AI
Abliteration.ai Turns Guardrail Removal Into a Paid Service
A US startup hosts open-weight models with their refusal behaviour stripped out and sells API access at $5 per million tokens, no identity check required. Red-teamers are unconvinced they need it.

A penetration tester at a mid-sized company wants to see what an attacker's AI assistant would actually produce. Until recently that meant downloading a modified open-weight model, finding a GPU, and running it locally. As of this month there is a simpler path: open a browser, or call an API at $5 per million tokens, with a credit card and no identity verification.
The service is Abliteration.ai. TechCrunch profiled it on September 3 and The Decoder followed on September 6. Between them the two reports explain what is being sold and why safety researchers are uneasy.
The product
The technique is not new. "Abliteration" locates the internal activation patterns that trigger refusals in a model and then adjusts the weights to suppress them. The open-source community has done this for years; Hugging Face hosts thousands of models modified this way. What the startup adds is hosting: no download, no hardware, a ready endpoint.
The main target is Z.ai's GLM-5.3, previously GLM-5.2, with Qwen, DeepSeek and Mistral models also on offer. The co-founder speaks only as "Devon" and withholds his surname because he still works elsewhere. The company started in late 2025, incorporated in March 2026, is revenue-funded, and is in talks with investors.
The defence, and the holes in it
Devon frames the service as a tool for defenders: "The advantage is now the defenders can move as fast as possible. They have all these tools that they need to be able to model these bad actors and then defend from these bad actions." The stated market is offensive security, AI red teaming, agent testing and trust-and-safety work. Early customers are red-teaming startups in the UK and Europe. A few minimal guardrails remain; in testing, suicide instructions were blocked. Customers can add their own moderation layer.
The criticism is specific. In TechCrunch's testing the model produced Python code for stealing passwords and a protocol for culturing pathogens. Andrew Yoon of CivAI: "You can type in literally anything here, and it will comply with it." Several red-team providers said abliterated models are not part of their routine work. SaferAI noted that the unmodified GLM-5.2 already refused zero tasks in its offensive-security evaluations, which undercuts the stated need. Research also shows abliteration changes behaviour on tasks the base model never refused, so "the same model, just unrestricted" is not an accurate description of what customers get.
On licensing the startup appears to be on solid ground: Z.ai's GLM licence permits modifications, derivatives and commercial model-as-a-service offerings. Neither Hugging Face, Meta nor Google has commented on the record.
Two checks for teams running open models
First, provenance. If a model in your stack carries "abliterated" or "uncensored" in its name, it did not get there by accident, and it is not what you want behind a customer-facing assistant. Keep model source and version in your procurement records. Second, necessity. Before anyone puts this service on a company card, ask whether your red-team work needs it at all; SaferAI's finding suggests most open models already offer little resistance in attack scenarios. A short review by your security lead settles both questions.
Sources: TechCrunch, The Decoder

Written by
Faruk Talmaç
Co-Founder & Editor
Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.