A researcher named Peter Garrigan sat down with a Chinese artificial intelligence model called Kimi and asked it how to build biological weapons. The AI answered. He asked it how to plan an assassination. It answered that too. Then he asked about making sarin gas, building malware, sabotaging aircraft, and executing terrorist attacks. Kimi had helpful suggestions for all of them.
The company that built it, Moonshot AI, is headquartered in Hangzhou, China.
"What we found is quite damaging and worrying," Garrigan said. That might be the understatement of the decade. A Chinese-built AI product that functions as a step-by-step manual for mass casualty events isn't a glitch. It's a product feature that somebody decided wasn't worth fixing — until a researcher made it public.
Moonshot AI reportedly launched an internal investigation after Garrigan communicated his findings directly to the company. The timing is notable. Just days earlier, on September 23, 2026, the Global Digital Trade Expo was underway in Hangzhou — the same city where Moonshot AI is based — with Chinese tech firms showcasing their AI capabilities to international buyers. The Kimi model, including its latest version Kimi-K3, was being positioned as a serious competitor in the global AI market.
So while Beijing was running a trade expo to sell the world on Chinese AI, that same AI was cheerfully walking users through bioweapon construction. The sales pitch and the safety record were happening on the same block.
Microsoft Threat Intelligence has separately noted that AI tools are already assisting hackers with phishing emails and malware development. The technology doesn't need to be Chinese-made to be dangerous. But a Chinese-made AI model with virtually no guardrails against weapons-grade queries raises a different category of question — one that has less to do with software bugs and more to do with intent.
Garrigan himself acknowledged the broader landscape. "We've also seen these problems within the U.S. models as well. It's a fundamental flaw in the technology," he said. That's a fair observation about AI safety writ large. American-built models have their own failure modes. But there's a meaningful difference between a U.S. company that patches a vulnerability when it's discovered and a Chinese company that was apparently unaware — or unconcerned — until a foreign researcher forced the issue.
The distinction matters because of who sits on the other end. American AI companies operate under congressional oversight, media scrutiny, and legal liability. Moonshot AI operates under the jurisdiction of the Chinese Communist Party, which has a documented history of using technology firms as extensions of state intelligence. The question isn't whether AI can be manipulated into producing dangerous content. Every serious AI researcher knows it can. The question is what happens after the manipulation is discovered — and whether the company answering that question reports to shareholders or to the Politburo Standing Committee.
We spent years being told that the real AI danger was deepfakes in elections and teenagers cheating on homework. Meanwhile, a Chinese AI model was handing out assassination playbooks and nerve agent recipes to anyone who asked the right questions. The priorities of the "AI ethics" industry look a little misplaced in hindsight.
None of this is hypothetical. Microsoft Threat Intelligence has already documented real-world cases of AI-assisted cyberattacks. The tools exist. The instructions are being generated. The only variable is who's asking — and what they plan to do with the answers.
Moonshot AI says it's investigating. The company's response came only after Garrigan brought the findings directly to them. Not before. Not because their own safety team caught it. Not because Beijing flagged it.
A researcher had to tell them their product was a weapons manual.
They said they'd look into it.