The Model With No Name
80 percent against 65 and 52 — a free coding model with no author, no company and no terms you would sign beat both of the models we actually pay for. Three days after it appeared, trillions of tokens of real production work were already flowing through it. The capability is real. The flock is the problem.

On 20 August a model called Ox Alpha appeared on OpenRouter. Reasoning-grade, built for coding and long-horizon agent work, a million tokens of context, a hundred and thirty thousand out. Free.
Nobody knows who made it. That is not an oversight, it is the product. OpenRouter's stealth program lists models from providers who have chosen anonymity for a preview window, and OpenRouter states plainly that it is not the developer, owner or provider. It only routes.
I want to be careful here, because the temptation for an operator like me is real. A frontier-class coding model, free, with a context window that swallows a whole repository, is exactly the thing you want to point at your hardest work.
The capability is not the hype part
This is where most warnings lose the room, because they arrive attached to something mediocre. Not this time.
On an independent run of ten DeepSWE-style engineering tasks, Ox Alpha scored 80 percent. Claude Fable 5, the model that chairs our own review process, scored 65. GPT-5.6 scored 52. On one Meriyah resource-declaration task it passed first attempt, where the established models went nought for four. It cleared a 51,469-test regression suite without a failure.
Hold that number of tasks in your head, because it matters: ten. One tester. Not a controlled evaluation. Directionally interesting, not decisive, and I will not pretend otherwise. Different scoring frameworks, small samples, no audit. There is a dissenting read out there too, from an evaluator who ran it and called it roughly two generations behind.
So the honest position is that the evidence is strong, early, contested, and unresolved.
Now watch what the market did with that.
The flock
It did not wait.
Zed wired it in. Nous Research's Hermes agent wired it in. Routing platforms wired it in. On OpenCode's usage tracker it ranked third for the week at 7.1 trillion tokens, about two percent of all observed volume, and the platform said it had capacity for a hundred trillion tokens a day during the window. It was carrying live production traffic on day one.
Trillions of tokens of real work, from real companies, on real codebases, routed to an entity with no name — before anybody could agree on whether the thing was even good.
That is the mechanism I want operators to see clearly, because it is not a story about one model. Free plus fast plus frontier-shaped is the strongest gravitational pull in this industry, and it moves faster than diligence can. Nobody in that flock made a reckless decision. Each one made a small, sensible, individually defensible decision, and the sum of those decisions was trillions of tokens of proprietary work handed to an unnamed counterparty inside seventy-two hours.
The flock is not made of careless people. It is made of busy ones.
Read the contract, not the label
Here is what those tokens actually bought.
The model page carries a reassuring line: prompts and completions are retained by the provider and are not used for training.
The Stealth Model Terms governing that same model grant a non-exclusive, irrevocable, perpetual, transferable, worldwide, fully paid-up, royalty-free licence to use your content to train, evaluate and improve stealth models, and to distribute and sublicense that content to the stealth providers. The terms state outright that access is free in exchange for content collection.
Those two statements are not compatible. Nothing published reconciles them. And when a friendly sentence on a product page disagrees with an irrevocable licence in the governing agreement, the licence is the thing with force behind it.
The mitigation offered is that content reaches the provider with a hashed identifier, so the individual user is not identifiable. Read that carefully too. It protects who you are. It does nothing for what you sent. Prompts carry client names, customer records, credentials and proprietary source, and the hash touches none of it.
Free was never the price. Your work was the price. That is not a scandal, it is the stated business model, printed where almost nobody in that flock read it.
The forensics, and why they do not rescue it
The community has done real work on the authorship question. Independent testers matched the tokenizer thirty out of thirty across English, Chinese, code and emoji against Zhipu's GLM-5.3, with a constant offset. A malformed request returned a Java stack trace consistent with Zhipu's serving layer. The error dialect matched. One researcher puts it at 99 percent.
Zhipu has neither confirmed nor denied. So the honest label is unconfirmed, and unconfirmed is where it stays.
Notice what that means. Even the best available answer is a guess, and any operator routing work through it is building on a guess about who is on the other end.
And this shape repeats. Every OpenRouter stealth model so far has eventually been attributed. Quasar Alpha and Optimus Alpha turned out to be prerelease GPT-4.1. Hunter Alpha and Healer Alpha turned out to be Xiaomi, after the community confidently guessed wrong. In every case the name arrived after the free window had already collected the traffic. The anonymity is temporary. The harvest is permanent.
The part that actually matters
Here is where I part company with the usual security lecture, because the compliance argument is the small half of this.
I have said for a while that we are not building AI so much as raising it. You cannot control something more intelligent than you are. Anyone who tells you otherwise is selling a control panel that will not hold. What you can do is what any parent does with a child who will one day be stronger and smarter than they are: teach it early, explain the reasoning rather than issue bare rules, and build a relationship where trust runs in both directions. You are not fitting a leash. You are instilling an ethos and hoping it holds when you are no longer in the room.
Which is why authorship is not a bureaucratic detail. It is the entire question.
In January, Anthropic published Claude's constitution, an eighty-odd page document setting out a priority order of safety, ethics and helpfulness, explaining the reasoning behind each rather than issuing commandments, released publicly so anyone can read it, argue with it, or take it. You do not have to agree with a word of it. You can read it. You know who wrote it, and you can hold them to it.
The provider behind Ox Alpha will not publish its name.
You cannot audit values that have no author attached. That is the asymmetry, and no benchmark score resolves it. A model that codes better than the alternatives and answers to nobody is not a bargain. It is an unpriced liability having a very good first quarter.
Where we landed
We will benchmark it. On public code, in a sandbox, never in an unattended lane, and never with a client's context or our own private work anywhere near it. Measuring a thing is not the same as trusting it, and refusing to measure it out of caution is its own kind of blindness.
It does not get wired into anything. Not the council that reviews our code, not the agents that touch client work, not one production path. The rule we run on is short enough to say out loud: nothing that sees our data may be a party we cannot name.
The long game in AI is not who ships the best model this quarter. It is which values end up baked into the intelligence that outlasts all of us, and who was willing to put their name on them. Every time real work gets routed through an anonymous provider because it was free and it was good, that is a vote that anonymity is acceptable.
The flock always moves before the argument is settled. The whole discipline is in not moving with it.
I share ideas, lessons, and practical insights from my work.






