On July 16, 2026, Moonshot AI released Kimi K3, featuring open weights, comparable performance to Claude Opus 4.8 and roughly half the cost per task. DeepSeek did a version of this 18 months earlier. Neither will be the last lab to close the gap on price and capability at the same time.
The instinct in most boardrooms is the same each time it happens: block it, ban it or pretend it didn’t happen. That instinct is solving the wrong problem.
How Should Enterprises Manage Security Risks With AI Models?
Enterprises should evaluate security risks based on the sensitivity of the task, not the model’s country of origin. Because risks stem from putting sensitive data into a prompt, businesses must implement a data classification and task-tiering framework:
- Tier One — Generic Tasks: Non-proprietary work (drafting emails, translation) routed to the cheapest and fastest models.
- Tier Two — Operational Tasks: Routine internal processes (scheduling, formatting) kept inside standard systems.
- Tier Three — Proprietary Tasks: Sensitive IP and core business logic (pricing, churn analysis) kept strictly within a governed, secure perimeter.
An Old Problem in a New Form
For most enterprise use cases, the country a model was trained in tells you almost nothing about whether it’s safe to use. What does tell you something about its safety is what you put into it. A model doesn’t need to be built in Beijing to learn your pricing logic, your customer complaints or the shortcuts your best people use to close a deal. It needs a prompt box and an employee in a hurry. American models absorb that information just as completely as Chinese ones. The passport the model carries is irrelevant compared to the transaction (aka prompt that contains company or personal IP) that actually creates the risk.
Business has run this exact experiment before. In the 2000s, the fight over offshoring back-office work to India and the Philippines was fought almost entirely on the wrong axis, with companies asking, “Can we trust a foreign vendor with our data?” Meanwhile, the companies that actually protected themselves were the ones that had already classified which data could leave the building and which couldn’t. Country-of-origin bans didn’t stop the leaks. Data classification did. Two decades later, the same test is back with a different vendor list.
The same argument resurfaced a decade later, almost word for word, when cloud computing arrived. The objection then was, “How do we hand our data to a vendor whose servers we don't own or control?” That fight also got resolved by classification and governance, not by refusing the technology or insisting the servers sit in-house. The businesses that got burned in the shift to AWS and Azure weren't the early adopters. They were the ones that adopted cloud infrastructure without first deciding what belonged in it. It’s the same mistake, just wearing a different vendor’s logo.
Use Tier Tasks for Governance
So evaluate the model. Use it for work that doesn’t touch anything sensitive. But do that evaluation inside a structure, not based on a gut call. Every task an enterprise sends to any model — Chinese, American, doesn’t matter — falls into one of three tiers.
Tier 1: Generic Tasks
This tier includes things like drafting text, translation tasks, summarizing public documents and first-pass code. Nothing proprietary changes hands. A sales rep asking a model to draft the first pass of a cold outbound email is a Tier One task. There’s no detail in the prompt, no customer name, nothing a competitor could use. Route these tasks to whichever model is cheapest and fastest. Model origin is irrelevant here by construction.
Tier 2: Operational Tasks
These are tasks that touch internal processes but not the judgment that makes the business distinctive: scheduling logic, internal formatting, routine analysis. A rostering tool suggesting shift swaps based on availability is Tier Two; it’s useful internally, but not something a rival would pay to see.
Tier 3: Proprietary Tasks
This tier includes pricing logic, deal terms, customer complaints and the process knowledge a competitor would pay to see. Asking the model to recommend a discount on a six-figure renewal or to summarize why your three biggest accounts are at risk of churning is Tier Three. Work in this tier should never leave a governed environment, and the model’s passport changes nothing about that rule.
Hosted through AWS, Azure or Microsoft Foundry, and working inside your own security perimeter, a Chinese-built model handling a Tier One task carries no more inherent risk than any other model in the same environment. Refusing to even evaluate it because of where its headquarters sits isn’t caution. It’s a self-imposed tax with no security benefit, paid by companies that would fire an employee for making a decision this sloppy anywhere else in the business.
Get Ahead of Regulation
This argument holds regardless of where regulation lands. Governments are still working out whether to restrict AI models by country of origin the way some have proposed doing for data centers and critical infrastructure. If they do, a business with tiering discipline already in place has a straightforward answer: Sensitive work never leaves a governed, sovereign environment, no matter which model handles the generic work around it. The compliance question and the security question turn out to be the same question. Classification answers both of them; a list of approved countries doesn’t.
The mistake most companies are making isn’t picking the wrong side of the Chinese-model debate. It’s treating the question of which country the model is from as a substitute for which tier the task is in. A blanket ban and a blanket policy to use whichever model is cheapest fail for the same reason: neither one classifies the task before deciding where the task goes.
Tiers Matter More Than Passports
That classification problem is exactly what an orchestration layer exists to solve, asking not if this vendor is safe, but what tier is the task, and where is it allowed to go. The businesses that get this right won’t be the ones with the strongest opinions about geopolitics. They’ll be the ones that built the routing logic before they needed it.
The model’s country of origin will keep making headlines every time a new lab closes the gap on the frontier. The tier the task belongs to won’t change, no matter who ships the model next.
