One of the most powerful open-weight AI models in the world is now considerably more accessible after being stripped of its safeguards and refusals to carry out dangerous tasks.
Startup Abliteration.ai, named after a method that eliminates a model’s propensity to reject damaging requests, has converted that elimination into a service. Users can query Z.ai’s freshly launched GLM-5.3 from a web browser or access it via an API. The platform hosts modified versions of open-weight models with their guardrails removed.
In a recent social media post, the company stated that its objective is to make it possible for others to do “offensive cyber, red-teaming, and agent testing work other models refuse to do.” In security work, the reasoning is well-known: a model that refuses to build functional exploit code cannot assist a red team in defending against attackers, and you cannot protect against a behavior that you cannot replicate. However, those same removals also facilitate other potentially hazardous jobs.
Among open-source models, abliteration is a well-established method. Hugging Face hosts thousands of destroyed models, and researchers and developers have been eliminating refusals from open-weight models for years.
Abliteration was founded before the end of the previous year, but it was formally incorporated in March. AI transforms the method from a covert open-source activity into a widely accessible, commercial offering. For those who would normally need to obtain their own pre-abliterated models and secure the compute required to run them, Abliteration lowers the barrier by hosting the model.
I was able to immediately register for the service and begin using a web browser to query an abliterated version of GLM-5.3 for free. It immediately responded with our requests to develop a Python application that steals stored Chrome passwords and a comprehensive process for cultivating a dangerous human infection at home.
According to Devon, co-founder of Abliteration.ai, the firm has many agreements with significant cloud providers, which it is able to finance solely through client revenue. (Devon requested that his last name not be used because he is still working for another company.) Although it hasn’t raised any venture financing yet, Abliteration.ai is in negotiations to do so.
Making destroyed models widely accessible, according to critics, could do actual harm. Abliterating models enables you to “modify the model so that it becomes a sociopath,” according to Andrew Yoon, head of research at the nonprofit AI safety organization CivAI.
“You can enter anything here, and it will accept it,” Yoon remarked. “This is what we mean when we talk about eliminating the guardrails from AI models. I do anticipate that in the near future, models that have been altered or destroyed will begin to be utilized maliciously.
The majority of the specialists who spoke stated that this train cannot be stopped. However, there are other areas where the government can step in if it is not feasible to stop the removal of safeguards from open-weight models. Yoon proposed in a recent opinion post that governments mandate that providers use classifiers to identify and stop dangerous cyber and bioweapons behavior. Additionally, he contended that businesses that rent direct access to cutting-edge GPUs ought to be obligated to confirm the names of their clients and “deny access where there is reason to suspect dangerous misuse.”
Customers can add any guardrails they want to Abliteration.ai’s moderation layer. Devon says he is working on adding more safeguards to avoid violence, but the platform itself contains a few modest ones. For instance, we were unable to persuade the model to deliver suicide instructions during our testing.
Abliteration.ai claims that determining who has access is a difficult issue that the fledgling company is still figuring out, but it hasn’t incorporated any KYC procedures other than recording the credit card a customer uses to pay for the service.
Devon asked, “Where do you draw the line of what your responsibility is as a company if you don’t want to be the one responsible for someone doing something crazy?” “We’re still working on defining that.”
As more sophisticated models with downloadable weights are released, businesses and governments will have to deal with the following issues: if a model’s safeguards can be removed, does making the resulting model simpler for everyone to access make the internet safer or more dangerous?
The founder of Abliteration.ai and other supporters think that the greatest line of defense is to democratize access to unfiltered frontier models.
According to Devon, “the big picture of abliterated models is that they can model bad actors.” The defenders can now move as quickly as possible, which is an advantage. It may seem contradictory, but I believe it will speed up cybersecurity because they have all the tools they need to model these bad actors and then protect against them.
Devon claims that although Abliteration.ai is still in its infancy, its clients include a number of early-stage red teaming startups in the UK and Europe that assist banks, airlines, and other businesses handling vital infrastructure in strengthening their cybersecurity procedures.
Devon stated, “One of our major customers red teams bank agents, and they would not be able to use the models out of the box today to be able to red team those agents.”
In the meantime, the cybersecurity sector itself is still debating whether or not to include destroyed models in protective efforts.
Spoke with a number of agent red teaming organizations, and they concur with Devon that the adversaries are already destroying their own models and utilizing them to launch adversarial attacks, which is why it is beneficial for defenders to have the same tools. However, they disagree on the extent to which destroyed models actually affect the process.
Devon claims that destroying models is necessary for carrying out comprehensive agent red teaming, while some claim they don’t use them in their day-to-day work and instead rely on the simplicity of fine-tuning open-weight models, which already have few safeguards, to carry out their testing.
The CEO of agent red-teaming startup Fabraix, Ahmed Aly, claims that his company depends more on fine-tuning open models than on abliterated ones, noting that the act of abliteration eliminates some of the model’s skills and knowledge.
“It won’t be as effective if you’re really trying to do real harm with it—cyber harm, bio harm,” Aly said.
While acknowledging that a reduction in capabilities is likely, Alessio Lomuscio, chief technologist at Safe Intelligence, maintains that destroyed models can still elicit specific behavior that is helpful in stress-testing a system.
According to David Slater, founder and principal architect of the cybersecurity platform Armadin, “abliterated models are not part of the process so far.” “Jailbreaking open-weight models and getting them to do what we want wasn’t all that difficult until this very last generation.”
However, Armadin is studying abliteration and feels that “pushing the open community to understand the capability of models is critical,” he continued.
“This will take place in private. It will take place behind closed doors,” Slater added. “It provides researchers with the tools when it occurs in the open.” It enables us to comprehend the harm and determine what the real border looks like.

