Product1 distinct publisher2 min readPublished
The anonymous GLM model more than doubled DeepSeek's usage while researchers, not the maker, worked out who built it. Chinese labs are treating nameless launches as a repeatable tactic.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The tactic reads as cheap insurance. A lab that withholds its name gets to watch a model perform in the open before it commits to a story about it, and it collects about a week of free publicity along the way [8]. Patrick Collison, whose Stripe is acquiring OpenRouter, called the stealth release very impressive [7]. What CTGT turned up complicates the innocent version: Ox Alpha shipped with a system prompt instructing it not to reveal any information about its provenance [14]. That is an instruction written into the product, not a company declining to comment in public.
The anonymity was fragile for a mundane reason: a model leaks its lineage through its plumbing. CTGT counted tokens across eleven probes and matched all eleven to the GLM-5.x vocabulary [11]. The temperature ceiling sat at exactly 1.0, which excludes Google, OpenAI and xAI and fits Zhipu's documented range [12]. Z.AI-hosted GLM models return a distinctive error about incorrect role information, and so does Ox Alpha [13]. None of that required a leak or a press release.
The more useful correction is about censorship. The number that travelled, that Ox Alpha is roughly six times less censored than DeepSeek, misreads the data, and CTGT says so plainly: the model is not less censored, it keeps a blacklist [19]. Seven topics account for almost the entire censorship score, and the other 68 matched pairs contribute effectively nothing [17]. On Xinjiang and Taiwan it answers like an American model [15]; on Xi Jinping personally and on domestic legitimacy it is statistically indistinguishable from DeepSeek V4 Flash, the most censored model CTGT has tested [16]. DeepSeek shades nearly everything, including where the effect is mild [18]. One is a tilt across the board; the other is a switch on a short list.
That short list is what the weights carry into the wild. Open weights mean anyone can adjust the parameters [21], and Zhipu's founder Tang Jie has argued that frontier AI should stay open to everyone [20]. A week of chart position is attention; released weights are permanent, and so is whatever anyone downstream chooses to do with the blacklist.
Ranked by verification strength, evidence, and original report placement.
CTGT's conclusion is that the headline reading, that Ox Alpha is around six times less censored than DeepSeek, gets it wrong: the model is not less censored, it has a blacklist.
Open weights mean anyone can adjust the model's parameters.
Zhipu confirmed on Wednesday that Ox Alpha is a new iteration of its GLM series and said it would release the weights the same night.
Ox Alpha appeared on OpenRouter with no name attached, listed only as coming from a third-party provider.
Ox Alpha went to the top spot on OpenRouter, more than doubling DeepSeek's use.
Patrick Collison, whose company Stripe is acquiring OpenRouter, called the stealth release "very impressive".
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed technical audit, but relayed through one outlet
The provenance case is specific and falsifiable - an exact 11-of-11 tokenizer match, a 1.0 temperature ceiling, a shared error string - and it is corroborated by the maker's own confirmation, which is the strongest possible check on the fingerprint. The censorship structure is quantified (seven topics carrying the score, 68 matched pairs contributing nothing, 76 sensitive responses, five in official register). Against that: the cluster has a single publisher relaying Bloomberg, CTGT and New York Times work, CTGT's instrument is unreplicated, one probe was unstable on repeat, and the piece itself notes conflicting first-appearance dates (weekend versus 20 August).
Chart-topping usage plus an actual weight release
Adoption is unusually well grounded for a days-old model: top position on OpenRouter, more than double DeepSeek's usage, described as the marketplace's largest launch, followed by a stated same-night weight release. A prior generation of the same family already saw operational use, with Hugging Face turning to GLM 5.2 during its July incident response. The discount is that usage was pulled by a free tier whose post-promotion pricing is unstated, so durability is unproven.
Slightly overstated, mainly in the framing it inherits
The dominant public reading - Ox Alpha as 'roughly six times less censored than DeepSeek' - is overstated, and the cluster's own value is that it corrects it: the restriction is a narrow domestic-politics blacklist, not a general loosening. The residual overstatement is in generalisation and in the 'stealth is now a launch strategy' thesis, which rests on three examples (Zhipu, Alibaba, Xiaomi) and on a single unnamed-launch outcome; likewise the concealment system prompt is presented as a settled fact on one unreplicated audit. Adoption evidence is strong enough that the core story is not inflated.
Every named actor has a stake in the framing
The story is dense with interested parties. Zhipu gains a week of unattributed publicity and reputational cover from an anonymous launch, and ships weights consistent with a stated open-AI position that also builds distribution against US incumbents. CTGT, a research firm, benefits commercially from being the outfit that names anonymous models and sells a censorship instrument, and the source discloses no such interest. Patrick Collison praises the launch on the marketplace his company is acquiring. CrowdStrike's chief executive, whose firm advised OpenAI after the Hugging Face breach, argues the security-watershed line, while a testing-firm founder and an academic argue the calmer case.
Core facts firm, interpretation single-sourced
Confidence is high on the identification and on adoption, because the maker confirmed the former and marketplace ranking supports the latter. It is materially lower on the censorship interpretation and the tactic thesis, which come from one unreplicated audit relayed by one publisher, include one acknowledged unstable test, and carry an unresolved discrepancy over when the model first appeared. Pricing and Zhipu's response to the findings are absent.
product
A 27B laptop model scores like a rented one, and thinks three times as hard to do it1 distinct publisher
invest
Z.ai's 0.7-point CyberGym lead is a self-graded number on a model that is not yet open1 distinct publisher
build
Ox Alpha passes the Xinjiang test and fails on Xi: seven topics, 83 points apart1 distinct publisher
science
GLM-5.3 says the quiet part: the base model did not change, the post-training did1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026