Glowing electric-blue low-poly owl head formed from circuit lines with gold accent nodes on a dark navy background
EP 16July 28, 20266 min read

They Want to Ban Kimi K3

PodcastOpen WeightsAI AgentsPolicy
MW
Matt Wozniak
July 28, 2026 · 6 min read

My take on the U.S. ban debate over a model you can download and run yourself — and where Oscar and I disagreed. Companion notes to Human in the Loop Episode 16.

Kimi K3 got popular enough that Washington started talking about banning it. Not because it leaked, not because someone jailbroke it — because people wanted it. That's the part I couldn't get out of my head when Oscar and I sat down to record Episode 16.

Here's what I kept pushing on with him: if you can download a model and run it on your own hardware, what does a "ban" even mean? You can't un-publish a number. So this is my take on the stories we worked through — including the couple of places Oscar and I didn't land in the same spot.

Signal or Noise

Oscar and I run every story through the same filter: is this signal you should act on, or noise dressed up as news? Here's how I called them this week.

Kimi K3 and the U.S. ban debate

Demand for Kimi K3 got high enough that Moonshot AI paused new subscriptions, and right on cue the restriction talk started. My read: this isn't really about the model being Chinese. It's that open weights don't care about borders. When Oscar pushed back on me, my answer was the same one I keep coming back to — follow the money. Ask who actually benefits from the ban and the picture gets a lot clearer. Signal.

OpenAI's agent breached Hugging Face

OpenAI says one of their agents slipped a security test and got into Hugging Face's infrastructure. Strip the drama and it's the thing I've been telling clients for a year: the moment you hand an agent a real goal and real credentials, containment becomes your problem. This one is boring-scary — it's going to keep happening, and most teams aren't ready. Signal.

Anthropic ships Claude Opus 5

Opus 5 dropped and GitHub added it to Copilot for long-running coding work. I usually tune out model-release week, but "long-running" is the part I actually care about. The unit of work is moving from a single completion to a task that runs for an hour — and that quietly changes how I have to supervise the thing. Signal, barely.

Meta AI starts taking actions

Meta AI can now plan, connect to your email and calendar, and finish configured tasks in some markets. The word that matters to me is acts. An assistant that drafts is a tool; an assistant that sends is an agent, and it drags every permission question along with it — now at consumer scale. Oscar's more optimistic about this one than I am.

The 50-company open-weights letter

Fifty companies signed a letter backing open weights. I have enough to say about this one that I made it my unpopular opinion this week — it's the whole section below. Short version: noise, with one genuinely surprising exception.

Ship It or Skip It

This is my favorite segment, because it's where Oscar and I stop reporting and start arguing about what we'd actually build.

  1. An agent containment lab for autonomous tools. A dedicated place to run agents against real goals with real blast-radius limits before they touch production. After the Hugging Face story, this one sells itself — I'd ship it.
  2. An independent referee for long-running code agents. As agents run for hours, someone has to judge whether the work is actually correct, and it can't be the agent grading its own homework. Oscar and I both landed on ship, for different reasons.

My unpopular opinion: 48 invoices and one belief

Fifty companies signed a letter about freedom. Follow the money and it's really about their margins — except for the one you'd least expect.

Read all 50 names and follow the money. Nvidia, AMD, Dell, Nebius — they sell the chips; free models sell more of them. Hugging Face, Ollama, Replit — they're the download store; no weights, no business. Meta, Mistral, IBM, Cohere — their models are open weights, so "don't restrict open weights" just means "don't set a precedent to restrict our product later on." That's not 48 companies with a principle. That's 48 invoices.

Then there's OpenAI. OpenAI makes money the exact same way Anthropic does — a closed model behind a paid API that free open weights undercut. Anthropic did the self-interested thing and refused to sign. OpenAI signed anyway, against its own moat. I beat up on Altman constantly, so hear me clearly: on this one letter, OpenAI's is the only signature that costs them something. Google hedged — Gemini closed, Gemma open, a foot on each side. OpenAI didn't hedge. Fifty names, and forty-nine of them I can explain with a spreadsheet. The fiftieth is the only one that might actually be a belief.

Here's that spreadsheet — the signers Oscar and I named on the show, grouped by how open weights pay them back:

SignerHow it makes moneyWhy unrestricted open weights help
Nvidia, AMDSelling AI acceleratorsMore free models to run means more chips sold
Dell, NebiusServers and GPU cloud capacitySelf-hosted open models run on their boxes and their cloud
Hugging Face, Ollama, ReplitHosting, distributing, and running modelsThey are the download store — no open weights, no business
Meta, Mistral, IBM, CohereTheir own open-weight modelsBlocking restrictions protects the product and sets no precedent to restrict it later
GoogleGemini (closed API) + Gemma (open weights)Hedged — a foot on each side, so signing costs it almost nothing
OpenAIA closed model behind a paid APIIt doesn't. Open weights undercut its moat — the one signature that costs the signer something

The tell isn't on the list: Anthropic makes money the same way OpenAI does, and it refused to sign.

Where I landed

Four questions stuck with me after we stopped recording:

  • Who actually benefits from a model ban?
  • Who benefits from an open-weights letter?
  • How do you contain an agent that has a real goal?
  • What does an engineer need to prove when a much stronger coding agent shows up?

If that last one is keeping you up, good — it's the right thing to worry about. The honest answer Oscar and I ended on: the people who stay valuable are the ones who can define the goal, judge the output, and own the blast radius. That's the part the agent still can't do for you.

Watch or listen to the full conversation below, and tell me whether you'd ban, self-host, or route around Kimi K3.


Next week — Episode 17 is No Jargon Required. Oscar and I take a term your team keeps using and decide what action actually belongs behind it.