Ox Alpha's Censorship Is a Switch, Not a Tilt—and Its Fingerprint Points to GLM-5

Behaviorally fingerprinting Ox Alpha's provenance

Ox Alpha's Censorship Is a Switch, Not a Tilt—and Its Fingerprint Points to GLM-5

CTGT's analysis of Ox Alpha, a model that appeared on OpenRouter in August, confirms community speculation that it belongs to the GLM family. Using tokenizer probes and API behavior, they match it to the GLM-5 line with 11-of-11 vocabulary overlap. More striking is the censorship profile: unlike DeepSeek's broad tilt, Ox Alpha censors only 7 topics—all domestic political risks—while answering freely on Xinjiang and Taiwan. The model's responses on Xi Jinping and domestic legitimacy are statistically indistinguishable from the most censored model tested, yet it appears uncensored on foreign-interest topics. This 'switch' pattern suggests a blacklist approach, not general evasiveness.

Its censorship is a switch, not a tilt.
  1. nijave

    Error messages matching Z.ai GLM I think are the simplest/most compelling. I had Opus 4.8 poke it and it came back with a couple different errors than the article mentions.

    Matching the tokenizer is interesting tho

  2. dang

    Recent and related:

    Ox-Alpha Is GLM? - https://news.ycombinator.com/item?id=49422226 - Aug 2026 (65 comments)

    A mysterious free AI model is impressing developers. Nobody knows who made it - https://news.ycombinator.com/item?id=49406289 - Aug 2026 (4 comments)

    Ox Alpha - https://news.ycombinator.com/item?id=49381896 - Aug 2026 (202 comments)

  3. johndough

    Another strong hint is that the uptime graph of GLM-5.3 by Z.ai is very similar to that of Ox Alpha:

    https://openrouter.ai/stealth/ox-alpha#uptime

    https://openrouter.ai/z-ai/glm-5.3#uptime

    Screenshot of a recent blip: https://files.catbox.moe/haq90y.png

More from this day

2026-08-25