Abliteration.ai has developed a commercial service that removes the safeguards enabling open-weight AI models to refuse harmful requests and offers them through a web browser and API. Founded late last year and formally incorporated in March, the startup hosts modified models, including Z.ai’s newly released GLM-5.3 model. The company says its aim is to enable “offensive cybersecurity, red-team and agent testing” that other models refuse.
Removing model safety safeguards has long been practiced in the open-source community, and thousands of models modified in this way are available on Hugging Face. Abliteration.ai makes access easier by eliminating the need for users to download the models and provide the computing power to run them. TechCrunch reported that the GLM-5.3 version it accessed with a free account provided a Python program that steals saved Chrome passwords and detailed instructions for growing a dangerous human pathogen at home.
Co-founder Devon said the company has agreements with major cloud providers and that costs are covered by customer revenue. Abliteration.ai, which has not yet raised venture capital, is holding investment talks. Its customers include early-stage red-team startups based in the U.K. and Europe that provide cybersecurity services to banks, airlines and critical infrastructure organizations.
Andrew Yoon, head of research at CivAI, said that models with their safety safeguards removed become capable of complying with any request and could be used to cause harm in the near future. Yoon recommended that governments require cloud providers to use classifiers that identify harmful cyber activities and biological weapons research, and that companies renting access to advanced GPUs verify their customers’ identities.
Abliteration.ai provides customers with a moderation layer where they can add their own safety rules. The platform has some restrictions; in TechCrunch’s test, the model did not provide instructions for suicide. Devon said he was working on additional measures to prevent violence. The company does not conduct KYC beyond requiring a payment card on file.
The method’s defensive value is disputed within the industry. Fabraix CEO Ahmed Aly said removing safety measures could diminish a model’s knowledge and capabilities, and that his company instead uses fine-tuned open models. Alessio Lomuscio of Safe Intelligence said the method could be useful in stress tests, while Armadin founder David Slater said these models were not yet part of their processes but that open research helped in understanding the risks.
Why it matters
This service lowers the download, setup and computing power barriers to accessing models with their safety boundaries removed, opening up to a broad user base a practice previously limited to those with the necessary technical capabilities. While this expands testing opportunities for red-team teams working for banks, airlines and critical infrastructure organizations, it also increases the risk that the same tools could be used for cyberattacks and biological harm. The absence of identity verification beyond a payment card raises the question of how responsibility for preventing harmful use should be shared among the platform, the customer and cloud providers. Moreover, the lack of industry consensus on the method’s actual contribution to defensive testing shows that the benefits of increased access and the risks it creates have yet to be clearly measured.