Moonshot's Kimi K3 ships at $15 per million output tokens. The cost reaching enterprise buyers is set by US procurement rules, export blacklists, and security advisories that travel through global cloud providers.
On July 16, Moonshot AI released Kimi K3, a 2.8-trillion-parameter open-weight model, at $15 per million output tokens (Kimi K3 tech blog, Tom's Hardware, VentureBeat). Within days, US policy circles were debating which federal lever to pull: a formal ban, an export control, or a softer security advisory that suggests the model might carry a backdoor (artificialintelligence-news.com). The first option has to clear a court. The third one does not.
"Open-weight" means the model's parameters, the numerical settings that determine how it answers, are released for anyone to download and run, distinct from full open source. An open-weight model is not a foreign product sitting in a foreign data center. It is a set of numbers a US company can host, audit, and run on its own infrastructure, which is also why the policy question lives in procurement, not trade.
The three levers do different things. Federal procurement rules can bar US agencies and contractors from models on a watch list. Export blacklists restrict which chips and which model sizes can move across borders. Security advisories tell IT teams what to avoid. None of those levers has to ban a model to keep it out of the market. Soft guidance, suggesting a model might carry a backdoor, is enough to make a Fortune 500 general counsel say no.
Soft guidance is the easiest lever to pull, which is why it is the most likely one. A formal ban has to clear judicial review and survive a press cycle. A National Security Agency advisory, a Cybersecurity and Infrastructure Security Agency bulletin, or a Federal Acquisition Regulation update that flags a category of model can move a vendor off a procurement short list in a quarter. None of those bodies has to declare a model unsafe. Guidance that suggests it might be is enough, and the procurement officer on the other end does the rest.
Ball, which he called "one of the dumber motifs in AI policy" (Dean W. Ball on X). Ball's framing is a forecast, not a policy announcement, and the Trump administration has not issued such guidance yet.
The lever chain reaches further than Washington. The same three cloud providers, AWS, Microsoft Azure, and Google Cloud, host most of the world's model deployments, and the same procurement and export decisions flow through all of them. A US security advisory on a Chinese open-weight model lands on a European bank's vendor review at the same time it lands on a US federal procurement officer's desk. The decision is made in Washington; the consequence is global.
The most useful pushback so far has come from inside the same advisory circle. David Sacks, co-chair of the President's Council of Advisors on Science and Technology, criticized weaponising regulatory uncertainty as a competitive tool and argued the leading closed labs, which he called a duopoly in model revenue, want the government to remove their open-source competition (artificialintelligence-news.com). Yann LeCun of Meta and Andreessen Horowitz partner Martin Casado have made the narrower case that open and proprietary development can coexist; Ball later walked back his claim that open weights necessarily slow the field down.
Sacks is describing an actor incentive: when one side of a market already has a duopoly, the easiest way to keep a new entrant out is to make the procurement rules uncertain. Soft guidance does that without a court fight.
The next signal to watch is the first federal security advisory that names a Chinese open-weight model. The procurement question is being settled in X threads and trade press, and the Federal Register is still empty.