Product1 distinct publisher3 min readUpdated
Ox Alpha arrived on OpenRouter free with a million-token window, and OpenRouter says the unnamed provider retains prompts and completions. Coding teams are using it anyway.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The capacity number is the part worth arithmetic. OpenCode put the provider's headroom at 100 trillion tokens a day [3]. That is about 1.16 billion tokens every second [10], or roughly 100 million complete fills of the advertised million-token window in a single day [11]. Someone is covering the inference bill for that and charging nothing for a week [3].
The listing's wording repays a slow read. The assurance is that retained prompts and completions are not used for training [2]. Training is the whole of the promise. Retention period, access control and storage location are not addressed, and there is no counterparty to ask, because the provider has not said who it is [1].
That gap is where the compliance problem sits rather than in model quality. European data protection law wants a contract with a named processor and an assessment of where the data ends up, and an anonymous supplier can satisfy neither [7]. The attribution guesses do not help: the leading theory names Z.ai, which has form here after testing GLM-5 anonymously under another name, while a tokenizer analysis points instead at Microsoft's MAI family [5]. Those two answers imply different places for your source code to land. The AI analyst Andrew Curran, writing over the weekend, said people seemed "less sure of anything" than they had been the night before [6].
The regulatory clock is already running. The AI Act's transparency obligations took effect on 2 August, with penalties reaching 15 million euros or 3 percent of global turnover [8]. The 3 percent limb only overtakes the fixed figure above about 500 million euros of turnover [12], so for most firms using this thing the binding exposure is the flat cap, and the regime it belongs to is built on knowing which provider is responsible for what [8].
Meanwhile the adoption is real and the reviews are good. Stripe's chief executive Patrick Collison called Ox Alpha "very impressive", and it is pitched at coding, long-horizon agent work and production use [4]. The model is being tried across the industry despite nobody taking credit for it [14]. TNW's own read is that a stealth launch is a legitimate way to benchmark before announcing, since open-weight releases have closed the capability gap faster than the safety one [13], and that the sensible European position is to test it with nothing that matters [9].
Strip out the mystery and the transaction is legible enough. An unnamed party is buying a very large sample of real engineering prompts, at a price it has chosen to pay in compute, and the only published term of the deal is that it keeps what arrives [2][3]. Free capacity of that size has to be worth something to whoever provisioned it, and the retention line is the only clue on offer as to what.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The open-source agent OpenCode said the model would be free for a week with near unlimited usage, and that its provider had capacity for 100 trillion tokens a day.
An anonymous model called Ox Alpha appeared on OpenRouter last Thursday as a stealth release from an anonymous third-party provider, free to use, with a context window of just over a million tokens.
OpenRouter's own listing states that prompts and completions "are retained by the provider and are not used for training."
Stripe's chief executive Patrick Collison tried the model and called it "very impressive", and it is positioned for coding, long-horizon agent work and production use.
Data protection law requires a contract with a named processor and an assessment of where data goes, neither of which is possible when the counterparty is anonymous.
The AI Act's transparency obligations took effect on 2 August, with penalties reaching 15 million euros or 3 percent of global turnover, in a regime built on knowing which provider is responsible for what.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet, but anchored in quotable artifacts
One publisher carries the whole cluster, yet the load-bearing facts are verifiable artifacts rather than unsourced assertion: the quoted OpenRouter listing text, OpenCode's stated terms, a named executive's reaction and a named analyst's comment. What is missing is independent confirmation of capacity, any benchmark result, and any provider identity, and two of the article's framing claims (industry-wide testing, the capability-versus-safety-gap assertion) carry no supporting data.
Live and reachable, usage largely anecdotal
The model is genuinely deployed and reachable: it is listed on OpenRouter, integrated into an open-source agent with stated free-week terms, and tried by a named executive. But there are no traffic figures, no named production deployments and no benchmark placements, and the free window is described as a week, so observed adoption is early experimentation rather than committed use.
Provider-side claims outrun verification
The article itself is cautionary rather than promotional, so the gap sits in the claims it relays: a 100 trillion tokens a day capacity figure (about 1.16 billion tokens per second) attributed to an agent project and never independently checked, capability praise resting on one executive quote, and confident attribution theories that the story concedes have collapsed. Positive but modest, because the load-bearing compliance facts are quoted verbatim and the piece explicitly discounts its own capability framing.
Undisclosed party subsidising data-retaining inference
The incentive structure is unusually legible even though the actor is not: an unnamed provider is giving away large-scale inference on terms that retain prompts and completions, which converts free access into an information transfer, and the story notes stealth launches are used to benchmark before announcing. Secondary incentives include an open-source agent promoting near-unlimited free capacity to its users, and a publisher whose framing lands on a European compliance stance.
Facts thin, central actor unknown
Confidence is limited by structure, not by contradiction: one publisher, no identified provider, competing attributions that the cited analyst says are weakening, and a time-boxed free window that may have changed since publication. The compliance implications are the most durable part of the assessment because they follow from the quoted retention terms regardless of who the provider turns out to be.
build
A million-token stranger on OpenRouter, and 30 of 30 tokenizer matches with GLM-5.31 distinct publisher
invest
Pick a side: Washington's draft AI letter turns model sourcing into a compliance problem1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 22, 2026