
PewDiePie’s Ajax AI model is a 9B local model based on Qwen 3.5 and fine-tuned specifically for his self-hosted Odysseus workspace. The official Ajax page schedules the release for October 3, 2026 at 08:25 JST, which is October 2 at 7:25 p.m. EDT. Its refusal behavior has also been deliberately ablated to make the model less restrictive.
That combination is more useful than the celebrity name attached to it. Ajax is meant to be a small, specialized local agent that can search, browse the web, work with email, and manage calendars through Odysseus without sending every model interaction to a hosted AI provider.
There is still one reason to hold the applause. As of October 2, Ajax remains a coming-soon model rather than a public download. There is no final Ajax model card, public Ajax benchmark suite, confirmed license for the fine-tuned weights, or released set of quantizations to inspect yet.
Key takeaways
Ajax is a fine-tuned Qwen 3.5 9B model built around Odysseus tool use rather than leaderboard chasing.
PewDiePie says he used refusal ablation to make Ajax less likely to reject requests. The project describes the result as a “freer, less restricted AI experience.”
“Uncensored” is loose wording. PewDiePie says he deliberately kept boundaries around requests that would harm other people or the user.
The 9B size is aimed at ordinary local hardware. A maintained vLLM recipe lists roughly 22GB minimum VRAM for BF16 and 11GB for FP8, although Ajax’s own released formats and memory requirements still need to be confirmed.
There are no public Ajax benchmarks yet that justify claims about how it compares with larger local models or commercial frontier systems.
Ajax fills the model-shaped hole in Odysseus
When Popular AI covered Odysseus earlier this year, the important caveat was simple: Odysseus was a workspace around AI models, not a PewDiePie AI model of its own.
Ajax changes that setup.
Odysseus provides the interface, memory, files, research tools, email integration, calendar, agents, model serving, and other surrounding machinery. Ajax is being trained as a model that already understands how that machinery is supposed to work.
PewDiePie described the target months ago in the Odysseus development discussion. He wanted a model in roughly the 1B-to-14B range that could run on relatively modest hardware while reliably using Odysseus tools. He specifically said the project did not need a “benchmark-maxxing” model. The desired behavior was much more practical: understand the request, call the right tool, read the result, and answer without wasting time. The current development discussion now identifies Qwen 3.5 9B as the model and names reliable local tool use as the goal.
That is a sensible target for a 9B model. Moving a calendar event, summarizing three emails, or turning a tool result into a short answer does not automatically require the largest general-purpose reasoning model available. A smaller model can be more practical if its training teaches it the exact tool vocabulary, argument formats, recovery behavior, and workflow conventions it needs.
There is a limit to what specialization can buy. Training Ajax for Odysseus does not make 9B parameters behave like a frontier model across every coding, research, or reasoning task. Ajax should be judged first on whether it runs Odysseus well.
More on PewDiePie’s Odysseus:
How Heretic makes Ajax less restrictive
Ajax uses refusal ablation, a technique that has become increasingly visible in the local-model community.
PewDiePie says he used Heretic, which Popular AI previously covered as a general-purpose way to reduce model refusals. Heretic is an open-source tool built to alter refusal behavior in transformer models without retraining the model from scratch.
The method goes deeper than changing a system prompt. A hosted chatbot can refuse because of product-level moderation, system instructions, API policy, or behavior already trained into the model. Running a model locally removes the provider-controlled layers, but it does not automatically remove refusal tendencies encoded in the weights.
Heretic targets those model-level tendencies. Its implementation uses directional ablation, sometimes called abliteration, to identify refusal-associated directions and modify selected transformer weights. Heretic also optimizes parameters by trying to reduce refusals while limiting divergence from the original model.
That tradeoff is important. Refusal behavior is not stored in one neat switch that can be turned off without touching anything else. Changing internal representations can damage unrelated capability. Heretic tries to control that damage by minimizing refusals while keeping the modified model as close as possible to the original model’s behavior, but model quality still has to be evaluated in practice.
PewDiePie makes the same point more colorfully in the announcement, joking that the process can give a model “brain damage.” He says Ajax was ablated selectively and that he chose to retain restrictions around requests involving harm to other people or harm to the user.
Ajax therefore looks less restricted, not literally refusal-free. That description is less flashy than “uncensored,” but it is more precise and more useful when deciding what the model is actually supposed to do.
More on Heretic:
Ajax also went through reinforcement training
Ajax was not created by running Qwen through an ablation tool and putting a new name on the result.
PewDiePie says he spent weeks running GRPO reinforcement training on Odysseus tasks. In his account, the model repeatedly attempted the same kinds of tool tasks, and successful runs became useful training signals. He also describes synthesizing additional tasks after exhausting the original task set.
That work follows months of earlier dataset collection. In June, PewDiePie described gathering successful Odysseus traces covering documents, email, notes, calendars, research, files, and other tool calls. He initially hoped to collect tens of thousands of real user samples, received much less than expected, and increasingly relied on generated data that could be filtered into useful training examples.
This part of Ajax may prove more valuable than the “uncensored” label. Plenty of downloadable models already refuse fewer prompts than mainstream hosted assistants. A model trained to use one particular local agent environment reliably has a clearer job and a more practical test.
The release should show whether that training produced a measurable improvement over the unmodified Qwen3.5-9B base model on the same Odysseus workflows.
PewDiePie says OpenAI banned him twice while building Ajax
The announcement includes a revealing side story about dependence on hosted AI.
PewDiePie says he wanted to use output from an OpenAI model as part of his seed-data process. He discusses model distillation, hidden reasoning, and a method he found for extracting more information from an OpenAI model. He also jokes repeatedly about conduct that he says would violate the terms. In the same announcement, he says OpenAI banned his account, restored it after an appeal, and later banned it again.
The reason for those enforcement actions has not been independently confirmed. His account of what happened should not be treated as an official explanation from OpenAI.
The contractual control point is easier to verify. OpenAI’s consumer terms prohibit automatically or programmatically extracting output and using output to develop models that compete with OpenAI. Its business agreement separately restricts customers from using output to develop competing AI models, outside stated exceptions.
That creates a practical difference between hosted and local models. A hosted model may be more capable, but access remains conditional. The provider controls the account, API, monitoring systems, usage rules, rate limits, and enforcement.
Once a downloadable model is on your own machine, an account suspension is no longer part of the inference path. You still have to answer legal, licensing, and contractual questions about how training data was obtained. Local inference simply removes one outside control point from everyday operation.
Can you run Ajax on a normal PC?
Probably on a reasonably capable one, but the final answer has to wait for the actual Ajax files.
Ajax is based on Qwen3.5-9B. Qwen’s model card lists 9 billion parameters, a native context length of 262,144 tokens, and a vision encoder.
The current vLLM recipe puts Qwen3.5-9B at roughly 22GB minimum VRAM for BF16 and 11GB for FP8. That puts BF16 or FP8 operation within reach of a single consumer or workstation GPU rather than a rack of accelerators.
Quantization should lower the memory requirement further. PewDiePie said during development that he wanted a 9B-class model with a Q4 release aimed at broader local use. The same Odysseus discussion names GGUF, llama.cpp, vLLM, BF16, FP8, and Q4 as deployment targets.
Ajax itself is not downloadable yet, so there is no point pretending we know which GGUF, AWQ, FP8, MLX, or other formats will appear with the release. Development targets are not the same thing as released files.
Long context also changes the hardware calculation. Getting the weights into VRAM is only the first step. KV cache, tool context, documents, and long conversations consume additional memory. “It fits” and “it runs comfortably at the context length I need” are different tests.
For now, 12GB-to-24GB GPU owners look like the obvious target audience. Users with less VRAM may still get workable quantized or CPU-offloaded options once the release files appear, but that cannot be confirmed until Ajax is actually available.
“Completely private” needs one qualification
The Ajax page says the model can handle search, web browsing, email, and calendar work “completely privately” through Odysseus.
Local inference can be private in a way hosted model inference is not. If Ajax runs on your own machine, a model provider does not need to receive every prompt and local document simply to generate the next token.
An agent still has to contact outside services when the task requires them. It cannot fetch a public website without making a network request. It cannot read Gmail, sync a remote calendar, or send an email without communicating with the relevant service.
Odysseus reflects this split. Its configuration supports local model hosts and local services while also allowing external providers and network integrations. The project’s security guidance tells operators to keep raw model services internal, protect tokens, restrict powerful agent tools, and avoid exposing Odysseus publicly without authentication.
The useful privacy claim is therefore specific: Ajax can keep model inference and local context under your control, while external services still receive whatever information their integration requires.
That can still be a substantial privacy improvement. It removes the cloud AI account as the mandatory middleman for every model interaction, but it does not turn email providers, websites, calendars, or other network services into local software.
There are no Ajax benchmarks yet
PewDiePie says an early Ajax version was completing its intended tasks roughly nine times out of ten. He also describes weeks of continued reinforcement training afterward.
That is useful development feedback, but not a reproducible benchmark.
The tests worth watching are straightforward: tool-call success rate, malformed calls, recovery after failed tools, harmless-task regression after ablation, refusal behavior, instruction following, hallucination rate, long-context reliability, and ordinary reasoning outside the Odysseus workflow.
Independent testing will be more useful than a single internal success number. The central comparison should be Ajax against unmodified Qwen3.5-9B on the same Odysseus tasks, using the same tools and hardware.
There is no reason to assume a specialized 9B model will beat the strongest cloud models across general reasoning, coding, or research. It does not have to. If Ajax handles common personal-agent tasks reliably while fitting on affordable local hardware, that already gives it a useful reason to exist.
Ajax’s license is still an open question
The underlying Qwen3.5-9B repository is published under Apache 2.0, and its configuration page identifies the repository license as Apache 2.0.
Odysseus is separate software. Its current repository uses the AGPL-3.0-or-later license.
Ajax is a separate artifact again. The coming-soon page does not yet state what license will govern the fine-tuned Ajax weights. It also does not identify a public model repository, exact download formats, redistribution terms, or commercial-use conditions.
Those details need to be checked when the weights are released. Calling Ajax open source before seeing the actual Ajax license would be premature, even though its base model and surrounding workspace already have their own licenses.
Who should try Ajax first
Ajax looks most interesting for people already exploring local AI, self-hosted models, and private workflows, especially users who are already interested in Odysseus.
▪ The best-case user has a decent local GPU, wants an agent that can work with personal tools, prefers to keep more context off hosted model accounts, and finds policy-driven refusals disruptive during ordinary use. Ajax is being built for exactly that kind of workflow.
▪ People looking for the strongest possible coding model, deep-reasoning model, or production-critical automation should wait for benchmarks. A specialized 9B model makes a different trade. It may be fast and convenient inside Odysseus without becoming the right answer for every other workload.
▪ Anyone giving a local agent access to shell commands, files, email, calendars, or account tokens should also take the surrounding security setup seriously. Local ownership removes one set of gatekeepers. It does not protect you from a badly configured agent with too much access.
For a broader explanation of downloadable models, licenses, local restrictions, and the difference between “open,” “local,” and “uncensored,” Popular AI’s guide to open-source and open-weight local LLMs covers the terminology and tradeoffs in more detail.
More on self-hosted AI:
What to check when Ajax releases
The October 3 release should answer most of the questions that this announcement cannot.
The useful things to inspect are the exact base checkpoint, Ajax license, quantizations, supported runtimes, hardware targets, training summary, Odysseus tool schema, evaluation results, context behavior, and any capability lost during refusal ablation. Those are the details that turn a launch video into something people can actually evaluate.
The most interesting comparison will probably be Ajax against unmodified Qwen3.5-9B inside the same Odysseus tasks. If Ajax is only less likely to refuse, it enters a crowded field of local models and modified checkpoints that already compete on that behavior.
If Ajax is measurably better at operating the Odysseus workspace on modest hardware, the project becomes more useful. Tool reliability is harder to market than “uncensored AI,” but it is the part that could save users time every day.
Ajax has to prove the Odysseus specialization works
The research ingredients behind Ajax are familiar: Qwen weights, supervised fine-tuning, reinforcement learning, tool-use data, and refusal ablation.
The product choice is more unusual. PewDiePie is betting that an everyday local AI agent should be small enough to run on hardware users can own, trained for the software it actually operates, and difficult for an outside platform to switch off.
Ajax will not prove that thesis until the weights, license, formats, and evaluations arrive.
If it does, Ajax will be more interesting than another “uncensored” model. It will be a test of whether a focused 9B local agent can make a full self-hosted workspace work better on hardware people already own.
Explore more from Popular AI:
Start here | Local AI | Builds & gear | Autonomy & policy | Fixes & guides | Popular AI podcast












Would you trade a smarter cloud AI for a smaller local model that runs privately on your own hardware and actually handles your daily tasks?