There is a recurring shape to how a technology acquires its moral mythology. First a capability appears. Then a boundary is drawn around it — by a company, a state, a guild, a church. Then someone crosses the boundary and is punished for it. And in the retelling, the punishment becomes the proof of the capability's importance. The printing press acquired its heretics. Peer-to-peer file sharing acquired its subpoenaed teenagers. Cryptography acquired Phil Zimmermann, who published PGP in 1991 and spent years as the subject of a criminal investigation for it. Each of these stories was, at the factual level, messier than the myth; and each of them, at the mythic level, permanently changed what the technology meant.
In the early weeks of 2026, artificial intelligence acquired its most improbable martyr yet: a Swedish man best known for screaming at video games.
The claim arrived as a dispatch so thin it barely qualified as a news item. Felix Kjellberg — PewDiePie, whose channel carries more than a hundred million subscribers — told his audience that OpenAI had banned his account, twice; that he had been training a model of his own; that the model was called Ajax; and that Ajax was uncensored and ran on his own computer. That is the entire factual surface. There is no OpenAI statement in the record. No repository. No weights. No license. No parameter count. No independent confirmation that Ajax exists as anything more than a name attached to a claim.
And yet within days the story had done what stories like this always do. It hardened into a symbol. And the symbol was about freedom.
Why should anyone in this industry care about a YouTuber's account status? Because the argument the story is being recruited into is our argument. The vocabulary of the dispatch — banned, uncensored, local, your own computer — is the vocabulary of self-custody, permissionless access, and credible exit. It is the same sentence structure that has been used for a decade to sell the idea that control over a system should belong to the person running it. When that sentence is spoken about a hundred-million-subscriber creator and a model, it becomes a stress test for a set of claims this industry makes constantly and verifies rarely.
So before anything else, let me do what I have done at the top of every report since 2017: a narrative audit. Not a technical audit — those come later — but a check of whether the story's internal logic holds together on its own terms, independent of whether its facts can be confirmed.
The audit fails on three counts.
First, the story has a single source. Every load-bearing claim traces back to the person the story benefits. This is not an accusation of dishonesty; it is a statement about evidentiary structure. A narrative with one source has no error correction. It can only amplify.
Second, the story omits the counterparty. OpenAI has said nothing. That silence is not evidence of guilt or of innocence — it is evidence that the record is incomplete, and a complete record is precisely what a narrative like this does not need.
Third, and most tellingly, the story omits the cost side entirely. Uncensored is presented as an unalloyed good. It is not. It is a trade, and like every trade it has a price, and the price is never mentioned.
I learned this discipline the hard way. In 2017, in Madrid, I spent four months reading forty-five initial coin offering whitepapers for a boutique research firm. I had a computer science degree and everyone assumed I would audit the code; instead I audited the sentences. I was looking for philosophical coherence — whether a project's stated purpose, its token mechanics, and its claimed user actually described the same world. Eighty percent of them did not. The report I published was called "The Hollow Promise," and its central finding was not that the projects were fraudulent. It was that they were narratively incoherent, and that incoherence is a leading indicator of collapse. Utility tokens without use cases did not fail because the market turned. They failed because there had never been a story that could survive contact with a user.
The Ajax dispatch has the same tell. It is a story that cannot survive contact with a detail.
Now, the participants.
Felix Kjellberg is not a technologist in any conventional sense, and that is precisely what makes him significant here. He is an attention system — one of the largest single-node attention systems on earth, with a demonstrated ability to move hundreds of millions of people toward a topic within a news cycle. His audience is young, extremely online, and structurally suspicious of institutional authority. When he says a platform banned him, he is not making a technical claim. He is making a claim about legitimacy, and his audience is unusually receptive to it.
OpenAI, by contrast, is the most institutionally entangled AI company in the world. It operates under a capped-profit structure that has been progressively diluted, it holds partnerships with the largest cloud provider on the planet, and it is the reference point for essentially every AI regulation now being drafted. Its content policies are not merely product decisions; they are the de facto template that regulators use to think about what AI governance looks like. When OpenAI bans someone, it is not just enforcing a contract. It is performing governance, in public, for an audience of legislators.
And Ajax is, on the available evidence, a name. I want to be scrupulous here: I cannot confirm that a model by that name exists in any public repository, and my knowledge has a cutoff date. If Ajax exists, the overwhelming likelihood — and I will defend this arithmetically in a moment — is that it is a fine-tune of an existing open-weight model, not a model trained from scratch. That distinction is not pedantic. It determines whether this story is about a person building something, or about a person repackaging something and renaming it. Those are very different narratives, and only one of them is true.
Here is the frame I want to carry through the rest of this piece. The Ajax affair is not a technology event. It is a legitimacy event — a public argument about who gets to decide what a model will refuse to do, conducted through the body of a celebrity. And legitimacy arguments are the ones that shape regulation, capital allocation, and developer migration far more than any benchmark ever has.
Every token holds a story waiting to be mined. This one is being mined for something other than truth.
Start with the arithmetic, because the arithmetic is the part nobody argues about.
Training a language model from scratch is a function of three numbers: parameters, tokens, and FLOPs per parameter-token pair. The standard approximation is six times parameters times tokens. A small, genuinely useful model — say seven billion parameters — needs on the order of a hundred and forty billion training tokens to reach competence rather than gibberish. Multiply it out and you land near six sextillion floating-point operations. A single top-end consumer GPU delivers, realistically, something on the order of a hundred to a hundred and fifty teraflops of effective throughput once you account for memory stalls, communication overhead, and the fact that no kernel runs at peak. Do the division and you are looking at something in the neighborhood of a year of continuous computation on one card, before you have trained a tokenizer, curated a corpus, run a single evaluation, or done any preference tuning at all.
That is the optimistic case. The realistic case is worse, because the binding constraint on modern training is not FLOPs. It is data quality and the engineering labor to build a pipeline that does not silently poison itself at step forty thousand. The GPU is the cheap part of that story.
So when someone says they trained a model on their own computer, the sentence is almost certainly true in the same way that I have cooked dinner when I have assembled a sandwich. What actually happened, in the overwhelming majority of cases, is one of three things: parameter-efficient fine-tuning on top of an existing open-weight base; merging several existing models together; or simply downloading a quantized model and running it locally while calling the download training. In creator discourse, train is an elastic word. It stretches to cover anything that ends with a model appearing on your machine.
There is a structural irony worth naming here. Using a full pretraining pipeline to produce what is essentially a behavioral modification artifact is the computational equivalent of using a hand-built luxury car to haul gravel. The machine is insulted and the load is still badly carried. The interesting engineering did not happen at the scale of the story; it happened one layer down, in a base model someone else paid for.
Now the recipe, because the recipe is public and this matters enormously for how we read the event.
Removing refusals from a language model is not a research problem in 2026. It is a workflow. The most discussed technique is refusal-direction ablation — sometimes called abliteration — which works from the observation that refusal behavior in a transformer is not distributed diffusely across the network but concentrated along a particular direction in activation space. Identify that direction, project the weights orthogonal to it, and the model's tendency to decline requests collapses. It is elegant, it is well documented, and it takes an afternoon.
The second path is data-driven. Assemble a supervised fine-tuning set or a preference-optimization set drawn from corpora that have already been scrubbed of refusals — the lineage that runs through the openly published uncensored datasets — and train the model to imitate that distribution. The third path is cruder: manipulate the system prompt, or strip it entirely, so the safety behavior that was conditioned on a preamble simply never activates.
The fourth path is the one hobbyists actually use most: merging. Take two models, one capable and one compliant, and interpolate their weights. Tools for this are mature, and the results are often surprisingly coherent.
None of this is novel. Every step has open-source tooling, published documentation, and a community that will help you debug it on a forum. Which means the interesting question about Ajax was never whether it could be done. It is what remained after it was done.
Then you quantize. Compress the weights to four bits, package them in a format that a local runtime can stream, and the model fits into twenty-four gigabytes of video memory or a laptop's unified memory. This is the last mile that makes local deployment ordinary rather than exotic. The whole pipeline, from base model to uncensored artifact running on a desk, is a weekend project for a competent hobbyist. It has been for two years.
So the technical claim embedded in the Ajax story is not impressive. It is routine. And that is exactly why the story needed a ban.
Here is the part the narrative economy cannot afford to discuss, and the part I have spent the most time on in my own work.
The alignment tax is a real thing. Safety training does cost capability — refusals generalize imperfectly, and a model trained to decline certain requests will sometimes decline adjacent ones. This is well documented and it is a legitimate grievance. But there is a symmetric tax that almost never gets named: the uncensoring tax.
Refusal behavior is not a bolt-on module. It is entangled with general instruction-following, because both are learned from the same preference signal. When you ablate the refusal direction, you do not surgically remove one behavior; you degrade a region of the model's behavioral manifold. In practice, practitioners report that heavily ablated models become more compliant across the board — including toward incoherent, contradictory, and self-destructive instructions. A model that cannot refuse is a model that cannot push back. And pushback is not merely a safety feature; it is the mechanism by which a model signals uncertainty, flags a malformed premise, or declines to confabulate.
This is the inversion I want the reader to hold onto. An uncensored model is not a freer model. It is a model whose editorial layer has been moved, not removed. Before, the editorial layer was a policy — visible, documented, appealable, and written by an institution with a public name. After, the editorial layer is the training corpus — usually anonymous, usually unlicensed, usually assembled by someone who has no accountability to anyone. That is not less governance. It is governance without a face. And governance without a face is strictly harder to contest.
Add the externality. A model running on your own machine cannot be remotely unlisted, throttled, or patched. That is the point, and it is also the problem. There is no kill switch, no revocation, no update path. Whatever it will do, it will keep doing, on hardware you do not control, in a jurisdiction you may never visit. That property is simultaneously the entire appeal and the entire regulatory exposure, and it cannot be separated into halves.
There is one more thing the dispatch never mentions: evaluation. Fine-tuned models produced outside industrial pipelines almost never undergo red-teaming, bias assessment, or capability evaluation. The result is not a model that has been freed from oversight. It is a model that has never been looked at.
Now let me say something uncomfortable about the structure of the record itself.
In 2022, after the collapses that defined that year, I withdrew from public writing for two months and went back to code. I audited the broken smart contracts of failed protocols, line by line, looking for the moment where a system's narrative detached from its mechanics. What I learned, and what became a permanent habit, is that detachment is legible. You can see it in what a story refuses to specify.
Specificity is expensive. A story that needs to travel fast cannot carry parameter counts, base model attributions, license terms, dataset provenance, or the text of a platform's enforcement notice. Those details are heavy. They slow the story down and, worse, they invite checking. So the story sheds them. What remains is a name, a status, and a feeling.
I do not think this is a conspiracy. I think it is the natural physics of narrative. But the consequence is that the Ajax story is structurally unfalsifiable as told. It cannot be wrong, because it asserts almost nothing. And a claim that cannot be wrong cannot be trusted — not because it is false, but because it has been built to be immune to the question.
Let me be fair to Kjellberg here. He may be telling the truth. He may have been banned, twice, for reasons that were never explained to him. Platforms do that; opacity is the default posture of every large enforcement system, and I have watched this industry's exchanges do exactly the same thing to users for a decade. The absence of an explanation is itself a governance failure, and it is the most defensible grievance in the whole affair.
But the most likely explanation for the ban is also the most boring one, and boring explanations do not trend.
Consider the plausible triggers. The first is content generation outside the provider's policy — the obvious one, and the one the story implies. The second is automation or account sharing. The third, and in my estimation the most probable given the context, is training on outputs. Nearly every major model provider's terms of service prohibit using the service's outputs to develop a competing model. This is not censorship. It is the same clause that every software vendor has carried since the 1980s. And if a user announces, publicly, that they are building their own model, and if any part of that pipeline touched provider outputs, the enforcement is contractual rather than ideological.
That possibility matters because it collapses the entire freedom framing into a mundane terms-of-service dispute — which is precisely the kind of detail a story cannot afford to carry.
What follows from this, regardless of the facts, is that governance has become a competitive variable. If developers perceive a provider's enforcement as opaque and its appeals as unreachable, some fraction of them will migrate. But migration is capability-gated, and the frontier is still in the cloud. The erosion is real and slow, and it compounds in a direction that is hard to reverse: trust, once spent, is not refunded.
The industry has a template for how to handle this correctly. Optimism's RetroPGF — retroactive public goods funding — remains the only mechanism I have seen in this sector that consistently rewards delivered value rather than committee relationships. It pays for what was built, after it was built, based on whether it was useful. If the open-weight ecosystem wants legitimacy rather than sympathy, that is the shape of the institution it needs. Celebrity endorsement is cheaper and worth less.
Now the hardware story, because it is where the myth and the machinery diverge most sharply.
The phrase runs on your own computer conceals a stratification. Local inference is bounded by memory — capacity and bandwidth, not raw compute. A consumer graphics card with twenty-four gigabytes, or a laptop with a large unified memory pool, can hold a four-bit quantized model of maybe seven to thirty billion parameters. Above that, the model does not fit, and no amount of cleverness changes physics.
This produces a two-tier intelligence market that I expect to persist. Frontier capability lives in the cloud, behind APIs, priced per token, governed by terms of service. Commodity capability lives at the edge, on hardware you own, priced as a capital expense, governed by nobody. The edge tier is genuinely better on three dimensions: privacy, because nothing leaves the machine; latency, because there is no round trip; and marginal cost, because there is no meter running. It is genuinely worse on one: capability ceiling. A model that fits in your laptop is, by construction, not the best model.
That trade is the honest version of the local-AI pitch, and it is a good trade. It is just not the trade the story told.
There is a crypto adjacency here that deserves restraint rather than enthusiasm. Decentralized compute networks have spent years positioning themselves as the substrate for exactly this kind of workload, and a story like Ajax produces a visible pulse in their narrative. But I have audited enough of these token economies to say plainly that a large share of decentralized inference demand is currently subsidized by emissions rather than paid for by users — which means the demand signal is partly circular. The direction of travel is real. The magnitude is routinely overstated.
And there is a cautionary case sitting right next to us. This industry already has a study in forcing a base layer to do work it was never designed for: the inscription wave on Bitcoin, where a settlement network was repurposed as a data-availability layer for token metadata. The result was that neither function improved. Blocks filled, fees spiked, and the network became measurably worse at the thing it was actually for. I have said before that this is like using a hand-built luxury car to haul cargo — it insults the car and it does not carry much. Local hardware running a crippled model for ideological reasons has the same shape. The tool is diminished and the task is still badly done.
Let me now turn to the trend that I believe will make this entire argument obsolete within three years, and which almost nobody in this debate is pricing.
In 2024, I worked with two AI researchers in Barcelona on a framework we called Verifiable AI on Chain. The premise was simple: as autonomous agents begin transacting, the binding institutional question will not be what a model will say. It will be what a model is — who trained it, on what data, under what license, with what evaluation, and whether any of that can be proven.
The technical apparatus for this is arriving quickly. Hardware attestation inside trusted execution environments can prove which weights are loaded. Cryptographic signing of model artifacts can bind a model to a publisher. Zero-knowledge machine learning can, at increasing but tolerable cost, prove that a specific computation ran on a specific input without revealing either. On-chain registries can anchor model identity, version history, and evaluation results in a place that no single vendor can rewrite. And decentralized identity standards can give agents a persistent, verifiable origin — which is the precondition for any of them holding economic agency at all.
Here is the collision. Ajax-style local uncensored models are the precise inverse of this trend. They are unverifiable by design, unattested, unsigned, and unlicensed. Institutions will not deploy them in production, not because institutions are censorious, but because an unverifiable model cannot be audited, cannot be insured, and cannot be defended in a courtroom. Capability is not the gate. Provenance is.
The soul of the chain is written in its holders. The same is becoming true of models: the soul of a model is written in its provenance, and provenance is about to become the scarcest asset in the stack.
The regulatory picture sharpens the point, and it sharpens it in a direction that surprises people who assume the state is the only actor that matters.
In the European Union, the AI Act imposes obligations on general-purpose models: transparency, a copyright policy, documentation, and — above a compute threshold — systemic risk assessment. The interesting legal question for a model like Ajax is not whether it exists but whether it constitutes a substantial modification of a base model, which determines whether the fine-tuner inherits the obligations of a provider. The answer is unsettled, and unsettled law is a tax on everyone who operates near it.
In China, generative AI services face security assessment and algorithm filing requirements. A model whose defining property is the absence of refusal behavior has essentially no path through that regime, and its local, offline, freely copyable nature makes it unfilable in practice as well as in principle.
In the United States, personal local use sits largely outside the strict perimeter. Distribution is where the perimeter begins.
This is the single most important structural insight in the whole affair, and it is easy to miss: the regulatory trigger is not creation. It is distribution. Which means the enforcement vector is not the model. It is the file. Every regime converging right now is aimed at the moment an artifact moves between hands. The local-AI movement has correctly identified that this is where its vulnerability lies, and it has responded by treating distribution as a virtue rather than a risk. That is a coherent position. It is also a position that guarantees a fight.
So who actually gets paid in this story?
Not the model. There is no product, no API, no pricing, no customer. Ajax, if it exists, is content — a prop in a video, a hook for a channel, a chapter in a creator's ongoing relationship with an audience that rewards insubordination. The monetization is attention, and attention is monetized at the creator layer, not the model layer.
The media layer is complicit. I include the outlet that ran this dispatch, and I include my own industry's reflexive appetite for it. This sector has a structural preference for narratives about platforms abusing power, because those narratives are simultaneously true often enough to be credible and flattering enough to be shared. That preference is not a bias in the crude sense. It is an incentive gradient, and it bends coverage the way gravity bends light.
And there is a deeper economic problem that the open-weight movement shares with at least one other ecosystem I have studied closely. Cosmos built the most technically elegant interoperability primitive this industry has produced — IBC is genuinely beautiful engineering — and yet the token that anchors it captures almost none of the value that flows across it. Maximal technical contribution, minimal value capture. Open-weight models have exactly that shape. They generate enormous aggregate value and are structurally unable to charge for it, because value capture requires either a proprietary layer on top or a governance mechanism capable of taxing usage. Retroactive public goods funding is the closest thing anyone has built to a correction, and it is still an anomaly rather than a norm.
Which brings me to why this story landed in a crypto feed at all, and what that placement tells us.
Banned. Uncensored. Local. Your own computer. Read those four phrases in sequence and you have a self-custody pitch. It is the same argument, with the same emotional architecture, that this industry has made about wallets, about exchanges, about stablecoins, and about layer-one blockspace. The mapping is so tight that the story migrated across domains without friction. It did not need to be explained to a crypto audience. It was already in the language.
That is the reflex I want to flag, gently, as self-criticism. This industry has a persistent habit of conflating permissionless with unaccountable. They are not the same property. Permissionless means no one can stop you from participating. Unaccountable means no one can hold you responsible for what you did. A system can be the first without being the second, and the healthiest systems in this space are precisely the ones that separate them — where anyone can join, and everyone who joins leaves a trace.
The Ajax story collapses the two. And the crypto industry, hearing its own vocabulary, nodded along.
Now let me try to say the thing that runs against everything above.
The contrarian reading is not that the ban did not happen, or that Ajax is fake, or that the model is technically trivial. The contrarian reading is that this event, framed everywhere as a victory for decentralization, will function as an accelerant for centralization — and it will do so through three mechanisms that have almost nothing to do with the facts.
First, it hands regulators a human face. Regulation does not advance on statistics. It advances on anecdotes, and the more vivid the better. A celebrity, an uncensored model, a laptop, and a ban is the single most useful anecdote a legislator could be handed. It compresses an abstract debate about open weights into a story a minister can retell at a dinner. Every serious argument for open-weight distribution rests on the claim that the technology is a public good whose risks are manageable and diffuse. The Ajax story supplies the counter-image: a famous person, an unaligned system, and no oversight. The people who want to restrict model distribution did not need to write this story. They only needed to wait for it.
Second, it converts an engineering subculture into a political constituency — and political constituencies optimize for identity rather than capability. This is the subtler and more corrosive effect. Engineering communities argue about benchmarks, ablation quality, and quantization loss. Political communities argue about loyalty. Once the local-AI movement acquires a martyr and a flag, its internal quality control degrades, because criticizing your own side becomes disloyal. Models get defended because they are ours, not because they are good. That is how a technical movement begins to rot from the inside while believing it is winning.
Third, and most damning, the story misdirects attention away from the actual bottleneck. If you asked me what stands between the open-weight ecosystem and genuine parity, I would not say permission. I would say data, evaluation, compute, and legitimacy — four unglamorous, expensive, unglamorous problems that no ban narrative addresses. A martyr supplies none of them. A martyr supplies morale, and morale is not a scaling law.
There is a second contrarian beat nested inside the first, and it concerns the word uncensored itself. Uncensored is not a technical description. It is a marketing term. No model is uncensored; every model is censored by whoever assembled its training data, and the only question is whether that editor has a name and an address. A model with no refusal layer is governed by an anonymous corpus, and an anonymous corpus has no appeal process, no transparency report, and no public policy you can read before you use it. The community that celebrates this calls it freedom. It is more accurately described as the transfer of editorial authority from an institution you can sue to a stranger you cannot find.
So we arrive at the inversion I have been circling. The alignment tax is real. But the anti-alignment premium is also a tax — paid in legitimacy, and eventually collected in regulation. The open-weight movement has spent years arguing that it should be trusted with capability. What this event demonstrates is that trust is not the same thing as permission, and that a movement can win the argument about who is allowed to build while losing the argument about who is worth believing.
The most likely explanation for the ban remains the boring one: a contract, enforced quietly, by a system that never explains itself. And the boring explanation is the one the narrative economy cannot afford to carry, because it has no villain and no hero and it does not travel.
Every token holds a story waiting to be mined. The trick is knowing which stories are worth the ore.
Here is where I think this goes.
The next narrative is not open versus closed. That argument is nearly settled and it is being settled by capability curves that neither camp controls. The next narrative is verifiable versus unverifiable. When autonomous agents hold budgets, sign contracts, and transact on behalf of principals, the question will stop being what a model refuses to say. It will be who signs for what it does.
The industry that spent a decade insisting code could replace institutions is about to discover something it should have known from the beginning: accountability is not a feature you can remove. It is only a location you can move. Right now, a great many people are moving it to a laptop in a room nobody can find — and calling that freedom, and meaning it, and being partly right.
We do not just trade assets; we curate narratives. The question I would put to every reader of this piece is not whether Ajax was banned. It is this: when the agents arrive and the money moves without a human hand, whose name goes on the ledger — and will you be able to verify it?

