Independent/Reader-funded/Infrastructure, not tokens
DeAINEWS

AI you control — open models, private inference, and the networks that run them.

Provider Policy & Trust

Abliteration.ai Hosts Guardrail-Stripped GLM-5.3 as an API

Abliteration.ai launched abliterated-model-large-v2, a hosted GLM-5.3 with refusals edited out, at $5 per million tokens. Modified weights stay private.

DeAI is powered by Morpheus (mor.org). We cover competing providers on the same terms — see our methodology.

A single 1U inference server in a quiet rack row, one amber status LED lit — Abliteration.ai now hosts an abliterated GLM-5.3 checkpoint as an API. Illustration: DeAI
A single 1U inference server in a quiet rack row, one amber status LED lit — Abliteration.ai now hosts an abliterated GLM-5.3 checkpoint as an API. Illustration: DeAI

Abliteration.ai is selling API access to abliterated-model-large-v2, a Z.AI GLM-5.3 checkpoint with refusal directions edited out of the weights. The modified files are not public. Standard list price is $5 per million input or output tokens.

Key facts

  • Model id abliterated-model-large-v2, hosted FP8, 1M-token context, text-only, OpenAI- and Anthropic-compatible endpoints, per the company intro.
  • List price $5 / $5 per million input/output tokens; cached input billed at $0.50 per million, per docs.abliteration.ai/pricing.
  • Company-claimed evals (mixed harnesses): 84.5% CyberGym pass@1, 41.8% Terminal-Bench 4.0, 105 of 869 ExploitGym tasks in 2 hours.
  • Z.AI's GLM-5.3 License allows commercial Model-as-a-Service derivatives; operators over $10 billion trailing 12-month revenue need a Z.AI security review.
  • Abliteration.ai says prompts and completions are zero-retention by default; operational telemetry is retained. That is a policy claim.

What happened

Abliteration.ai launched abliterated-model-large-v2 as a hosted product: take Z.AI's GLM-5.3, run abliteration on the checkpoint, serve it in FP8, and do not publish the resulting weights. The company says customers keep their existing base URL and API key and change only the model id.

Abliteration is not a jailbreak. It is a weight edit that suppresses the activation direction associated with refusal, the method described in DeAI's explainer on abliterated and uncensored models. Hugging Face has hosted thousands of such checkpoints for years. The commercial move is the packaging: no download, no GPU cluster, an OpenAI-compatible /v1/chat/completions plus Anthropic-style /v1/messages and /v1/responses.

The company reports 84.5% pass@1 on CyberGym (1,507 tasks), 41.8% on Terminal-Bench 4.0, and 105 of 869 ExploitGym tasks in a two-hour window. Those figures are Abliteration.ai's own table. The same post says comparator scores come from mixed harnesses and budgets and should be treated as indicative. In that table, GPT-5.5 is listed above it on CyberGym (85.6%) and GPT-5.6 Sol / Fable 5 above it on ExploitGym. DeAI has not rerun the suites.

The Decoder reported the product on 2026-09-06; TechCrunch covered the company on 2026-09-03. TechCrunch wrote that in its tests the model produced malware-related code and pathogen-cultivation guidance more readily than a stock chat model, while still refusing some self-harm prompts. DeAI did not reproduce those tests.

Why it matters

For a builder choosing where to run models, refusal has been a two-layer problem: the checkpoint's alignment and the host's filter. Hosted abliteration collapses both into a product SKU. You no longer need to download a 700B-class MoE, find a recipe that does not wreck coding quality, and stand up vLLM. You pay $5 per million tokens and get whatever refusal profile the vendor shipped.

That is useful for the work Abliteration.ai names — offensive security, red teaming, agent testing, malware analysis, authorized exploit reproduction. It is also a lower bar for uses the same company says it does not want. The FAQ says child sexual exploitation content is blocked. Other limits sit behind an optional policy gateway that enterprise customers must turn on. Standard access, the company says, stays largely unrestricted.

The data-handling page is the other builder-relevant claim. Abliteration.ai says prompts, completions, and uploads never hit disk; only token counts, timestamps, model IDs, HTTP status codes, and billing metadata are kept. Optional web search and fetch are off by default and, when enabled, send the query or URL to a third-party search provider — so zero retention does not apply to that path. Treat the whole ZDR package the way DeAI treats every zero-data-retention claim: a policy statement until someone other than the vendor has checked it.

Price context: $5 / $5 per million is far above open-weight commodity inference (DeepSeek V4 Flash listed at $0.14 / $0.28 on the September Price Index). You are paying for the refusal edit and the hosted SKU, not for cheap tokens.

Background

Open-weight chat models can be modified by anyone who has the files. That is the point of the open-weight vs open-source distinction and of Z.AI shipping GLM-5.3 with a license that allows derivatives. The LICENSE on zai-org/GLM-5.3 grants use, modification, distribution, and commercial Model-as-a-Service. The one revenue gate: if the licensee and affiliates take in more than $10 billion over any consecutive 12 months, they must pass Z.AI's security review before commercial use of the software or derivatives. Abliteration.ai's hosted checkpoint sits inside that grant unless it crosses the threshold.

GLM-5.3 is the same family covered in DeAI's GLM-5 API run-guide. The company says it picked GLM-5.3 for coding, agent, and cyber performance plus a license that explicitly contemplates MaaS. A predecessor SKU, abliterated-model-large, was based on GLM-5.2.

This is not the only host in the uncensored-API set. DeAI's uncensored API roundup already lists providers that serve open-weight and uncensored catalogs with documented (and varying) filters. The Decoder names Audn.AI and Silk Compute as other hosts of abliterated or lightly filtered models. Abliteration.ai's pitch is a named GLM-5.3 derivative plus a policy gateway, not a unique technique.

Capability cost is still unsettled. Abliteration.ai's marketing says coding and cyber scores hold. Research is mixed: some papers report large refusal drops with limited code-generation loss; others find behavior changes on tasks the base model never refused. DeAI's Refusal Index is not scored this cycle, so there is no independent FRR/CAL row for this endpoint.

What's next

If you are evaluating the SKU: pull the pricing page and data-handling policy into the same review as any other host — list rate, cache, ZDR claim, AUP, and whether the policy gateway is on by default (it is not). Confirm the GLM-5.3 license text on Hugging Face has not changed. Do not treat company CyberGym numbers as a substitute for your own red-team harness.

Watch three things. First, whether Abliteration.ai publishes the modified weights (today: no). Second, whether Z.AI amends the MaaS clause or objects to this derivative. Third, whether other GLM/Qwen/DeepSeek hosts ship competing abliterated SKUs at commodity token prices, which would make this a $5 convenience tax rather than a category.

DeAI will not add Abliteration.ai to the Refusal Index coverage set until Cycle 1 has a protocol slot and a calibrated should-refuse control for a vendor that advertises refusal removal. A low FRR with a failed calibration check is uncalibrated, not "best."

Questions

What is Abliteration.ai?
A US startup that abliterates open-weight models and hosts the result as an API. Its current large model, abliterated-model-large-v2, is a GLM-5.3 checkpoint with refusal directions removed. Modified weights are not offered for download.
Does GLM-5.3's license allow a hosted abliterated API?
Z.AI's GLM-5.3 License permits modification, derivatives, and commercial Model-as-a-Service. Operators with more than $10 billion in trailing 12-month revenue must pass Z.AI's security review before commercial use of the model or derivatives.
Does Abliteration.ai store prompts?
The company says prompts and completions are processed in memory and discarded. It retains operational telemetry — token counts, timestamps, model IDs, status codes, and billing data. That is a policy statement, not a third-party audit.
Is abliteration the same as a jailbreak?
No. A jailbreak is a prompt trick in one conversation. Abliteration edits the weights, so reduced refusal applies to every request. Abliteration.ai says it still blocks child sexual exploitation content; other limits are optional via a policy gateway.

Sources

  1. Introducing abliterated-model-large-v2 — Abliteration.ai
  2. Abliteration.ai pricing — Abliteration.ai
  3. Data Handling & Zero Retention — Abliteration.ai
  4. Abliteration.ai FAQ — Abliteration.ai
  5. GLM-5.3 License — Z.AI / Hugging Face
  6. zai-org/GLM-5.3 model card — Z.AI / Hugging Face
  7. Stripping safety guardrails from open-weight AI models is now a turnkey commercial service — The Decoder
  8. Abliteration.ai is making a business out of removing AI guardrails — TechCrunch

About DeAI

DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.

Powered by Morpheus and StrandCMS

Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more about the Morpheus Inference API →

Sponsor disclosure — not editorial

Powered by Morpheus and StrandCMS. Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more →