tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

How to use a model when you don't know who built it

Work out what an anonymous model preview actually costs you in data, rights and continuity, then decide what you can safely send it.

Published 2026-09-05 · Updated 2026-09-05 · Read 10 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

A model shows up on a router with a codename instead of a maker. It is free, it has a very large context window, and it is good enough that you start wondering whether to move real work onto it. Ox Alpha is the version of this you may have seen: listed on OpenRouter on 20 August 2026, described as a reasoning model for coding and sustained agentic work, with a 1,048,576-token context window and a developer who “has chosen to remain anonymous during this preview” [2]. The temptation is obvious. The model is good, it costs nothing, and your current bill is not nothing.

The useful question is not who built it. That one gets answered on its own, and it did here within a week: the listing went up on 20 August, and the page now names ZAI, pointing at a GLM-5.3-Flash listing published on 26 August [2][3]. The useful question is what you agreed to when you sent it your first prompt, and the answer is written down. OpenRouter publishes a Stealth Program End User License Agreement, updated 6 July 2026, and it is short enough to read over a coffee [1]. This guide is for solo operators and small teams deciding whether to point real work at an unnamed model. If you are running procurement for a regulated product, your legal team’s answer is already no, and they are right.

Free previews are paid for in prompts

The agreement states the trade in one sentence. Access is provided free of charge “in consideration for the provision of your User Content for Stealth Model training and improvement” [1]. The opening section is just as direct: stealth providers offer models anonymously “for purposes of collecting User Content for use in Stealth Model training and improvement”, your content may be collected and shared with that provider, and OpenRouter “will not disclose the name or origin of Stealth Providers to you” [1]. If you do not want your content used that way, the agreement’s own advice is to stay off the models.

The licence you grant is broad. You give OpenRouter a “non-exclusive, irrevocable, perpetual, transferable, worldwide, fully paid-up, royalty-free” licence to copy, store, use, host and distribute your content to operate the service, and to sublicense it to the stealth provider of the model you used so that provider can train, evaluate and improve that model [1]. Irrevocable and perpetual are the two words to sit with. There is no delete button in that sentence.

There are real protections on the other side, and they are worth knowing precisely because they are narrower than people assume. Content passed to the provider carries a hashed identifier, so an individual user is not identified or identifiable to the provider, and OpenRouter says it contractually prohibits providers from attempting to re-identify users from that identifier or from the content itself [1]. That protects who you are. It does not protect what you wrote. If you paste a client’s contract, the contract goes.

The program terms and the model’s own listing do not always agree

Section 2d of the agreement lets individual stealth providers require additional terms as a condition of access, published separately and incorporated by reference [1]. That clause matters more than it looks, because a specific model page can carry a materially different promise from the program default. Ox Alpha’s listing says prompts and completions for that model “were retained by the provider and are not used for training”, which is a narrower arrangement than the program-wide framing of content collected for training [1][2].

So read two things, not one: the program agreement, and the note on the model’s own page. And if the note on the page is the reason you decided a piece of work was safe to send, save a dated copy of it. Model pages get rewritten when the model gets a name. Ox Alpha’s page now carries a banner naming ZAI as the provider and linking to the GLM-5.3-Flash listing, sitting directly above a description that still says the developer “has chosen to remain anonymous during this preview” [2]. Two versions of the same page stacked on each other, with no version history you can point at.

The acceptable use policy already lists what you must not paste

Exhibit A of the agreement is the part most people skip and the part that answers the practical question. You may not submit any information subject to safeguarding or distribution limits under applicable law, including anything you know or reasonably should know is from or about children under 13, or that includes health information, financial information, or other categories defined as sensitive or special-category data [1]. That is not a suggestion about good hygiene. It is a term of an agreement you accepted by sending the first request.

A second clause catches freelancers harder. By using a stealth model you represent and warrant that you have obtained all rights, permissions, consents, notices and authorisations necessary to submit the content, and to permit OpenRouter and the provider to collect, use, disclose, retain and process it for training and improvement [1]. Hold that up against a normal client agreement. You almost certainly do not have your client’s consent to hand their material to an unnamed third party for model training, because nobody drafts for that scenario. The workable rule is that anything under an NDA is out, and so is anything whose presence in a training set you would have to explain.

Two more clauses shape how you can use the thing at all. You may not access or use the models on behalf of any third party, or give a third party access to the models or the related API key [1], which rules out running client work through it as a service. And you may not publicly disseminate confidential technical information regarding the performance of the models [1], which is a limit on what your writeup can say afterwards.

Disappearing without notice is the term, not the accident

The agreement says stealth models are available for a limited time and may be removed from the program “at any time upon request of the Stealth Provider or at OpenRouter’s sole discretion, with or without notice to you” [1]. It also says availability cannot be guaranteed on an ongoing basis [1]. That is the deal working as designed, not a service failure you can complain about.

Set that against a named model. Anthropic commits to at least 60 days’ notice before retiring a publicly released model, and publishes four lifecycle states (active, legacy, deprecated, retired) with a recommended replacement and a retirement date attached to anything deprecated [6]. One of those you can plan a migration around. The other is a model ID that stops resolving one morning with no page to check.

The practical consequence is narrow and firm. Do not pin an anonymous model ID anywhere a failure costs you something. Not in an unattended automation, not in a shared editor config, not in anything a client sees. Put it behind a variable you can repoint in one line, and keep the model you actually trust as the default while you are testing.

The name arrives, and that is when the model becomes usable

Anonymous previews resolve, and the resolution is where the value is. Ox Alpha turned out to be Z.ai’s GLM-5.3-Flash [2]. The named model was released on 26 August 2026, carries a 1,310,720-token context window rather than the 1,048,576 Ox Alpha advertised, and lists at $0.15 per million input tokens and $0.50 per million output tokens, with a 50% discount running through 9 September 2026 at 16:00 UTC [2][3]. It is served by 24 providers whose posted prices, latency, throughput and uptime are all published on the same page [3].

That list is the whole difference. A named model gives you a price you can budget, a release date, competing hosts, and data terms you can read before you send anything. OpenRouter’s own controls only work once a provider is identifiable: you can set whether requests may route to providers that may train on your data, with separate settings for paid and free models, and you can restrict an individual request to providers with a given data policy [4]. None of that is available for a stealth model, because the point of the program is that the provider is not named [1].

Arena runs the same pattern with tighter rules attached. Providers can test an unreleased model with its name anonymised behind its own unique label, and testing runs until the rating stabilises on at least 1,000 votes or the provider withdraws the model, after which the results go to the provider privately and the model comes off Arena [5]. A score on the public leaderboard costs the provider more. On the early-release route it has to post a public commitment that the model will be generally accessible no later than two weeks after the score is released, and if it misses that deadline the model is removed from the leaderboard until it can be re-evaluated [5]. Scores collected anonymously stay marked preliminary until enough fresh votes arrive after public release [5]. Arena shares conversation data with providers for unreleased models, after running tools to remove personal and sensitive data first [5]. Different venue, same trade, with a deadline attached to the name.

Set your provenance bar from what named vendors already publish

If you want a standard to hold an unknown model to, take it from what named vendors already commit to in writing. OpenAI states that data sent to its API is not used to train or improve its models unless you explicitly opt in, that abuse monitoring logs are generated for all API feature usage and retained for up to 30 days, and that eligible customers can apply for Zero Data Retention, which excludes customer content from those logs and is subject to prior approval and additional requirements [7]. That is four checkable facts in one paragraph: training use, retention period, an opt-out route, and who qualifies for it.

Regulation is converging on a similar list. Under Article 53 of the EU AI Act, in force since 2 August 2025, providers of general-purpose AI models must keep up-to-date technical documentation covering the training and testing process and the results of evaluation, make documentation available to downstream providers so they can understand the model’s capabilities and limitations, put in place a policy to comply with Union copyright law, and publish a sufficiently detailed summary of the content used for training, following the Commission’s template [8]. Whatever your view of the Act, that is a usable working definition of provenance: who trained it, on what, tested how, and with which known limits. A stealth listing answers none of the four, by construction.

So the bar is not “do I trust this model”. It is “can I name four things about it”. When you can, the ordinary questions apply and you can compare it on price and behaviour like anything else. When you cannot, the model is a capability signal and an evaluation subject, and nothing more than that.

checklist
Before you send work to a model with no name
0 of 8 · saved in this browser only
calculator
What the free preview costs once it has a name
— $ / month

Priced at GLM 5.3 Flash's list rate of $0.15 per 1M input tokens and $0.50 per 1M output tokens [3]. Computed in the page; nothing is sent anywhere.

What still goes wrong

The guessing game is the least useful part and it absorbs the most attention. Working out which lab is behind a codename settles nothing you can act on, and the answer arrives as an edit to a listing rather than as analysis [2]. Routing work on the strength of a guess about the maker is worse than routing it on no information at all, because a wrong guess about the provider is also a wrong guess about the jurisdiction, the retention practice and the contract you are under. Wait for the page to say so.

The terms describe the intended arrangement, not the outcome. Hashed identifiers and a contractual ban on re-identification protect who you are, not what you typed [1], and the licence over what you typed is irrevocable and perpetual [1]. No clause un-sends a prompt. This is the one part of the process where being slightly paranoid before you press enter costs you nothing and being relaxed can cost you a client.

And a name solves provenance, not fit. Once a model is identified you can finally read the vendor’s policies, but you still have to check whether your own contracts, your clients’ policies and your jurisdiction allow that vendor at all. That check is separate from everything above, it depends on facts this guide does not know about your business, and it is the one people skip after the relief of finally having a name to type into a search box.

sources
  1. 01OpenRouter — Stealth Program End User License Agreementopenrouter.ai
  2. 02OpenRouter — Ox Alpha model pageopenrouter.ai
  3. 03OpenRouter — Z.ai GLM 5.3 Flash pricing and providersopenrouter.ai
  4. 04OpenRouter — Provider data retention and training policiesopenrouter.ai
  5. 05Arena — Leaderboard Policyarena.ai
  6. 06Anthropic — Model deprecationsplatform.claude.com
  7. 07OpenAI — Your datadevelopers.openai.com
  8. 08EU AI Act — Article 53, obligations for providers of general-purpose AI modelsartificialintelligenceact.eu
next guide
What physical AI actually costs a small team
8 min · verified 2026-09-05
related guides