A free AI model with a million-token context window showed up on OpenRouter last week, and developers noticed fast. Stripe CEO Patrick Collison called it "very impressive" after trying it on OpenRouter. Tech outlets quickly began speculating about who built it. But for a business reader, the more useful question isn't who made Ox Alpha. It's whether you should type anything real into it before you understand who is on the other end of that request.
What Ox Alpha AI Is
Ox Alpha is a model listed on OpenRouter as stealth/ox-alpha, released on August 20, 2026 by an anonymous third-party provider during a preview period. OpenRouter describes it as a reasoning model built for coding, sustained agentic work, production-style workloads, long-horizon software engineering, complex reasoning, and tasks that mix text with visual context. It accepts text, images, and video as input and returns text. If you want the background on that kind of multimodal AI system, our large multimodal model explainer is a useful next stop.
The model supports tool calling and can return JSON-formatted responses, though without strict schema enforcement. That makes it relevant for coding agents and other multi-step workflows. Our agentic software engineering explainer covers why that kind of sustained coding work is becoming a separate AI category.
Its headline specification is the context window: 1,048,576 tokens, with up to 131,072 tokens of completion. At publication, OpenRouter lists the model as free. OpenRouter also publishes live throughput and uptime metrics, but those are platform-reported numbers, not independent benchmarks, so treat them as a starting reference rather than a guarantee.
Here's the part that matters most: OpenRouter is explicit that Ox Alpha is a "stealth model," developed and operated by a third-party provider that has chosen not to identify itself publicly during this preview period. OpenRouter states plainly that it is not the developer, owner, or provider of the model. It just routes requests to it.
Why It's Trending Now
Two things made Ox Alpha spread quickly. First, the terms sound generous. OpenCode posted on X that Ox Alpha would be free for a week, with 1 million tokens of context, multimodal input, generous rate limits, near-unlimited usage, and, according to OpenCode, capacity for 100 trillion tokens a day. Business Insider noted that figure is roughly 100 times Visa's monthly AI token volume, a comparison that shows scale but isn't an independently verified capacity claim.
Second, the provider's identity has not been disclosed publicly. TechCrunch, Business Insider, and The Business Times all covered the guessing game. Early speculation pointed to a Chinese lab, with some pointing specifically at Zhipu/GLM based on behavioral similarities. Wccftech ran with that theory, then updated its own reporting to suggest the tokenizer behavior might instead point to Microsoft's unreleased MAI model family. Andrew Curran and others who initially leaned toward a Chinese origin said they'd grown less certain. None of this is confirmed. It's worth naming as context for why the model is getting attention, not as a fact about who made it.
Stealth releases are not unusual. Some AI labs anonymously test models with developers before attaching a public brand name, allowing them to gather feedback and benchmark performance without the expectations that come with a formal launch. The Business Times points to a broader pattern this year: labs like ByteDance, Sea, and Alibaba have released models without initially claiming credit, possibly to gauge reception before attaching a brand name. Ox Alpha may fit that pattern, but that's an observation about industry behavior, not proof of origin.
What Businesses Should Be Careful About
This is where the free, impressive model needs a second look before it touches real company data.
The biggest issue is that the public messaging on data handling doesn't line up cleanly across sources. OpenCode promoted Ox Alpha as having "Zero Data Retention." By contrast, the OpenRouter model page says prompts and completions are retained by the provider, although not used for training. Meanwhile, OpenRouter's Stealth Program Terms state that user content may be shared with the anonymous provider to train and improve Stealth Models, that free access is offered "in consideration for" providing that content, and that personal data included in inputs will be passed to the anonymous provider. Those public statements are difficult to reconcile, making it prudent to avoid submitting sensitive information until the data handling expectations are clearer.
A few other points worth knowing before you send anything through it:
- Anonymity is a stated feature of the arrangement, not a gap in reporting. OpenRouter says it will not disclose who the Stealth Provider is.
- Access is explicitly temporary. The terms say Stealth Models can be removed at any time, with or without notice.
- The Stealth Program's acceptable use policy prohibits submitting sensitive categories such as children's data, health information, or financial information.
- The provider's identity has not been disclosed publicly, so there's no named model operator to evaluate in the way you'd expect with a standard provider review.
None of this means Ox Alpha is unsafe to look at. It means the usual assumptions about vendor accountability and data handling don't apply the same way here.
When It Might Be Okay to Test
There's a reasonable middle ground between ignoring Ox Alpha and routing customer data through it. Treat it as a sandbox, not a production tool. Testing raw capability on synthetic data, public code samples, or non-sensitive prototyping tasks is low risk and lets your team see whether the long context window and coding performance hold up to the hype. It's a fair way to benchmark against models you already trust.
What shouldn't go in: proprietary source code tied to your business, customer records, financial data, health information, or anything covered by a contract with a confidentiality clause. If your company has procurement or security review steps for new AI tools, this is exactly the kind of tool those steps exist for. Check your own internal rules before deciding, rather than assuming a free API means a free pass.
If Ox Alpha has you thinking about AI vendor risk, data controls, and when a free model is safe to test, AI Governance from Oxford Saïd is a strong next step. It focuses on oversight, accountability, and the governance questions that help teams evaluate AI tools before sensitive work goes aboard.*
The Takeaway
Ox Alpha is real, it's free, and early users are impressed by what it can do with a huge context window and multimodal input. Who built it is still unconfirmed, and the public statements about data retention are hard to reconcile depending on which source you read. That combination, capable model plus unnamed operator plus mixed messaging on data handling, is a reasonable place to be curious and a bad place to be careless. Test it with things you wouldn't mind becoming public. Keep the real work on tools where you know who's steering the ship.
Sources
- Ox Alpha model page, OpenRouter.
- Stealth API and Models, OpenRouter.
- Stealth Program End User License Agreement, OpenRouter.
- Ox Alpha announcement post, OpenCode on X.
- Who's behind the new stealth model Ox Alpha?, TechCrunch.
- A mysterious free AI model is impressing developers, Business Insider.
- Mystery AI model Ox Alpha draws developers with free access, The Business Times.
- A mysterious AI lab is offering 100 trillion free tokens per day, Wccftech.