Here is how the AI industry’s business model works, at the moment. Companies like OpenAI spend vast sums training enormous models, then rent you access to them by the month and by the token. The terms of that rental include — reasonably enough, from their perspective — a rule that you may not use the model’s outputs to train a competing model. That rule is doing a lot of work, because one of the cheapest ways to make a small free model smarter is to ask a big expensive model a million questions and train the small one on the answers. This is called distillation, and it is, contractually speaking, the one thing you definitely cannot do with your ChatGPT subscription. OpenAI’s terms explicitly restrict it.
Felix Kjellberg — PewDiePie, the YouTuber — appears to have done it anyway, or something like it, twice. According to his own video, Kjellberg says OpenAI suspended his account for distillation violations while he was building Ajax, a locally run AI model. He reportedly displayed a suspension email citing “distillation” as the cause; his account was restored on appeal, and then suspended a second time when he ran the model to generate seed training data. OpenAI has not publicly confirmed the individual case, so all the ban details are Kjellberg’s account. But the basic shape of the story — man builds open-source AI, gets jettisoned from proprietary AI platform for using it as a teacher, finishes the project anyway — has the pleasing symmetry of a folk tale about the commons.
The end product is Ajax, which is worth describing precisely because the description is funnier than any joke about it. It is a fine-tune of Alibaba’s Qwen3.5-9B — a 9-billion-parameter open-weight model, genuinely small by frontier standards — built to run on consumer hardware inside Odysseus, an always-on agent harness Kjellberg built to handle web search, browsing, email and calendar. Planned next steps include more reinforcement learning, a second “decensoring” pass, quantization and benchmarking. No independently verified benchmarks exist yet. So it is a personal AI butler, trained partly on the output of a much smarter AI whose landlord kept evicting its student, running on a gaming PC.
About the uncensoring
The other notable feature is that Ajax is deliberately de-refused. Kjellberg used an open-source tool called Heretic to perform “automatic abliteration,” a technique that modifies the internal directions in the model associated with refusals, without fully retraining it. “Uncensored” here means reduced refusal behavior, not a model that will do anything. Kjellberg said he wanted to avoid “brain damage” — his term for degrading the model’s general capability while ripping out its guardrails — and says Ajax was not built to produce dangerous actionable instructions. Assessing whether that’s true would require model access, the system prompt and reproducible testing, none of which has been published.
Kjellberg, for his part, questions whether distillation is meaningfully different from training on publicly available material — if the big models learned from the open internet, why can’t the small models learn from the big ones? This is a genuinely interesting philosophical position and also, one should note, contractually beside the point: OpenAI’s terms restrict using its outputs to train competitors, whatever one thinks of the ethics of web scraping. The companies that trained on everything the internet ever published would now like to prevent you from training on the thing they trained on everything the internet ever published. You can see why. It’s their most valuable output.
The pitch for running your own model is data control — your email and calendar stay off someone else’s cloud — though “local” is not a synonym for “private”: an always-on agent wired into your email, calendar and browser can leak through misconfigured permissions or tool servers just as well as it can through a data center, and now the security patching is your job too. You get independence from platform decisions about what your AI will and won’t do, in exchange for taking responsibility for everything the platform used to handle. Kjellberg, incidentally, has asked viewers to donate training data rather than hoovering it from Odysseus users; at announcement time, nobody had sent any. Building the commons turns out to be lonely work. At least he has a poster-child story about why the platforms can’t be trusted — he was banned twice for it.
