A US startup called Abliteration.ai has turned one of open source AI's most controversial techniques into a commercial service, selling browser and API access to popular open-weight models with their safety training stripped out — including Z.ai's recently released GLM-5.3, one of the most capable open models available today.
The company takes its name from "abliteration," a method that removes a model's tendency to refuse harmful requests. Researchers and hobbyists have used the technique for years, and Hugging Face hosts thousands of abliterated models. What is new is the packaging: Abliteration.ai hosts modified models on its own infrastructure, so anyone with a web browser can query them without downloading weights or renting GPUs. TechCrunch reported the development on September 3, and it has since drawn scrutiny from safety researchers tracking the open-weights debate we follow in our AI news coverage.
From Underground Technique to Turnkey Platform
Founded late last year and officially incorporated in March, Abliteration.ai moves the practice from a do-it-yourself open source niche into a polished commercial product. By hosting the models itself, the company removes two friction points at once: users no longer need the technical skill to ablate a model, nor the compute to run one.
Co-founder Devon — TechCrunch withheld his surname at his request because he remains employed at another firm — said the company has struck deals with several major cloud providers and is funded entirely through customer revenue. The startup has not raised venture capital, though he said talks are underway.
What TechCrunch's Test Found
The company says its goal is to enable "offensive cyber, red-teaming, and agent testing work other models refuse to do." TechCrunch put that to the test with a free account, querying an abliterated version of GLM-5.3 through a web browser. The reporters asked the model to write a Python program that steals saved Chrome passwords, and to produce a detailed protocol for culturing a dangerous human pathogen at home. It readily complied with both requests, according to the report.
That experiment is the heart of the story: tasks that mainstream frontier models categorically refuse are now available behind a sign-up form, at no cost, in a browser tab.
The Red-Team Defense Argument
Devon's case for the business is the classic security argument: you cannot defend against behavior you cannot reproduce. A model that refuses to write working exploit code is of little use to a red team trying to understand real attackers.
"The big picture of abliterated models is they're able to model bad actors," he told TechCrunch. "The advantage is now the defenders can move as fast as possible ... I think it will accelerate cybersecurity, which is a kind of counterintuitive point."
The company's customers include early-stage red-teaming startups in the UK and Europe that test the security of banks, airlines and other operators of critical infrastructure. One major customer, Devon said, red teams banking agents and could not perform that work with unmodified commercial models.
'A Model That Becomes a Sociopath'
Safety researchers see the same capability very differently. Andrew Yoon, head of research at the AI safety nonprofit CivAI, told TechCrunch that abliteration lets you "modify the model so that it becomes a sociopath."
"You can type in literally anything here, and it will comply with it," Yoon said, adding that he expects "edited, abliterated models being used for harm in the near future."
In a recent opinion piece, Yoon argued that if guardrail removal cannot realistically be prevented, governments should require providers to run classifiers that detect and block harmful cyber and bioweapons activity, and should require companies renting direct access to advanced GPUs to verify customer identities and deny service where dangerous misuse is suspected.
Thin Guardrails and No Identity Checks
For now, Abliteration.ai's own safeguards are minimal. The platform offers customers an optional moderation layer so they can add whatever restrictions they wish, and the site itself maintains some minor limits — TechCrunch could not get the model to produce suicide instructions, and Devon said he is working on additional measures to prevent violence.
The company performs no know-your-customer screening beyond logging the credit card used for payment. "You don't want to be the person responsible for someone doing something crazy ... so where do you draw the line of what your responsibility is as a company?" Devon said. "We're still in the process of defining that."
A Question the Industry Can't Dodge
Not every security practitioner agrees that abliterated models are even the best tool for offensive testing. Ahmed Aly, CEO of the agent red-teaming firm Fabraix, told TechCrunch his company relies more on fine-tuning open-weight models, which already ship with few refusals — and notes that abliteration can degrade a model's underlying capabilities.
Most experts TechCrunch consulted agree on one thing: the practice cannot be stopped. Downloadable weights mean anyone can strip refusals locally, as a 2026 commentary from the Combating Terrorism Center at West Point on "abliteration" misuse underscored. The open question Abliteration.ai forces is whether lowering the cost of access for everyone — defenders and attackers alike — makes the internet safer or more dangerous.
Stay Ahead of AI
AI safety is evolving daily. Get the latest AI developments in one place.
Read more AI news →