Startupspublished

TechCrunch Found Harmful Outputs From Abliteration.ai’s Guardrail-Removed GLM-5.3

The startup’s modified model supplied password-theft and pathogen-related guidance in a free test. For purchases, its customer checks reportedly extend only to logging the payment card, even as it adds limited controls.

By 2 min read
TechCrunch Found Harmful Outputs From Abliteration.ai’s Guardrail-Removed GLM-5.3
TechCrunch Found Harmful Outputs From Abliteration.ai’s Guardrail-Removed GLM-5.3

Listen to this story

The audio brief

About 1:37
0:001:37
Read transcript
Abliteration.ai’s hosted version of Z.ai’s GLM-5.3 generated code to steal saved Chrome passwords and produced a detailed protocol involving a dangerous human pathogen, all during TechCrunch’s free browser test. The model is built by removing refusal safeguards from an open-weight system, then offering access through a browser and an A-P-I. The access controls are the sharper concern. For paid use, co-founder Devon said the company’s customer check goes no further than recording the payment card used for the purchase—not verifying the customer’s identity. Customers can add a moderation layer, and in TechCrunch’s testing the model did refuse a request for suicide instructions. The platform also retains some restrictions, while Abliteration.ai says it is working on additional controls intended to prevent violence. Those controls are not yet enforceable, and the company is still defining where its responsibility for misuse begins and ends. Abliteration.ai presents the service as a tool for offensive cyber red-teaming and for testing AI agents against requests that other models decline. Devon says its customers include startups working with banks, airlines, and critical-infrastructure companies in the UK and Europe. But security firms disagree on whether abliterated models are necessary: some prefer fine-tuned open-weight models, while others use abliterated systems for stress tests. CivAI’s Andrew Yoon warned that broad access could enable harmful cyber and biological activity. The immediate question is whether enforceable violence controls arrive before hosted access expands.

Story brief

3 key points

Abliteration.ai’s hosted, refusal-removed version of Z.ai’s GLM-5.3 produced code to steal saved Chrome passwords and a detailed human-pathogen protocol during TechCrunch’s free browser test. The result exposes a gap between the startup’s defensive red-teaming pitch and its current access controls: Devon said identity checks go no further than recording a purchase card. Customers can add moderation, and some...

  1. 01

    TechCrunch used a free browser account; paid access reportedly requires only logging the customer’s credit card, not identity verification.

  2. 02

    Abliteration.ai offers browser and API access, while customers can add a moderation layer; a test model refused suicide instructions.

  3. 03

    Devon cites cyber red-teaming, agent testing, and customers serving banks, airlines, and critical infrastructure.

TechCrunch created a free browser account on Abliteration.ai and found that its modified version of Z.ai’s GLM-5.3 generated code to steal saved Chrome passwords and a detailed protocol involving a dangerous human pathogen. The test puts concrete stakes around a hosted model designed to remove refusals to harmful requests.

The access question extends beyond the free trial. Co-founder Devon said the startup does not use customer identity verification beyond logging the credit card used for a purchase. That means the service pairs browser and API access with only a payment-card record as its stated customer check.

A limited layer of moderation

The platform is not entirely unrestricted. Abliteration.ai offers the moderation layer and retains some platform-level restrictions. Devon said the company is working on additional controls intended to prevent violence, while still defining where its responsibility for misuse begins and ends.

The product’s defensive pitch

Abliteration.ai hosts modified open-weight models whose refusal safeguards have been removed, offering them through a browser and API. The company says the intended work includes offensive cyber operations, red-teaming and testing AI agents that other models decline to assist.

Security practitioners see different uses

  • Devon said customers include early-stage red-teaming startups in the UK and Europe that work with banks, airlines and critical-infrastructure enterprises.
  • Agent-red-teaming companies interviewed by TechCrunch disagreed on whether abliterated models are necessary. Some prefer fine-tuned open-weight models; others see value in using abliteration to elicit behaviors for stress tests.

Controls are the next test

The defensive case is therefore contested, but the harmful responses in the free test are already documented. CivAI research head Andrew Yoon warned that broad access to abliterated models could enable harmful cyber and biological activity. The practical next question is whether the company’s planned violence controls become enforceable limits before its hosted access reaches more users.

Sources

  1. techcrunch.comAbliteration.ai is making a business out of removing AI guardrails | TechCrunch