kimi has been particularly shameless in copying codex 1:1, wow.
Like, I get it, before condex there was conductor and a ton of other guis but this looks like they just copied the code.
Also, their privacy disclosure is incredibly misleading:
> How does Kimi Work protect my privacy when accessing local files?
You have absolute control over your files. The built-in Ask before acting safeguard means Kimi will prompt you for explicit authorization before it modifies, overwrites, or runs code within your local directories. Nothing happens without your consent.
They fail to mention that is has unfettered read access to your files. ie, without your consent.
“How does Kimi Work protect my privacy when accessing local files?”
It doesn’t protect your privacy. It’s like asking, “how do I know you’re not spying on me?” And getting the reply “we cannot physically enter your house.”
>It doesn’t protect your privacy. It’s like asking, “how do I know you’re not spying on me?” And getting the reply “we cannot physically enter your house.”
In light of the recent grok build snafu, "Nothing happens without your consent" seems like an upgrade. Moreover what are they supposed to do here? By that should any sort of non e2e email/storage provider not be able to put "How does [product] protect my privacy" in their faq?
Looking through their privacy policy, it looks like the bigger issue is that they are (or refuse to refute) training on your data/prompts. That's probably what people should be complaining about rather than complaining about how it "has unfettered access to your files", when that describes all coding harnesses.
Not sure what that's about, I was just copying the wording from OP. Their harness probably has the same restrictions as most other coding harnesses. That is, the read tool gives all project files by default without prompting, and everything else requires manual approval (or opting into auto-run all). If you decide to run it from your home directory however, then your "project" is all your files.
Sharing among AI friends what’s the problem, scraping the Internet or hiring new employees between companies who like to share? It’s a tradition among the AI model makers…
Looks like this can use webBridge, run Python and shell code in the background. Cowork can take over application UI as well which is still a differentiator (and a higher security risk) unless kimi offers it elsewhere.
I wish they had some kind of US hosted option, NDR policy, or something like that. I love the price and power, but I have concerns around data sovereignty and leaking IP to an overseas company.
Same. No way I am uploading data to a PRC company. It's not just an IP issue ... there's a very high likelihood such companies will be restricted in the United States, even if they try "Chinawashing" stunts like Bytedance.
As soon as the K3 weights are published on July 27th, there will be many US providers hosting the model. I realize model hosting doesn't really apply to kimi work specifically, but in terms of accessing K3, there will be US options likely in 7 days. Just look at OpenRouter to see the providers hosting K2.6 https://openrouter.ai/moonshotai/kimi-k2.6.
> Over the past 48 hours, demand has pushed close to the limits of our current capacity. To protect the experience of existing subscribers, we're temporarily pausing new subscriptions and prioritizing compute for current members. Existing subscribed users are not affected.
> We're adding capacity as fast as we can and will reopen new subscription spots in batches.
That might even be a beneficial move, creating (well, actual, not artificial) scarcity works well to draw interest usually. Curious how this one plays out.
Models need richer context to do well. They also generally need a verifier, but better context is already an improvement. So to fix it, you need to rethink UIs to be agent-first.
I'm not saying Kimi Work and its peers are entirely useless. I'm just saying they're a hack that puts a pretty low upper limit on agent capabilities and speed.
Say's who? Why? I honestly don't get the problem. OpenAI just did what you said with the Mac app and were forced to roll it back because of the uproar. A chat box is simple, relatable, easy to use. K.I.S.S. is a thing
Says everyone who's not using this stuff. It's an empirical argument. Is anyone actually using this for work? How long has it been since Cowork was released?
It's such an inadequate tool for work it reeks of SF hubris to think you can just slap a chat input box onto a PC and replace 90% of white collar jobs.
Is there a link anywhere for a docs site for this? Really curious to know what "deep data sources" they have set up for the Native Global Market Data feature.
It rubs me the wrong way that they have to copy everything, the UI is almost exact copy of Codex. The entire mind set of just copy the best is holding them back.
I have a UI I developed from first principles about 10 years ago, I use it to replace my os, its like my personal do everything emacs os but not at all emacs, and its funny to see other Uis iteratively convergence on it as context finally gets its due.
For the past 3 years, many software engineers were coping that AI (particularly LLMs) was only going after juniors. Given the documented history of mass layoffs related to AI from 2024 to today, it is clear that everyone including seniors and staff level folks are just as affected.
So let's just say, if your whole identity is for being a typical software engineer no matter the seniority and nothing else, perhaps it is time for you to reconsider options as of course 100% avoiding AI is futile at this point.
There will still be new jobs, but there will be no need for more excess people, even under Jevon's paradox. Software engineers were just the test bed for this and now there is an oversupply of SWEs without jobs in the market and will have to use AI tools like Kimi Work and Claude Cowork to be employable.
First of all to reply to your deleted comment, yes this is completely relevant to the article.
As token costs drop significantly (thanks to local models and hosted Chinese models.) employers will consider using cheaper models like Kimi Work and others, even if they are already using expensive ones like Claude Cowork. They won't be able to operate without it.
Secondly, do I actually believe this? Of course, I already said that there will be more mass layoffs because of AI years ago. [0]
kimi has been particularly shameless in copying codex 1:1, wow.
Like, I get it, before condex there was conductor and a ton of other guis but this looks like they just copied the code.
Also, their privacy disclosure is incredibly misleading:
> How does Kimi Work protect my privacy when accessing local files? You have absolute control over your files. The built-in Ask before acting safeguard means Kimi will prompt you for explicit authorization before it modifies, overwrites, or runs code within your local directories. Nothing happens without your consent.
They fail to mention that is has unfettered read access to your files. ie, without your consent.
>They fail to mention that is has unfettered read access to your files.
Isn't that totally expected of a coding agent? Otherwise it's like complaining dropbox "has unfettered access to your files".
Yes, but the answer is an indirection.
“How does Kimi Work protect my privacy when accessing local files?”
It doesn’t protect your privacy. It’s like asking, “how do I know you’re not spying on me?” And getting the reply “we cannot physically enter your house.”
>It doesn’t protect your privacy. It’s like asking, “how do I know you’re not spying on me?” And getting the reply “we cannot physically enter your house.”
In light of the recent grok build snafu, "Nothing happens without your consent" seems like an upgrade. Moreover what are they supposed to do here? By that should any sort of non e2e email/storage provider not be able to put "How does [product] protect my privacy" in their faq?
Looking through their privacy policy, it looks like the bigger issue is that they are (or refuse to refute) training on your data/prompts. That's probably what people should be complaining about rather than complaining about how it "has unfettered access to your files", when that describes all coding harnesses.
Yes I’m saying a question answered deceptively should not be one of the four featured questions on your product page.
> Looking through their privacy policy, it looks like the bigger issue is that they are (or refuse to refute) training on your data/prompts.
You’re making my entire point. They’ve designed an ingestion engine that is not private by design. Any sort of privacy posturing is wrong.
The repo you’re working on, sure. But all files?
Not sure what that's about, I was just copying the wording from OP. Their harness probably has the same restrictions as most other coding harnesses. That is, the read tool gives all project files by default without prompting, and everything else requires manual approval (or opting into auto-run all). If you decide to run it from your home directory however, then your "project" is all your files.
> The repo you’re working on, sure. But all files?
Yes, any tool, including any coding agent, has access to all files $USER has access to.
Sandbox it explicitly to give access to only the current directory - https://github.com/ashishb/amazing-sandbox
I am more concerned about what happens to the file if I give permission.
Opensource and local are seeming like the only way.
if your model ever touches bash, it has unfettered acess to all your files.
Not if the harness applies an OS-level sandbox to the process, as Codex does.
https://learn.chatgpt.com/docs/sandboxing?surface=cli
No, you need to apply the sandbox to the codex process itself. Codex does not do this.
Unfortunately it was possible in codex too, until recently.
https://github.com/openai/codex/issues/5237
How dare they copy the largest plagiarism machine ever created.
Everyone’s saying that it looks like Codex but TBH it just looks like all the AI chat websites on the side and some frequent actions on the top.
Sharing among AI friends what’s the problem, scraping the Internet or hiring new employees between companies who like to share? It’s a tradition among the AI model makers…
Pretty shameless copy, but also shows how easy it is to do so. OpenAI and Anthropic had first-mover advantage, but easy come, easy go.
wow -- "Let's take something off your plate" just copied word-for-word from the Claude Cowork UI.
And it is above the fold in their hero image!
that looks exactly like the recent codex!
Looks like this can use webBridge, run Python and shell code in the background. Cowork can take over application UI as well which is still a differentiator (and a higher security risk) unless kimi offers it elsewhere.
I wish they had some kind of US hosted option, NDR policy, or something like that. I love the price and power, but I have concerns around data sovereignty and leaking IP to an overseas company.
It'll most likely land on Bedrock when the K3 weights are released.
Will it? Bedrock doesnt have deepseek v4, GLM 5.2, Qwen 3.6, minimax m3.
Same. No way I am uploading data to a PRC company. It's not just an IP issue ... there's a very high likelihood such companies will be restricted in the United States, even if they try "Chinawashing" stunts like Bytedance.
As soon as the K3 weights are published on July 27th, there will be many US providers hosting the model. I realize model hosting doesn't really apply to kimi work specifically, but in terms of accessing K3, there will be US options likely in 7 days. Just look at OpenRouter to see the providers hosting K2.6 https://openrouter.ai/moonshotai/kimi-k2.6.
The Chinese marketing blitz is on! Ha ha
Guess where the models are gonna be hosted? Hint, not China.
Just wire in "teh cloud!!1" to your local files.
What could go wrong?
The Pricing page shows all plans are sold out.
Gotta generate that FOMO
They say that they have too much demand so are stopping new subscriptions while they scale up: https://x.com/Kimi_Moonshot/status/2078855608565207130
> Over the past 48 hours, demand has pushed close to the limits of our current capacity. To protect the experience of existing subscribers, we're temporarily pausing new subscriptions and prioritizing compute for current members. Existing subscribed users are not affected.
> We're adding capacity as fast as we can and will reopen new subscription spots in batches.
That might even be a beneficial move, creating (well, actual, not artificial) scarcity works well to draw interest usually. Curious how this one plays out.
Yea, they had so much demand for Kimi K3 that they hit the limits of their compute: https://news.ycombinator.com/item?id=48969291
First time I've ever seen something like this. Fascinating.
Still a chat interface, so definitely not an "AI Desktop".
Also this was released about a month ago
https://tech.yahoo.com/ai/meta-ai/articles/moonshot-ais-kimi...
Aren’t there all chat interfaces? Same goes for Claude Work, ChatGPT Work, etc
That's precisely the problem.
People are building UI/UX for a paradigm that is so utterly new that they miss the mark entirely.
Everyone defaults to a big chat input because that's all they know. It's the expectation, so it's safer, faster, and cheaper to not deviate.
It's also wrong and bad for work.
How would you fix it?
Models need richer context to do well. They also generally need a verifier, but better context is already an improvement. So to fix it, you need to rethink UIs to be agent-first.
I'm not saying Kimi Work and its peers are entirely useless. I'm just saying they're a hack that puts a pretty low upper limit on agent capabilities and speed.
> It's also wrong and bad for work.
Say's who? Why? I honestly don't get the problem. OpenAI just did what you said with the Mac app and were forced to roll it back because of the uproar. A chat box is simple, relatable, easy to use. K.I.S.S. is a thing
> Says who.
Says everyone who's not using this stuff. It's an empirical argument. Is anyone actually using this for work? How long has it been since Cowork was released?
It's such an inadequate tool for work it reeks of SF hubris to think you can just slap a chat input box onto a PC and replace 90% of white collar jobs.
Is there a link anywhere for a docs site for this? Really curious to know what "deep data sources" they have set up for the Native Global Market Data feature.
Could I use the browsing feature to search for land to buy? Or is there an easier way I’m overlooking?
Hoping to find something on a creek with a Mountain View and fairly remote.
If this is what pops this bubble, I'll take it!
It rubs me the wrong way that they have to copy everything, the UI is almost exact copy of Codex. The entire mind set of just copy the best is holding them back.
I have a UI I developed from first principles about 10 years ago, I use it to replace my os, its like my personal do everything emacs os but not at all emacs, and its funny to see other Uis iteratively convergence on it as context finally gets its due.
What's your UI like?
China copying shit blatantly haha but winning surely
No linux? They should ask k3 to add linux feature lol.
For the past 3 years, many software engineers were coping that AI (particularly LLMs) was only going after juniors. Given the documented history of mass layoffs related to AI from 2024 to today, it is clear that everyone including seniors and staff level folks are just as affected.
So let's just say, if your whole identity is for being a typical software engineer no matter the seniority and nothing else, perhaps it is time for you to reconsider options as of course 100% avoiding AI is futile at this point.
There will still be new jobs, but there will be no need for more excess people, even under Jevon's paradox. Software engineers were just the test bed for this and now there is an oversupply of SWEs without jobs in the market and will have to use AI tools like Kimi Work and Claude Cowork to be employable.
Do you actually believe this and are concerned about it?
First of all to reply to your deleted comment, yes this is completely relevant to the article.
As token costs drop significantly (thanks to local models and hosted Chinese models.) employers will consider using cheaper models like Kimi Work and others, even if they are already using expensive ones like Claude Cowork. They won't be able to operate without it.
Secondly, do I actually believe this? Of course, I already said that there will be more mass layoffs because of AI years ago. [0]
So this outcome was expected.
[0] https://news.ycombinator.com/item?id=42490692
this landing page looks like a cheap ripoff of google's antigravity: https://antigravity.google/