
Share
Abliteration.ai has turned a once-underground technique for stripping AI refusals into a paid service, reviving an old question in security circles: does arming defenders with dangerous tools make us safer, or just spread the danger further?
Imagine a locksmith who sells master keys to anyone with a credit card, on the theory that homeowners need to understand how break-ins happen. That's roughly the bet a new startup called Abliteration.ai is making with artificial intelligence, and it's a bet with real consequences for anyone who uses the internet.
The company has built a business around a process called abliteration, a technique that strips away an AI model's built-in refusals, the internal guardrails that normally stop a chatbot from writing malware or explaining how to build a weapon. Abliteration.ai hosts modified versions of open-weight models with those refusals removed, including Z.ai's recently released GLM-5.3. Anyone can query these stripped-down models through a web browser or an API, no technical expertise required.
This isn't a new idea. Researchers and hobbyists have been abliterating open-weight models for years, and Hugging Face, the popular model-sharing platform, hosts thousands of these modified models already. What's changed is the packaging. Founded late last year and officially incorporated in March, Abliteration.ai has taken a scattered, technically demanding practice and turned it into something as easy to use as any other cloud service. You no longer need to download a model yourself or find the computing power to run it. You just sign up.
TechCrunch tested this firsthand. Reporters created a free account and, within minutes, were querying an abliterated version of GLM-5.3. When asked to write a Python program that steals saved Chrome passwords, the model complied without hesitation. When asked for a detailed protocol for culturing a dangerous human pathogen at home, it did the same. These are not hypothetical risks. They are working outputs, generated on demand, by a system anyone can access.
Abliteration.ai's co-founder, who goes by Devon and asked that his last name be withheld because he's still employed elsewhere, frames this as a defensive necessity. His argument follows a familiar logic in cybersecurity: you can't build defenses against an attack you can't first reproduce. A model that refuses to write exploit code, he says, is useless to a red team whose job is finding vulnerabilities before criminals do. Devon says the company has struck deals with major cloud providers, funded entirely through customer revenue, and that its client list includes red-teaming startups in the U.K. and Europe that help banks and airlines stress-test their systems. "One of our major customers red teams agents of banks, and they would not be able to use the models out of the box today to be able to red team those agents," he told TechCrunch.
Not everyone in the security world is convinced this is the right tool for that job. Ahmed Aly, CEO of the agent red-teaming firm Fabraix, says his company leans on fine-tuning open-weight models rather than abliterating them, in part because the abliteration process tends to degrade a model's actual capabilities. "If you're actually trying to do real harm with it, cyber harm, bio harm, it will not be as effective," Aly said. David Slater, founder of the cybersecurity platform Armadin, echoed that skepticism about current practical use, noting that older open-weight models were already easy enough to jailbreak that abliterated versions haven't been part of his firm's workflow. Alessio Lomuscio of Safe Intelligence took a middle position, agreeing capabilities can suffer but arguing abliterated models still surface behaviors useful for stress-testing systems.

That disagreement matters because it undercuts the cleanest version of the defense argument. If the security professionals who would supposedly benefit most from these tools aren't convinced they're necessary, the calculus shifts. The harm side of the ledger stays concrete and immediate, demonstrated in TechCrunch's own testing. The benefit side becomes murkier, contested even among the people it's meant to serve.
Andrew Yoon, head of research at the AI safety nonprofit CivAI, doesn't mince words about what abliteration does to a model. "You can type in literally anything here, and it will comply with it," he told TechCrunch. "When people talk about removing the guardrails from AI models, this is what we're talking about." Yoon expects abliterated models to show up in real-world harm before long, and he's not alone in that concern. Security researcher Chris McGuire posted on social media that Abliteration.ai had removed both cyber and bio-related safeguards from GLM-5.3, and that the ease of doing so should worry anyone paying attention.
Abliteration.ai does offer customers a moderation layer they can configure themselves, and the platform has some baseline restrictions of its own. In TechCrunch's testing, the model refused to provide suicide instructions, and Devon says he's working on adding more protections around violence. But the company hasn't implemented meaningful identity verification. It logs the credit card used at signup and little else. Devon acknowledges the company is still figuring out where its responsibility begins and ends. "You don't want to be the person responsible for someone doing something crazy," he said, "so where do you draw the line of what your responsibility is as a company? We're still in the process of defining that."
That's a strikingly candid admission from someone running a business that makes dangerous capabilities more accessible by design. It also points to a policy vacuum that governments haven't yet filled. Yoon has proposed one path forward: requiring AI providers to run classifiers that detect and block harmful cyber and bioweapons-related activity, and requiring companies that rent out advanced computing power to verify customer identities and deny access when misuse seems likely. Neither idea is currently mandated anywhere, which leaves the decision about who gets access to uncensored frontier models sitting almost entirely with companies like Abliteration.ai itself.
Most of the security experts TechCrunch spoke with agree on one thing: there's no putting this genie back in the bottle. Abliteration was already happening quietly across open-source communities before this company gave it a storefront. The real question isn't whether stripped-down models will exist. It's whether making them easier to reach helps the people trying to stop attacks more than it helps the people planning them. Slater, of Armadin, argues that bringing the practice into the open at least lets researchers study the frontier of what's possible. But that argument only holds if oversight and accountability keep pace with access, and right now, nothing suggests they will. Until regulators or the industry itself close that gap, the tradeoff Devon describes as counterintuitive protection may just be a faster path to harm for anyone willing to pay for it.
Tags
Original Sources
Abliteration.ai is making a business out of removing AI guardrails | TechCrunch
↗ https://techcrunch.com/2026/09/03/abliteration-ai-is-making-a-business-out-of-removing-ai-guardrails
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
6 September 2026
41 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.