PewDiePie Banned by OpenAI Twice: What Distillation Is and What Ajax Has to Do With It
PewDiePie got banned by OpenAI. Twice. The biggest individual YouTuber on the planet decided to train his own AI model, Ajax, and lost his account along the way.
The reason, according to PewDiePie himself, was spelled out in the email: distillation. He used the output of an OpenAI model to build the training data for Ajax, a local 9-billion-parameter model that runs on a consumer graphics card.
In this post you'll see what actually happened in the PewDiePie vs. OpenAI case, what model distillation is, how OpenAI detects the pattern (it published a report on exactly this two days earlier), what's inside Ajax, and where the line sits between legitimate synthetic data and a ban on your account.
TL;DR
- What happened: PewDiePie says OpenAI banned his account, restored it after an appeal, and banned it again. One of the emails cites "distillation".
- The model: Ajax, a fine-tune of Qwen 3.5 9B built for Odysseus, his self-hosted AI workspace. Refusals removed with Heretic.
- Cost/Access: weights not published yet. The official page says "coming soon", with no license defined.
- Why it matters to you: generating training data with a third-party API is the same activity that took down his account. And detection has gotten a lot better over the last few months.
What happened: PewDiePie banned by OpenAI twice
Felix Kjellberg unveiled Ajax this week. It's a model he tuned to run inside Odysseus, the self-hosted environment he's been building: interface, memory, files, email, calendar, agents.
To train it, he needed seed data. High-quality examples of a strong model solving tasks. And he went to OpenAI to get them.
The sequence, according to Tom's Hardware and the Free Press Journal:
- OpenAI banned the account. One of the emails explicitly cites "distillation".
- He appealed. The account came back.
- He ran the process again to generate the seed data. Second ban.
His reaction to the second one: "How did they even know?"
Two caveats before moving on. First: all of this is his account of events. OpenAI hasn't commented on the case publicly. Second: the story going around on X is that the distilled model was GPT-6.1 Sol and that he used a trick to read the hidden reasoning. The coverage I read talks about "an OpenAI model" and "a method he found to extract more information", without naming the model. Treat that detail as unconfirmed.
What model distillation is (and why the reasoning is worth more than the answer)
Distillation is training a smaller model, the student, on the outputs of a larger model, the teacher. You send thousands of tasks to the teacher, save the responses, and use that material as the student's training dataset.
It's an old, legitimate technique. Every lab does it with its own models. That's how a "mini" model gets made from a big one.
The trouble starts when the teacher belongs to another company.
OpenAI's terms of use prohibit two things that, together, describe this pipeline exactly: extracting output in an automated way, and using that output to develop models that compete with theirs. It doesn't matter whether you're a Chinese lab with 15,000 accounts or a YouTuber with one.
And there's one more layer. A model's final answer teaches the student to get things right. The intermediate reasoning, the chain-of-thought, teaches the student to think. That's why labs hide or encrypt that part. And that's why anyone distilling goes after it.
This is the kind of thing that separates using AI from building with AI: people who only consume an API never had to know where a training dataset comes from, and people who train models run into licenses, terms of use, and detection in the first week. That second group is who we work with at Clã Beer and Code, and it's paid, it's a subscription, no beating around the bush.
How OpenAI knew: the report published two days earlier
PewDiePie's question has an answer. And it came out on September 30, when OpenAI published Disrupting a coordinated model-distillation campaign.
The numbers from the report, as summarized by The Hacker News:
| Data point | Value |
|---|---|
| Activity began | July 1, 2026 |
| Peak | July 24 and 25: 16,000 requests from more than 4,000 users |
| Accounts mapped to the pattern | more than 15,000 |
| Campaign shut down | July 28 |
| Attribution | a "core" tied to people associated with Moonshot AI, the maker of Kimi |
The technique is the interesting part. Nobody broke encryption or breached a database. The operators took the encrypted reasoning from one conversation, injected it into another, and asked the model to decode and repeat it. What was supposed to stay hidden came out readable.
OpenAI says it closed that replay path and added checks to detect the pattern in streaming output.
Now put the two stories together. OpenAI spent the quarter building a reasoning-extraction detector because of an industrial-scale campaign. The detector doesn't ask how many subscribers you have. An individual pipeline that repeats the same prompt pattern gets caught in the same net.
It's not just OpenAI. In September, Anthropic accused the same Moonshot of relaying Claude requests and retaining the exchanges to train its own model. We'd already covered the geopolitical side of this when the US threatened to sanction Chinese open source AI.
Do not just follow the news — master it. Hands-on AI Engineering, live, every week, in the largest community in Brazil.
Join the ClãInside Ajax: Qwen 3.5 9B, GRPO and 11 GB of VRAM
What's known about the model, according to Popular AI and the official page:
| Item | Detail |
|---|---|
| Base | Qwen 3.5 9B |
| Training | supervised fine-tuning + reinforcement with GRPO on Odysseus tasks |
| Dataset | successful Odysseus traces: documents, email, notes, calendar, search, files |
| VRAM | about 22 GB in BF16, 11 GB in FP8; quantized should need less |
| Context | 262,000 tokens (inherited from Qwen 3.5 9B) |
| Role | always-on agent: search, browsing, email and calendar, running locally |
| License | not defined |
On performance, the only number is his: an early version completed the task "about nine out of ten times". That's not a reproducible benchmark. There's no independent evaluation.
The architecture of the idea is good, and it's worth separating that from the drama. A small model, specialized in a closed set of tools, trained on real traces from its own environment. It's the rare case where fine-tuning makes sense, as we discussed in fine-tuning, RAG or prompt. The problem wasn't the training. It was where part of the data came from.
What Heretic does
Ajax ships with refusals "ablated". The tool used was Heretic, which is open source.
It isn't a prompt jailbreak. It's surgery on the weights. Heretic identifies, in the internal activations, the direction associated with refusal behavior and alters the weights to neutralize it. What sets it apart is automating the tuning: an optimizer searches for the parameters that minimize both the number of refusals and the divergence from the original model at the same time.
In practice: the model stops saying "I can't help with that" and keeps behaving almost the same everywhere else.
What this changes in your pipeline
You're probably not going to train a 9B model this week. But there's a good chance you already generate synthetic data with a third-party API: an eval dataset, few-shot examples, data to train a classifier.
Where the line sits:
| Activity | Risk |
|---|---|
| Generating test cases for your eval | low |
| Generating examples for an internal intent classifier | low to medium; read the terms of your plan |
| Mass-generating question/answer pairs to fine-tune your own LLM | high |
| Trying to extract the model's hidden reasoning | that's what got him banned |
| Doing any of the above through a consumer account, with automation | even worse: consumer terms are the most restrictive |
Three practical rules:
- Separate the account. A data generation pipeline doesn't run on the same account, or the same key, as your production product. A ban on one can't be allowed to take down the other.
- Use an open-weights teacher when the destination is training. A Qwen, DeepSeek or Kimi running locally has no terms of use that prohibit distilling. The model's license is what counts. If you've never spun one up, start with the step-by-step guide to running a local LLM.
- Keep the provenance of every example. If you ever publish or sell the model, someone is going to ask where the dataset came from.
Limitations and things to watch
The story has a single source. The account of the bans is PewDiePie's. OpenAI has confirmed neither the reason nor the method.
There's no model to test. Until the weights are out, any claim about Ajax's quality is marketing. One of the sources mentions a release on the night of October 2, Brasília time. The official page doesn't promise a date.
A refusal-free agent with access to your email is attack surface. A model that refuses nothing, reading web pages and touching your calendar, is the textbook scenario for prompt injection. Model refusal was never a sufficient defense, but removing that layer means compensating with permissions and sandboxing. It's the same tension that showed up when Kimi K3 fixed bugs that Codex and Fable refused.
No license, no commercial use. A fine-tune inherits the base model's license and still depends on whatever license the author puts on top. Right now there isn't one.
Quick FAQ
What is PewDiePie's Ajax? It's a fine-tune of Qwen 3.5 9B built to operate Odysseus, his self-hosted AI workspace. The pitch is an always-on agent that handles search, email and calendar running on your machine, without sending data to the cloud.
Why did OpenAI ban PewDiePie? According to him, for distillation: using the output of an OpenAI model to train another model. The terms of use prohibit automated extraction of output and using that output to develop competing models. OpenAI hasn't commented on the case.
Is distillation illegal? It isn't a crime in itself. It's a breach of contract when the provider's terms prohibit it, and the practical consequence is an account ban. Distilling an open-weights model, while respecting its license, is allowed.
Can you run Ajax on a 12 GB card? Going by the published numbers, the FP8 version needs about 11 GB of VRAM, so it's right at the limit. Quantized versions should fit comfortably, but they haven't been published yet.
Conclusion
The case is fun to tell: a YouTuber training a model at home and getting banned by a trillion-dollar lab. But the useful part is something else. The labs cracked down on reasoning extraction in 2026, and the same detection that caught a 15,000-account campaign catches a script running on a single account.
The next step in this fight is predictable: more hidden reasoning, more pattern detection, and more people moving the teacher role over to open-weights models.
If the idea of training your own model got you excited, first read the guide to fine-tuning and when not to use it. In most cases, you don't need it.
{AI Engineer} — apaixonado por Laravel, arquitetura de software e construir produtos com impacto. Compartilho aqui tutoriais, descobertas e reflexões sobre o dia a dia de engenharia.
There is no shortage of content. What is missing is someone to untangle it: what matters now is how to implement it the right way. In the Clã you get that live, every week, with people who have already filtered out the noise.
Join the Clã