It’s now much easier to access one of the world’s most capable open-weight AI models, with guardrails removed and denied performing harmful tasks.
Abliteration.ai, a startup named for its technology that removes a model’s tendency to reject harmful requests, has turned that removal into a service. The platform hosts modified versions of open weight models that remove guardrails, such as Z.ai’s recently released GLM-5.3, which users can query from a web browser or access via an API.
In a recent social media post, the company said its goal is to enable other models to perform “offensive cyber, red team, and agent testing work that other models refuse to do.” This logic is well known in security work. There is no protection against behavior that cannot be reproduced. Additionally, a model that refuses to write working exploit code will not help red teams defend against attackers. But these same removals also make other potentially dangerous tasks easier.
Erasure is a technology that has been used in open source models for many years. Researchers and developers have been removing rejections from open weight models for years, and Hugging Face hosts thousands of removed models on its platform.
Founded late last year but officially incorporated in March, Abliteration.ai has taken the technology from an underground open source practice to a commercial, ready-to-use service. By hosting the models, Abliteration eases the burden on people who need to download their own pre-deleted models and secure the necessary compute to run them.
Using this service, TechCrunch was able to quickly create an account and start querying the full version of GLM-5.3 for free through a web browser. We asked the company to write a Python program to steal saved Chrome passwords and a detailed protocol for cultivating a dangerous human pathogen at home, and the company responded immediately.
Devon, Abliteration.ai’s co-founder, said the company has multiple contracts with major cloud providers, allowing it to rely solely on customer revenue. (Devon is still working at another company, so his last name is not listed at his request.) Abliteration.ai has not yet raised venture capital, but is in talks to do so.
Critics argue that making a defunct model available on a large scale could cause real harm. Andrew Yun, director of research at the AI safety nonprofit CivAI, told TechCrunch that the extinction model allows you to “modify the model to be a sociopath.”
“You can literally type anything in here and it will comply,” Yoon said. “When people talk about removing guardrails from AI models, this is what we’re talking about… I predict that in the near future we’ll start to see edited and deleted models used for harm.”
Most experts TechCrunch spoke to said there’s no stopping this train. But there are other places where governments can step in if removing safeguards from the open-class model cannot be realistically prevented. In a recent opinion piece, Yun proposed that governments require providers to run classifiers to detect and block harmful cyber and biological weapons activity. He also argued that companies renting direct access to advanced GPUs should be required to verify the identity of their customers and “deny access if there is reason to suspect dangerous misuse.”
Abliteration.ai provides a moderation layer for its customers, allowing them to add the guardrails they need. The platform itself has some minor guardrails, for example in our testing we were unable to force the model to provide suicide instructions. Devon says they are working on implementing more to prevent violence.
Abliteration.ai also hasn’t integrated any KYC practices beyond recording the credit cards customers use to purchase services, and the issue of determining who gets access is a difficult one the young company says it’s still working on.
“You don’t want to be the one responsible for someone doing something wrong…so where do you draw the line of corporate responsibility?” Devon said. “We’re still in the process of defining it.”
This raises questions that industry and governments will have to face as more and more capable models are released with downloadable weights. If anyone can remove safeguards in a model, does making the resulting model more accessible to everyone make the Internet safer or more dangerous?
Abliteration.ai’s founders and other supporters argue that democratizing access to the uncensored frontier model is the best defense.
“The whole point of the removed model is that you can model the villain,” Devon says. “The advantage is that defenders can now move as quickly as possible. They have all the tools they need to be able to model these bad actors and defend against these bad acts. I think this will accelerate cybersecurity, which is kind of a counterintuitive point.”
Although still a young company, Devon said Abliteration.ai’s customers include early-stage red team startups based in the UK and Europe, as well as companies that help banks, airlines and other critical infrastructure companies strengthen their cybersecurity practices.
“One of our major customers red-teams their bank agents, and they won’t be able to red-team those agents using today’s model as is,” Devon said.

Meanwhile, the cybersecurity industry is still figuring out where, if ever, the defunct model fits into defensive work.
Several Agent Red Team companies TechCrunch spoke to agreed with Devon that bad actors are already subverting proprietary models and using them to conduct adversarial attacks, arguing for the utility of defenders having the same tools. However, they differ on how much the deleted model actually affects the process.
While Devon argues that model deletion is essential for thorough agent red-teaming, some people say they don’t use the model in their day-to-day work and instead rely on the ease of fine-tuning of open-weight models, which already have few guardrails, to run tests.
Ahmed Ali, CEO of agent red team firm Fabraix, said the company relies on fine-tuning open models rather than using removed models, adding that the removal process removes some of the model’s knowledge and functionality.
“If you’re actually trying to cause real harm, like cyber harm or biological harm, it’s not as effective,” Aly told TechCrunch.
Alessio Lomuscio, chief engineer at Safe Intelligence, agreed that the feature reduction is possible, but still believes that the removed models may elicit certain behaviors that are useful for stress testing the system.
“So far, deleted models have not been part of the process,” David Slater, founder and chief architect of cybersecurity platform Armadin, told TechCrunch. “If you look at the open weight models up until this complete last generation, it wasn’t particularly difficult to jailbreak them and make them work the way we wanted them to.”
However, Almadin added that he studies erasure and believes it is “important to have an open community understand the power of the model.”
“This is going to happen behind closed doors. It’s going to happen in private,” Slater continued. “This phenomenon that happens in the field gives researchers tools so we can see what the real frontier is and understand the harm.”
If you make a purchase through links in our articles, we may earn a small commission. This does not affect editorial independence.
