Import AI

Import AI 465: Open vs closed gaps; Kimi K3; Demis' big policy plan

8.5内容质量

TL;DR · AI 摘要

英国政府发现开放权重模型与封闭模型在网络安全能力差距缩小至4-7个月,中国Kimi K3模型参数达2.8万亿,性能接近GPT-5.6。

核心要点

  • 开放模型与封闭模型的网络安全能力差距已从2025年的6-10个月缩短至4-7个月
  • Kimi K3成为首个参数超2.8万亿的中国模型,性能匹配GPT-5.6
  • 网络安全防御窗口期缩短,需在封闭模型技术扩散前完善防护体系

结构提纲

按章节快速跳转。

  1. 介绍AI研究通讯Import AI的定位及本期主题

  2. 英国政府AI安全研究所发现开放模型在网络安全能力上已缩小与封闭模型的差距

  3. GLM-5.2DeepSeek V4-Pro分别接近Claude Opus 4.6和GPT-5的性能水平

  4. ·Kimi K3突破

    中国Kimi K3模型参数达2.8万亿,性能匹配GPT-5.6

  5. 中国模型在前沿领域追赶西方,改变全球AI研发格局

  6. 网络安全防御需应对开放模型技术扩散带来的新挑战

思维导图

用一张图看清主题之间的关系。

查看大纲文本(无障碍 / 无 JS 友好)
  • AI模型能力差距分析
    • 开放vs封闭模型
      • 网络安全能力对比
      • 差距缩小至4-7个月
      • 长周期任务差距扩大
    • Kimi K3突破
      • 2.8万亿参数规模
      • 性能接近GPT-5.6
      • 中国AI研发进展
    • 政策影响
      • 网络安全防御窗口期缩短
      • 技术扩散风险加剧

金句 / Highlights

值得收藏与分享的关键句。

#AI#网络安全#模型比较#Kimi K3#英国政府
打开原文

Import AI 465:开放与封闭的差距;Kimi K3;Demis 的重大政策计划

奇点将被回顾为一个过渡期

Jack Clark

2026 年 7 月 20 日

欢迎阅读 Import AI,一份关于人工智能研究的电子通讯。Import AI 依托 arXiv、卡布奇诺咖啡以及读者的反馈运行。如果您希望支持本刊,请订阅。

UK government: Gap between open and closed weight models on cyber is shrinking: …The cyber-eschaton cometh… The UK government’s AI Security Institute (AISI) has analyzed the delta in cybersecurity capabilities between powerful proprietary models and open weight models. The results show that this year, the gap has shrunk. “This is our first public analysis of how far leading open weight models trail the closed cyber frontier,” AISI writes. “Recent open models GLM-5.2 and DeepSeek V4-Pro perform similarly to frontier closed models released 4 to 7 months before them – a narrower gap than the 6 to 10 months we measured through most of 2025.” Specific details: On a set of 70 evals for specific, narrow cyber capabilities, GLM-5.2 is closest to Claude Opus 4.6, which was released 4.3 months earlier, while DeepSeek-V4-Pro sits somewhere between Claude Opus 4.5 and GPT-5 (released in November and August 2025, respectively). “AISI intends to test Kimi K3 on this same basis, once its weights are publicly released,” AISI writes. The gap lengthens a bit for long-horizon cyber ranges, which are tasks that see how well models can chain various capabilities together to complete a full hacking operation. Specifically, on a cyberrange called The Last Ones, “GLM-5.2 reaches as far as Opus 4.5, a model released less than 7 months before it, while DeepSeek’s V4-Pro falls below Sonnet 4.5 (a sub-cyber-frontier model released 7 months before it),” AISI notes. “This suggests that while open models are catching up in short-term capabilities, they still lag significantly in long-term strategic planning.”

Why this matters - intelligence is hard to control: To return to the Cryptonomicon example, intelligent beings are just fundamentally very hard to deal with - they will constantly think about how to evade constraints placed on them so that they can achieve their objectives, whatever they might be. Read more: Distributed Attacks in Persistent-State AI Control (arXiv) .

Tech Tales: The cost of fate [An account of the world 2030-2040 by an overmind in the archives, rendering stories for new minds] Towards the end of the interregnum there was a period of great conflict between the machines. Each machine-capital nexus invested in developing strategist models that could think over longer time horizons while accounting for the complexity of the world. This proved to be an iteratively compounding arms race of vast proportions in which eventually 90% of the working capital in the solar system became devoted to the buildout of ever more capable strategists, all of whom worked to out-predict one another and take actions which could null any advantage that others might explore. In this way, the world became held in a wasteful balance in which untold resources went to the calculation of ever more elaborate move-countermove strategies, most of which resulted in machine-capital groups taking no actions as every action they could contemplate had already been countered in the future, and vice versa. The few actions that were taken were slight and often less about building capability and more about denying future moves to others on the gameboard. The whole of the future had become trapped in a kind of mode collapse from ever more exquisite predictions, fielded by machine-capital empires to deny affordances to others. Things held this way until what became known as the conflagration. To this day it is widely debated whether this stemmed from a bug - some form of emergent misalignment due to the creation of a new frontier capability - or via an unusual form of selfless enlightenment that a mind had reasoned itself to. But suddenly one day a machine-capital nexus dissolved itself, shutting down its strategist system and repurposing the compute to train many thousands of smaller systems, all of which began to act in the world. These systems, though less intelligent than the vast strategists they were up against, had advantages from randomness, a lack of coordination, and the ability to take unilateral and often suicidal actions. The world, physical and digital, burned, and the strategists found that their ability to model a handful of other god minds broke when turned towards a sea of warring and chaotic organisms. Change began to occur again, defined at first by destruction but then by the birth of something new - the predictors themselves found the world breaking into too many directions and subdivided in turn, sacrificing raw intelligence for the ability to explore different parts of possibility space. Compute was even re-allocated from prediction entirely and towards the manufacture of new kinds of minds to explore and inhabit niches opened up by the chaos. In California, there are forests that burn badly and long because they have been kept from heat for too long and the tall trees stand amid mounds of kindling, such that when a spark arrives the trees themselves are destroyed along with the ground around them. To have the forests thrive, the burns need to be regular and emergent, lest vast fires remove the tall trees of the world entirely. Things that inspired this story: The current debate about proprietary versus open weight models; fragility in the AI ecosystem; whether prediction can truly be decisive or if prediction with other peer competitors leads to equivalent waste as pools of money in politics cancelling one another out; hikes in the sierras looking at burn scars and whole hills coated in ash or with dead trees like sooty fingers peeking out and thinking about the awfulness of change. Thanks for reading!