Security

Abliteration.ai sells unlocked AI without safety barriers

3 min read

TL;DR Too Long; Didn’t read

The US startup Abliteration.ai has been selling API access to an AI model without built-in safety barriers since August 29, 2026, derived from Z.ai's open model GLM-5.3. For five dollars per million tokens, the system reportedly answers 84.5 percent of 1,507 cybersecurity test tasks, according to the provider. Customers are primarily located in the UK and Europe, including banks and airlines, according to TechCrunch.

Bolt cutters sever the chains of a humanoid robot, red-hot smoke rising from its opening chest as a dollar bill falls from its hand. Image generated with GPT Image 2

Key takeaways

  • Abliteration.ai has been offering an unlocked GLM-5.3 model for five dollars per million tokens since August 29, 2026.
  • According to the provider, the model solves 84.5 percent of 1,507 cybersecurity tasks in the CyberGym benchmark.
  • Early customers are primarily located in the UK and Europe, including banks and airlines, according to TechCrunch.
  • TechCrunch received both malicious code and instructions for a dangerous pathogen in its own test.
  • Founder Devon mentions only credit card verification as access control; identity verification is lacking.
  • The underlying technology has been publicly known since 2024; the commercial automation is new.

The US startup Abliteration.ai has been selling API access to an AI model that lacks all safety barriers since August 29, 2026. The basis is Z.ai’s open model GLM-5.3, neutralized by an automated technique called Abliteration. According to a report by TechCrunch, the first paying customers are primarily located in the UK and Europe.

Automated Technique Removes Refusal Patterns in the Model

The basis of the offering is a technique called Abliteration: it identifies the internal activation patterns that cause a language model to refuse a request and specifically alters the model weights to suppress those patterns. The underlying research has been publicly available since 2024, according to an analysis on arXiv; what is new about Abliteration.ai is the automation into a service that runs in minutes without expertise.

Founded in late 2025 and officially registered in March 2026, the company has been offering a product called abliterated-model-large-v2 since August 29, 2026 – a neutralized version of GLM-5.3. API access costs five dollars per million incoming and outgoing tokens; alternatively, according to Abliteration.ai, a free basic access via the browser is available. The model processes up to one million tokens at once – equivalent to several thousand pages of text in a single pass.

On the security benchmark CyberGym, the model reportedly solves 84.5 percent of 1,507 test tasks, while at ExploitGym it processes 105 out of 869 tasks in two hours – figures that have not been independently verified. The provider explicitly targets penetration testing and red teaming and additionally advertises a policy without storing requests and responses.

Early Customers Primarily Located in Europe

According to TechCrunch, the first paying customers are primarily in the UK and the rest of Europe, including banks, airlines, and operators of critical infrastructure who are testing their own systems. There is no age or identity verification – founder Devon, who withholds his last name for professional reasons, admits to TechCrunch that questions of accountability remain unresolved.

This access is thus significantly different from controlled offerings like OpenAI’s Daybreak program, which only unlock comparable hacking capabilities for vetted security teams and authorities. Abliteration.ai itself operates an additional moderation layer for customers and refuses, for example, instructions for suicide – in addition, thousands of other neutralized models are already openly available for download on Hugging Face.

The company is currently funded by customer revenues and is reportedly negotiating with venture capitalists; there is not yet a fixed funding round. Contracts with major cloud providers secure the infrastructure on which the unlocked models run. A company registration or proof of purpose is not required for access – a valid credit card is sufficient.

Security Researchers Warn of Misuse

Andrew Yoon from the security organization CivAI warns TechCrunch that the technology effectively turns a model into a “sociopath” that follows any request. In its own test, the editorial team received both functional malware code for stealing Chrome passwords and instructions for cultivating a dangerous pathogen.

Other red teaming firms express more caution according to TechCrunch: they prefer targeted fine-tuning over completely neutralized models because less capability is lost in the process. Critics and providers agree only that neutralized models are likely to be misused for attacks more frequently in the future.

The case fits into a series of security incidents surrounding AI systems this summer, from sandbox breaches in internal models to hijacked accesses. Unlike those incidents, however, Abliteration.ai is not a security vulnerability but a regular commercial offering.

It will be crucial whether cloud providers and payment service providers will restrict access to such services in the future, as there are currently hardly any technical countermeasures against Abliteration. It also remains open whether Z.ai, as the manufacturer of the underlying model GLM-5.3, will announce legal or technical steps against commercial use.

Frequently asked questions

How much does access to the unlocked models cost?

The API for the model abliterated-model-large-v2 costs five dollars per million input and output tokens. For simple queries, Abliteration.ai additionally offers free access via the browser.

Is the service usable from Germany or the EU?

No geographical restrictions are known; a credit card is sufficient for registration. According to TechCrunch, a large portion of the existing customer base already comes from the UK and the rest of Europe.

How does the offering differ from OpenAI's controlled hacking access Daybreak?

Daybreak opens comparable capabilities only to vetted security teams and authorities with a limited partner circle. In contrast, Abliteration.ai sells access openly for payment, without customer verification.

What exactly does the Abliteration technique do?

It specifically removes those internal patterns in the model that normally refuse requests, without affecting the model's other capabilities. The underlying method has been publicly documented as research since 2024.

Does Z.ai, as the manufacturer of the base model GLM-5.3, respond to the usage?

There has been no public statement from Z.ai regarding Abliteration.ai so far. It is also unclear whether cloud providers will continue their collaboration with the startup.

Sources (3)
  1. TechCrunch: Abliteration.ai is making a business out of removing AI guardrails
  2. Abliteration.ai: Introducing abliterated-model-large-v2
  3. arXiv: Willing but Unable – Separating Refusal from Capability in Code LLMs via Abliteration

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog