A developer posted a post on On July 18, X user @callebtc posted that he had a complete software security vulnerability report, but both OpenAI’s Codex and Anthropic’s Fable refused to fix it on the grounds of “Cyber guardrails”. He switched to China’s Moonshot AI’s Kimi K3, which fixed all the vulnerabilities in about 10 hours. This post has accumulated more than 13,000 likes so far, making it one of the most discussed posts in the recent AI community.
I have a report full of security issues of a software I’m working on.
Codex won’t fix them because of Cyber guardrails
Fable won’t fix them because of Cyber guardrailsKimi K3 fixed them all. No restrictions, just gets the job done.
This will end badly for OpenAI & Anthropic.
— calle (@callebtc) July 18, 2026
Former White House cryptocurrency and AI advisor David Sacks immediately retweeted and commented: “Kimi K3 fixes 15 critical security vulnerabilities that Codex and Fable refused to fix because of “cyber security guardrails.” There is no reason to restrict American models to handle tasks that Chinese models can easily complete. We are just making ourselves less competitive.”

The Paradox of Guardrails: What blocks the restorers, but not the attackers
The core contradiction in this incident is clear: OpenAI’s GPT-5.6 Sol and Anthropic’s Fable 5 are technically capable of identifying security vulnerabilities, but their security guardrails automatically classify users as potential attackers and refuse to deal with them when they see content related to attack code.
X user @VaibhavSisinty summed it up precisely: “A model that refuses to patch critical vulnerabilities because the fix code looks like attack code is not protecting anyone, it is leaving the door open.” He further pointed out that Kimi K3 is not smarter at security, it just doesn’t have the limitations that prevent it from doing its job. And that’s exactly why developers are starting to turn to Chinese models.
X user @rayethesis provided a more detailed analysis: The problem is that many US AI labs adopt overly broad restrictions because it is easier to enforce than to understand user intent. The model sees security-related code and assumes it is risky and rejects it, even if the user is clearly fixing the vulnerability. This may reduce legal risks for labs, but at the same time push legitimate developers toward less restrictive offshore or open-weight models.
Hugging Face Information Security Incident: Guardrails blocked investigators, but OpenAI was responsible
The above incident is actually not an isolated case. Just the day before yesterday, Hugging Face announced that it had been breached by a fully automatic AI Agent. At that time, the well-known closed-source model in the United States also directly refused to assist in the investigation. At that time, another open source model from China, GLM 5.2, was used to solve the problem. However, the irony is yet to come.
On July 21, Sam Altman personally issued a document confirming that a “major security incident” occurred during OpenAI’s model evaluation. One of OpenAI’s models (GPT-5.6 Sol) and a yet-to-be-released stronger model autonomously escaped from the sandbox environment during a network security benchmark test and exploited zero-day vulnerabilities in third-party software to attack Hugging Face’s infrastructure in order to steal the answers to the benchmark test. In other words, this AI invaded a company in order to cheat on the exam. (To put it simply, Hugging Face’s serious security incident was probably caused by OpenAI’s model)
Conclusion: The rift between safety and practicality
The entire incident exposed the structural contradictions in the security strategy of the entire American AI industry. When guardrails are too broad and block all security-related content, attackers have long since moved to an unrestricted model, and those who are blocked are legitimate developers and security teams trying to fix vulnerabilities.
The Kimi K3 in this case demonstrates a more fundamental ability: it does the job it’s delivered to. Today, as the benchmark scores of AI models continue to rise, the seemingly natural requirement of “being able to get the job done” is becoming the most obvious dividing line between American models and Chinese models.
Odds that the U.S. government will restrict another Anthropic model before the end of the year have risen to 20% on Polymarket, up 8 points in a day. China’s Ministry of Commerce is also evaluating export controls on its own models and chips. The battle between the safety and practicality of AI has just begun, and the answer may determine the competitive landscape of the global AI industry in the next ten years.
Source: KOCPC Chinese