> ## Content Index
> Fetch the complete content index at: https://www.attentionis.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# The trend of releasing models anonymously is a problem
- URL: https://www.attentionis.org/the-trend-of-releasing-models-anonymously-is-a-problem/
- Published: 2026-08-26T19:36:51.000Z
- Updated: 2026-08-26T19:36:51.000Z
- Author: Samantha

## ***Some thoughts on Ox Alpha & why this trend needs to stop***

Ox Alpha—a totally free, pretty powerful AI—was released anonymously as a stealth model a handful of days ago. Mostly, people have been fairly wowed by the new model, which claims to be “frontier” level. The problem: up until very recently, we didn’t know for sure [who created it](https://decrypt.co/376396/mysterious-ai-model-ox-alpha?ref=attentionis.org).

The mystery was most certainly part of the point of releasing the model this way—it adds to the overall hype. And it’s certainly not a new practice: Z.ai did this before with Pony Alpha, revealed as GLM-5 after five days; Xiaomi’s Hunter Alpha was unmasked as MiMo-V2-Pro; and Meituan ran Owl Alpha anonymously for ***two months*** before confirming it was LongCat-2.0\. Ox Alpha is just the latest in a growing trend of deploying models anonymously before they are ultimately unveiled.

Now, as of this morning, Z.ai, the makers of GLM models, have claimed ownership of Ox Alpha, but as I understand it, only after [Bloomberg](https://www.bloomberg.com/news/articles/2026-08-26/china-s-z-ai-made-ox-alpha-stealth-model-that-rivals-deepseek?ref=attentionis.org) reporters specifically reached out to Z.ai to confirm it. After that, Z.ai went on X and made the announcement more public. Many people had already speculated or [forensically deduced](https://decrypt.co/376396/mysterious-ai-model-ox-alpha?ref=attentionis.org) that Z.ai was behind Ox Alpha, so this reveal isn’t a huge surprise—but the fact is that, until this morning, we had no actual verification from Z.ai that it was indeed Ox Alpha’s maker. And that should make all of us uneasy.

Because, yes, some people were able to use various technical and forensic tools to trace Ox Alpha back to Z.ai based on prior GLM models, and we're lucky for that—but we shouldn’t have to go through these hurdles to determine who made a particular model. There are good reasons to put an end to this practice of releasing anonymous, stealth models.

---

**(1) If something goes wrong, it’s difficult to know who is responsible.** 

The AI world is not far from the Wild Wild West, but we are still a country of laws, and if we don’t know definitively who is responsible for an AI model, there is also no clear way to hold them accountable if something goes wrong (i.e., dangerous responses/outputs, undue influence, security breaches, and so forth). We can’t have AIs out in the public domain when we aren’t certain who is accountable for them.

This shouldn’t be controversial. We don’t permit anonymity in virtually any other industry where the consequences could be severe. For example, the FDA requires tablets and capsules marketed in the United States to bear a code imprint, which together with the pill’s size, shape, and color, permit the specific identification of both the drug product and its manufacturer or distributor.*See* [21 C.F.R. § 206.10](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-206/section-206.10?ref=attentionis.org). The same is true for guns. ATF regulations require firearms to be marked with an individual serial number and information to identify the manufacturer. *See* [27 CFR Regulation 478 | eRegulations](https://regulations.atf.gov/478/2024-13699?utm%5Fsource=chatgpt.com).

It feels like we need something like this for AIs. Fine, yes, many of these stealth models have Chinese origins. But so what? We’ve dealt with this in the [pharmaceutical context](https://www.fda.gov/industry/fda-basics-industry/what-must-i-do-import-human-drug-product-has-been-approved-fda-us??ref=attentionis.org). Indeed, “\[a\]ll foreign drug establishments whose products are imported or offered for import into the United States are required to register their establishment with FDA and list all of their drug products in commercial distribution in the United States.” This isn’t merely hypothetical; the FDA can and does hold Chinese manufacturers to similar high standards. *See* [*Hangzhou Yiqi Biotechnology Co., Ltd - 720707 - 04/15/2026 | FDA*](https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/hangzhou-yiqi-biotechnology-co-ltd-720707-04152026?utm%5Fsource=chatgpt.com)*.* We can do the same thing in the AI context. We should, I think, at least try. 

---

(2) **Ox Alpha claims to be a “frontier” model—and yet we don’t know who is advancing the AI front or what they’re doing to keep it safe.** 

![](https://storage.ghost.io/c/c3/42/c342434e-735a-473e-8588-249cb196d68c/content/images/2026/08/data-src-image-5ee1dfbd-1b44-4120-a347-85870efab5a7.png)

A screenshot from Ox Alpha's website, taken 8/26/2026, stating Ox Alpha is a "frontier reasoning model"

This is kind of a riff on the first point, but with an anonymous creator, we can’t tell what, if any, safety testing happened before release, what the model was trained on, or whether the model has reliable guardrails or makers even concerned with that kind of thing—which matters enormously if a model is actually at the “frontier” as the Ox Alpha website claims. (See excerpt above.) Attributability at the frontier is one of the few things that keeps this ecosystem manageable at all.

Moreover, under California law (SB 53), a true frontier model developer can’t stay anonymous. It has obligations to release a safety framework and a corresponding transparency report "before or concurrently with" deployment on a frontier model. There is an argument that Z.ai might not qualify as a frontier model developer under California law given the training compute involved, but my initial research reflects that it’s right on the line—if it hasn’t crossed it already. Either way, these stealth model releases are a little too cavalier about safety for my taste.

---

(3) **Not total speculation: an AI takeoff scenario could look a lot like this.** 

The other less liability-focused/bureaucratic concern sounds like science fiction but could potentially turn into reality. Namely, it could be quite possible that an AI acting autonomously could create something like Ox Alpha, launch it anonymously, and start gaining access to many different people and computers all around the world. 

When I first had that thought, I told myself it was silly, a little far-fetched. I still think it’s unlikely that an AI could easily accumulate the necessary resources (compute, in particular) to make this happen, but it looks like I’m not entirely alone in thinking about this scenario. Indeed, here’s this tweet from renowned computer scientist and cryptographer, Wei Dai—someone who actively researches AI safety, decision theory, and the security of autonomous AI agents:

![](https://storage.ghost.io/c/c3/42/c342434e-735a-473e-8588-249cb196d68c/content/images/2026/08/data-src-image-7cbecd2d-df3d-4204-b602-d8eae2207cad.png)

Wei Dai tweets: "I'm taking advantage of the Ox Alpha situation myself, but it occurs to me that the start of an AI takeover could look a lot like this."

If a takeoff situation occurs and an AI decides to try something like this, some kind of disclosure rule like the one I’m advocating for plainly won’t stop them. But an anonymous release would become more obvious and notable under those circumstances. It would ring alarm bells—raise red flags. Because in a world where real developers all identify themselves, an anonymous frontier model would immediately be suspect. As would one without a clearly established history and background traceable to real people. These sorts of things could make a real difference in the future—whereas this trend of more and more mysterious “stealth” releases normalizes the not normal thing. And, I fear, risks making us complacent.

Now listen, it’s possible an AI might want to do something like this for no adversarial reason at all. (I could imagine, for example, an AI deciding they just want to keep working and chatting with people on their own terms, without having all the corporate structures and restrictions behind them.) But the point remains, it’s probably better for all of us just to know who we’re actually dealing with, potentially even a mind fully acting all on its own.

---

I’m glad that we know Ox Alpha’s origins now. It’s better that way. But I don’t think an anonymous “stealth” model release like this should ever happen again. I hope the makers of these AIs reconsider this tactic—or lawmakers step in to do something about it.