The Signal — July 17, 2026
A big week for anyone tracking where AI actually lands: a Chinese lab put out the largest open model yet, a survey found most companies have already been burned by their own AI agents, and Major League Baseball told teams to stop letting chatbots call the game.
China's Moonshot ships Kimi K3, the largest open model yet
Moonshot AI released Kimi K3 on Wednesday, and the headline number is hard to miss: 2.8 trillion parameters, making it the biggest open-weight model anyone has shipped. It uses a mixture-of-experts design that activates only 16 of its 896 experts per token, so the full parameter count overstates how much compute each request actually touches. It carries a 1-million-token context window, native vision, and two architectural pieces Moonshot is introducing here, a hybrid linear attention scheme it calls Kimi Delta Attention and something it labels Attention Residuals. Moonshot says the attention change decodes up to 6.3 times faster at very long context lengths.
On the independent Artificial Analysis Intelligence Index, K3 scores 57 and lands fourth out of roughly 189 models, behind Anthropic's Claude Fable 5 and two reasoning settings of OpenAI's GPT-5.6 Sol, and ahead of Claude Opus 4.8 and GPT-5.5 at its high setting. It also tops Arena.ai's Code WebDev leaderboard. The pricing is the part that will get enterprise attention: $3 per million input tokens and $15 per million output, well under the frontier closed models it trades blows with. It is live now on kimi.com, the Kimi apps, Kimi Work, Kimi Code, and the API, with open weights rolling out. The through-line worth holding onto is that the gap between the best closed models and the best openly available ones keeps narrowing, and a lot of the pressure is coming from China.
Sources: Platformer · Simon Willison · Moonshot · BigGo
Most companies have already had an AI agent security incident
A VentureBeat survey of 107 organizations found that 54% have already experienced a confirmed AI-agent security incident or a near-miss. The uncomfortable detail underneath that number is how these systems are wired: only about a third of organizations give each agent its own scoped identity. The rest let agents share credentials or run on the same API keys and service accounts a human or another service already uses. When agents share a key, one compromised agent can inherit the access of every other agent using it.
The rest of the picture is consistent with a technology deployed faster than it was secured. Only about 30% of organizations isolate their highest-risk agents, most defenses are borrowed from model providers and cloud platforms rather than built for agents specifically, and spending on the problem is still a thin slice of the security budget. A separate survey from the Cloud Security Alliance and Zenity found 47% of organizations reporting an agent-related incident, close enough to VentureBeat's figure to suggest the pattern is real rather than a quirk of one sample. Agents are being handed real access to real systems before the identity plumbing to contain them exists.
Sources: VentureBeat · Techzine · Cloud Security Alliance
MLB tells teams to stop letting AI call the game
Major League Baseball has effectively banned teams from using their league-issued dugout iPads to reach generative AI during games. According to a commissioner's office memo from June 11 obtained by The Athletic's Eno Sarris, teams had been installing custom apps that pushed the tablets past their intended use into "recommendations regarding substitutions, pitch calling, and other in-game decisions traditionally made by players and coaches." People familiar with the practice told The Athletic that as much as a third of the league had used the iPads this way.
The iPads first showed up in dugouts in 2021, meant for reviewing live in-game video. The jump from watching video to querying a model for the next pitch call is exactly the kind of scope creep that tends to happen once a general-purpose tool is sitting in someone's hands during a decision. No clubs are being punished; MLB reviewed the situation and found everyone now compliant with the new rules. It is a small story with a familiar shape, an institution drawing a line about where automated recommendations stop and human judgment is supposed to take over, and doing it only after the practice had already spread.
Sources: The Athletic · Engadget · NY Post
On the Editor's Desk
A few things we looked at and set aside. Anthropic's push to get states regulating AI faster, a Google DeepMind researcher's resignation over a Pentagon contract, and the Future of Life Institute's summer safety index all came up again, but we covered each within the last few days and there was no new development to justify a second pass. Hyundai's move to buy out SoftBank's remaining stake in Boston Dynamics was a genuinely interesting robotics story, but it broke a couple of days ago and sits closer to the corporate-finance side of the line than to anything new about the technology, so it stayed on the desk this time.