YouTuber Felix Kjellberg, known as PewDiePie, says OpenAI banned his account twice while he built Ajax, a fine-tuned open model for his self-hosted AI workspace. By his account, OpenAI banned him, restored access after an appeal, then banned him again. He says the trigger was trying to use an OpenAI model's output to seed training data and distill its reasoning. Social posts put it more bluntly as "banned for distilling Sol." OpenAI has not publicly confirmed the reason, and we could not open the primary sources, so this post separates what is reported from what is inferred.
It matters beyond celebrity gossip. It lands days after OpenAI described a Moonshot-linked reasoning-extraction campaign, and it tests a question many open-model builders have been quietly asking: where is the line between learning from a frontier model and stealing from it?
TL;DR: the questions people asked
| Question | Answer |
|---|---|
| What happened? | PewDiePie says OpenAI banned him twice over his Ajax work, with one restore after appeal |
| What is Ajax? | A Qwen3.5-9B fine-tune for his Odysseus workspace, built as an always-on local agent |
| Why was he banned? | His account: he tried to seed training data from an OpenAI model's output and distill its reasoning. OpenAI has not confirmed |
| Was it Sol? | Posts say Sol; sources we could read say only "an OpenAI model". Unconfirmed |
| Did he hack anything? | One unverified social post claims he used an exploit to decrypt reasoning tokens. No source we found confirms it |
| Is distillation banned? | OpenAI's terms bar using output to develop competing models and circumventing protective measures |
| Does this affect my API use? | Only if you train models on outputs or touch reasoning protections |
What is Ajax, and why was he building it?
Ajax is the model, Odysseus is the product. Odysseus is a self-hosted AI workspace with agentic features, deep research, coding tools, and email and calendar integration, all designed to run on your own hardware as a privacy-first alternative to hosted chat apps.
Per the reporting, Ajax is a fine-tune of Qwen3.5-9B meant to behave as an always-on agent: web search, browsing, email, and calendar handled privately and locally. Its refusal behavior has been ablated, which is what makes it "de-censored" in press descriptions. A 9B model is small enough to run on a good consumer GPU or a Mac, which is the point.
The weak spot of any small model is reasoning quality, and that is where the temptation comes in. A teacher model's step-by-step reasoning is the most valuable training signal there is, because it shows the student how to think, not just what to answer. That is exactly what frontier labs now hide or encrypt.
What does PewDiePie say OpenAI did?
Reports of his statement say:
- OpenAI banned his account while he worked on Ajax.
- It was restored after an appeal.
- It was then banned again.
- He had wanted to use an OpenAI model's output to seed training data, and discussed distilling its reasoning.
- He suggests OpenAI was sensitive to attempts to distill reasoning tokens.
Those are his claims about his own account. OpenAI has not published a statement about it, and enforcement notices to individual users are rarely public. The accurate framing is "he says," not "OpenAI banned him for distillation," even though the second is the headline everyone will repeat.
One more thing to keep straight: a post on X claimed PewDiePie "used an exploit to decrypt reasoning tokens." Another said he was "banned by OpenAI for distilling Sol." Neither is a primary source, and the first goes well beyond what the reporting we found says. We are flagging them as unverified, not repeating them as fact.
Why is reasoning the thing OpenAI protects?
Frontier labs treat chain-of-thought as the crown jewel for three reasons: it is what makes reasoning models better, it is expensive to produce, and it is the cheapest possible training data for a competitor. That is why OpenAI and Anthropic return summaries or encrypted blocks instead of raw reasoning.
The research context is concrete. In August, researchers showed that encrypted reasoning blocks can be replayed across sessions and models, letting a weaker model decode a stronger one's hidden thoughts. OpenAI's own account of the Moonshot-linked campaign describes the same pattern: operators copied encrypted reasoning from one conversation and asked the model in another to decode and transcribe it. OpenAI said the encryption was not broken and no stored conversations were accessed, and it labeled the technique adversarial distillation: the unauthorized harvesting of one model's outputs or reasoning to build a competing model.
According to the same reporting, activity began July 1, spiked July 24 and 25 with more than 4,000 users sending 16,000 requests, and was halted by July 28, with OpenAI publishing its account on September 30. Against that backdrop, any user whose traffic looks like reasoning harvesting is likely to trip automated defenses, whatever their intent.
Is this the same as the Moonshot case?
No evidence says so. The two stories share a vocabulary but not a scale or an intent:
| Moonshot-linked campaign | PewDiePie's case | |
|---|---|---|
| Actor | Operators OpenAI links to Moonshot AI associates | One creator building a personal local model |
| Scale | Thousands of users, 16,000 requests in two days | Unknown, likely small |
| Method (per OpenAI) | Replay encrypted reasoning, ask model to decode | Not confirmed |
| Goal | Build a competing model | Seed training data for a 9B fine-tune |
| OpenAI statement | Published September 30 | None found |
The uncomfortable part is that automated enforcement does not distinguish between them. If the signal is "this account is pulling reasoning-like output at scale and it looks like a training pipeline," a small independent builder and a state-adjacent lab can look similar from the server side. That is also why developers have been posting for months about accounts banned for "distillation" with little or no human reply.
What are the actual rules?
OpenAI's terms state that you may not use output to develop models that compete with OpenAI, and may not circumvent rate limits, restrictions, or protective measures. Anthropic, Mistral, and xAI have comparable anti-competitive-distillation clauses.
Three consequences for builders:
- "Competing" is vague. A hobbyist's 9B fine-tune is not an obvious competitor, but the clause does not carve out hobbyists, and enforcement is OpenAI's call.
- Circumvention is the sharper line. Anything that tries to recover hidden reasoning, such as replaying encrypted blocks, is more clearly a violation than training on ordinary visible answers.
- Accounts are the penalty. The practical risk is losing your account, API keys, or organization access, not a lawsuit.
There is a live policy argument that the rules are wrong. Y Combinator's Garry Tan has argued for an American distillation regime that would let domestic open-weight labs train on frontier outputs. Meanwhile the White House has been treating foreign distillation as a security issue, as in the Moonshot and Claude distillation coverage and the Jensen Huang distillation interview. Our explainer on what AI distillation is covers the technique itself, and Proxy-KD covers how black-box distillation works without access to weights.
What should open-model builders do instead?
If you are fine-tuning a small model and want reasoning data, here is the order we would try:
- Use open-weight teachers with permissive licenses and generate your own traces. Check the license for output-use restrictions.
- Use public reasoning datasets whose licenses allow training.
- Generate synthetic data with your own pipeline, then filter by verifiable correctness for math and code.
- Use reinforcement learning with verifiable rewards rather than imitation.
- If you must use a closed API for data, read the terms for your provider, keep volumes small and visible answers only, and never attempt to recover hidden reasoning.
- Keep keys and orgs separate so a ban on an experiment does not take down production.
Ajax's own path is a reminder that open models are catching up fast without needing closed teachers; see how Odysseus fits into the broader local-model ecosystem.
Questions people are asking
Will OpenAI ban anyone who trains on its outputs?
Not automatically. The terms prohibit it, but enforcement depends on detection and discretion. Do not read the absence of a ban as permission.
Is it fair?
That is the argument. Critics point out that frontier labs trained on scraped public data; labs reply that outputs and reasoning from their own paid models are a different asset. Garry Tan's view and OpenAI's view are on opposite sides of that.
What if my account was banned by mistake?
Appeal in writing, document your usage, and expect delays. Developer forum threads show multi-week waits with few responses, and PewDiePie's account suggests an appeal can work and still be undone.
Honest limitations of this post
- We could not open the original reporting or PewDiePie's own statement, so details come from search summaries. Verify before quoting.
- OpenAI has not confirmed the reason for either ban.
- The model (Sol) is unconfirmed in the sources we read.
- The decryption-exploit claim is unverified and we do not endorse it.
- Moonshot facts come from OpenAI's account as relayed by news outlets.
Related reading
- What is AI distillation? Knowledge transfer explained
- Stealing reasoning traces from frontier APIs
- Odysseus: the self-hosted AI workspace
- Garry Tan's American distillation regime
- White House, Moonshot AI, and Claude distillation
- Jensen Huang on distillation and competition
- Proxy-KD: black-box distillation
- GPT-6.1 Sol launch and pricing
Details are accurate as of October 2, 2026 and based on search summaries of news reports and OpenAI's public account of the Moonshot case.
