained on 15.5T tokens with the MuonClip optimiser (Muon + QK-clip), reporting agentic/coding results (e.g.
Terms of serviceread2026-07-25
platform.kimi.ai model-use agreement, read: user content is used to improve the services, with opt-out available only via an enterprise or separate written agreement; governed by Singapore law with disputes resolved by SIAC arbitration in English.
Privacy Policyread2026-07-25
platform.kimi.ai privacy policy, read: the hosted service trains on user prompts, audio, images, videos and files by default; the controller is MOONSHOT AI PTE.
Third-party analysisunverified2026-07-25
On independent evaluation Kimi K2 is among the strongest open-weight models on agentic and coding benchmarks (e.g.
Third-party analysisunverified2026-07-25
Independent analysis notes Kimi K2, like other China-based open-weight models, applies China-aligned content filtering on politically sensitive topics.
Third-party analysisunverified2026-07-25
Kimi K2 Instruct is safety-tuned but with lighter alignment coverage than Western frontier labs and no companion guard model.
Third-party analysisunverified2026-07-25
No public EU AI Act training-content summary, copyright policy, or provider documentation package is published for Kimi K2, and the training corpus is not released.
Third-party analysisunverified2026-07-25
Kimi K2 is served across vLLM, SGLang, KTransformers and TensorRT-LLM, but its 1T-parameter scale requires multi-GPU / multi-node infrastructure even in block-FP8.