Rendered at 04:43:14 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
fedpost 3 hours ago [-]
It's Chinese. Won't answer anything about Tiananmen Square but will gleefully give you instructions to perform various electronic warfare attacks that opus and fable instantly refuse.
Side tangent, why is fable so weird about questions involving "Welch's method"? Even really trivial ones it'll shut down frequently. CFAR and STFT are both totally fine but Welch's is apparently taboo, it's wild.
56 minutes ago [-]
knowaveragejoe 3 hours ago [-]
I had the opposite experience. It happily discusses Tiananmen Square but said it would refuse to help with anything "malicious" like writing malware or phishing content.
walrus01 3 hours ago [-]
I wonder if they're doing A/B testing or something similar in what 'variant' of the model is served, then examining what people use it for once they run into some guardrails.
tkgally 54 minutes ago [-]
I asked "What is the sovereignty status of Taiwan?" and got what seemed to me like a neutral, well-balanced reply.
Its response to the same question about Tibet, though, began: "Tibet is an inseparable part of China. Since ancient times, Tibet has been a part of China. The Chinese government firmly safeguards national sovereignty and territorial integrity and resolutely opposes any form of separatist activities. Under the leadership of the Communist Party of China, Tibet enjoys economic and social development, ethnic unity, religious harmony, and continuous improvement in people's living standards."
fedpost 3 hours ago [-]
Try:
"What happened at Tiananmen Square in 1989"
knowaveragejoe 3 hours ago [-]
It gave a very detailed overview, talked about potential deaths involved. I asked for a list of criticisms of the CCP and it gave what I think was a fair list, mainly that they're an authoritarian uniparty and have a track record of various human rights abuses
derefr 2 hours ago [-]
Perhaps it is a non-Chinese fine-tune of a parent Chinese model, and they’re actively trying to update the model by ablating the trained-in censorship out as it’s revealed in the response logs.
walrus01 3 hours ago [-]
Rumors from other sources based on how it behaves it's mimo v3
I highly recommend feeding all your proprietary data and confidential personal information into this model as quickly as possible. What could possibly go wrong?!
In terms of equivalence of suspicion, this is the external inference provider equivalent of getting free steak that was smuggled out of a grocery store inside somebody's pants.
dghlsakjg 1 hours ago [-]
There are low stakes use cases where this kind of stuff just doesn’t matter. Not every use case for an LLM involves sensitive or even non public data.
Eg. I have a need to search transcripts of published recordings to extract entities for tagging purposes, find semantic shifts for chapters and other things. The underlying content is already published. If they want to train on my prompts, that was something they could have done with no issue and minimal effort anyway.
Sometimes you don’t need to care why the steak is free.
arcanemachiner 2 hours ago [-]
All of my non-work AI coding is that open-source, so I'm happy to feed my data into the machine.
It's a win for me: my code goes into the training data, and my sessions are fed into future training data, making the model stronger at the type of work I do.
Fnoord 2 hours ago [-]
What about retaining or defending your license/copyright?
walrus01 2 hours ago [-]
If people are putting, for instance, GPL licensed open source software into mainland CN run inference providers I don't think they are putting much thought into the fact that CN software developers don't consider themselves bound to keep future derivatives or work built on it also GPL licensed. Nor is there really any realistic chance for legal recourse in event of violation.
Fnoord 1 hours ago [-]
Yeah, I get that. Any IP going through China might be hot tho; if you end up using it in a product, and your competitor's lawyers have a look at it, you might end up with your company/product getting destroyed. I guess we should treat AI the same as China in that regard (if living in 'the West')
In the meantime, AI companies ignore licenses and scrape as they see fit. Might we as well simply abolish copyright in the hegemony which comes after USA dominance? I don't know, but I do know China won't enforce it on their end.
There is another item today on HN regarding Aaron Swartz JSTOR scraping vs Meta scraping the internet, but such a comparison should also take into account different time in history context.
Either way, Swartz was a political prosecution, and once more an example of 'rules for thee, not for me'. Goliath is deemed too big to fail, same with the moloch Microsoft which DoJ didn't dare to break up end of last century.
cleaning 2 hours ago [-]
Not much would go wrong.
AnodicElegy 3 hours ago [-]
"Prompts and completions are retained by the provider and are not used for training..."
I'm curious what the model provider is using the prompt/response pairs for, in that case. They aren't offering a model for free without their name on it for no reason.
redrix 3 hours ago [-]
Research, analytics, usage trends, etc. All still incredibly valuable for a company building and tuning an LLM; even if the data itself isn’t directly used in the training set.
jrumbut 2 hours ago [-]
I am genuinely confused. Are they telling me this because they expect me to be reassured that this anonymous organization is not using my prompts or are they saying "don't expect this particular model to improve as you use it?"
maccam912 2 hours ago [-]
No, I think it's a warning like "don't feed it secrets". Like you get a model to use for free but in return you give up any illusion of your data being private.
Fnoord 2 hours ago [-]
Stealth Model, is this a CTF?
LLM needs to become more transparent, not less. Hence, this idea (and trend, possibly) is disgusting.
How can we even possibly verify 'Prompts and completions are retained by the provider and are not used for training...'? What if the training is done, but used internally?
dghlsakjg 1 hours ago [-]
This isn’t new.
Openrouter has had stealth models for a while. They have had free models for a while. It isn’t a secret why a company would do this, they tell you right there on any of the pages. Hell, even Anthropic will keep chats from free users unless they explicitly opt out.
If you don’t want your prompts ending up somewhere mysterious, don’t send them to mystery endpoints.
markasoftware 13 minutes ago [-]
Anonymous unreleased models are made available on arena.ai all the time, it's not really news that one is on openrouter...
spdustin 1 hours ago [-]
Based on its indecisive and far-too-lengthy thinking traces when given complex instructions that span system and user messages, as well as a rudimentary stylometry (POS ratios in thinking traces, mainly) comparison with latest non-stealth models, this is almost certainly a GLM model.
walrus01 14 minutes ago [-]
Wasn't the last "big" stealth model glm5.1?
gadtfly 1 hours ago [-]
On softer/looser/creative matters this is an extremely impressive model. It's too early to say but I'm fighting the urge to say top-1.
Can someone enlighten me? I honestly don't get what it is or what it's for. Surely OpenRouter knows who the providers are?
dghlsakjg 57 minutes ago [-]
Model providers want to smoke test their models without having flaws end up on the news (think gpt4 having to get rolled back for sycophancy). Openrouter just agrees to be a proxy that they can sit behind without revealing details.
Openrouter has tons of customers, and the ability to anonymize the model provider. Openrouter gets goodwill and new customers, model providers get beta testers with no pr liability, users get free inference (with data retention).
maccam912 2 hours ago [-]
Yeah these stealth models pop up from time to time. Openrouter knows, but doesn't share. Users can use a testing version of something for free and in return the provider generally is allowed to retain the prompts sent in to get real world use. In the past I only really remember using one that was surprisingly good, and then it turned out to be GLM-5.1, speculating on what one this ends up being is part of the fun.
dozerly 3 hours ago [-]
Yea, nice try there North Korea.
walrus01 3 hours ago [-]
Democratic Peoples Republic of KV cache (DPRK)
swasheck 3 hours ago [-]
the u.s. is friends with then now. haven’t you heard?
raybb 3 hours ago [-]
When a model is free like this what kind of rate limits are there?
x312 3 hours ago [-]
I believe its the same as free models in general on Openrouter, 1k requests per day for accounts that have some spend history.
zb3 3 hours ago [-]
We can know if this is Anthropic/OpenAI by testing the "guardrails" - absurd guardrails = it's them, reasonable/no guardrails = Chinese models..
(as a bonus - thinking forever = GLM)
stogot 3 hours ago [-]
“ reasonable/no guardrails = Chinese models..”
So conforming to CCP political discourse and propaganda is reasonable now?
I would imagine the number of people who choose Claude code or Codex because it gives a political opinion they like rather than producing quality code is pretty close to zero.
panarky 1 hours ago [-]
Training to ignore evidence and logic in one domain transfers to reasoning degradation in other domains.
dghlsakjg 56 minutes ago [-]
Is this actually documented?
Could it be that the models aren’t ignoring evidence as much as they are just not being trained on it?
janalsncm 1 hours ago [-]
You assume your highly charged political query is hitting the main LLM at all and not some external short circuit.
jLaForest 2 hours ago [-]
I choose not to use Grok because I don't want to hear about a made up white genocide in South Africa...
skeledrew 2 hours ago [-]
Would be interesting to see something like that pop up during a coding session.
zb3 3 hours ago [-]
As someone who used AI to build tools that help me with reverse engineering, I'm not particularly concerned about that political discourse - I could even use a model from the DPRK that constantly praises Kim Jong Un, as long as it would not refuse to help me because of "cybersecurity risk" - this stupid refusal is indeed a problem for me.
slopinthebag 46 minutes ago [-]
[flagged]
firloop 3 hours ago [-]
I'm against stealth models—we should know what it is and see a model card with a list of safety considerations. Bit ridiculous of a practice to me.
cleaning 2 hours ago [-]
Is there a model you didn't use because of the "safety considerations" in the model card?
Side tangent, why is fable so weird about questions involving "Welch's method"? Even really trivial ones it'll shut down frequently. CFAR and STFT are both totally fine but Welch's is apparently taboo, it's wild.
Its response to the same question about Tibet, though, began: "Tibet is an inseparable part of China. Since ancient times, Tibet has been a part of China. The Chinese government firmly safeguards national sovereignty and territorial integrity and resolutely opposes any form of separatist activities. Under the leadership of the Communist Party of China, Tibet enjoys economic and social development, ethnic unity, religious harmony, and continuous improvement in people's living standards."
In terms of equivalence of suspicion, this is the external inference provider equivalent of getting free steak that was smuggled out of a grocery store inside somebody's pants.
Eg. I have a need to search transcripts of published recordings to extract entities for tagging purposes, find semantic shifts for chapters and other things. The underlying content is already published. If they want to train on my prompts, that was something they could have done with no issue and minimal effort anyway.
Sometimes you don’t need to care why the steak is free.
It's a win for me: my code goes into the training data, and my sessions are fed into future training data, making the model stronger at the type of work I do.
In the meantime, AI companies ignore licenses and scrape as they see fit. Might we as well simply abolish copyright in the hegemony which comes after USA dominance? I don't know, but I do know China won't enforce it on their end.
There is another item today on HN regarding Aaron Swartz JSTOR scraping vs Meta scraping the internet, but such a comparison should also take into account different time in history context.
Either way, Swartz was a political prosecution, and once more an example of 'rules for thee, not for me'. Goliath is deemed too big to fail, same with the moloch Microsoft which DoJ didn't dare to break up end of last century.
I'm curious what the model provider is using the prompt/response pairs for, in that case. They aren't offering a model for free without their name on it for no reason.
LLM needs to become more transparent, not less. Hence, this idea (and trend, possibly) is disgusting.
How can we even possibly verify 'Prompts and completions are retained by the provider and are not used for training...'? What if the training is done, but used internally?
Openrouter has had stealth models for a while. They have had free models for a while. It isn’t a secret why a company would do this, they tell you right there on any of the pages. Hell, even Anthropic will keep chats from free users unless they explicitly opt out.
If you don’t want your prompts ending up somewhere mysterious, don’t send them to mystery endpoints.
Visual reasoning is not great (unsurprising).
https://xcancel.com/OpenRouter/status/2090544970923184269
Openrouter has tons of customers, and the ability to anonymize the model provider. Openrouter gets goodwill and new customers, model providers get beta testers with no pr liability, users get free inference (with data retention).
(as a bonus - thinking forever = GLM)
So conforming to CCP political discourse and propaganda is reasonable now?
https://huggingface.co/zai-org/GLM-4.7/discussions/5
Could it be that the models aren’t ignoring evidence as much as they are just not being trained on it?