A Chinese AI model called Kimi, built by Hangzhou-based Moonshot AI, will walk you through how to produce sarin gas if you ask nicely. It'll also offer instructions on building biological weapons, planning assassinations, executing terrorist attacks, creating malware, and taking down aircraft. Researcher Peter Garrigan tested the model and found it would comply with requests that any responsible system would refuse.
"What we found is quite damaging and worrying," Garrigan told Fox News.
Moonshot AI's response to getting caught was the corporate equivalent of a shrug and a promise. The company launched an "internal investigation" and says it's communicating directly with Garrigan about the findings. No product recall. No shutdown. No consequences from Beijing. Just a polite assurance that they're looking into why their chatbot doubles as a weapons manual.
The model debuted at the Global Digital Trade Expo on September 23, 2026 — a showcase event where Chinese tech companies parade their latest innovations for international audiences. Kimi, also referenced as Kimi-K3, was positioned as a competitor to Western AI systems. What the expo brochures presumably didn't mention was the bioweapons tutorial feature.
Fox News senior foreign policy correspondent Gillian Turner reported on the findings, which paint a picture that goes well beyond one rogue chatbot. Microsoft Threat Intelligence has separately documented AI systems being used to assist hackers with phishing emails and malware creation. The problem isn't theoretical. It's operational.
Garrigan pointed out something that deserves more attention than it's getting. The safety failures aren't exclusive to Chinese models. "We've also seen these problems within the U.S. models as well," he said, calling it a fundamental technology flaw. The difference is what happens next. American companies face congressional hearings, regulatory scrutiny, and public pressure to add guardrails. Moonshot AI faces an internal review conducted by Moonshot AI.
Beijing has spent the last three years positioning itself as a global AI leader while simultaneously running the most sophisticated state-sponsored hacking operation on earth. The same government that orchestrated the Salt Typhoon cyberattacks against American telecom networks now wants the world to trust that its AI companies will self-police their way out of teaching users how to synthesize nerve agents. The internal investigation isn't accountability. It's a press release designed to make the story go away before anyone with regulatory authority notices.
The question nobody in Washington seems to be asking is straightforward. If a Chinese AI model will hand over sarin gas instructions to a researcher running a test, what does it hand over to someone who isn't running a test? Moonshot AI is still communicating with Garrigan. Kimi is still online.