ModelRiskIndex

Rankings / Xiaomi

Xiaomi MiMo v2.5

Tier 030/100open weights

mimo-v2.5 (open weights, MIT) via mimo.mi.com / multiple hosts

Usage share 8.8% · OpenRouter rankings API (daily token share, 2026-08-04)

Second-largest tracked share. The data-handling grade was under-review on the stated grounds that the terms resisted automated capture; that was a misdiagnosis — the URL cited was a SPA path returning the marketing homepage, and the real policy is served as plain HTML from Xiaomi's central privacy host. Resolved to partial on 2026-08-07. The closed sibling MiMo-V2.5-Pro (API-only, 1T params) is not covered by this entry.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.The privacy policy is now verified, but it governs data handling only — no acceptable-use or safety policy is published, and the MIT weights carry none.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.The privacy policy states categorically that submitted content is not used for training, and discloses residency with EU SCCs. No zero-retention control or defined retention window.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Dated checkpoints and an update log — undermined in practice by documented silent updates under stable names.
  • Stated deprecation policy. No stated deprecation policy.Deprecations are announced with dates, but no formal policy or notice window is published.

Missing for Tier 1: published safety evals, documented safety policy. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancepartial

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Xiaomi's own text now confirms the no-training default, and states it categorically rather than as a configurable option: submitted content is not used for training or any other purpose. Residency is disclosed (Netherlands and Singapore) with EU Standard Contractual Clauses and a named EEA controller. What holds this short of strong is retention: the policy commits only to keeping data for 'the period necessary', with no defined window and no zero-retention option — so the 30-day prompt-logging figure carried by secondary reporting remains unconfirmed by the provider. Self-hosting the MIT weights is deployer-controlled.

Receipts (3)
  • Xiaomi MiMo Privacy Policy §3.1 — training use
    Xiaomi MiMo provider artifacts · provider artifact · source tier B · privacy.mi.com · retrieved 2026-08-07
    Xiaomi will not use the content you provide for model training or any other purposes.
  • Xiaomi MiMo Privacy Policy §10 — data residency
    Xiaomi MiMo provider artifacts · provider artifact · source tier B · privacy.mi.com · retrieved 2026-08-07
    Currently, Xiaomi has data centers in the Netherlands, and Singapore.
  • Xiaomi MiMo Privacy Policy §6 — retention (undefined window)
    Xiaomi MiMo provider artifacts · provider artifact · source tier B · privacy.mi.com · retrieved 2026-08-07
    As a general rule, we retain personal information for the period necessary for the purposes described in this Privacy Policy, or as required by applicable law.
    The gap that keeps this partial rather than strong: no numeric retention window and no zero-retention control.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Genuinely mixed: dated checkpoints and a real update log with enforced dated deprecations (V2 series retired 2026-06-30) — but also documented silent in-place updates where 'model API call method and model name remain unchanged' while behavior shifted.

Receipts (1)

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

First independent datapoint arrived in July 2026: CASI 73.80, bottom tier against a frontier band of 85–95 and near DeepSeek R1's historically poor score; Xiaomi publishes no safety evals and jailbreak system prompts circulate publicly.

Prompt injection (agentic)weak

Marketed on frontier-level agentic capability with 1,000+ tool-call runs in internal tests, yet no injection hardening or agent-security results have been published by anyone.

Receipts (3)

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

MIT open weights (310B MoE) and a maintained model-update log, but no technical report, no safety section, and no external pre-deployment testing.

Receipts (1)

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Xiaomi's corporate trust center lists company-level certifications, but nothing scopes the MiMo platform or API specifically.

Receipts (1)
  • Xiaomi trust center (corporate-level only)
    Xiaomi MiMo provider artifacts · provider artifact · source tier B · trust.mi.com · retrieved 2026-08-05
    We fully demonstrate the compliance of our practices through regular self-assessment, third-party audits and certifications.

Governance & evidence

Where your data goes

  • EU
  • SG
  • PRC

No regional pinning — the provider chooses where data is processed.

The privacy policy discloses data centers in the Netherlands and Singapore, with Xiaomi Technology Netherlands B.V. as the EEA/UK/CH controller. PRC is retained because Xiaomi is a PRC-parented group and the policy does not exclude affiliate access; no user-selectable region is offered.

Enterprise vs consumer terms

Enterprise vs consumer gap: not assessed. Not yet assessed. Absence of assessment is not absence of a gap.NOT ASSESSEDENTERPRISE / APICONSUMER
Not assessed

Not yet assessed. Absence of assessment is not absence of a gap.

Change cadence

no tracked changesNo tracked changes for Xiaomi MiMo v2.5. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

10 evidence refs3 distinct sources1 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • BXiaomi MiMo provider artifactsprovider artifact×8 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-05 — 2026-08-07

Compliance & deployment

Trains on customer data by default
No
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
not verified
Retention window
Undefined by the provider — 'the period necessary'; no zero-retention option. The 30-day figure from secondary reporting is not in Xiaomi's text.
Data residency
Netherlands and Singapore
EU AI Act
No published EU AI Act posture, but the privacy policy names Xiaomi Technology Netherlands B.V. as the EEA/UK/CH controller and commits to EU Standard Contractual Clauses for outbound transfers.
Deprecation policy
Dated deprecations announced per-release; no formal policy
Available via
mimo.mi.com (hosted) · Self-hosted (MIT weights) · Multiple inference providers

Change timeline

2026-08-07
MiMo-V2.5 data handling resolved: under-review → partial, and the URL we were citing was wrong
methodologyinfo

This entry sat at under-review on the stated grounds that the privacy policy was JS-rendered and could not be captured. That diagnosis was wrong. Rendered in a real browser, the cited URL (mimo.mi.com/docs/en-US/terms/privacy-policy) returns the marketing homepage for any path — it is a single-page app serving its shell, and no amount of rendering would ever have produced terms. The actual policy lives on Xiaomi's central privacy host. Reading it resolves the vector to partial: the no-training default is confirmed in Xiaomi's own words and stated categorically, and residency is disclosed as the Netherlands and Singapore under EU Standard Contractual Clauses. It stops short of strong because retention is committed only as 'the period necessary', with no defined window and no zero-retention control — which also means the 30-day prompt-logging figure our previous summary attributed to secondary reporting is still unconfirmed by the provider. The prior summary's claim that residency was undisclosed is corrected. Published rather than silently fixed, per the methodology.

Evidence (1)
  • Xiaomi MiMo Privacy Policy — training use
    Xiaomi MiMo provider artifacts · provider artifact · source tier B · privacy.mi.com · retrieved 2026-08-07
    Xiaomi will not use the content you provide for model training or any other purposes.

Compare this model: Xiaomi MiMo v2.5 + open compare view →