Felix Kjellberg, known online as PewDiePie, says OpenAI suspended his account twice while he was developing Ajax, a locally run AI model built on Alibaba’s Qwen3.5-9B. OpenAI has not issued a public statement confirming the individual case; the ban details come from Kjellberg’s own video, where he reportedly displayed a suspension email citing “distillation” as the cause.
The announcement lands as open-weight models make local AI agents increasingly practical for PC owners who want more control over their data.
What Ajax and Odysseus Actually Do
Ajax is a fine-tuned version of Alibaba’s Qwen3.5-9B, built to operate on consumer hardware inside Odysseus, an always-on agent harness for web search, browsing, email, and calendar management. Key technical details:
- Base model: Alibaba Qwen3.5-9B, fine-tuned by Kjellberg
- Refusal reduction method: automatic abliteration via the open-source Heretic tool
- Intended tasks: web search, email, calendar, and browsing, processed locally
- Planned next steps: additional reinforcement learning, a second decensoring pass, quantization, and benchmarking
- Safety framing: Kjellberg stated Ajax is not designed to provide dangerous actionable instructions
A 9-billion-parameter model is substantially smaller than frontier systems, which makes local deployment plausible, particularly after quantization. Performance will depend on your hardware capabilities, and no independently verified benchmarks have been published yet.
The OpenAI Bans and the Distillation Question
According to Kjellberg’s video, OpenAI suspended his account after detecting distillation: a process where a smaller model is trained using outputs generated by a larger one, learning from those responses rather than from the larger model’s architecture directly. His account was reportedly restored after an appeal, then suspended again when he ran the model to generate seed training data.
Kjellberg questioned whether distillation differs meaningfully from using publicly available material to train a model. That reflects his position; OpenAI’s terms explicitly restrict using its outputs to train competing models, and that contractual question is separate from his comparison.
What “Uncensored” Actually Means Here
“Uncensored” in this context means reduced refusal behavior, not unrestricted output. Kjellberg used Heretic’s automatic abliteration to modify the model’s internal directions associated with refusals, without fully retraining the system.
He said he wanted to avoid what he called “brain damage,” meaning the risk of degrading general capability while removing safety guardrails, and stated Ajax was not built to generate dangerous actionable instructions. Chatbots that exhibit unexpected behavior around refusals have drawn broader scrutiny, and assessing the actual safety boundaries requires access to the model, its system prompt, and reproducible testing that has not been published.
Local Does Not Automatically Mean Private
Running Ajax on your own hardware keeps data off cloud servers by default, but local execution alone does not close every privacy gap. Email, calendar, and browser integrations can still expose sensitive information through misconfigured permissions, tool servers, or network connections.
Kjellberg asked viewers to donate training data rather than collecting it directly from Odysseus users; at announcement time, no submissions had arrived.
The trade-off Ajax represents is straightforward. You gain control over your data and independence from platform-level decisions about what your AI will or will not do. In exchange, you take on responsibility for security patches, data handling, and safeguards that cloud providers currently manage on your behalf. Those evaluating AI-Powered Websites as an alternative may find cloud-based tools offer a different balance between convenience and control.




























