Stripping safety guardrails from open-weight AI models is now a turnkey commercial service
Abliteration.ai removes trained refusal mechanisms from powerful open-weight models and sells access to the modified versions as a service. There’s a legitimate market for that, but the same setup creates a difficult security trade-off.
Anyone with access to an open-weight model’s weights can modify its trained safety mechanisms. The US startup Abliteration.ai has built a business around exactly that. In late August, it launched “abliterated-model-large-v2,” a modified version of Z.AI’s GLM-5.3 designed to refuse sensitive requests far less often. The technique is called abliteration. Put simply, the process finds internal activation patterns in the model that trigger refusals. The model weights are then tweaked to suppress those patterns. This isn’t a prompt jailbreak but a change to the model itself. Abliteration.ai claims that coding, cyber, and agentic capabilities stay mostly intact.Ad The company’s in-house evaluations are meant to back that up. For the abliterated GLM-5.3 version, Abliteration.ai reports 84.5 percent on CyberGym, 41.8 percent on Terminal-Bench 4.0, and 105 solved ExploitGym tasks in two hours. The model doesn’t lead across the board, though. In the company’s own table, GPT-5.5 tops CyberGym at 85.6 percent, and GPT-5.6 Sol and Fable 5 score well above it on ExploitGym. Abliteration.ai also acknowledges that the comparison scores come from different harnesses and compute budgets, which limits how directly they can be compared.Ad The predecessor model, “abliterated-model-large,” was also based on GLM-5.2. According to Abliteration.ai, earlier GLM versions were deliberately trained in ways that made them harder to use for practical security work. Z.AI has written that GLM-5.3’s cyber capabilities grew faster than expected during post-training. GLM combines strong coding, agentic, and cyber performance with open weights and a commercially usable license.