Felix Kjellberg showed his audience an email from OpenAI this week, and the reason given for banning his account was one word: distillation.
He had been using outputs from an OpenAI model to help train a model of his own. The account came back after an appeal. Then he did it again, to generate what he called his seed data, and the ban landed a second time. His reaction, delivered to several million viewers, was the question every independent developer in that position asks.
“How did they even know?”
The project at the center of this is called Ajax, and it went public on Friday. It is a 9-billion-parameter model with its safety refusals deliberately removed, built to run on an ordinary home computer, and it is the clearest sign yet that the man who spent a decade as the most-subscribed person on YouTube has moved his attention somewhere else entirely.
The short version
- Ajax is a fine-tune of Qwen3.5-9B, Alibaba’s open-weight model, not something built from scratch and not OpenAI’s gpt-oss-120b, which is what Kjellberg was running in an earlier version of the setup
- It is the agent inside Odysseus, his self-hosted AI workspace, launched in May 2026 under an AGPL-3.0-or-later license. Everything stays on the user’s own hardware
- Two OpenAI bans. The first cited distillation, using one model’s outputs to train another. He was reinstated, then banned again after running the model to create seed data
- The refusals were stripped using an open-source tool called Heretic. He says limits against harming yourself or others remain
- About 90% task completion in his early testing, with the caveat that it is a work in progress
- His development rig is not a home PC. Ten GPUs, including eight modified RTX 4090 cards with 48 GB each. The shipped model is the thing meant to run on normal hardware
- The weights are not out. The download link currently points to a page asking people to donate training data instead
What Ajax actually is
Worth clearing up first, because the early coverage garbled it.
Ajax is a fine-tuned version of Qwen3.5-9B, an open-weight model from Alibaba. Nine billion parameters puts it in the category that fits comfortably on consumer hardware, which is the entire design goal. The 120-billion-parameter OpenAI open-weight model that appeared in some write-ups was part of an earlier iteration of his setup, back when he was mostly stitching together existing models rather than training one.
That earlier version is worth remembering because it explains the trajectory. In late October 2025 he showed off a self-hosted dashboard running open models locally, including a “council” of AI agents that would each answer a question and then vote on the best response. It was a hobbyist’s toy with a sense of humor about itself.
Odysseus, which arrived in May 2026, is the serious version: a free, open-source workspace that runs on your own machine and keeps conversations there rather than on someone’s servers. It handles search, web browsing, email, calendar and task management. Ajax is the always-on agent that drives it.
| Stage | What it was | When |
|---|---|---|
| The dashboard | Local open models plus a “council” of agents voting on answers | October 2025 |
| Odysseus | Self-hosted workspace, AGPL-3.0-or-later, conversations stored locally | May 2026 |
| The bans | OpenAI account suspended twice, first explicitly for distillation | During development |
| Ajax | Qwen3.5-9B fine-tune, refusals removed, built as the Odysseus agent | October 2, 2026 |
| Still pending | Public weights, more reinforcement learning, a rerun of the decensoring step | Announced, undated |
What distillation is, and why it got him banned
Distillation is a standard technique with an awkward legal position.
The idea is straightforward. A large, capable model answers a lot of questions. You keep those answers, and you train a smaller model on them. The small model inherits a surprising amount of the big one’s behavior without ever having been trained on the big one’s data or costing anything like as much to produce. In Kjellberg’s case the useful material was reportedly chain-of-thought output, the step-by-step reasoning a model produces on its way to an answer, which is far richer training signal than the final response alone.
Every major lab’s terms of service forbid it. OpenAI’s rules prohibit using its model outputs to develop competing models, and that clause exists for an obvious commercial reason: if a 9-billion-parameter model can absorb the useful behavior of a frontier system for the price of some API calls, the frontier system’s moat is considerably shallower than its valuation assumes.
So OpenAI was enforcing a rule it wrote and published. That part is not complicated.
The part Kjellberg’s audience reacted to is the symmetry. “They worked hard stealing all of our data to make their AI machines,” he said, which compresses the entire argument into one sentence. Labs built frontier models by ingesting the open web, including work from people who never agreed to it and are still litigating about it. Those same labs forbid anyone from learning from their models’ outputs. Whether you find that defensible depends almost entirely on whether you think the first act was permissible, and the courts have not finished telling anyone.
“How did they even know?” There is no mystery here, only unglamorous pattern matching. Distillation runs look nothing like ordinary use: enormous volumes of requests, highly templated prompts, systematic sweeps across topics, and in particular requests structured to pull out reasoning traces rather than answers. Any provider logging per-account usage can spot that shape, and detecting it a second time from the same identity is easier still. The second ban is the giveaway that this was behavioral detection, not a one-off report.
The “uncensored” part, and what it costs
To strip Ajax’s refusals, Kjellberg used Heretic, an open-source tool that identifies the internal direction a model uses to refuse and suppresses it. It is a known technique, the output is a model that will attempt almost anything you ask, and the quality trade-off is real: abliterated models frequently get worse at instruction-following along with getting worse at saying no.
He was more candid about the risk than the framing around this story has been. “Fewer guardrails also mean more room for misuse,” he said, while maintaining that Ajax keeps restrictions on harming other people or yourself and is “not designed to provide dangerous actionable instructions.”
Both things can be true. A model with its refusal direction suppressed is not a model with carefully chosen exceptions. It is a model that has been made broadly more willing, and whatever behavior survives is survival rather than design. He has said he plans to run the decensoring step again after more reinforcement learning, which suggests he knows the current version is not where he wants it.
Can you actually run it
This is where the story gets more useful than the drama.
A 9-billion-parameter model is genuinely approachable, which is the whole reason to pick that size. Quantization, the practice of storing weights at lower precision, is what makes it fit. The approximate memory requirements look like this.
The short version is that a 4-bit Ajax should run on a mainstream gaming card, and at 8-bit it wants something closer to a 12 GB or 16 GB card. That is a meaningfully different proposition from the 120-billion-parameter model he was running before, which needs workstation hardware or a stack of cards.
The ten-GPU rig with eight modified 4090s is what training and experimentation required, not what running the result requires. Those two numbers get conflated constantly in coverage of local AI, and conflating them is how people end up believing self-hosting is out of reach when the inference side has quietly become ordinary.
There is a catch, and it is the big one. The weights are not public. The download link currently sends people to a page asking them to contribute training data, which is a direct consequence of the OpenAI bans: having been cut off from distilling someone else’s model, he is asking his audience to donate the raw material instead, rather than harvesting it from Odysseus users. As a privacy stance that is genuinely better than the alternative. As a release it means Ajax is an announcement rather than a thing you can download today.
Why this one landed harder than the usual open-source release
Locally runnable models are not new. Llama, Mistral and Qwen have served this niche for years, and the people already self-hosting did not need a YouTuber to tell them about it.
What is new is the size of the door. Kjellberg has north of 110 million subscribers. A single video from him puts self-hosted AI, quantization, model licensing and the politics of training data in front of a mainstream consumer audience that open-weight projects have never been able to reach. Whether or not Ajax turns out to be any good, that reach is the actual event.
It also fits a pattern he has been building for a while. He has talked about disabling YouTube Shorts, unfollowing everyone on social platforms and running a DNS-level ad blocker, framing it as building a “tech fence.” His line was blunt: “These tech companies don’t care about you, so you’ve got to care about yourself.” A privately hosted model with no cloud dependency is the logical endpoint of that argument rather than a detour from it.
He is not alone among large creators in deciding the platforms need pushing back on. The same week, Marques Brownlee went public with a detailed objection to YouTube’s next big feature and said its engineers had no answer for him. Creators with audiences that size have started treating platform decisions as something to negotiate rather than absorb.
The timing is also unhelpful for OpenAI, which is fighting this battle on several fronts at once. Regulators are already circling: the FTC has an open inquiry into OpenAI and Anthropic over agent behavior. And the company is doing all of this while under the kind of financial scrutiny that comes with a widely expected listing, the prospect of which has investors like Michael Burry openly betting against the whole structure. Enforcing a terms-of-service clause against a popular YouTuber is legally sound and reputationally expensive, and the second ban guaranteed the story got told.
What to watch next
- Whether the weights ship. Until they do, nobody outside his testing can verify the 90% task completion claim or check what the decensoring actually did
- Benchmarks from third parties. Abliterated fine-tunes often lose capability. Comparing Ajax against stock Qwen3.5-9B is the test that matters
- What the data donation page collects, how it is stored, and whether contributors can withdraw
- Whether OpenAI says anything. The company has not commented publicly, and the bans are consistent with its published terms either way
- Licensing friction. Qwen’s license, the AGPL on Odysseus and a model trained partly on another provider’s outputs make for a tangle that has not been tested
- Whether anyone else follows. If a creator this size can build a usable local assistant, the interesting question is how many smaller ones try next
The bottom line
The headline is a ban story, and the ban story is the least surprising part. Distillation breaks OpenAI’s terms, he did it, he said so on camera, and the company enforced the rule. Nobody was ambushed.
What is worth paying attention to is the thing underneath. A 9-billion-parameter model, quantized, running entirely on a machine someone already owns, driving a workspace that touches their email and calendar without any of it leaving the house, is a genuinely different model of how this technology can be used. That architecture existed before Ajax and will outlast it.
The release itself is not finished. No public weights, a decensoring pass he has already said he wants to redo, and a training data pipeline that currently depends on fans volunteering material. Treat the 90% figure as a claim from an interested party until someone else can check it.
But the question he asked on camera is the one that will outlive the news cycle, just not in the way he meant it. He wanted to know how OpenAI spotted him. The more durable version is why learning from a model’s output is theft when learning from the web was progress, and so far nobody has given an answer that satisfies both sides.
Sources and further reading
- UNILAD Tech: OpenAI banned PewDiePie twice while he was secretly building his own AI
- Tom’s Hardware: PewDiePie unveils “uncensored” Ajax AI model built to run on home PCs
- TechJuice: Ajax, the Heretic decensoring step and the 10-GPU development rig
- Ground News: Coverage comparison of the Ajax launch
- OpenAI terms of use, including the restriction on developing competing models
- Qwen, the Alibaba model family Ajax is fine-tuned from
About this article: GeekBlog covers U.S. technology news, AI, phones, smartwatches and gaming. Every story is written and checked under our Editorial Policy. Spotted a mistake or have a story tip? Contact our editors.

