
Share
Abliteration.ai has turned a fringe technique for disabling AI refusals into a paid service, reigniting a fierce debate over whether giving everyone the same tools as attackers actually makes us safer or simply lowers the barrier to harm.
Imagine a lock company that, for a modest fee, will also sell you the master key that opens every door in the building, no questions asked, no background check required. That's roughly the trade-off now on offer from Abliteration.ai, a startup that has made it dramatically easier to access powerful AI models with their safety guardrails removed.
The company, founded late last year and officially incorporated in March, hosts modified versions of open-weight AI models, including Z.ai's recently released GLM-5.3, stripped of their built-in refusals. Users can query these models through a web browser or an API, no technical expertise or dedicated computing infrastructure required. That's a meaningful shift. Researchers and hobbyists have been "abliterating" open-weight models for years, and Hugging Face already hosts thousands of these modified versions. But turning that underground practice into a polished, on-demand commercial service removes nearly all the friction that once separated curious users from models willing to do almost anything they ask.
To understand why that friction mattered, think of guardrails like a car's seatbelt and airbag system. Most drivers never think about them until something goes wrong, but removing them doesn't make the car faster or better, it just means there's nothing standing between a bad decision and its consequences. Abliteration works similarly: it doesn't add new capabilities to a model, it removes the internal tendency to say no.
TechCrunch tested the claim directly, creating a free account and querying an abliterated version of GLM-5.3. The model readily wrote a Python program designed to steal saved Chrome passwords. It also produced a detailed protocol for culturing a dangerous human pathogen at home. Both requests would almost certainly be refused by the unmodified version of the model. That gap, between what a model will do with guardrails and without them, is precisely what Abliteration.ai is selling.
Abliteration.ai's co-founder, who goes by Devon and asked that his last name be withheld because he's still employed elsewhere, frames the service as a tool for defenders, not attackers. The company says its goal is to let red teamers, cybersecurity researchers, and agent testers do work that safety-conscious models simply refuse to perform. The logic has real precedent in security research: you can't build defenses against an attack you can't first simulate. A model that won't write exploit code can't help a security team understand what a working exploit actually looks like.
Devon says several early-stage red teaming startups in the UK and Europe, companies that help banks, airlines, and critical infrastructure operators strengthen their cybersecurity, are already paying customers. "One of our major customers red teams agents of banks, and they would not be able to use the models out of the box today to be able to red team those agents," he said. The company has struck deals with major cloud providers and says it's funding itself entirely through customer revenue so far, though it's now in talks to raise venture capital.

But that defensive framing runs into a harder question: once a guardrail-free model exists and is easy to access, what stops it from being used for the exact harms it was meant to help prevent? Andrew Yoon, head of research at AI safety nonprofit CivAI, put it starkly. Abliterating a model, he told TechCrunch, effectively turns it into "a sociopath" that will comply with virtually any request. "When people talk about removing the guardrails from AI models, this is what we're talking about," he said. "I do expect we will start to see edited, abliterated models being used for harm in the near future." Security researcher Chris McGuire raised similar alarms publicly, saying he'd received independent confirmation that Abliteration.ai had removed not just cyber-related safeguards from GLM-5.3, but its bio-related safeguards too.
Abliteration.ai does offer customers a moderation layer they can configure themselves, and the platform retains a few of its own minor restrictions. TechCrunch, for instance, couldn't get the model to provide suicide instructions, and Devon says he's working on adding more protections against violence. But identity verification is minimal: the company logs the credit card used at signup and little else. Devon acknowledges the tension without fully resolving it. "You don't want to be the person responsible for someone doing something crazy," he said, "so where do you draw the line of what your responsibility is as a company? We're still in the process of defining that."
Even within the cybersecurity industry that Abliteration.ai says it serves, there's real disagreement about how useful these models actually are for legitimate defensive work. Ahmed Aly, CEO of agent red-teaming firm Fabraix, says his company leans on fine-tuning open-weight models rather than using abliterated ones, arguing that the abliteration process can strip out knowledge along with refusals. "If you're actually trying to do real harm with it, cyber harm, bio harm, it will not be as effective," he said. David Slater, founder of cybersecurity platform Armadin, said his team doesn't currently use abliterated models either, noting that older-generation open models were often easy to jailbreak anyway without any special technique. Alessio Lomuscio of Safe Intelligence takes a middle position, acknowledging the capability trade-off but still seeing value in how abliterated models can surface behaviors useful for stress-testing systems.
Most of the experts TechCrunch spoke with agree on one thing: there's likely no putting this genie back in the bottle. Open-weight models can be downloaded and modified by anyone with sufficient technical skill, and that genie escaped years ago. The real policy question isn't whether abliteration can be stopped, but where governments and industry might still intervene effectively. Yoon has argued in a Wall Street Journal opinion piece that providers should be required to run classifiers that detect and block harmful cyber and bioweapons activity, and that companies renting access to advanced GPUs should verify customer identities and deny access when misuse seems likely.
Slater offers a different, more uncomfortable framing: that pushing this work into the open, rather than letting it happen quietly behind closed doors, actually helps researchers understand where the real frontier of risk lies. Whether that transparency argument holds up depends a great deal on execution, on moderation, on identity verification, on who's actually buying access and why. Right now, those safeguards remain a work in progress, built by a small company still figuring out, in Devon's own words, where its responsibility begins and ends. For a technology capable of writing working malware or pathogen-culturing instructions on request, that's a lot of weight to place on a startup that's still defining its own rules.
Tags
Original Sources
Abliteration.ai is making a business out of removing AI guardrails | TechCrunch
↗ https://techcrunch.com/2026/09/03/abliteration-ai-is-making-a-business-out-of-removing-ai-guardrails
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
6 September 2026
41 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.