PewDiePie has announced Ajax, an AI model designed to handle everyday tasks on a home PC. It is Alibaba's "Qwen3.5-9B" with additional training, optimized for tool use in Odysseus, the AI workspace he is developing, and it is also said to be tuned to refuse fewer requests. However, as of October 3, 2026, the official page no longer shows a countdown and instead says the model will be released "when it's ready," so we cannot confirm that distribution has begun.
Ajax aims to let a local AI take over everyday tasks such as search, email, and calendar management. What matters here is not only whether it can answer a wide range of questions. It also has to use the right tools correctly and run at practical speeds on a home PC. The descriptions "uncensored" and "local" need to be examined separately, in terms of actual behavior and conditions of use.
Ajax aims to be an AI that gets everyday tasks done correctly
Odysseus is an AI workspace that lets you handle chat, document editing, email, and more from a single screen. It also has calendar and memory features, and it can connect both to locally run models and to models accessed through external APIs. Ajax is a model trained further to suit tool use within Odysseus, which makes it an effort to optimize the AI model and the environment it runs in together.
In development discussions on GitHub, PewDiePie lists specific problems that occur when existing local models are used with Odysseus: they cannot handle the long instructions Odysseus passes to them, they misread tool definitions and generate invalid calls, and users end up choosing models that are poorly suited to tool use. His stated goal is not simply to score highly on benchmarks, but to build a model that picks the right tool, passes the correct arguments, and returns results concisely.
For example, when asked to add an appointment, the model has to organize the date and details and pass them to the calendar tool in the correct format. Simply returning plausible-sounding text does not complete the actual task. An agent is also expected to avoid reporting success when a tool returns an error or an empty result, and to choose the next action it needs to take.
The development discussions outline a plan to begin with supervised fine-tuning using records of successful tool operations, teaching the model to select the right tools and recover from errors. This is only a development plan, not evidence that the finished version of Ajax has already achieved that performance. Even so, the intent is clear: to narrow the role of a small model from "an AI that answers anything" to "an AI that reliably gets work done in a specific environment."
Fewer refusals don't guarantee correct answers or actions
Ajax's official description says it reduces behavior that leads to refusals, aiming for an experience with fewer restrictions. It is reasonable to assume that "uncensored" mainly refers to this kind of tuning. It does not mean the model can answer every question correctly, nor that it can prevent dangerous operations.
One concrete example of a technique for suppressing refusals is the public tool "Heretic." Heretic implements a method that finds the direction associated with refusal by comparing the model's internal responses to questions it tends to refuse with those to ordinary questions, then weakens its influence. Unlike approaches that try to persuade the model through carefully worded input, it modifies the model's internal computation itself.
However, tuning to reduce refusals can also damage the model's original ability to answer. Heretic reduces how often the model refuses while adjusting so that its output on ordinary questions does not change much from the original model. It uses a metric called KL divergence to evaluate the latter, but this number alone cannot guarantee quality for every use.
Heretic is an example for understanding the general mechanism of suppressing refusals, and it does not allow us to infer Ajax's specific tuning method or performance. In evaluating Ajax, one would need to check separately how much refusals have decreased and whether the model passes correct arguments to tools. A model that no longer refuses but also carries out erroneous operations without hesitation does not become more reliable as an agent.
Running a 9B model on a home PC
According to the official specifications of the base model, Qwen3.5-9B, the language model portion has 9 billion parameters. To run it on a home PC, the first requirement is to fit these learned parameters, known as "weights," into memory.
A simple calculation of the required capacity: if 9 billion weights are stored at 16 bits each, that is 9 billion × 16 ÷ 8, or about 18 GB. At 4 bits, it is 9 billion × 4 ÷ 8, or about 4.5 GB. Both are theoretical estimates covering only the model's weights, calculated using decimal GB. Quantization is a technique that reduces the required capacity and computational load by storing these values at lower precision.
That said, this roughly 4.5 GB cannot be treated as the minimum VRAM Ajax needs. Additional information that accompanies quantization is needed, as well as working space during inference and a cache to hold the input. The vision-processing portion of the underlying Qwen is also not included in this estimate. The memory actually required varies with the distribution format and the software used to run it, and response speed is not determined by parameter count alone.
In PewDiePie's development discussions, Q4-quantized versions and the GGUF format are named as candidates for distribution so the model can be used in a wide range of local environments, with llama.cpp and vLLM envisioned as runtimes. However, these are policies stated during development, and they do not guarantee speeds on particular GPUs or minimum system requirements for the unreleased Ajax.
There are also caveats about installing Odysseus itself. The official setup guide says that on Apple Silicon Macs, the Metal GPU cannot be used from a Docker container, so users who want to run models on the GPU should choose native execution. Being able to launch Odysseus itself is a separate matter from being able to run the AI model at a practical speed.
Separating "local" and "uncensored" into actual conditions
Odysseus can connect not only to local AI inference but also to models via external APIs. It supports integration with IMAP/SMTP for email and CalDAV for calendars, so depending on the services and settings you use, communication with external parties may occur. Even for the goal the Ajax official page states, handling everyday tasks in a private environment, where the AI model runs and what data is sent to external services need to be considered separately.
Separating the Ajax description and the Odysseus README and threat model, all checked on October 3, 2026, into answer behavior versus connection and operation mechanisms, the points to verify are as follows. This is not the result of actually running and measuring Ajax, but a summary of the features and design described in public documents.
| What to check | Mechanism described in public documents | Conditions for users to verify |
|---|---|---|
| Refusal of answers | Ajax suppresses behavior that leads to refusals | Not only the refusal rate, but whether answers and tool arguments are correct |
| Where the model runs | Odysseus supports both local models and external APIs | The connection destination actually selected, and the input sent there |
| Communication with external services | Integrates with email, calendars, and more | Which services, and what data, are configured to be sent |
| Tool execution permissions | Administrators can operate the shell, files, email, and more | Whose permissions it runs under, and how far operations are allowed |
The table is based on the Ajax description, the Odysseus feature list, and the permission design in the threat model. The mechanism by which Ajax reduces refusals, the connection destinations managed by Odysseus, integration with external services, and tool permissions are each separate things. Being "uncensored" alone does not guarantee the privacy of communications or the safety of operations.
The breadth of operating permissions is also a problem specific to an AI agent that carries out real work on your own PC. The development version of Odysseus's threat model assumes use by trusted users within a private network, while listing as a known issue the absence of a sandbox to isolate shell and file operations. It explains that these tools run with the privileges of the process running Odysseus, and that there is no mechanism to restrict outbound network traffic or to isolate the file areas that can be accessed.
The same document also lists "prompt injection" as a threat to be addressed, in which instructions embedded in web pages, emails, and the like lead the AI into unintended actions. Even if the model runs locally, the information the AI is made to read is not necessarily safe. This is a design challenge the developers recognize, and it is neither a report that an actual incident has occurred with Ajax nor the result of a safety evaluation.
After release, the model's license will also need to be checked. The base model, Qwen3.5-9B, is under Apache-2.0, and Odysseus's code is under AGPL-3.0-or-later, but these are licenses that apply to separate works. The terms under which Ajax's weights can be used and redistributed must be judged by checking the license set for Ajax itself.
Once Ajax is released, a straightforward way to evaluate its practicality would be to compare it with the original Qwen model on the same PC under the same quantization conditions, measuring the proportion of multi-step tasks, such as registering an appointment or editing a document, that it completes correctly from start to finish, along with the time it takes. If a small model can keep tool use reliable while holding down the computational load, the prospect of entrusting everyday tasks to AI on a home PC becomes more realistic.
