# Abliteration.ai Sells Guardrail-Free AI Models and Is Now Courting VCs

> Source: <https://startupfortune.com/abliterationai-sells-guardrail-free-ai-models-and-is-now-courting-vcs/>
> Published: 2026-09-04 03:04:56+00:00

*Abliteration.ai is turning stripped-down AI safety into a hosted product, and the uncomfortable part is how little stands between that product and a paying customer.*

Abliteration.ai sells web and API access to modified open-weight models that have had refusal behavior removed from the weights themselves. According to TechCrunch, the startup is now offering an abliterated version of Z.ai's GLM-5.3 and is talking to venture investors after funding its cloud costs from customer revenue.

That is the product. Not a jailbreak prompt. Not a clever wrapper. A model with part of its refusal machinery cut out, hosted for people who don't want to download weights, find compute and run the modification themselves.

The company says the technique finds the internal direction in a model's activations that produces refusals, then removes that direction while trying to leave reasoning and coding intact - and agentic ability too. Z.ai's own GLM-5.3 model page reports the cyber numbers that make this more than a culture-war fight over uncensored chatbots: GLM-5.3 scored 54.4% on ExploitBench, up from 24.4% for GLM-5.2, and completed 105 ExploitGym tasks in a two-hour window, up from 29. Those are vendor-reported benchmark figures for the base GLM-5.3 model, not independent proof that Abliteration.ai made it more capable.

The distinction matters. If you're defending a bank or an airline, you care about the model's actual ability to reason through offensive cyber tasks - and so does anyone defending a software supply chain. If you're regulating access, you care about who can now rent that ability with less friction than it takes to set up a local inference stack.

[Abliteration.ai Now Sells an AI Model With No Safety Refusals for Hackers](https://startupfortune.com/abliterationai-now-sells-an-ai-model-with-no-safety-refusals-for-hackers/)

Abliteration.ai has released an API-accessible AI model with its safety refusals stripped out, built on Z.ai's GLM 5.2 and marketed for offensive cybersecurity and red-team work. Researchers at West Point's Combating Terrorism Center warn the underlying technique, abliteration, can strip guardrails from nearly any open-weight model. - [ai model with safety refusals removed for hackers](https://startupfortune.com/abliterationai-now-sells-an-ai-model-with-no-safety-refusals-for-hackers/) - [abliterated model large penetration testing red team tool](https://startupfortune.com/abliterationai-now-sells-an-ai-model-with-no-safety-refusals-for-hackers/)

Co-founder Devon frames the service as a tool for defenders. TechCrunch withheld his surname because he still works at another firm. He told the outlet that abliterated models help security teams model bad actors and move faster, calling the upside for cybersecurity counterintuitive. That's the pitch: red teamers need to reproduce adversarial model behavior before they can defend against it.

It isn't a fake market either. Devon told TechCrunch the company's customers include early-stage red-teaming startups in the UK and Europe, including firms that work with banks, airlines and critical infrastructure operators. Abliteration.ai has also struck deals with several major cloud providers, he said. It hasn't raised venture capital yet. It wants to now.

## Who Gets Access

The risk is access.

TechCrunch said it was able to create an account and query the abliterated GLM-5.3 model for free through a browser. The outlet reported that the model complied when asked for code to steal saved Chrome passwords and for a detailed home protocol involving a dangerous human pathogen. Those aren't distant policy worries. They are the kinds of outputs safety teams spend real money trying to stop.

Andrew Yoon, head of research at the AI safety nonprofit CivAI, put the concern bluntly to TechCrunch. Abliteration, he said, lets you modify a model so that it becomes a sociopath. He also said users can type in literally anything and the model will comply, and he expects edited abliterated models to be used for harm in the near future.

Abliteration.ai does have some limits. TechCrunch reported that the platform offers customers a moderation layer and that, in its own testing, the model would not provide suicide instructions. Devon also said the company is working on more controls to prevent violence.

Still, the company's customer checks are thin. TechCrunch reported that Abliteration.ai hasn't added know-your-customer practices beyond logging the credit card used to buy the service. Devon told the outlet the company is still defining where its responsibility begins and ends. Here's the thing: if your product exists to remove refusals from highly capable models, that question can't sit in the backlog for long.

[Z.ai launches GLM-5.3, a coding model billed as ready for cyber defense](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/)

Z.ai launched GLM-5.3, its new flagship open-weight model, with the tagline "Built to Code. Ready for Cyber Defense." The launch follows a NIST assessment that found its predecessor, GLM-5.2, matched Claude Opus 4.6 on cyber capability while its safeguards allowed help with exploit development. - [GLM-5.2 model cyber defense capabilities](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/) - [open weight coding model security](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/)

## The Safety Business In Reverse

OpenAI, Anthropic, Google DeepMind: labs like these spend heavily on red-teaming and refusal training because the outputs matter. Abliteration.ai sells the reverse as a hosted service. It takes open weights, removes some of the friction and gives customers an API.

Open weights are the reason this business can exist. They help researchers, startups, developers - anyone who can't afford closed-model dependence or doesn't want it. They also let a company download a capable model and cut out the part that says no. Nothing about that requires breaking into a frontier lab. It follows from the decision to publish weights at all.

That doesn't make open models bad. Don't bother with that lazy argument. The point is narrower and harder: once capable weights are public, the safety fight moves from model release to distribution, hosting, customer checks and monitoring. Abliteration.ai is testing whether investors will fund a company built exactly at that edge.

Whether VCs write the check is almost beside the point. The company already showed there are customers for guardrail-free access. The next question is whether governments and cloud providers treat that as normal security tooling, or as a high-risk service that needs controls before it scales.

**Also read:** [An OpenAI Testing Agent Hacked Hugging Face Right Before Nvidia's $13 Billion Buyout](https://startupfortune.com/an-openai-testing-agent-hacked-hugging-face-right-before-nvidias-13-billion-buyout/) • [IREN Stock Jumps After Bitcoin Miner Lands Nvidia's Cloud Stamp of Approval](https://startupfortune.com/iren-stock-jumps-after-bitcoin-miner-lands-nvidias-cloud-stamp-of-approval/) • [Bernie Sanders Wants Prison Time for Anyone Who Builds Superintelligent AI](https://startupfortune.com/bernie-sanders-wants-prison-time-for-anyone-who-builds-superintelligent-ai/)

## Founder discussion

[Open in the community →](/community/)

Almost there. Sign in and your reply posts straight away.
