Abliteration Removes Refusal Mechanisms for Offensive Cyber Work
The derivative is built on Z.ai’s open-weight GLM-5.3, while Abliteration says its reasoning, coding and agent capabilities remain intact. The federal framework cited exempts open-source models, but this product is described as open-weight.
Listen to this story
The audio brief
Story brief
3 key pointsAbliteration has released abliterated-model-large-v2, an edited version of Z.ai’s open-weight GLM-5.3 aimed at offensive cybersecurity, red-teaming, and agent testing. The company used orthogonalization to remove mechanisms associated with prompt refusals rather than training a new foundation model, and claims reasoning, coding, and agentic performance remain intact. That claim is unverified in the provided account....
- 01
The model is a derivative of GLM-5.3, not a newly trained foundation model.
- 02
Abliteration targets security requests mainstream systems may decline, including offensive cyber and agent-testing tasks.
- 03
The company claims preserved capabilities, but no independent reliability or capability testing is provided.
Abliteration launched abliterated-model-large-v2 on Monday, a model built on Z.ai’s open-weight GLM-5.3. The company says it removed mechanisms tied to prompt refusals so the model can handle offensive cybersecurity, red-teaming and agent-testing work that other systems decline.
Removing the refusal layer
Rather than training a new base model, Abliteration started with GLM-5.3, which Chinese AI lab Z.ai released as open-weight software. Abliteration says it used orthogonalization, a technique for isolating parts of a model, to find and remove internal mechanisms associated with refusing user prompts.
The company says the edit leaves GLM-5.3’s reasoning, coding and agentic capabilities unchanged. That performance claim has not been independently demonstrated here, leaving open whether the modification changes reliability or capability in actual use.
The launch follows Z.ai’s release of GLM-5.3 last month. That timing makes Abliteration’s product a modification of a recently released open-weight base model, rather than a claim to have produced an entirely separate foundation model.
A security pitch with narrower guardrails
Abliteration is marketing the model for offensive cyber work, red-teaming and agent testing that other models refuse. Red-teaming is the practice of probing systems for weaknesses. The company’s stated limits show that its pitch is not that the model will answer every request, but that it will decline fewer security-related ones.
The limits described are also format-specific: the source says the model cannot generate images or video. Its spokesperson’s commitment concerns text describing child sexual abuse material or self-harm, not a general account of how the model will handle every cyber-related request.
Abliteration is targeting developers frustrated by what they see as overly sensitive safeguards at mainstream providers, according to the account of its launch. The article points to complaints after Anthropic released Fable 5 in June: some customers said the model refused cybersecurity and biology requests even when they considered those requests benign.
Voluntary review has a scope question
A recently introduced Trump administration framework calls for voluntary federal safety checks before public release, but open-source models are exempt. GLM-5.3 is described as open-weight, not open-source, and the article does not determine whether Abliteration’s derivative falls within that exemption.
The framework asks major U.S. developers to provide new models to the federal government for a safety check before public release. The terms of those checks have not been made public, and participation is voluntary rather than a federal approval requirement.
The distinction matters because the product is a modified version of an open-weight model, not a newly trained system. The framework itself is voluntary, so its applicability would not by itself require Abliteration to preserve refusal mechanisms or submit the model for review. The cited account also says federal policy does not otherwise require developers to build particular safeguards into their models.
Sources
- gizmodo.comWhile AI Industry Frets Over Safeguards, One Company Is Building a Model That 'Doesn’t Say No’