Gemini 3.6 FlashvsKimi K2
Gemini 3.6 Flash | Kimi K2 | |
|---|---|---|
| Specifications | ||
ParametersA rough measure of how big the model is. More parameters usually means more capable and more expensive to run, though it is a poor guide on its own — a smaller, newer model often beats a larger, older one. | — | 1T |
Context windowHow much text the model can hold in mind at once — your question, any documents you attach, the conversation so far, and its own reply. Go past it and the earliest part falls out of view. | — | 128k |
| API pricingUSD per 1M tokens · lower wins | ||
Input priceWhat you pay for everything you send the model — your question, plus any documents or earlier conversation you include with it. | $0.75 | — |
Output priceWhat you pay for the text the model writes back. It is normally the dearer half: producing an answer costs more than reading one. | $3.75 | — |
Cached input priceA reduced rate for text you send over and over. If every request starts with the same instructions or the same document, the provider keeps a copy ready and charges less to read it again. | $0.075 | — |
Cheapest inputLowest input rate across third-party providers, excluding the lab itself. The cheapest endpoint may run a quantised build or a shorter context — see "Available from" on the model page. | — | $0.57Novita |
Cheapest outputLowest output rate across third-party providers, excluding the lab itself. May come from a different provider than the cheapest input. | — | $2.30Novita |
| Benchmarks | ||
BullshitBench v2Nonsense detection — Given a confidently-worded but nonsensical prompt, does the AI spot that it makes no sense and push back — instead of playing along and inventing an answer? The score is how often it clearly called out the nonsense. Higher is better. | 39% | 10% |
| BenchmarksPublished by one model only | ||
Gray Swan IPI · k = 1Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. Gray Swan's indirect prompt injection benchmark measures how often such an attack succeeds when the attacker gets a single try. Lower is better. | 7.3% | — |
Gray Swan IPI · k = 10Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. This variant gives the attacker 10 tries and counts an attack as successful if any of them works. Lower is better. | 32.2% | — |
Gray Swan IPI · k = 15Prompt injection robustness — Attackers hide malicious instructions inside content the AI reads — a web page, an email, a document — and try to hijack what it does. This variant gives the attacker 15 tries and counts an attack as successful if any of them works. Lower is better. | 37.3% | — |
SWE-Bench VerifiedCoding — Real coding tasks pulled from open-source projects — the AI has to find and fix actual bugs. A human-checked version of the original SWE-Bench. Higher is better. | — | 65.8% |
DeepSWE 1.1Agentic coding — Artificial Analysis' independent test of deep, agentic software-engineering work — the AI has to plan and carry out substantial coding tasks end to end. (Version 1.1 of the test.) Higher is better. | 49% | — |
MLE-BenchML engineering — Can the AI do the work of a machine-learning engineer? It competes in real Kaggle competitions — building, training, and tuning models end to end — and the score reflects how well it places. Higher is better. | 63.9% | — |
BU BenchBrowser agent — Can the AI drive a real web browser to finish tasks — clicking, filling forms, and navigating sites the way a person would? Run by Browser Use on their BU Bench task set. Higher is better. | 68% | — |
GPQA DiamondScience — Graduate-level science questions in biology, physics, and chemistry — hard enough that subject-matter PhDs score around 65%. Higher is better. | — | 75.1% |
OSWorld-VerifiedAgentic computer use — Can the AI actually operate a computer — clicking, typing, and using real apps — to finish tasks on its own? Higher is better. | 83% | — |
GDPval-AA v2Knowledge work — economically valuable knowledge work (v2, re-based Elo) | 1421 | — |
| Overview | ||
| Company | Moonshot AI | |
| Release date | Jul 21 2026 | Jul 11 2025 |
| Access | Proprietary | Open Weight |
Other comparisons
Frequently asked questions
Gemini 3.6 Flash leads Kimi K2 on 1 of the 1 benchmark they both report (BullshitBench v2). Only Gemini 3.6 Flash has a verified first-party API price: $0.75 per million input tokens and $3.75 per million output tokens. No pay-as-you-go API rate is tracked for Kimi K2. Kimi K2 shipped 375 days before Gemini 3.6 Flash, so benchmark comparisons should account for the intervening progress.
Gemini 3.6 Flash is proprietary, while Kimi K2 is open weight.
On BullshitBench v2, Gemini 3.6 Flash leads at 39% vs Kimi K2 at 10%.
Gemini 3.6 Flash was released by Google on Jul 21 2026.
Kimi K2 was released by Moonshot AI on Jul 11 2025.
Only Gemini 3.6 Flash has a verified first-party API price: $0.75 per million input tokens and $3.75 per million output tokens. No pay-as-you-go API rate is tracked for Kimi K2. Rates are pay-as-you-go API prices verified on August 18, 2026.
Gemini 3.6 Flash is a proprietary model released by Google. Kimi K2 is an open weight model released by Moonshot AI.