Ox Alpha's Censorship Is a Switch, Not a Tilt—and Its Fingerprint Points to GLM-5
Behaviorally fingerprinting Ox Alpha's provenance

CTGT's analysis of Ox Alpha, a model that appeared on OpenRouter in August, confirms community speculation that it belongs to the GLM family. Using tokenizer probes and API behavior, they match it to the GLM-5 line with 11-of-11 vocabulary overlap. More striking is the censorship profile: unlike DeepSeek's broad tilt, Ox Alpha censors only 7 topics—all domestic political risks—while answering freely on Xinjiang and Taiwan. The model's responses on Xi Jinping and domestic legitimacy are statistically indistinguishable from the most censored model tested, yet it appears uncensored on foreign-interest topics. This 'switch' pattern suggests a blacklist approach, not general evasiveness.
Its censorship is a switch, not a tilt.
- nijave
Error messages matching Z.ai GLM I think are the simplest/most compelling. I had Opus 4.8 poke it and it came back with a couple different errors than the article mentions.
Matching the tokenizer is interesting tho
- dang
Recent and related:
Ox-Alpha Is GLM? - https://news.ycombinator.com/item?id=49422226 - Aug 2026 (65 comments)
A mysterious free AI model is impressing developers. Nobody knows who made it - https://news.ycombinator.com/item?id=49406289 - Aug 2026 (4 comments)
Ox Alpha - https://news.ycombinator.com/item?id=49381896 - Aug 2026 (202 comments)
- johndough
Another strong hint is that the uptime graph of GLM-5.3 by Z.ai is very similar to that of Ox Alpha:
https://openrouter.ai/stealth/ox-alpha#uptime
https://openrouter.ai/z-ai/glm-5.3#uptime
Screenshot of a recent blip: https://files.catbox.moe/haq90y.png