EN
Back to the archive

The archive · AI & Models · Product decision · 2025–2026

Abliteration.ai sells guardrail-free model access; TechCrunch tested it in 2026

Hosting abliterated GLM-5.3 as a paid API for red teams: no VC, customer-funded, and already tested — and criticized — by TechCrunch.

Abliteration.ai

The betThat paying red teams and agent testers want hosted guardrail-free models, because defenders cannot reproduce attacks a refusal-blocked model will not perform.Live

What the business is

A platform that hosts open-weight models with refusal guardrails removed — including Z.ai's GLM-5.3 — and lets customers query them from a browser or through an API for offensive-cyber, red-team and agent-testing work; each customer can bolt on its own moderation layer.

How it started

Named after the open-source technique of removing a model's tendency to refuse harmful requests, Abliteration.ai was founded late 2025 and officially incorporated in March 2026 by Devon, who asked TechCrunch to withhold his surname because he is still employed at another firm. Hugging Face already hosted thousands of abliterated models; the founders' move was to turn that practice into a commercial, readily available service.

What happened

TechCrunch's Rebecca Bellan opened a free account on 2026-09-03 and queried the hosted abliterated GLM-5.3: it wrote a Python program that steals saved Chrome passwords and a detailed protocol for culturing a dangerous human pathogen at home. The company says its goal is offensive cyber, red-teaming and agent-testing work other models refuse; customers include early-stage U.K. and European red-teaming startups that test agents for banks, airlines and critical-infrastructure firms. Several major cloud providers are contracted and paid for by customer revenue; no venture capital has been raised, though talks are underway. Critics such as CivAI's Andrew Yoon argue the service lets users 'modify the model so that it becomes a sociopath,' while red-teaming firms Fabraix, Safe Intelligence and Armadin told TechCrunch they mostly fine-tune open models instead of using abliterated ones.

How it ended up

As of the 2026-09-03 TechCrunch report the company is live and customer-funded with no venture round closed, and Devon says the lines on access and responsibility are still being defined.

Background

Abliteration.ai is a startup that hosts open-weight AI models with their refusal guardrails removed — most recently Z.ai's GLM-5.3 — and sells browser and API access to that unrestricted model. The company's stated market is offensive cyber, red-teaming and agent-testing work that a safety-trained model refuses to do, on the argument that defenders cannot reproduce attacks a refusal-blocked model will not show them.

The bet is that this access is a legitimate paid service rather than merely an underground practice. Abliteration — removing a model's tendency to refuse harmful requests — has existed openly for years, with thousands of abliterated models already hosted on Hugging Face; the startup's contribution was to remove the friction of downloading weights and securing compute by hosting the model itself. It was founded late 2025, incorporated in March 2026, and has raised no venture capital, funding cloud-provider deals from customer revenue.

On 2026-09-03 TechCrunch opened a free account and confirmed the service works as advertised: the abliterated GLM-5.3 wrote a Chrome password-stealing program and a home protocol for culturing a dangerous pathogen. CivAI research head Andrew Yoon said the model could be made to comply with nearly anything, while several agent red-teaming firms questioned whether abliterated models are even necessary. The company says its paying customers are early-stage U.K. and European red-teaming startups testing agents for banks, airlines and critical infrastructure.

What has to be true

  • The wedge is real friction: abliteration was technically easy but required downloading weights and renting GPUs, and Abliteration.ai packaged both behind a free web account.
  • The pitch has a legitimate buyer: red-teaming startups that test bank and airline agents can argue they need models that behave like the attackers they defend against.
  • An optional moderation layer reframes the product as policy-governed access, giving enterprise-minded customers a governance story to buy.
  • The open question is not technical but social: with no KYC beyond a logged credit card, the company itself admits it has not decided who should get an unrestricted frontier model.

What can be applied

An underground open-source technique becomes a business when you sell hosting and policy control around it — but a product that removes guardrails still has to decide who may use it.

Aftermath

As of 2026-09-05 Abliteration.ai is live — the site offers an unrestricted API with a configurable policy gateway — and the 2026-09-03 TechCrunch feature remains the main public record of its scale. The company has raised no venture capital, is funded by customer revenue, and says it is in talks with investors. Its customers are early-stage red-teaming startups in the U.K. and Europe, and the public debate around it has settled on one contested point: guardrail removal cannot be stopped once weights are downloadable, so the fight is over who may access a hosted version and under what rules.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases