The US startup Abliteration.ai has been selling API access to an AI model that lacks all safety barriers since August 29, 2026. The basis is Z.ai’s open model GLM-5.3, neutralized by an automated technique called Abliteration. According to a report by TechCrunch, the first paying customers are primarily located in the UK and Europe.
Automated Technique Removes Refusal Patterns in the Model
The basis of the offering is a technique called Abliteration: it identifies the internal activation patterns that cause a language model to refuse a request and specifically alters the model weights to suppress those patterns. The underlying research has been publicly available since 2024, according to an analysis on arXiv; what is new about Abliteration.ai is the automation into a service that runs in minutes without expertise.
Founded in late 2025 and officially registered in March 2026, the company has been offering a product called abliterated-model-large-v2 since August 29, 2026 – a neutralized version of GLM-5.3. API access costs five dollars per million incoming and outgoing tokens; alternatively, according to Abliteration.ai, a free basic access via the browser is available. The model processes up to one million tokens at once – equivalent to several thousand pages of text in a single pass.
On the security benchmark CyberGym, the model reportedly solves 84.5 percent of 1,507 test tasks, while at ExploitGym it processes 105 out of 869 tasks in two hours – figures that have not been independently verified. The provider explicitly targets penetration testing and red teaming and additionally advertises a policy without storing requests and responses.
Early Customers Primarily Located in Europe
According to TechCrunch, the first paying customers are primarily in the UK and the rest of Europe, including banks, airlines, and operators of critical infrastructure who are testing their own systems. There is no age or identity verification – founder Devon, who withholds his last name for professional reasons, admits to TechCrunch that questions of accountability remain unresolved.
This access is thus significantly different from controlled offerings like OpenAI’s Daybreak program, which only unlock comparable hacking capabilities for vetted security teams and authorities. Abliteration.ai itself operates an additional moderation layer for customers and refuses, for example, instructions for suicide – in addition, thousands of other neutralized models are already openly available for download on Hugging Face.
The company is currently funded by customer revenues and is reportedly negotiating with venture capitalists; there is not yet a fixed funding round. Contracts with major cloud providers secure the infrastructure on which the unlocked models run. A company registration or proof of purpose is not required for access – a valid credit card is sufficient.
Security Researchers Warn of Misuse
Andrew Yoon from the security organization CivAI warns TechCrunch that the technology effectively turns a model into a “sociopath” that follows any request. In its own test, the editorial team received both functional malware code for stealing Chrome passwords and instructions for cultivating a dangerous pathogen.
Other red teaming firms express more caution according to TechCrunch: they prefer targeted fine-tuning over completely neutralized models because less capability is lost in the process. Critics and providers agree only that neutralized models are likely to be misused for attacks more frequently in the future.
The case fits into a series of security incidents surrounding AI systems this summer, from sandbox breaches in internal models to hijacked accesses. Unlike those incidents, however, Abliteration.ai is not a security vulnerability but a regular commercial offering.
It will be crucial whether cloud providers and payment service providers will restrict access to such services in the future, as there are currently hardly any technical countermeasures against Abliteration. It also remains open whether Z.ai, as the manufacturer of the underlying model GLM-5.3, will announce legal or technical steps against commercial use.


