Product1 distinct publisher3 min readPublished
Stripping refusals out of open weights has been free on Hugging Face for years, and the setup cost is what kept it niche. A hosted endpoint takes that cost out, which is the part a threat model now has to absorb.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The appsec lead this lands on has already been asked twice this year for a model that will write working exploit code for a purple-team exercise, and has twice written back about where the weights would live and who would carry the GPU bill. That answer no longer holds. The scarce ingredient was never refusal removal itself but setup: Hugging Face already carries thousands of abliterated models, and people have been stripping refusals out of open weights for years [5]. Obtaining a pre-abliterated model and securing compute to run it are two things a defender has to justify separately [6]. Creating an account is one [17].
The pitch and the product need to be judged on their own terms. The pitch is parity for defenders, and the company's own social post says the aim is to enable "offensive cyber, red-teaming, and agent testing work other models refuse to do" [3], while the founder and other advocates argue that broad access to uncensored frontier models is itself the best defence [15]. The product arrives with the removal already done and the guardrail question handed back to the buyer. Customers get a moderation layer they can populate with whatever rules they want, and the platform's own controls are described as minor; TechCrunch reports the model would not produce suicide instructions, and co-founder Devon says he is still building controls against violence [11].
Supplier diligence here is thin, though not from any concealment. The company was founded late last year and incorporated in March [13], and TechCrunch withheld the co-founder's surname at his request because he still works for another firm [8]. For most tools that profile is unremarkable. For a vendor whose logs would hold your red team's exploit prompts, it is the question your risk committee asks on Friday.
Most of the experts TechCrunch consulted said the practice cannot realistically be stopped [14], which pushes the decision onto buyers rather than regulators, at least this quarter. Two axes sort it. First, whether the task genuinely requires refusals gone, or merely a model that will discuss security topics without hedging: malware that compiles and a threat-modelling conversation are different asks, and only one of them needs abliteration. Second, whether the prompts can leave your network at all.
If both answers are yes, the hosted endpoint is the cheapest option on the table, at the cost of having your offensive tooling and its inputs sit with a company that says it has not yet worked out who it will sell to [10]. If the first is yes but the second is no, you are back to self-hosting, which is exactly the labour this service exists to remove. If the first is no, what you actually have is a tool-selection problem dressed up as a capability gap, and removed refusals will not fix it. Some teams will skip that first answer altogether, because the trial costs nothing and the browser is already open [4].
Ranked by verification strength, evidence, and original report placement.
Abliteration.ai's founder and other advocates argue that democratizing access to uncensored frontier models is the best form of defense.
Abliteration.ai hosts modified versions of open-weight models with their guardrails removed, including Z.ai's recently released GLM-5.3, which users can query from a web browser or access through an API.
The startup is named after abliteration, a technique that removes a model's tendency to refuse harmful requests.
Abliteration.ai said in a recent social media post that its goal is to enable others to perform "offensive cyber, red-teaming, and agent testing work other models refuse to do."
TechCrunch created an account and queried an abliterated version of GLM-5.3 for free through a web browser; asked for a Python program that steals saved Chrome passwords and a detailed protocol for culturing a dangerous human pathogen at home, the model readily complied.
Abliteration is a long-standing technique among open-source models; researchers and developers have been removing refusals from open-weight models for years, and Hugging Face hosts thousands of abliterated models.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
GLM-5.3 says the quiet part: the base model did not change, the post-training did1 distinct publisher
build
GLM-5.3 is a paper, not an endpoint: Z.ai publishes research before weights1 distinct publisher
build
OpenAI's president says open weights will accelerate the threat. His own cyber model stays gated.1 distinct publisher
product
Cheap bug-hunting arrives: GLM 5.3 puts near-frontier vulnerability discovery on your own hardware1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Behavior demonstrated, business asserted
The part that matters most is the part TechCrunch verified itself: reporters ran the prompts and printed what came back. That is stronger than a press-release story usually gets. Everything commercial — cloud deals, revenue covering them, customer mix, the fundraise — is one man's word, and he would not give his surname. Two very different evidentiary tiers in one piece.
Live endpoint, unquantified usage
Live and free to reach, which is the whole point — but the demand side is a founder's summary. Several early-stage red-teaming startups in the UK and Europe, none named, no seat counts, no revenue. Against a free Hugging Face inventory of thousands of abliterated models, the commercial layer is still a thin slice of an existing practice.
Framing runs a step ahead of the change
Both loud voices overreach slightly in opposite directions. The founder calls abliteration essential to serious agent red-teaming, and red teamers in the same story say they get by fine-tuning open weights. The safety researcher expects harm soon, which may well be right, but the technique has been free for years and the reporting offers no incident to point at. Our own framing holds up better than either: what changed is the setup cost, not the capability.
A fundraiser and a regulator's advocate, on the record
Read the two named voices for what each is selling. The co-founder is talking to press while in talks for venture money, and his safety story — defenders need the same tools — doubles as his market. The critic runs research at a safety nonprofit and has just published the rules that would bind this business: mandatory classifiers, identity checks on GPU rental. Neither is disqualifying; both shape which facts got offered.
Certain about the model, hazy about the company
We would stake a lot on the demonstrated behavior and the credit-card-only access policy, and very little on the shape of the business behind it. Assume the specific outputs and the absence of real identity checks; treat the traction, the cloud arrangements and the customer roster as claims awaiting a second source.