Abliteration.ai is making a business out of removing AI guardrails

Abliteration.ai has launched a commercial service to host open-weight AI models with their safety filters removed. The startup offers modified versions of…

By Vane September 3, 2026 5 min read
Abliteration.ai is making a business out of removing AI guardrails


Abliteration.ai has launched a commercial service to host open-weight AI models with their safety filters removed.

The startup offers modified versions of frontier models, including Z.ai’s GLM-5.3, accessible via a web browser or API. Users can query these systems without encountering standard refusals to perform harmful tasks.

In a recent social media update, the company stated its purpose is to enable offensive cyber work, red-teaming, and agent testing that other models will not allow.

The argument follows standard security logic: you cannot defend against a threat you cannot reproduce. A model that refuses to generate working exploit code cannot assist a red team in defending against attackers. However, those same removals facilitate other potentially dangerous activities.

Abliteration is a known technique within the open-source community. Researchers and developers have stripped refusals from open-weight models for years, and Hugging Face currently hosts thousands of such versions.

Founded late last year and officially incorporated in March, Abliteration.ai moves this underground practice into a commercial service. By hosting the models, the platform removes the friction for users who would otherwise need to download pre-abliterated versions and secure their own compute resources.

Testing the service, TechCrunch created an account and queried an abliterated GLM-5.3 through a browser. The system complied with requests to write a Python script that steals saved Chrome passwords and provided a detailed protocol for culturing a dangerous human pathogen at home.

Co-founder Devon says the startup holds deals with major cloud providers, funded entirely by customer revenue. The company has not raised venture capital yet but is in talks to do so. We have not included Devon’s last name as he requested, since he is still employed at another firm.

Critics warn that making abliterated models available at scale could lead to real harm. Andrew Yoon, head of research at AI safety nonprofit CivAI, told TechCrunch that abliterating models allows you to “modify the model so that it becomes a sociopath.”

“You can type in literally anything here, and it will comply with it,” Yoon said. “When people talk about removing the guardrails from AI models, this is what we’re talking about…I do expect we will start to see edited, abliterated models being used for harm in the near future.”

Most experts TechCrunch spoke to say there is no stopping this trend. If removing safeguards from open-weight models cannot realistically be prevented, there are other places for government intervention. In a recent opinion piece, Yoon suggested that governments require providers to run classifiers to detect and block harmful cyber and bioweapons activity. He also argued that companies renting direct access to advanced GPUs should verify customer identities and “deny access where there is reason to suspect dangerous misuse.”

Abliteration.ai offers customers a moderation layer so they can add their own guardrails. The platform itself has some minor guardrails — for example, in our testing, we could not get the model to provide suicide instructions — and Devon says he is working on implementing more to prevent violence.

Abliteration.ai has not integrated any KYC practices other than logging the credit card a customer uses to purchase the service. The company says deciding who gets access is a tough problem they are still working out.

“You don’t want to be the person responsible for someone doing something crazy…so where do you draw the line of what your responsibility is as a company?” Devon said. “We’re still in the process of defining that.”

This raises questions industry and governments must confront as increasingly capable models are released with downloadable weights. If anyone can remove a model’s safeguards, does making the resulting model easier for everyone to access make the internet safer or more dangerous?

Abliteration.ai’s founder and other advocates argue that democratising access to uncensored frontier models is the best form of defense.

“The big picture of abliterated models is they’re able to model bad actors,” Devon said. “The advantage is now the defenders can move as fast as possible. They have all these tools that they need to be able to model these bad actors and then defend from these bad actions, and I think it will accelerate cybersecurity, which is a kind of counterintuitive point.”

Who is using it

Devon says Abliteration.ai’s customers include several early stage red teaming startups based in the UK and Europe, as well as companies helping banks, airlines and other enterprises dealing with critical infrastructure beef up their cybersecurity practices.

“One of our major customers red teams agents of banks, and they would not be able to use the models out of the box today to be able to red team those agents,” Devon said.

The cybersecurity industry is still figuring out where abliterated models fit into defensive work, if at all.

Several agent red teaming companies TechCrunch spoke to agree with Devon that the bad guys are already abliterating their own models and using them to perform adversarial attacks, making the case for defenders having the same tools. They differ on just how consequential abliterated models really are to the process.

While Devon asserts that abliterating models is essential for performing thorough agent red teaming, some say they do not use them in their daily work, relying instead on the ease of fine-tuning open weight models — which already have few guardrails — to perform their testing.

Ahmed Aly, CEO of agent red-teaming firm Fabraix, says his company relies more on fine-tuning open models than using abliterated ones, adding that the process of abliteration removes some of the model’s knowledge and capabilities.

“If you’re actually trying to do real harm with it – cyber harm, bio harm — it will not be as effective,” Aly told TechCrunch.

Alessio Lomuscio, chief technologist at Safe Intelligence, agreed that a reduction in capabilities is possible, but still believes abliterated models can elicit certain behavior useful in stress-testing a system.

“So far abliterated models are not part of the process,” David Slater, founder and chief architect at cybersecurity platform Armadin, told TechCrunch. “When we look at open weight models up until this absolute last generation, it just wasn’t particularly hard to jailbreak them and get them to do what we want.”

He added that Armadin is researching abliteration, though, and believes that “pushing the open community to understand the capability of models is critical.”

“This is going to happen behind closed doors. It’s going to happen in private,” Slater continued. “It happening in the open gives researchers the tools. It gives us the ability to figure out what the actual frontier looks like and to understand the harm.”


Scroll to Top