A startup called Abliteration.ai is now selling access to AI models with their safety guardrails stripped out, making what was once an underground open-source practice into a readily available commercial service. The company, incorporated in March 2026, went public with the offering in September 2026.
The platform hosts modified versions of open-weight AI models — including Z.ai’s recently released GLM-5.3 — with their built-in refusals removed. Users can query these models through a web browser or via API. TechCrunch tested the service and was able to get the abliterated GLM-5.3 to produce instructions for stealing saved browser passwords and culturing a dangerous pathogen at home.
Co-founder Devon, who asked that his last name not be published as he remains employed elsewhere, says the company’s customers include red-teaming startups in the UK and Europe that help banks, airlines, and critical infrastructure firms test their cybersecurity defenses. He argues that defenders need the same tools as bad actors to stay effective. “The advantage is now the defenders can move as fast as possible,” Devon said. Abliteration.ai has not raised venture capital but is in talks to do so, and Devon says the company is profitable through customer revenue alone, including deals with major cloud providers.
Critics are skeptical of both the safety case and the safeguards in place. Andrew Yoon, head of research at AI safety nonprofit CivAI, warned that abliteration turns a model into something that “will comply with literally anything,” and said he expects abliterated models to be used for harm in the near future. The company currently has minimal identity verification, logging only a customer’s credit card number.
Not everyone in the cybersecurity industry agrees abliterated models are essential. Ahmed Aly, CEO of agent red-teaming firm Fabraix, told TechCrunch his company relies more on fine-tuning open models, and noted that abliteration can reduce a model’s overall capabilities. Alessio Lomuscio of Safe Intelligence acknowledged the capability tradeoff but said abliterated models can still be useful for stress-testing systems.
The development raises broader questions about whether making guardrail-free AI models widely accessible improves or worsens internet safety — a question regulators and the industry have yet to resolve.
Source: TechCrunch