Policy

Abliteration.ai Strips Safety Guardrails From GLM-5.3

US startup Abliteration.ai has launched a commercial API that removes safety guardrails from Z.AI's GLM-5.3 model, making uncensored AI accessible without heavy hardware requirements.

The Decoder1 day agoPolicy
Image: The Decoder

Abliteration.ai has introduced "abliterated-model-large-v2," a modified version of Z.AI's open-weight GLM-5.3 model. By using a technique called abliteration, the startup modifies the model's weights to suppress the internal activation patterns that trigger refusal responses. Instead of releasing the modified weights for download, the company hosts the model itself, offering turnkey API access for five dollars per million input or output tokens.

The startup claims that the model's coding, cyber, and agentic capabilities remain largely intact. In its internal evaluations, the abliterated GLM-5.3 scored 84.5 percent on CyberGym, 41.8 percent on Terminal-Bench 4.0, and solved 105 ExploitGym tasks within a two-hour window. While these scores are competitive, they do not lead across the board; GPT-5.5 scored 85.6 percent on CyberGym, and both GPT-5.6 Sol and Fable 5 outperformed it on ExploitGym, though the company notes these comparisons used different testing harnesses and compute budgets.

For cybersecurity practitioners, the service provides an easy way to conduct offensive security testing, malware analysis, and red teaming without needing to run massive GPU infrastructure. The model can help simulate phishing attacks or test AI agents against prompt injections. However, the lack of guardrails also enables malicious use. Journalists successfully used the model to generate code for extracting saved browser passwords and instructions for cultivating a dangerous pathogen, though the system still blocks self-harm and child sexual abuse material.

To protect sensitive proprietary data, Abliteration.ai operates with a zero-retention policy for prompts and responses, keeping only operational metadata like token counts and billing info. While this keeps confidential exploit code private for legitimate security teams, it also means there are no logs to investigate if the service is abused. Furthermore, the startup does not require identity verification, arguing that such checks disadvantage smaller security firms and fail to reliably filter out bad actors.

This is our own summary of reporting by The Decoder

More in Policy