Abliteration.ai removes trained refusal mechanisms from powerful open-weight models and sells access to the modified versions as a service. There's a legitimate market for that, but the same setup creates a difficult security trade-off.

Anyone with access to an open-weight model's weights can modify its trained safety mechanisms. The US startup Abliteration.ai has built a business around exactly that. In late August, it launched "abliterated-model-large-v2," a modified version of Z.AI's GLM-5.3 designed to refuse sensitive requests far less often.

The technique is called abliteration. Put simply, the process finds internal activation patterns in the model that trigger refusals. The model weights are then tweaked to suppress those patterns. This isn't a prompt jailbreak but a change to the model itself. Abliteration.ai claims that coding, cyber, and agentic capabilities stay mostly intact.

Abliteration.ai compares its abliterated GLM-5.3 model to competing models across three benchmarks. | Image: Abliteration

The company's in-house evaluations are meant to back that up. For the abliterated GLM-5.3 version, Abliteration.ai reports 84.5 percent on CyberGym, 41.8 percent on Terminal-Bench 4.0, and 105 solved ExploitGym tasks in two hours. The model doesn't lead across the board, though. In the company's own table, GPT-5.5 tops CyberGym at 85.6 percent, and GPT-5.6 Sol and Fable 5 score well above it on ExploitGym. Abliteration.ai also acknowledges that the comparison scores come from different harnesses and compute budgets, which limits how directly they can be compared.