Leaked Model Names Are Not Candidates: A Rumor-Intake Rule

Leaked model names are not candidates. Admit a model only with an API ID, a price page, terms and a named provider, and park every rumor on a dated watch list.

Leaked model names hero: a name tag reading Sonnet 5.5 with a question mark, held outside a gate with four empty checkboxes for API ID, price page, terms and named providerLeaked model names hero: a name tag reading Sonnet 5.5 with a question mark, held outside a gate with four empty checkboxes for API ID, price page, terms and named provider
Until Sep 28, Sonnet 5.5 was a name with four empty boxes. A name is not a model until the documents exist.

Leaked model names travel faster than models, and this month one of them traveled on a borrowed spec sheet. On Sep 24, according to the two outlets that later took it apart, an X post presented four figures as the specs of an unreleased Claude Sonnet 5.5. Every one of them was already on Anthropic’s price list, attached to Sonnet 5, which shipped on Jun 30.

OrcaRouter said so that same day, and Startup Fortune two days later. Nine hours after that, the rumor ran again with a launch week attached. Then, on Sep 28, Anthropic shipped Sonnet 5.5 with the same four numbers, because it kept Sonnet 5’s price and limits. The rumor got the week right and the debunk got the figures right, and until that launch page existed there was still nothing a lane could call.

The same week, a free endpoint called Pixel Canary went live on a major gateway, with no maker named and terms that say your prompts may be used for training.

Being right early is not the same as being admissible. Here is the rule that keeps names out until they are models: a model enters the fleet only with an API ID, a price page, terms and a named provider. Anonymous or stealth endpoints never touch private code. Every rumor goes on a watch list with the date it becomes testable, and whatever clears the list climbs the promotion ladder like any other candidate.

Sep 22–28: a promise, a recycled spec sheet, two stealth endpoints and the launch

Until Sep 28, the only primary fact about Sonnet 5.5 was one sentence in Anthropic’s Opus 5.5 launch post of Sep 22: “Claude Sonnet 5.5 and Claude Haiku 5.5 will follow in the coming weeks, with many of the same improvements to performance, efficiency, and safety.” No date, price, context window or model ID followed that week.

The Sep 24 post itself is unverified: it is known only through secondary accounts, chiefly Startup Fortune’s, which attributes it to the X account @kimmonismus. As those reports describe it, the post pitched Sonnet 5.5 as a GPT-6 Sol rival and said it was in stealth testing. Startup Fortune frames the claim as “beating” GPT-6 Sol; OrcaRouter reads it as a pricing comparison and notes “no screenshot, no model string, no API response”.

The debunk came the same day. At 11:18 UTC on Sep 24, OrcaRouter wrote that the four figures were “on Anthropic’s own price list right now, attached to Claude Sonnet 5”. Startup Fortune’s version went up at 22:56 UTC on Sep 26 and put it more bluntly: “What looked like a leak was an old spec sheet wearing a new label.”

Startup Fortune article by Judith Murphy on the Sonnet 5.5 leak, with the paragraph explaining that all four figures in the Sep 24 post are the listed context window, output limit and pricing for Claude Sonnet 5, released June 30, 2026 Screenshot: Startup Fortune, “The Claude Sonnet 5.5 leak beating GPT-6 Sol is not what it looks like” (Sep 26, 2026, 22:56 UTC), captured Sep 28, 2026.

The figures read as news for a mundane reason. Sonnet 5’s $2/$10 introductory price became permanent, per Anthropic’s pricing page, and GPT-6 Sol had just dropped to the same $2/$10, per Artificial Analysis on Sep 22. That overlap is what made the post read as a response to OpenAI, and it is also why the figures identified nothing new.

Then the repeat. At 08:06 UTC on Sep 27, nine hours after Startup Fortune’s debunk and three days after OrcaRouter’s, the same account posted that Sonnet 5.5 is launching next week. It cited no source, and the week turned out to be right.

The launch came the next day. Anthropic’s Sonnet 5.5 post, dated Sep 28, says the model “is priced the same as Sonnet 5”, and the models overview now lists claude-sonnet-5-5 with the same context window and output limit as Sonnet 5. The same day, Claude Code 2.1.284 made it “the default Sonnet model on the Anthropic API”, per the changelog, and Haiku 5.5 is still due “in the coming weeks”.

So the four numbers from Sep 24 now describe a real model, and they still identified nothing when they were posted: a successor that keeps its predecessor’s price and limits makes any copy of the old spec sheet look prescient. The rule below admitted Sonnet 5.5 on Sep 28, when an API ID, a price row, terms and a named provider existed, and not a day earlier.

The stealth endpoints were live from the start, which makes them the harder case. Vercel’s changelog of Sep 25 put “Pixel Canary” on its AI Gateway as stealth/pixel-canary, free “for a limited time while in stealth”. Its Next.js eval ties GPT 6 Astra (high) at 28 of 31 tasks, scored pass@4, meaning a task passes if any of up to four attempts succeeds. The same page says: “ZDR is not available for this model, and prompts and responses sent through it may be used for training and model improvement.”

Vercel changelog entry for Pixel Canary on AI Gateway, stating pass@4 scoring on Next.js evals and that ZDR is not available and prompts and responses may be used for training Screenshot: Vercel changelog, “Pixel Canary is now available in stealth for free on AI Gateway” (Sep 25, 2026), captured Sep 28, 2026.

No company has claimed Pixel Canary, and the guesses point three ways. Startup Fortune’s standfirst says “tokenizer analysis points to a possible Qwen derivative” without saying whose analysis. One fingerprinting site leans to Z.ai’s GLM family and calls it a guess; name-based blog posts say Google. The name is not evidence either: Android Canary is Google’s pre-release Android channel, and nothing ties the stealth model to it beyond one word.

Two days earlier, OpenCode had offered its own stealth model, Space Bunny, with the opposite terms. Its Zen docs say “Its provider follows a zero-retention policy and does not use your data for model training.” Two anonymous models, one week, opposite data terms, and neither maker named.

The week’s one big-lab roadmap line was not an announcement. At The Information’s AI Agenda Live event, Google DeepMind’s Koray Kavukcuoglu said Gemini 4 is in post-training and that the intention is, “as soon as possible”, to release an early post-training output, as 9to5Google reported on Sep 24. No date was given, and Google’s models page, updated that day, lists no Gemini 4. That is a watch-list entry, not a candidate.

Why leaked model names cannot enter an agent lane

A chat user who tries a rumored model risks a bad answer. A lane that runs one hands it a checkout, credentials and permission to push. Everything a fleet does to govern a model assumes you can name it: the pin needs an ID, the cost gate needs a price, the retention review needs terms, and the served-model check needs a model string to compare against. A rumor has none of those, and a stealth endpoint is missing at least two.

Step 1: Admit a model on four documents, and nothing less

Write the admission rule as a checklist a tired person can apply at 6 p.m. on a Friday:

Document Counts as evidence Does not count Check it on
API model ID A string the provider lists and you can pin, such as claude-sonnet-5 A name in a post, a codename, a sighting in someone’s model picker The provider’s models page
Price page A per-token or per-seat price on the provider’s own pricing page A price inside a leak; “free for a limited time” The provider’s pricing page
Terms Retention and training terms that bind whoever serves the model Silence, or a summary with no provider behind it Provider terms, or the gateway’s model page
Named provider A company that says it built or serves the model, and answers for it A tokenizer guess, or a name that sounds like a brand The provider’s own announcement

All four, or the name stays on the watch list. The rule is deliberately dull. It does not ask whether the model is any good; the ladder asks that later, on your own tasks, with your own merge and revert numbers. Nor does it ask whether the rumor was right: Sonnet 5.5’s was, and it still waited for Sep 28.

Rumor-intake gate for leaked model names: a name seen in a post, leak or gateway listing meets a four-document check for API ID, price page, terms and named provider; with all four it enters shadow on the promotion ladder, without them it goes to a dated watch list that re-checks on its review date, and a live anonymous endpoint is limited to public code on a sandbox hostRumor-intake gate for leaked model names: a name seen in a post, leak or gateway listing meets a four-document check for API ID, price page, terms and named provider; with all four it enters shadow on the promotion ladder, without them it goes to a dated watch list that re-checks on its review date, and a live anonymous endpoint is limited to public code on a sandbox host One gate, two exits. Nothing reaches a lane on a name alone.

Step 2: Keep anonymous and stealth endpoints away from private code

The live Ox Alpha piece already has the workload table for a model nobody will claim, and its one-line version still holds: “never send an anonymous model proprietary code you would not post publicly.” Pixel Canary adds a primary source for why. Its gateway model page says in writing that prompts and outputs may be retained for training, and nobody has said who would be doing the training.

Write the rule where the fleet reads it. The shape below is illustrative; the prefix comes from Vercel’s model string:

# model-intake-policy.yaml (illustrative)
admit:
  require: [api_model_id, price_page, terms, named_provider]
  on_pass: promotion_ladder.shadow      # never straight to default
stealth_or_anonymous:
  blocked_prefixes_on_private_lanes: ["stealth/"]
  when_provider_unnamed: treat_as_stealth
  allowed: {repos: public_only, credentials: none, host: sandbox}
rumor:
  on_sight: watch_list
  required_fields: [name, first_seen, source, claim, testable_when, review_on]
  never: [pin, default, private_code]

Be honest about what a YAML file stops: nobody with a personal API key. The rule is a guardrail. The wall behind it is that private-repo credentials never exist on the host where a stealth model runs, and your private lanes call models through a key or router with no route to stealth/ models. If someone tries a stealth model on real code anyway, treat it as a data exposure, not a style violation, and rotate whatever that session could see.

Then test the wall the way you would test a backup. From a private-lane host, request stealth/pixel-canary through the lane’s normal key and expect a refusal. From the sandbox host, look for a private-repo credential and expect to find none. A wall nobody has tested is a guess with a diagram.

Step 3: Park every name on a watch list with a testable date

A watch list turns “have you seen this?” into a row with an owner. Every entry records where the name came from, whether that source is primary, the claim in its own words, which of the four documents exist, the condition that makes it testable and a date to look again. The entries below are illustrative, built from this week’s names:

# model-watchlist.yaml (illustrative): names seen, not models admitted
- name: Claude Sonnet 5.5
  first_seen: 2026-09-22
  source: Anthropic, Opus 5.5 launch post (primary)
  claim: "will follow in the coming weeks"
  api_model_id: claude-sonnet-5-5          # models overview, 2026-09-28
  price_page: Anthropic pricing page       # row added 2026-09-28
  terms: zero data retention available     # launch post, 2026-09-28
  named_provider: Anthropic
  testable_when: listed on the models overview and pricing pages
  cleared: 2026-09-28                      # all four; enters shadow
  rumors:
    - seen: 2026-09-24
      via: Startup Fortune and OrcaRouter accounts; the post itself unverified
      verdict: all four figures are Sonnet 5 specs, launched 2026-06-30
      outcome: Sonnet 5.5 kept those figures, so they never identified it
    - seen: 2026-09-27
      via: X post, search-result text
      verdict: unsourced launch date
      outcome: right; launched 2026-09-28
- name: Claude Haiku 5.5
  first_seen: 2026-09-22
  source: Anthropic, Opus 5.5 and Sonnet 5.5 launch posts (primary)
  claim: "will join the Claude 5.5 family in the coming weeks"
  api_model_id: null
  testable_when: listed on the models overview and pricing pages
  review_on: 2026-10-05
- name: Pixel Canary
  first_seen: 2026-09-25
  source: Vercel AI Gateway changelog (primary)
  api_model_id: stealth/pixel-canary
  price_page: free for a limited time; no paid price
  terms: no ZDR; prompts and responses may be used for training
  named_provider: null
  allowed: public repos, sandbox host, no credentials
  testable_when: a named provider, a price page and retention terms
  review_on: 2026-10-02
- name: Gemini 4
  first_seen: 2026-09-24
  source: 9to5Google report of an on-stage remark (secondary)
  api_model_id: null
  testable_when: listed on the Gemini API models page
  review_on: 2026-10-24

Two rules keep the list honest. testable_when is a condition you can check, never a guessed date: “coming weeks” and “as soon as possible” are the vendor’s words, not yours. And the list is the only place a rumored name may be written down. Nobody adds it to a lane config to be ready; being ready is what the ladder is for.

Give the list one owner and a weekly fifteen-minute review. Each row gets three questions: did a primary page change, has the review date passed, and has anyone wired the name into a config anyway? A row that goes 90 days without a single primary document gets archived with its history, not deleted.

Step 4: Check the claim against the primary source before anyone repeats it

When a name arrives with numbers attached, do the ten-minute check before the team chat does. Put each claim beside the primary page it would have to appear on:

Claim, as reported Reported by What the primary source said that week
Sonnet 5.5 has a 1M-token context window Sep 24 post, per Startup Fortune and OrcaRouter Sonnet 5 already has a 1M-token context (Anthropic models overview)
Sonnet 5.5 has a 128K output ceiling Same Sonnet 5’s max output is 128K
Sonnet 5.5 costs $2 per million input tokens Same Sonnet 5’s input price is $2, made permanent; the scheduled rise to $3/$15 “will not occur”
Sonnet 5.5 costs $10 per million output tokens Same Sonnet 5’s output price is $10; GPT-6 Sol also lists at $2/$10 (Artificial Analysis, Sep 22)
Sonnet 5.5 is in stealth testing Same Anthropic: “will follow in the coming weeks”; no model ID, price or benchmark until the Sep 28 launch
Sonnet 5.5 launches next week @kimmonismus, Sep 27 No date on any Anthropic page on Sep 27; launched Sep 28
Pixel Canary is a Qwen, GLM or Google model Startup Fortune standfirst, a fingerprinting site, name-based blogs Vercel names no maker; its model page lists the provider as “Stealth”
Pixel Canary ties GPT 6 Astra on Next.js Vercel changelog 28 of 31 tasks, scored pass@4, on Vercel’s own eval
Gemini 4 is coming “as soon as possible” 9to5Google, reporting Kavukcuoglu No Gemini 4 on Google’s models page, updated Sep 24

Then date the cycle. Times matter more than they look: the first debunk beat the repeat by three days, the repeat went out anyway, and the launch settled it the next day.

Timeline of the September 2026 rumor cycle around leaked model names, Sep 22 to Sep 28: Anthropic’s coming-weeks line, Space Bunny, the Sep 24 claim and same-day debunk, the Gemini 4 remark, Pixel Canary on Sep 25, the Startup Fortune debunk on Sep 26, the repeat on Sep 27, and Anthropic’s Sonnet 5.5 launch on Sep 28, with no leaked figures chartedTimeline of the September 2026 rumor cycle around leaked model names, Sep 22 to Sep 28: Anthropic’s coming-weeks line, Space Bunny, the Sep 24 claim and same-day debunk, the Gemini 4 remark, Pixel Canary on Sep 25, the Startup Fortune debunk on Sep 26, the repeat on Sep 27, and Anthropic’s Sonnet 5.5 launch on Sep 28, with no leaked figures charted Dates, not figures. Nine events in one week, ending with the Sep 28 launch that gave Sonnet 5.5 its model ID.

Four habits make the check fast:

  1. Find the model string first. A claim with no string is a claim about a brand.
  2. Trace the claim to its earliest source. If the oldest trace is a secondary account of a post nobody links, the claim is unverified until the post turns up, however many outlets repeat it.
  3. Compare every number with the spec sheets already published. A figure that matches an existing product identifies nothing.
  4. Read each benchmark line for its scoring rule. Pass@4 is a different claim from a single attempt, and the discipline for reading agent benchmarks applies to a stealth model’s launch post as much as to a leaderboard.

Step 5: When the four documents land, hand the name to the ladder

The watch list has one exit: on the review date, or the day a primary page changes, re-run Step 1. If all four documents exist, the model enters shadow on the promotion ladder: pinned by full ID, at a pinned effort, with the incumbent untouched. Sonnet 5.5 took that exit on Sep 28 and starts in shadow like any other candidate, even though Claude Code made it the default Sonnet model the same day. A stealth model that gains a named provider, a price page and terms becomes an ordinary candidate that day.

Close the entry when it exits, and keep the row. Six months from now, the useful question is which sources were right about dates, and the watch list is the only record that can answer it.

Five ways leaked model names still reach a lane

The unpinned default that picks a stealth model. Cline’s Sep 24 CLI refresh made “Space Bunny Free” the resolved default for its OpenCode Go provider, so anyone on that provider without a pinned model got a stealth model nobody on the team chose. Signal: a served model with no named maker in your logs. Fix: pin a model on every provider, and keep stealth/ off private lanes.

The price echo. Every figure in the Sep 24 claim matched a product already on sale, and $2/$10 matched two of them, three once Sonnet 5.5 launched at the same price. Sonnet 5’s $0.20 cache read is also Opus 5.5’s. Signal: each number in a “leak” appears on an existing price page. Fix: count matching numbers as zero evidence, even after a launch makes them look prescient.

The name collision. “Pixel Canary” sounds like Google, and Android Canary is a real Google channel. Signal: a maker inferred from a word. Fix: named_provider stays null until a company says so.

The free window that closes. Vercel does not say how long “free for a limited time” lasts. Signal: a lane that depends on a model with no price page. Fix: nothing you depend on runs on a model without one.

The repeat that outruns the debunk. The Sep 27 post came after both debunks, and this time it got the week right. Signal: a teammate quotes a launch date with no primary link. Fix: the watch-list row carries each debunk beside its rumor, so paste the row into the thread, not the post.

A fleet admits models the way it admits code

Names arrive through a feed. Models should enter through a gate, on the same kind of evidence a pull request needs before it merges. The gate is operating-layer work: the intake policy file, a watch list with an owner, a sandbox host with no credentials, a router with no route to stealth/, and the ladder waiting at the exit. It belongs beside permission modes chosen by repository trust, and it shows up on the same command center as every other lane decision.

The feed will produce another name this week. It gets a row, a source and a review date, and your lanes never notice.

FAQ

Is Claude Sonnet 5.5 released?

Yes. Anthropic launched Sonnet 5.5 on Sep 28, 2026 as claude-sonnet-5-5, priced the same as Sonnet 5 at $2/$10 per million tokens, and Claude Code 2.1.284 made it the default Sonnet model on the Anthropic API. The figures shared as a Sep 24 leak were Sonnet 5’s public specs; Haiku 5.5 is still coming.

Is it safe to use a stealth model like Pixel Canary for coding?

Only on code you would publish anyway. Vercel’s page says ZDR is not available for Pixel Canary and that prompts and responses may be used for training, and no company has claimed the model. Run it on public repositories, from a sandbox host with no credentials, and never on private code.

Sources

YOU'RE THROUGH THIS ONE.

Keep connecting the dots.

Back to the library