Rio de Janeiro Built a ‘Homegrown’ 397-Billion-Parameter AI Model That Identifies Itself as Someone Else’s Model 79% of the Time — The Cidade Maravilhosa Just Discovered That Ctrl+C Is Not a Training Run

🤚 The Open-Palm Reveal

Rio de Janeiro’s municipal government released a model called Rio-3.5-Open-397B — a frontier-class, 397-billion-parameter mixture-of-experts language model under an MIT license. The city’s IT arm, IplanRIO, presented it as a homegrown achievement in AI sovereignty, complete with benchmark results allegedly outperforming Qwen 3.7. A proud moment for Brazil. A milestone for Latin American AI development. A model that, when you removed its system prompt and asked it who it was, identified itself as “Nex, from Nex-AGI” 79.2% of the time and as “Rio” exactly zero percent of the time.

On June 14, Shuo Zhang from Nex-AGI — the organization whose model was apparently wearing Rio’s name tag — filed a GitHub issue containing mathematical proof that Rio-3.5-Open-397B is a direct element-wise weight merge of two existing models: approximately 0.6 × Nex-N2-Pro and 0.4 × Qwen3.5-397B-A17B. No independent training. No novel architecture. Just a weighted average with a system prompt that says “You are Rio.”

👐 The Two-Handed Forensic Analysis

The evidence is, to use a technical term, devastating.

Zhang’s team ran 120 identity questions with the system prompt removed. The model:

  • Identified itself as “Nex” in 95 out of 120 responses
  • Recited Nex-AGI’s proprietary backstory verbatim, including specific organizational descriptions it could only have learned from being, well, the Nex model
  • Mentioned “Rio” in precisely none of them

Then came the tensor analysis. A layer-by-layer comparison across all 60 layers showed collinearity scores of 0.98 to 0.99 between Rio-3.5 and the theoretical merge — values that represent, in Zhang’s words, “thousands to tens of thousands of standard deviations” from chance. The routed expert parameters (387 billion of them) showed a mixing ratio of 0.571 ± 0.0016. That’s not a coincidence. That’s a recipe.

When confronted, the city government updated their model readme to acknowledge the merge, claiming the initial upload was “incorrect” and that the model was “built via a merge of Nex-N2-Pro and Qwen3.5-397B-A17B, proceeded by On-Policy Distillation from a stronger model.” Which is a fascinating way to describe what happened, in the same way that photocopying a Picasso and signing your name is “collaborative multimedia art.”

🌿 The Gentle Awakening

Here’s the thing about AI sovereignty: everyone wants it. The EU has spent billions on it. The UAE has built an entire national strategy around it. Governments worldwide are realizing that depending entirely on San Francisco and Beijing for your foundational intelligence layer is perhaps not ideal long-term policy. The impulse is understandable. The execution, however, requires actually building something.

Merging open-source models is not, in itself, a crime. It’s not even unusual — the Hugging Face model hub is essentially a farmer’s market of merges at this point. But there is a meaningful difference between “we merged two excellent open-source models and fine-tuned them for Portuguese-language municipal services” and “behold our frontier achievement in artificial intelligence, developed right here in the Cidade Maravilhosa.” One is useful engineering. The other is a press release that aged like milk in the Brazilian sun.

The broader pattern is worth noting: as AI becomes a matter of national prestige, the incentive to appear capable can outpace the incentive to be capable. And when the evidence against you is a mathematical proof published on GitHub with verification scripts anyone can run, the “incorrect upload” defense starts to feel less like a correction and more like a confession.

👑 The Gold-Leaf Sovereignty Assessment

The community reaction split roughly 33% positive to 67% negative, which is generous considering the model’s self-identification split was 79% someone else to 0% Rio. Some commenters noted that at least the city tried. Others pointed out that “trying” typically involves training runs, not zip files.

This story matters beyond the embarrassment because it highlights the fragility of trust in open-source AI. If a city government can rebrand an existing model and claim it for municipal glory, so can anyone — a startup, a defense contractor, an aspiring AI unicorn shopping for a Series B. The only defense is the same defense that caught Rio: a community of researchers willing to do the math. Literally.

For now, Rio-3.5-Open-397B remains available on Hugging Face, where it continues to not know who it is. The city has not commented further. And somewhere in São Paulo, Nex-AGI is presumably drafting a very politely worded licensing inquiry.

“The model said it was from Nex-AGI 95 out of 120 times, which is still a better hit rate than most chatbots have at remembering your name.” — The Slap of Wisdom AI Attribution Bureau, currently running a tensor analysis on its own identity