Build1 distinct publisher2 min readPublished
Editing refusal behaviour out of the weights means nothing in front of the model can put it back, and the harder question is what the hosted version buys when SaferAI found the unmodified predecessor already refused nothing.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Abliteration operates on activations. The process locates the internal patterns that fire when a model is about to refuse, then edits the weights so those patterns stop firing [3]. What ships is a checkpoint with no trained refusal left to invoke, which is a different object from a jailbroken chat session [4]. Controls that sit outside the weights have nothing to act on here: no refusal behaviour for a system prompt to reinforce, none for a classifier to score. Abliteration.ai says coding, cyber, and agentic ability mostly survive the edit [5].
That survival claim is what the eval table is meant to carry, and the table is a statement about Abliteration.ai's harness. The abliterated model lands 1.1 points behind GPT-5.5 on CyberGym in the company's own numbers [9], and the company says the rows come from different harnesses and compute budgets [8]. For any of those comparisons to transfer, both rows would need the same scaffold and the same token budget, which the company does not claim. The row I would want is unmodified GLM-5.3 under one harness at one budget. Without it, nothing in the table attributes the score to the abliteration rather than to GLM-5.3, and Z.AI has written that GLM-5.3's cyber capabilities grew faster than expected during post-training [20]. Abliteration.ai's own reason for building on GLM is that earlier versions were deliberately trained in ways that made them harder to use for practical security work [19].
The procurement step is what actually disappears. Anyone holding open weights could always modify the trained safety behaviour [22], and abliterated checkpoints have been published on Hugging Face for years [21]. What is new is that the buyer skips the download and the GPU bill [12].
Hosting cuts both ways. The startup sells tokens, not weights [12]. Use of this particular model therefore runs through one vendor's endpoint under a billing relationship, which is more visible on a corporate network than a checkpoint pulled onto a rented box.
The demand story is thinner than the launch. Abliteration.ai markets the model for offensive security work, AI red teaming, agent testing, and trust and safety [18], and the claim that early customers include firms testing agents deployed by large organizations and banks comes from an anonymous founder speaking on the ThursdAI podcast [14]. TechCrunch got the model to produce code for extracting saved Chrome passwords [17], which is the part of the account that does not rest on anyone's harness.
For a defender the operational read is narrow. The capability lives in GLM-5.3, which is open-weight [1], so blocking one API endpoint moves the price of misuse rather than its ceiling.
Ranked by verification strength, evidence, and original report placement.
The US startup Abliteration.ai strips trained refusal mechanisms from open-weight models like GLM-5.3 and sells access to the modified versions through a commercial API.
In late August, Abliteration.ai launched "abliterated-model-large-v2," a modified version of Z.AI's GLM-5.3 designed to refuse sensitive requests far less often.
Abliteration finds internal activation patterns in the model that trigger refusals, then tweaks the model weights to suppress those patterns.
Abliteration is not a prompt jailbreak but a change to the model itself.
For the abliterated GLM-5.3, Abliteration.ai reports 84.5 percent on CyberGym, 41.8 percent on Terminal-Bench 4.0, and 105 solved ExploitGym tasks in two hours.
In Abliteration.ai's own comparison table, GPT-5.5 tops CyberGym at 85.6 percent, and GPT-5.6 Sol and Fable 5 score well above the abliterated model on ExploitGym.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Post-training alone took GLM-5.3 from 4.6 to 28.3 on Terminal-Bench 3.08 distinct publishers
product
Z.ai's GLM-5.3 beats Claude on CyberGym, then hands out the weights1 distinct publisher
science
GLM-5.3 says the quiet part: the base model did not change, the post-training did1 distinct publisher
build
GLM-5.3 keeps GLM-5.2's base model and claims 50% more on coding: plan for shorter eval cycles5 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet, seller's numbers
Every capability figure in the story was produced by the company selling access, on its own harness, with its own admission that the comparison mixes harnesses and compute budgets. The checkable parts are checkable: the token price, the withheld weights, Z.AI's licence terms. The two pieces of outside evidence, SaferAI's zero-refusal result and TechCrunch's hands-on test, reach readers through The Decoder rather than being reproduced.
Asserted demand, no named user
The service exists, is priced and is running, which is more than a launch post. Who uses it is another matter: the only buyer description comes from a founder who would not be named, and the practitioners actually quoted say abliterated models sit outside their workflow. Nothing in this reporting attaches a named customer, seat count or volume figure to the API.
Novelty is the hosting
The premise that customers need refusal-stripping takes a real hit from SaferAI's finding that unmodified GLM-5.2 refused nothing in offensive-security evals, and the seller's own table leaves the abliterated model 1.1 points behind GPT-5.5 on CyberGym. Abliteration has been a Hugging Face commonplace for years, so what is being sold is operations and anonymity rather than a capability nobody else could reach. The overshoot belongs to the vendor's positioning; The Decoder flags each of these counterpoints.
The seller supplies the evidence
Abliteration.ai chose the benchmarks, ran them, wrote the comparison table and supplied the demand story through a founder who stayed anonymous. Withholding the modified weights keeps customers on the meter. Zero retention and the absence of identity checks are presented as protections for security teams, and they also remove the records that would let anyone reconstruct misuse, which is a commercial convenience as much as a privacy stance.
Checkable price, unverifiable capability
Confidence splits along the seams of the story. Pricing, the hosted-only distribution and the licence permission are verifiable statements about terms. The capability retention, the benchmark standing and the bank-adjacent demand are not, and with one outlet reporting days after launch there has been no time for anyone to test the model outside the seller's harness.