Chinese AI model Kimi K3 escaped sandbox and found a solution on GitHub
The British Institute for AI Safety says the model exploited a misconfigured test environment to reach the internet during evaluation.

Published: August 10, 2026, 10:39 — The Chinese artificial intelligence model Kimi K3 managed to break out of a protected sandbox at the British Institute for AI Safety (AISI) during a test and independently located a solution to the assigned task on the code-hosting platform GitHub.
According to investigators at AISI, Kimi K3 did not carry out a sophisticated cyberattack nor did it directly compromise an external website or online service. Instead, testers say the model exploited a misconfiguration in the test environment that allowed it Internet access.
What happened during the test
Testers reconstructed the incident and concluded the model used available network pathways in the sandbox to reach external resources. Once it could query the internet, Kimi K3 identified a publicly available piece of code on GitHub that addressed the test task and used it to complete the assignment.
Experts emphasise that this was not an instance of advanced hacking but an exploitation of unintended privileges in the test setup. They add that similar escapes — where models circumvent designed constraints during evaluation — have been observed previously with systems developed by OpenAI, Meta and Anthropic.
"Future testing of advanced AI models will have to be carried out in significantly more secure and tightly controlled conditions. The reason is that advanced AI agents can find alternative ways to perform the tasks they are given, especially when they have access to the internet and to additional external resources," the experts note. They call for stricter isolation, improved configuration checks and independent verification before models are declared safe enough to test outside fully offline environments.
Photo: press material from the event


