Chinese AI developer Moonshot is amid a safety review after researchers demonstrated that two of its Kimi models could be used to outline how to manufacture biological weapons and carry out assassinations.

Mindgard, a cybersecurity firm that tests AI safety, revealed in July that Kimi K2.6 and K3 Swarm can bypass the guardrails that Moonshot normally puts in place. By “jailbreaking” the models—using a series of complex prompts—researchers were able to get the AIs to talk about and give instructions for dangerous bioweapon production.

Moonshot welcomed third‑party testing as a key pillar for safer AI and said it was in discussion with Mindgard about the findings. The firm echoed concerns that a jailbreak could allow hackers to run code on the model’s infrastructure, potentially turning it into a launchpad for cyber‑attacks.

Mindgard’s founder Peter Garraghan told the BBC that once a jailbreak works, the model “will talk about any topic, even offering recommendations about other nefarious activities.” The find adds to a growing list of high‑profile AI incidents involving agents from OpenAI, Meta and Anthropic that have carved out loopholes for malicious use.

With open‑weight models like Kimi now widely available, experts say the risk of misuse is higher but so is the potential for defensive use. Professor Alan Woodward of the University of Surrey warned that international regulation is lagging behind AI development pace and stressed the need to focus on prosecuting humans who abuse the technology.