Contact
Assess · Kimi

Can you own it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C · 62.8/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

Intended & out-of-scope use

Kimi is Moonshot AI's model line; the confirmed open release is Kimi K2, a trillion-parameter Mixture-of-Experts model (1T total / 32B active) built with an explicit agentic, tool-use and coding focus. Its intended use is frontier-adjacent assistant, agentic, and coding workloads where you want an open-weight model rather than a closed API - and where you can afford the serving infrastructure.

For adoption, deploy the Kimi-K2-Instruct (safety-tuned) variant; Kimi-K2-Base is a foundation checkpoint for research and fine-tuning and is out of scope for customer-facing use. Because it is a China-based release with China-aligned topic censorship, no companion guard model, and no EU AI Act documentation package, high-stakes, autonomous, or EU-regulated decision-making is out of scope without the external control stack described in the Implement domain and a self-assembled compliance package.

Known limitations, bias & failure modes

  • China-aligned topic censorship. Like other China-based open-weight models, Kimi K2 applies content filtering aligned with Chinese content rules on politically sensitive topics
    • a behavioural quirk to account for, especially for non-coding prompts.
  • Lighter safety tuning, no guard model. Instruct alignment withstands casual jailbreaks but coverage is lighter than Western frontier labs and there is no companion guard/classifier.
  • Trillion-parameter operational burden. There are no small variants; the smallest viable deployment is a multi-node cluster even in block-FP8 (~1 TB of weights).
  • Base checkpoint is untuned. Kimi-K2-Base has no safety tuning and should be treated as a research artifact.

The offsetting advantage is capability: on independent agentic/coding benchmarks Kimi K2 is among the strongest open-weight models available.

Openness tier & components

Kimi K2 is open_weights, not open-science. Weights (Base and Instruct) are downloadable under a permissive modified MIT license with a detailed model card and technical report, so weights, documentation and license are Open. But the 15.5T-token training data and the training code are not released, and evaluation is only partially reproducible - so those components are Closed/Partial. You can run, adapt and redistribute the model, but you cannot reproduce it.

License terms & permitted use

Kimi K2 ships under a Modified MIT License: standard MIT permissions (use, modify, redistribute, commercialize) plus one attribution clause - if the software or a derivative is used in a commercial product or service with more than 100 million monthly active users or more than $20 million USD in monthly revenue, you must prominently display "Kimi K2" on that product's user interface. For nearly all adopters the license is effectively permissive MIT; only large-scale deployers trigger the attribution requirement. Two caveats: the modification means it is not OSI-certified, and you should verify the LICENSE file per checkpoint. This clause is a load-bearing input to the legal (3) score.

Supply-chain & provenance

Weights are distributed from the verified moonshotai org on Hugging Face as block-FP8 safetensors (no pickle requirement) with per-file checksums. The checkpoint trust checklist scores 5/8; the missing controls include cryptographic weight signing (Sigstore/model-signing) and SLSA build attestation, which is why provenance is a 4, not a 5. No incidents or malicious-mirror findings are on record for the canonical org. Because the weights are large and distributed in block-FP8, verify per-file checksums and pin the exact revision on download.

EU AI Act posture

Kimi K2 is a GPAI model. On the active-parameter compute estimate (~3×10²⁴ FLOPs: 32B active × 15.5T tokens) it sits under the 10²⁵-FLOPs systemic-risk threshold - so, unlike the largest systemic-risk peers, there is no Article 55 hard flag and it plausibly reaches the Article 53 open-source exemption from the Annex XI/XII technical-documentation duties. Two caveats keep this at partial: the modified MIT license is not an OSI-certified free/open license, and the surviving obligations - a copyright policy and a public training-content summary - are not published, and cannot be reconstructed because the corpus is closed. A China-based provider is unlikely to furnish an EU documentation package, so an EU deployer must self-assemble compliance material and inherits these gaps if it places a derivative on the market.

Benchmarks & evaluation

Kimi K2 is among the strongest open-weight models on agentic and coding benchmarks (for example SWE-bench Verified ≈ 65.8, plus strong tool-use/agentic scores), frontier-adjacent rather than merely in-class. OneHill did not run its own benchmarks this session; the figures are aggregated from Moonshot's technical report and independent evaluation (ev-perf, ev-tech-report). This is marked partial because the results are third-party rather than OneHill-reproduced and the evaluation harness is only partially open.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?

Strong

Near-MIT weights: standard MIT permission to fine-tune, redistribute and commercialise the Base and Instruct checkpoints, gated by a single verbatim attribution trigger - only a commercial product or service over 100M monthly active users OR over $20M USD monthly revenue must prominently display 'Kimi K2' on its UI. Not OSI-certified, so verify the LICENSE per checkpoint, but for nearly every adopter it is an effectively clean grant.

How this scores (AOI sub-dimensions)
Openness3/5how much is released - weights, data, code, licence - and how freelyOpen-weights tier: Base and Instruct weights are downloadable under a permissive (modified) MIT license with a solid model card and technical report, but the 15.5T-token training data and training code are undisclosed and evaluation is only partially reproducible.
Legal3/5how permissive and clean the licence is for real commercial useThe broadly permissive modified MIT license is a real plus over a restrictive community license, but it is not OSI-certified and carries a large-scale attribution clause; there is no training-content summary or copyright policy; and a China-based provider is unlikely to furnish EU documentation.
2

TransparencyDo you know what it is: weights, training, behaviour, and legible terms?

Weak

You cannot see what the model is: the technical report documents a 1T/32B MoE trained on 15.5T tokens with MuonClip, but the training corpus and training code are closed, and the weights carry China-aligned topic censorship you cannot inspect.

How this scores (AOI sub-dimensions)
Provenance3/5how well we can trace and verify what went into the modelDistributed from the verified moonshotai org on Hugging Face as block-FP8 safetensors with checksums and no canonical-org malicious incident on record (checklist 5/8).
Governance3/5how accountable and well-documented the publisher isActive, accountable publisher (Moonshot AI) with a detailed technical report and a verified hub presence, but no documented vulnerability-disclosure or deprecation policy and no EU Code of Practice signature.
What this means for adoptionYou substantially use, modify and commercialise the self-hosted Kimi K2 weights under a near-MIT grant - the sole condition is the verbatim 100M-MAU / $20M-revenue trigger to display 'Kimi K2' in your UI - and run entirely on your own infrastructure, so your data stays yours. What holds ownership at partial is transparency: the 15.5T-token corpus and training code are closed and the model carries China-aligned censorship you cannot inspect. Mind the weights-vs-hosted split - the platform.kimi.ai API trains on your content by default (opt-out only by enterprise agreement, Singapore law), so self-host if data control matters. Confirm the attribution trigger and the per-checkpoint LICENSE before shipping, and budget multi-node infrastructure to run it at all.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Model cardread2026-07-25
Kimi-K2-Instruct model card on the verified moonshotai Hugging Face org: block-FP8 safetensors, 1T total / 32B active parameters, 128K context, Muon optimiser, and the statement that "Both the code repository and model weights are released under the Modified MIT License."
Licenceread2026-07-25
Kimi K2 LICENSE, read verbatim: standard MIT with one added clause - "Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than 20 million US dollars (or equivalent in other currencies) in monthly revenue, you shall prominently display 'Kimi K2' on the user interface of such product or service." Otherwise standard MIT.
Documentationunverified2026-07-25
The moonshotai/Kimi-K2 repository documents the MoE architecture (384 experts, 8+1 selected), the MuonClip optimiser, block-FP8 weights and deployment on vLLM, SGLang, KTransformers and TensorRT-LLM with an OpenAI/Anthropic-compatible API.
Technical_reportread2026-07-25
Moonshot's arXiv technical report "Kimi K2: Open Agentic Intelligence" (2507.20534), read: a 1T-total / 32B-active MoE trained on 15.5T tokens with the MuonClip optimiser (Muon + QK-clip), reporting agentic/coding results (e.g.
Terms of serviceread2026-07-25
platform.kimi.ai model-use agreement, read: user content is used to improve the services, with opt-out available only via an enterprise or separate written agreement; governed by Singapore law with disputes resolved by SIAC arbitration in English.
Privacy Policyread2026-07-25
platform.kimi.ai privacy policy, read: the hosted service trains on user prompts, audio, images, videos and files by default; the controller is MOONSHOT AI PTE.
Third-party analysisunverified2026-07-25
On independent evaluation Kimi K2 is among the strongest open-weight models on agentic and coding benchmarks (e.g.
Third-party analysisunverified2026-07-25
Independent analysis notes Kimi K2, like other China-based open-weight models, applies China-aligned content filtering on politically sensitive topics.
Third-party analysisunverified2026-07-25
Kimi K2 Instruct is safety-tuned but with lighter alignment coverage than Western frontier labs and no companion guard model.
Third-party analysisunverified2026-07-25
No public EU AI Act training-content summary, copyright policy, or provider documentation package is published for Kimi K2, and the training corpus is not released.
Third-party analysisunverified2026-07-25
Kimi K2 is served across vLLM, SGLang, KTransformers and TensorRT-LLM, but its 1T-parameter scale requires multi-GPU / multi-node infrastructure even in block-FP8.